Automated Security Testing Framework for Web Services: A DevSecOps-Integrated Approach

Mohnish Neelapu · International Journal For Multidisciplinary Research · 2025

The advanced nature of web services creates security weaknesses such as SQL Injection (SQLi), Cross-Site Scripting (XSS) and API exploitation which threaten both data reliability and system stability. This research introduces the Automated Security Testing Framework (ASTF) to bring together different security testing methods within the DevSecOps development pipeline for web application security enhancement. Vulnerabilities get discovered in real time by Dynamic Application Security Testing (DAST), static Application Security Testing (SAST) which works alongside penetration testing and fuzz testing through their integration of OWASP ZAP, Burp Suite, Acunetix, SonarQube and Snyk tools. Application of AI security monitoring with continuous threat analysis optimizes security risk mitigation through reduced false positive incidents to 6% and it enhances security response efficiency. An evaluation of an e-commerce platform proves that its 90% decreased high-risk vulnerability exposure sustains development agility alongside ISO 27001 and GDPR compliance. The research showcases ASTF because it detects threats efficiently and handles automated patching as well as its easy CI/CD integration which protects modern web services actively.

Read the paper · More papers on PaperTik