Apparently there is some confusion amongst people who are new to web application scanning regarding the "time it takes for a scan to run." That metric is typically perceived as a delta between the time at which the scanner starts running and the time at which the scanner completes. However, in reality there are different methods of tracking how long a scanner takes to complete, and some are more thorough than others. Probably the two most common methods of thinking about tracking this time are as follows:
- Robert Hansen, Technical Evangelist, WhiteHat Security
- Viewpoints
- Posted On