Traceable’s API Security Testing (APIST) provides you with a set of predefined scan policies you can use without defining your own attack selections. Each predefined policy bundles a fixed set of test plugins chosen for a specific testing requirement, so you can start scanning without deciding which individual attacks to enable.
Predefined policies appear alongside your own policies under Testing → Policies. For more information on predefined policies, see Policies. Traceable measures the performance of predefined policies to help you anticipate scan behavior before running one in your own environment.
Note
The performance figures later in this topic are based on Replay scans.
What you will learn from this topic
By the end of this topic, you will be able to understand:
What you need in place before running a scan with a predefined policy.
How predefined policies perform as API counts increase.
Performance testing
The performance results provide a reference as API counts increase. They are based on controlled testing under realistic performance conditions. The results highlight how scan duration and test-case count scale across policies, helping you select the right policy for your use case.
Scope
The following table defines the scope of the testing:
Parameter | Value |
|---|---|
Environment | Production-like benchmark environment |
Traffic type | Replay |
API counts | 10, 20, 40, 80 |
Policies | Eight predefined policies |
Auth hook | Enabled on echo app |
Runners | 1 (to isolate variables) |
Fixed test configuration
The following parameters were held constant across all runs, ensuring comparable results:
Parameter | Replay |
|---|---|
App |
|
Pipeline |
|
| Built-in name |
API latency | 200 ms |
Authentication | Enabled |
Request headers | 5 |
Request body | 20 |
Request query | 5 |
Scenarios per API | 40 |
API buffer % | 25% |
Scan execution threads | 40 |
CLI version | 2.7.0 or later |
Runners | 1 |
Runner configuration | 2 CPU, 4Gi Memory |
Environment | Production |
Results
The test results show the execution times and the number of test cases generated as the API count increases. The following tables show the performance results of 8 predefined policies for scans:
PipelineScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 31s | 130 |
20 | 32s | 260 |
40 | 41s | 520 |
80 | 1 min | 1.04k |
DailyScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 5 min | 12.45k |
20 | 8 min | 24.90k |
40 | 14 min | 49.80k |
80 | 26 min | 99.60k |
SafeScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 1 min | 300 |
20 | 1.2 min | 600 |
40 | 2 min | 1.2k |
80 | 2 min | 2.4k |
QuickScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 6 min | 16.94k |
20 | 11 min | 33.88k |
40 | 20 min | 67.74k |
80 | 38 min | 135.52k |
PciDssScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 8 min | 25.92k |
20 | 13 min | 49.13k |
40 | 23 min | 96.11k |
80 | 40 min | 176.04k |
OwaspTopTenScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 7 min | 27.32k |
20 | 13 min | 50.87k |
40 | 23 min | 100.59k |
80 | 41 min | 191.96k |
WeeklyScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 7 min | 29.28k |
20 | 13 min | 58.55k |
40 | 24 min | 117.10k |
75 | 45 min | 219.57k |
ExtensiveScanPolicy
API count | Execution time | Tests generated |
|---|---|---|
10 | 16 min | 100.61k |
20 | 35 min | 208.30k |
40 | 1 hr 12 min | 424.29k |
80 | 2 hr 16 min | 850.01k |