Static Application Security Testing (SAST)
A white-box testing method that analyses source code, bytecode or binaries without running the application, to find security flaws such as injection, unsafe functions and hard-coded secrets early in development.
SAST tools parse code into models such as abstract syntax trees and control-flow and data-flow graphs, then apply rules to detect insecure patterns. Taint analysis traces untrusted input from sources, such as request parameters, to sensitive sinks, such as database queries or HTML output, and flags paths that lack validation or encoding. Because the code is visible, findings point to the exact file and line.
SAST runs early in the software development life cycle, in developer IDEs, on pull requests and in CI/CD pipelines, when fixes are cheaper than after release. It supports secure coding programmes and code review, and code analysis is a recommended practice in secure development frameworks such as the NIST Secure Software Development Framework (SSDF). Many tools also detect hard-coded credentials and insecure configuration files.
SAST can produce false positives and cannot see runtime configuration, deployed infrastructure or issues introduced by the environment, so it is combined with DAST, IAST and software composition analysis. Language and framework support varies between tools, and tuning rules, triaging results and setting sensible thresholds for failing a build are essential to keep developers engaged.
Key points
- Analyses code without executing it, so it can run from the first commit.
- Pinpoints the file and line of each finding.
- Prone to false positives; tuning and triage are essential.
- Complements DAST, IAST and SCA rather than replacing them.
Where AiVibe comes in
AiVibe's code security analysis services cover SAST, DAST, IAST and SCA.
Related terms
- Dynamic Application Security Testing (DAST)Cybersecurity & Compliance
- Interactive Application Security Testing (IAST)Cybersecurity & Compliance
- Software Composition Analysis (SCA)Cybersecurity & Compliance
- Secrets ManagementCybersecurity & Compliance
- SQL Injection (SQLi)Cybersecurity & Compliance
- OWASP Top 10Cybersecurity & Compliance