Documentation Index

Fetch the complete documentation index at: https://docs.traceable.ai/llms.txt

Use this file to discover all available pages before exploring further.

Scan Policy Performance

Prev Next

Traceable’s API Security Testing (APIST) provides you with a set of predefined scan policies you can use without defining your own attack selections. Each predefined policy bundles a fixed set of test plugins chosen for a specific testing requirement, so you can start scanning without deciding which individual attacks to enable.

Predefined policies appear alongside your own policies under Testing → Policies. For more information on predefined policies, see Policies. Traceable measures the performance of predefined policies to help you anticipate scan behavior before running one in your own environment.

Note

The performance figures later in this topic are based on Replay scans.

What you will learn from this topic

By the end of this topic, you will be able to understand:

  • What you need in place before running a scan with a predefined policy.

  • How predefined policies perform as API counts increase.


Performance testing

The performance results provide a reference as API counts increase. They are based on controlled testing under realistic performance conditions. The results highlight how scan duration and test-case count scale across policies, helping you select the right policy for your use case.

Scope

The following table defines the scope of the testing:

Parameter

Value

Environment

Production-like benchmark environment

Traffic type

Replay

API counts

10, 20, 40, 80

Policies

Eight predefined policies

Auth hook

Enabled on echo app

Runners

1 (to isolate variables)

Fixed test configuration

The following parameters were held constant across all runs, ensuring comparable results:

Parameter

Replay

App

echo (perf-echo)

Pipelinetest_type

perf_replay

policy_type

Built-in name

API latency

200 ms

Authentication

Enabled

Request headers

5

Request body

20

Request query

5

Scenarios per API

40

API buffer %

25%

Scan execution threads

40

CLI version

2.7.0 or later

Runners

1

Runner configuration

2 CPU, 4Gi Memory

Environment

Production


Results

The test results show the execution times and the number of test cases generated as the API count increases. The following tables show the performance results of 8 predefined policies for scans:

PipelineScanPolicy

API count

Execution time

Tests generated

10

31s

130

20

32s

260

40

41s

520

80

1 min

1.04k

DailyScanPolicy

API count

Execution time

Tests generated

10

5 min

12.45k

20

8 min

24.90k

40

14 min

49.80k

80

26 min

99.60k

SafeScanPolicy

API count

Execution time

Tests generated

10

1 min

300

20

1.2 min

600

40

2 min

1.2k

80

2 min

2.4k

QuickScanPolicy

API count

Execution time

Tests generated

10

6 min

16.94k

20

11 min

33.88k

40

20 min

67.74k

80

38 min

135.52k

PciDssScanPolicy

API count

Execution time

Tests generated

10

8 min

25.92k

20

13 min

49.13k

40

23 min

96.11k

80

40 min

176.04k

OwaspTopTenScanPolicy

API count

Execution time

Tests generated

10

7 min

27.32k

20

13 min

50.87k

40

23 min

100.59k

80

41 min

191.96k

WeeklyScanPolicy

API count

Execution time

Tests generated

10

7 min

29.28k

20

13 min

58.55k

40

24 min

117.10k

75

45 min

219.57k

ExtensiveScanPolicy

API count

Execution time

Tests generated

10

16 min

100.61k

20

35 min

208.30k

40

1 hr 12 min

424.29k

80

2 hr 16 min

850.01k