Selenium is often used by software development and quality assurance (QA) teams to automate the security testing of web applications, enabling users to record a series of events and to analyze the results. With this integration, security teams can automatically detect security defects earlier in the software development lifecycle, such as during the nightly build process, improving enterprise web security with minimal additional costs and without supplementary assistance from developers and/or QA teams.
In regard to web applications and security testing, one of the main challenges is to bridge the security divide between the software development/QA teams and security teams. While most individuals agree that security defects should be detected early, most security professionals are experts in security and are generally less familiar with the applications; additionally, the inverse is also true, as QA teams are application experts, and are usually not familiar with web application security.
"Security, software development and QA teams have been trying to find an effective way to integrate security testing earlier in the development lifecycle, when security defects are less costly to fix," said Dan Kuykendall, co-CEO and CTO of NT OBJECTives, Inc. "By implementing the execution of Selenium scripts to our comprehensive web application security scanning solution, we can supply our clients with maximum coverage on all applications, with a minimal increase in cost and without additional work from developers or QA. It's a win all around."
In addition to improving web application security testing for software development/QA and security teams, NTOSpider's integration with Selenium can also be used to automate complex authentication solutions, as well as specific application workflows, such as shopping cart sequences. It supports the following two methods of Selenium integration: