Website Security Testing Embedded in Automated UI Journeys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional application security testing requires significant manual effort and time to onboard endpoints for scanning, as user journeys need to be manually created and maintained, making it difficult to scale and maintain, especially when UI changes occur.
Innovation Solution
Integrate application security testing into user interface (UI) tests by embedding API calls at specific points during the UI test progression, allowing automated execution without manual user input, leveraging machine learning to determine vulnerable pages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual user journey creation and maintenance is used for DAST scanning, then security testing can be performed, but significant manual effort and time are required (over four hours per test case)
Solution Approach 1:
The patent combines UI testing automation frameworks with DAST scanning by integrating security testing API calls directly into the UI test execution flow. This merging allows the same automated user journey that validates UI functionality to also perform security vulnerability scanning, eliminating the need for separate manual user journey creation and maintenance while achieving both UI validation and security testing goals simultaneously.
Solution Approach 2:
The patent creates a multi-functional testing system where a single automated user journey script serves dual purposes: validating UI functionality and performing security vulnerability assessment. By making the testing framework universal, it can handle both standard UI testing tasks and security scanning requirements without requiring separate manual interventions for each type of testing.
2Reliability
If manual user journey scripts are created and maintained, then DAST scanning can be performed, but the process is difficult to maintain and does not effectively scale
Solution Approach 1:
The patent merges DAST scanning functionality with existing UI testing automation frameworks, allowing security testing to be performed through the same automated user journey scripts used for UI validation. This integration eliminates the need for separate manual script creation and maintenance processes, reducing complexity while maintaining reliable DAST scanning capability through the unified automation framework.
3Productivity
If automated UI tests are used, then testing efficiency improves, but integration with security testing requires additional API calls and coordination
Solution Approach 1:
The patent combines UI testing and security testing into a single integrated execution flow by embedding DAST scanning API calls within the UI test automation framework. This merging allows both testing types to share the same user journey automation logic, reducing the need for separate coordination while maintaining high testing efficiency through unified automated execution.
Data Source
AI summary
Systems and methods are provided for automated website security testing. The systems and methods reduce or eliminate the need for a user to manually click through a web application to perform application security testing by embedding one or more API calls to the application security testing service within an already-existing automated user interface test. When a web page is reached during the user interface that that is desired to be tested using the application security test, a cookie associated with the web page is obtained and provided to the API associated with the application security test. The application security test then returns a result and the user interface test continues. Any number of additional API calls for to the application security test service may be performed for any other number of web pages as the user interface test progresses through the web pages as well.


