Squaring the software security circle

Squaring the software security circle

Veracode is using artificial intelligence to make applications more secure – at the speed of business.

Issued by ITWeb Security Summit

Johannesburg, 03 May 2024

Visit our press office

Sagaran Naidoo, Sales Director, CASA.

Two hacks over the last 12 months in South Africa – at the Companies and Intellectual Property Commission of South Africa (CIPC) and a famous retailer – illustrate yet again how urgent is the need for a multi-layered approach to security, including robust application security, says Sagaran Naidoo, Sales Director at CASA.

“Given the proliferation of apps in today’s business world – it’s no mistake we now talk about the application economy – it’s become imperative that software is designed from the ground up with security in mind,” says Naidoo. “This requires a massive mindset change for developers because they are typically focused on speed. They live under constant pressure from the business to get new applications ready for use. This in turn means that issues with the software are often undetected early on and require manual fixes late in the development life cycle – a very time-consuming and expensive process that can introduce new issues.

“Many of the issues simply don’t get fixed, creating a ‘security debt’ that makes the application more vulnerable to hackers.”

Globally, Statista figures indicate the app economy grew by a compound annual rate of 37%, from US$1.3 trillion in 2016 to US$6.3 trillion in 2021, while South Africa’s app economy grew by 10% in the 2020-22 period, with more growth to come.

The conclusion is clear, Naidoo argues: software must be created with security in mind from the get-go given this inevitable growth and the proliferation of cyber attacks.

“The big change is that we have to move from finding the issues to fixing them rapidly – developers simply don’t have the time to fix bugs manually given their tight deadlines,” Naidoo says. “Another big factor is that advances in software development, including DevOps, automation and the use of AI itself in coding are making the process faster, but often more insecure.”

The security debt trap

Veracode’s State of Software Report 2023 shows 56% of Java applications have flat or rising security debt, underlining the need to identify and fix flaws at scale.

As this security debt accumulates, the risks that come with using vulnerable applications increases. It is worth repeating that the later in the development cycle a bug is identified, the more expensive it is to fix. Fixing is seen as a distraction by developers, who are more focused on creating software that delivers great user experiences and thus drives the bottom line.

In short, says Naidoo, finding bugs rapidly has to become paired with the ability to fix them as quickly. Veracode has seen this need and has augmented its leadership in finding coding flaws with the ability to fix them rapidly.

“Veracode Fix uses AI to generate a list of suggested fixes, which a developer can review and then choose the best one – the chosen fix is then implemented automatically without the need to write code manually,” he says. “This is a great example of how AI can be used to complement the abilities of humans, to make them more effective, not to replace them.”

Responsible AI

An important differentiator for Veracode Fix is that it uses responsible AI to deliver its benefits, again showing a unique understanding of how humans and algorithms can work effectively together.

One important element is that Veracode Fix is trained on a proprietary and highly curated dataset of reference patches. As numerous examples have shown, using open datasets leads to inaccurate or even ridiculous results. For example, made-up facts generated by ChatGPT and preposterous images created by Google Gemini have received saturation media coverage over past months.

In addition to using a curated, reliable dataset, Veracode Fix’s training is supervised by human security experts, ensuring optimal results.

“There’s no AI black box here,” comments Naidoo.

Veracode Fix’s adherence to responsible AI best practice means that customer data is encrypted in transit and at rest and is not used or retained for training purposes.

“Veracode Fix represents a paradigm shift that integrates find and fix into a single process that optimises the use of overstretched developers and bakes security into the application, without sacrificing the speed today’s business environment demands. It works with both custom and third-party code, so the organisation’s security debt is constantly being reduced. This is the future of application security,” concludes Naidoo.

For more information, read Veracode Fix and the future of intelligent software security.

Veracode is a sponsor of the annual ITWeb Security Summit 2024 to be held at Sandton Convention Centre in Sandton, Johannesburg from 4 to 5 June 2024. Visit and register.

Share

Provided by SyndiGate Media Inc. (Syndigate.info).

