Software

Web Application Security: The Truth About White Box Testing Vs. Black Box Testing

Download Now Free registration required

Executive Summary

This paper explores the role of white box vs. black box testing. White box testing technologies have a definite but limited use and value. From a Web application security perspective it must be understood that significant blind spots come with white box testing. Ultimately white box testing is not sufficient to secure applications: simply put organizations that rely solely on white box technologies will be exposed to vulnerabilities in their applications, thus making it an ineffectual method of testing real-world risks. This paper will demonstrate black box or dynamic testing is ultimately the appropriate solution for "Truly" securing Web applications.

  • Format: PDF
  • Size: 188.17 KB