WeAreDevelopers LIVE • Dec 16, 2024

Plants vs. Thieves: Automated Tests in the World of Web Security

Ramona Schwering

What if your standard automated tests could block active web attackers? Learn how to weaponize frameworks like Cypress to catch critical OWASP vulnerabilities before production.

Pause
Mute Enter Fullscreen
#1 about 5 min

Plants vs zombies as an analogy for web security

Treating web security threats as zombies highlights how application defense mechanisms like testing act as protective plants.

#2 about 2 min

Why write security tests instead of relying on tools

Using normal testing frameworks for security checks offers cost benefits and deepens knowledge of application vulnerabilities.

#3 about 3 min

Identifying core risks with the OWASP top ten

Understanding broken access control, cryptographic failures, and injection provides primary targets for security automation.

#4 about 5 min

Writing end-to-end tests to catch SQL injection vulnerabilities

Mimicking an attacker with Cypress verifies that malicious input generates the expected error messages.

#5 about 2 min

Validating content security policy headers in automated tests

Configuring test requests to intercept and assert the presence of proper CSP headers protects against cross-site scripting.

#6 about 3 min

Testing for broken access control and unpermitted routes

Creating negative test cases ensures users without proper permissions are blocked from administrative pages.

#7 about 1 min

Detecting cryptographic failures with test runner behavior

Leveraging the strict same-origin policies of test runners like Cypress catches unencrypted HTTP navigation attempts.

#8 about 3 min

Supplementing custom tests with security tools and plugins

Incorporating community-driven tools and vulnerability databases uncovers risks that custom test scripts miss.

#9 about 3 min

Incorporating security into standard test plans and pipelines

Executing a mix of unit, integration, and end-to-end security tests during nightly builds provides continuous validation.

#10 about 3 min

Summary of security testing strategies and best practices

Reviewing the use of automation and negative testing reveals a complementary layer in overall application security.

Matching moments

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

3:47 min

Deploying structural security analysis within general testing workflows

Ramona Schwering Ramona Schwering · World Congress 2024

4:00 min

Evolution from manual hacking to automated security testing

Chris Wysopal Chris Wysopal · World Congress 2024

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

1:08 min

Automating security and performance evaluations during the testing phase

Jemiah Sius Jemiah Sius · World Congress 2023

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers