<?xml version='1.0' encoding='UTF-8'?>
<ArticleSet>
  <Article>
    <Journal>
      <PublisherName>Apadana</PublisherName>
      <PublisherNameVernacular>موسسه آموزش عالی آپادانا</PublisherNameVernacular>
      <JournalTitle>Journal of Apadana ...........</JournalTitle>
      <JournalTitleVernacular>نشریه مطالعات مهندسی کامپیوتر آپادانا</JournalTitleVernacular>
      <Issn>-</Issn>
      <Volume></Volume>
      <Issue></Issue>
      <PubDate PubStatus="epublish">
        <Year></Year>
        <Month></Month>
        <Day></Day>
      </PubDate>
    </Journal>

    <ArticleTitle>Integrating Penetration Testing, Static Analysis, and Dynamic Analysis in the Software Development Cycle: Structure, Analysis, and Applications</ArticleTitle>
    <VernacularTitle>یکپارچه سازی آزمون نفوذ، تحلیل ایستا و تحلیل پویا در چرخه توسعه نرم افزار: ساختار، تحلیل و کاربردها</VernacularTitle>

    <FirstPage></FirstPage>
    <LastPage></LastPage>
    <ELocationID EIdType="doi"></ELocationID>
    <Language>FA</Language>

    <AuthorList>
      <Author>
        <FirstName>Ali</FirstName>
        <LastName>Owjifard</LastName>
        <Affiliation>Ali Owjifard | Department of Computer Engineering | University of Apadana</Affiliation>
        <VernacularFirstName>علی</VernacularFirstName>
        <VernacularLastName>اوجی فرد</VernacularLastName>
        <VernacularAffiliation>موسسه آموزش عالی آپادانا</VernacularAffiliation>
      </Author>
    </AuthorList>

    <PublicationType></PublicationType>

    <History>
      <PubDate PubStatus="received">
        <Year></Year>
        <Month></Month>
        <Day></Day>
      </PubDate>
    </History>

    <Abstract>In today&#039;s world, where software plays a key role in all areas of business and critical infrastructure, &quot;assurance of software security&quot; is an inevitable necessity. Identifying and preventing security vulnerabilities, especially in the software development cycle, is considered the main tool for dealing with cyber threats. The present study, with a structured and comparative analytical review, examines the integration of three prominent security approaches - penetration testing, static analysis, and dynamic analysis - in the software development process. The article emphasizes analyzing trends, comparing the effectiveness, indicators, and tools presented, and studying a real case of implementing these methods. Finally, after a comprehensive review of standards, tools, and evaluation indicators, practical strategies are proposed to improve the security resilience of organizational software by presenting a cost-benefit discussion and business implications.</Abstract>
    <OtherAbstract Language="FA">در دنیای امروز که نرم افزارها نقشی کلیدی در تمامی عرصه های کسبوکار و زیرساختهای حیاتی دارند، »اطمینان از
امنیت نرمافزار« ضرورتی اجتنابناپذیر است. شناسایی و پیشگیری از آسیبپذیریهای امنیتی، به ویژه در چرخه توسعه
،نرمافزار، به عنوان اصلی ترین ابزار مقابله با تهدیدات سایبری مطرح میشود. پژوهش حاضر با مروری تحلیلی
ساختارمند و تطبیقی به بررسی یکپارچهسازی سه رویکرد برجسته امنیتی-آزمون نفوذ، تحلیل ایستا، و تحلیل پویا-در
فرآیند توسعه نرمافزار می پردازد. تأکید مقاله بر تحلیل روندها، مقایسه کارآمدی، شاخصها، ابزارهای مطرح و مطالعه
،موردی واقعی پیادهسازی این روشها است. در نهایت، پس از بررسی جامع استانداردها، ابزارها و شاخص های ارزیابی
با ارائه بحث هزینه-فایده و پیامدهای کسبوکاری، راهبردهای عملی برای ارتقای تاب آوری امنیتی نرمافزارهای
.سازمانی پیشنهاد میگردد.</OtherAbstract>

    <ObjectList>
      <Object Type="keyword"><Param Name="value">Penetration testing</Param></Object>
      <Object Type="keyword"><Param Name="value">SAST</Param></Object>
      <Object Type="keyword"><Param Name="value">DAST</Param></Object>
      <Object Type="keyword"><Param Name="value">threat modeling</Param></Object>
      <Object Type="keyword"><Param Name="value">SBOM</Param></Object>
      <Object Type="keyword"><Param Name="value">API security</Param></Object>
      <Object Type="keyword"><Param Name="value">business logic testing</Param></Object>
      <Object Type="keyword"><Param Name="value">CI</Param></Object>
      <Object Type="keyword"><Param Name="value">CD</Param></Object>
      <Object Type="keyword"><Param Name="value">supply chain security</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">تست نفوذ</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">تحلیل ایستای امنیت برنامه</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">تحلیل پویای امنیت برنامه</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">مدل‌سازی تهدید</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">صورت‌فهرست اجزای نرم‌افزار</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">امنیت واسط‌های برنامه‌نویسی کاربردی</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">آزمون منطق کسب‌وکار</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">یکپارچه‌سازی و تحویل پیوسته</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">امنیت زنجیره تأمین</Param></Object>
    </ObjectList>

    <ArchiveCopySource DocType="pdf">https://ajce.apadana.ac.ir/downloadfilepdf/684760</ArchiveCopySource>
  </Article>
</ArticleSet>