Publication / 2026

DASTestBed: An Automated Benchmarking Framework for DAST Scanners with Extensible Ground Truth Modeling

A repeatable DAST benchmarking framework that compares detection outcomes with request volume and resource use.

Overview

Published at IEEE ISDFS 2026, DASTestBed addresses a practical problem in scanner evaluation: results are hard to compare when environments differ and the expected vulnerabilities are not recorded in a machine-readable form.

The framework runs scanners and targets in isolated containers. Structured vulnerability records define the benchmark scope and the concrete request instances used for scoring. Scanner outputs are parsed into a common representation, matched against that scope and deduplicated before evaluation.

Detection metrics are considered alongside CPU usage, memory usage and HTTP request volume. The paper demonstrates the pipeline with Nuclei and OWASP ZAP on DVWA. The purpose is to make the conditions and costs of a comparison inspectable; results remain tied to the chosen target, scope and tool profiles.

Key facts

Publication
2026
Published in
IEEE International Symposium on Digital Forensics and Security (ISDFS 2026)
Topics
DASTestBed · DAST evaluation · Ground truth · Repeatable measurements
Primary source

Related work

08Contact

Let’s solve the next hard problem.

Tell me what you’re building, what is at stake and when you need a result. I’ll discuss the fit and propose a defined scope, deliverables and price.