Applications Five Years or Older Likely to have Security Flaws

Jan. 11, 2023
Applications Five Years or Older Likely to have Security Flaws

Nearly 32% of newly introduced enterprise applications contain security flaws from the first vulnerability scan, software security firm Veracode found in its latest annual State of Software Security Report, published on January 11, 2022.

While the report also shows what the Veracode researchers call a ‘honeymoon period’ that runs until a year and a half after introducing the applications, where fewer flaws are found to be introduced in the applications’ code; this number picks up again after a longer period.

By the time they have been in production for five years, nearly 70% of applications contain at least one security flaw.

“What it shows is that, as they get further along in the applications lifecycle, there’s something that allows the applications to get worse, whether it’s the composition of the teams or developers moving on and off or the codebase just getting more complex,” Chris Eng, chief research officer at Veracode, told Infosecurity.

No Correlation Between Flaw Introduction and the Code Length

Veracode’s researchers, however, found no direct correlation between the growth of an application – when its code gets longer – and the rate of flaw introduction.

Based on these findings, Veracode concluded that “developer training, use of multiple scan types, including scanning via API, and scan frequency are influential factors in reducing the probability of flaw introduction, suggesting teams should make them key components of their software security programs”.  

“For example, skipping months between scans correlates with an increased chance that flaws will be found when a scan is eventually run,” a spokesperson said in a statement.

Furthermore, top flaws in apps vary by testing type: for instance, server configuration flaws accounted for 96.5% of vulnerabilities identified by Veracode’s dynamic analysis but for only 11.1% of their static analysis.

Tags:

No tags.

JikGuard.com, a high-tech security service provider focusing on game protection and anti-cheat, is committed to helping game companies solve the problem of cheats and hacks, and providing deeply integrated encryption protection solutions for games.

Explore Features>>