OTHER NEWS

23 minutes ago

Esperance v Al Ahly: A tale of two keepers in African Champions League final

23 minutes ago

'Couldn't agree terms': Tuchel confirms exit despite Bayern U-turn

24 minutes ago

2024 Isle of Man TT: Full live broadcast details

24 minutes ago

3 Orlando Pirates players Kaizer Chiefs can sign

24 minutes ago

Vatican tightens rules on apparitions to put an end to hoaxers fleecing the faithful

24 minutes ago

Second surgery raises hopes of recovery for Slovakian prime minister Robert Fico after shooting

24 minutes ago

Temperatures could soar to more than 30°C on bank holiday, Met Office predicts

24 minutes ago

Amid ‘Ram’ and ‘Samvidhan’ debate, more lowly concerns in Ayodhya

24 minutes ago

Obituary: Late Comrades legend Dave Lowe, 78, ‘the epitome of a gentleman’

24 minutes ago

Born in the bush, 95-year-old Kevin Waters takes one last trip back to Old Toomelah

24 minutes ago

Synagogue Arson Attempt Fuels Antisemitism Fears in France

24 minutes ago

‘We will fight until Kanaky is free’: how New Caledonia caught fire

24 minutes ago

NCC DG calls on L-G Sinha, discusses expansion of NCC

29 minutes ago

Pascal Siakam helps Indiana Pacers beat New York Knicks to send Eastern Conference semifinals to nail-biting Game 7 at Madison Square Garden

29 minutes ago

Trump demands Biden take a 'DRUG TEST' before they debate and makes shock accusation against president

30 minutes ago

Biden heading to Georgia to shore up declining support with Black voters

30 minutes ago

Memorial Day Beauty Sales Came Early This Year and They’re Top-Notch

30 minutes ago

Unmarried millennials are twice as likely as boomers to buy homes solo—and 10 times as likely to buy with a friend

31 minutes ago

Singaporean David Tan in MasterChef Australia’s Top 22

31 minutes ago

NEA steps up enforcement against high-rise littering, investigating 29,000 cases yearly

31 minutes ago

It was once a center of Islamic learning. Now Mali's historic city of Djenné mourns lack of visitors

32 minutes ago

Magdala, South Australia: Two people dead after horror head-on collision between truck and a ute

33 minutes ago

Proof Farmer Wants A Wife is FAKE: Participant left furious after producers gutted his family home to make it TV-worthy as he reveals more behind-the-scenes edits

33 minutes ago

Magnetic Island: Eerie video shows how a once-thriving Aussie tourist island is now completely deserted - as holidaymakers reveal the alarming reason why it's empty

33 minutes ago

The Vampire Diaries' Claire Holt details Cannes Film Festival travel chaos as 'deranged' Texas thunderstorm grounds her flight

33 minutes ago

Intel Announces Thunderbolt Share for PC-to-PC File and Device Sharing

33 minutes ago

Don’t get swept away by ‘S&P 500 envy’ as stocks shatter records and bonds lag

33 minutes ago

Former Manchester United striker Robin van Persie appointed Heerenveen head coach

33 minutes ago

As crowd management fails, CM Dhami takes upon himself to monitor Chardham Yatra

34 minutes ago

Shock reason Aussie teens at risk from violent, extremist terror groups

37 minutes ago

Trump demands drug test for Biden before first presidential debate 

38 minutes ago

Former Trump attorney John Eastman pleads not guilty in Arizona election interference case

38 minutes ago

Jurgen Klopp's parting promise to 'special city' ahead of final game as Liverpool manager

38 minutes ago

Queensland ‘needs’ a new stadium that will ‘serve’ the community for generations

38 minutes ago

Palace can repeat Wharton blinder by signing 20m gem with "Eze's dynamism"

38 minutes ago

Plaid Cymru abruptly ends Welsh Labour government co-operation deal

39 minutes ago

Is it a bird? Is it an SUV? No, it’s a supermini: Toyota Aygo X Exclusive

39 minutes ago

From Rebus to The Responder, it’s time to bury the defective detective

39 minutes ago

What happens if you take Ozempic when you are not officially ‘overweight’?

39 minutes ago

How Anna Jones became the standard bearer for modern British vegetarian cooking

Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch