当前位置:首页 >英文主页 >中英对照 > 中译版报告详情

Veracode:2024年度全球软件安全状况报告:应对安全债务威胁(中译版)(45页).pdf

上传人: Y**** 编号:710374 2024-12-29 45页 33.96MB

下载:

1、Addressing the Threat of Security DebtState of Software Security2024Veracode State of Software Security 202402Veracode State of Software Security 202402Letter from the EditorArtificial Intelligence(AI)wasnt born last year,but 2023 was its coming-of-age party.The proliferation of AI-generated code br

2、ings with it insecure code at scale and the likelihood of it becoming security debt.Research indicates that code developed by AI contains about the same percentage of security flaws as that generated by humans.Other research suggests that programmers with a variety of experience levels fail to ident

3、ify incorrect ChatGPT answers more than a third of the time.While AI allows more code to be written more quickly,it does not deliver more secure code.The result is more risk introduced into your code base in the same amount of time.The regulatory landscape has also evolved in the past year,with the

4、US White House Executive Order on the Safe,Secure,and Trustworthy Development and Use of Artificial Intelligence,the European Unions Cyber Resilience Act,and the US Security and Exchange Commissions Rules on Cybersecurity Risk Management,Strategy,Governance,and Incident Disclosure by Public Companie

5、s all coming into effect.Its within this context that we explored Veracodes 18 years of data to answer questions about the accumulation of risk associated with insecure code.Its not news that applications contain security flaws,but we are excited to share insights on where,how,and why flaws persist

6、over time.In this years report,our 14th,we do a deep dive into the distribution of security debt within applications,across industries and languages.We also continue the conversation that we began in last years report regarding risks associated with how developers choose open-source libraries for th

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要讨论了软件安全债务(security debt)的问题,并提供了减少这种债务的策略。文章指出,尽管高严重性安全漏洞在应用程序中的普遍性有所下降,但安全债务仍然普遍存在。大约63%的应用程序包含第一方代码中的缺陷,而70%的应用程序包含第三方(主要是开源)代码中的缺陷。安全债务在42%的应用程序和71%的组织中存在。文章还指出,修复第三方缺陷所需的时间比第一方缺陷长50%,其半衰期为11个月,而第一方缺陷的半衰期为7个月。文章建议通过在整个软件开发生命周期中整合安全测试、加快缺陷修复速度、优先修复关键安全债务、提高开发人员的安全技能和了解所用语言的安全债务特征等方法来减少安全债务。此外,文章还强调了保护软件供应链的重要性,特别是第三方(开源)代码的安全性。
安全债务如何影响软件开发? 如何有效减少安全债务? 开源代码依赖对软件安全有何影响?
客服
商务合作
小程序
服务号
折叠