91% noise: A look at what’s wrong with traditional SAST tools

Wait 5 sec.

Traditional static application security testing (SAST) tools are falling short. That’s the key takeaway from a recent report that tested these tools against nearly 3,000 open-source code repositories. The results: more than 91% of flagged vulnerabilities were false positives. The Exorcising the SAST Demons report comes from Ghost Security, which scanned public GitHub projects in Go, Python, and PHP. The study focused on three vulnerability types commonly found in real-world apps: SQL injection, command injection, … More →The post 91% noise: A look at what’s wrong with traditional SAST tools appeared first on Help Net Security.