Security Testing - Emerging Trends

 Cloud, Mobile and Rich Internet Application (RIA) platforms, tower  

Today the application security testing space is not what it used to be. There are several trends that are affecting the development and testing of next generation applications from a security perspective. The three towering facets that are rewriting the conventional path taken for security testing are – Cloud, Mobile and Rich Internet Application (RIA) platforms. 

RIAs challenge traditional application security testing tools, which tend to focus on testing the web server side of the application. With RIA, the client side of the application logic has become equally important, if not more and has to be tested as well. This is bringing in new tides of challenges. 

Cloud platforms will require application security testing tools to evolve to support the testing of applications built for specific cloud platforms, and built using cloud-specific languages and frameworks. The other disruption cloud platforms are driving demand testing to support XML-based APIs used to reach out and consume cloud-based services. 

Mobile platforms like iPhone, iPad, Android, Windows Phone 7 (WP7) are also driving the disruption in security testing by no small measure. Proper testing of these applications will require static application security testing (SAST) tools that are explicitly designed to test the languages' and frameworks' used for these platforms.

In the world we live in it is not just enough to produce applications. It is necessary to produce secure applications.