Revista Científica y Tecnológica UPSE (RCTU)
versión On-line ISSN 1390-7697versión impresa ISSN 1390-7638
Resumen
Static Security Testing Models in Inefficiency Reduction Identification of SQL Injection in Web Applications. RCTU [online]. 2024, vol.11, n.2, pp.130-144. ISSN 1390-7697. https://doi.org/10.26423/rctu.v11i2.800.
Early detection of vulnerabilities is crucial in software development to ensure the security of web applications, especially against SQL injection attacks. Static Application Security Testing (SAST) allows for the identification of vulnerabilities from the early stages of the development lifecycle. This article systematically reviews the literature to identify and analyze the most effective SAST models in reducing inefficiencies in detecting SQL injections. Following PRISMA 2020 guidelines and Kitchenham’s approach, exhaustive searches were conducted in databases like EBSCO and Scopus. The results show that early integration of SAST and the use of artificial intelligence significantly improve vulnerability detection, reducing false positives and negatives. The implementation of advanced SAST models is essential for enhancing the security of web applications, with future research suggested to explore more integrated methodologies and new tools.
Palabras clave : Static application security testing; Secure software development; DevSecOps; SQL Inyection..











uBio 
