start portlet menu bar

HCLSoftware: Fueling the Digital+ Economy

Display portlet menu
end portlet menu bar
Close
Select Page

There is no silver bullet that can solve the application security challenge. Each of the core technologies (IAST, DAST, and SAST) has strengths and weaknesses.

Auto Issue Correlation allows us to leverage the strengths of each technology, while overcoming weaknesses with the advantages of the others. Furthermore, Auto Issue Correlation enhances your AST capabilities, improves your prioritization process and reduces remediation time and effort.

For example:

  • enriches DAST issues with IAST/SAST details.
  • prioritizes SAST findings using the accuracy of your IAST/DAST results.
  • validates SAST fixes from the status updates of your IAST/DAST issues.
  • reduces the number of vulnerabilities and remediation tasks by grouping issues together.

Once Auto Issue Correlation is activated, correlation is updated automatically whenever any relevant IAST, DAST or SAST issues are found. Existing groups are automatically updated with the new issues, and new groups are created as necessary. No user action is needed.

How it Works

HCL AppScan’s Auto Issue Correlation is based on our IAST solution.

IAST has access to the application at runtime (like DAST) and is able to see the source code (like SAST). By combining these technologies into a suite of application security testing tools, our automatic correlation algorithm matches IAST issues with DAST and SAST issues. It extracts data from each issue and then uses a variety of heuristics to identify correlations. This brings optimization of the remediation process to a new level. So, adding IAST and Auto Issue Correlation to your arsenal can reduce the overall number of issues/vulnerabilities to be addressed.

How to Use It

All you need is to have an active IAST session, and to activate Auto Issue Correlation. AppScan on Cloud (ASoC) will then automatically create correlation groups and show them in the “Correlation group” tab under “All Issues”. ASoC will keep updating and creating new groups as new issues are added to the application.

Here are some examples:

Dashboard

When correlation is identified, it’s indicated on the Issues chart in the dashboard of an application.

Dashboard

Correlation groups page

Click on the Correlation link to open the Correlation page for the application, listing the correlation groups it contains.

 
Correlation groups page

Issues in a group

Click on a group to see its issues.

Issues in a group

Issue details

The issue pane for a specific issue indicates when it belongs to a correlation and/or fix group in the “Related” section:

 
Issue details

Once Auto Issue Correlation is activated, correlation is updated automatically whenever any relevant IAST, DAST or SAST issues are found. Existing groups are automatically updated with the new issues, and new groups are created as necessary. No user action is needed.

We all know that code reuse is a best practice in software development. However, this also means that a single weak link can create multiple security vulnerabilities in an app. The diagram below illustrates how a weak sanitizer could cause multiple SQL Injection vulnerabilities. Since REST API 1 has a different route/source to RESP API 2, their vulnerabilities would appear unrelated in scan results.

Rest API

Correlation aggregates together vulnerabilities that should be remediated as a single task.

Note in the example below, that the correlation group includes issues found by different technologies (IAST and DAST), of different issue types, and with different severities.

Thanks to Auto Issue Correlation, diverse issues, which would not have otherwise been seen as connected, can now be resolved with a single remediation effort.

Reflected Cross Site Scripting

Visit hcltechsw.com/AppScan to learn more or schedule a demo.

Start a Conversation with Us

We’re here to help you find the right solutions and support you in achieving your business goals.

HCL AppScan Wins 2025 Fortress Cybersecurity Award for Leadership in Application Security
  |  September 23, 2025
HCL AppScan Wins 2025 Fortress Cybersecurity Award for Leadership in Application Security
HCL AppScan wins the 2025 Fortress Cybersecurity Award for leadership in application security, reinforcing its innovation, trust, and impact in enterprise AppSec.
HCL AppScan Wins Gold at the 2025 Globee® Awards for Technology!
  |  July 9, 2025
HCL AppScan Wins Gold at the 2025 Globee® Awards for Technology!
HCL AppScan wins Gold at the 20th Annual Globee® Awards for Technology in the Application Security Testing category, highlighting its innovation, technical excellence, and growing industry leadership.
Developers – Say Hello to AUDIT!
  |  June 20, 2025
Developers – Say Hello to AUDIT!
Introducing AUDIT by HCL AppScan—a developer-first DAST solution for fast, targeted security scans within the IDE. Shift left and secure code early.