3 Tips for Finding the Best Website Security Scanner

3 Tips for Finding the Best Website Security Scanner

3 Tips for Finding the Best Website Security ScannerWhile it takes some work to find the best website security scanner for your organization, if you follow these three simple guidelines, you’ll be off to a good start.

Although accurate automated application security testing has been common practice for many organizations for over 10 years, it remains a very difficult and complex process. There are automation techniques that ensure a scan is as automated as possible, reduces scan times, increases results accuracy and saves you time and money on manual testing.

If you are involved in website security scanning in any way, you know all too well, that it’s difficult to create an effective test environment. When you are evaluating alternative solutions, we always recommend the following:

  • Allow enough time. It is difficult to test for accuracy under a compressed timeframe. It takes time to get comfortable with different configuration techniques and compare results. It takes a lot of time to check and re-check reports for accuracy. To read more about how to ensure the most accurate results, check out our blog, “7 Features of Accurate Application Security Software, SaaS and Services.
  • Use a real application, not a public test app. Use one of your real applications that you know has vulnerabilities. Scanning vendors are very familiar with the few test applications that exist and most make sure their scanners find the vulnerabilities in those test applications.
  • Find a vendor you trust. Unfortunately, you will be, in certain instances, forced to rely on the word of the scanning vendor because the way a scanner crawls an application and executes attacks can be a black box. For this reason, you’ll find the best website security scanner for your needs if you spend some time on the phone or in person with vendors to learn about what works and what doesn’t. Usually, this just means find a technical enough person to spend some time with you to explain how it actually works, where it performs well and which type of applications might give it trouble.

When you follow these three simple guidelines, you improve your chances of getting the most automated, accurate and easy to manage application security testing solution for any deployment model combination of software, SaaS and services. To read our top 15 tips for evaluating application security scanners, download this white paper, “Web Application Security Solutions Buyers Guide.

About Dan Kuykendall
Dan Kuykendall is the founder and co-CEO at the premier application security solutions provider NT OBJECTives, Inc. Throughout his career, Dan has helped develop advanced dynamic application security testing software, a fundamental aspect to NT OBJECTives’ reputation as a leader in comprehensive web application scanning. Dan has also worked for McAfee’s Foundstone and Fortis, where he founded the U.S. Information Security team. Connect with Dan on Google+

1 Comment on 3 Tips for Finding the Best Website Security Scanner

  1. I would also like to add that talking with other businesses that have a scanning solution in place can also be very helpful. These people will give honest insight into what works, and what doesn’t.


Leave a comment

Your email address will not be published.