The State of Software Security in 2022: How Far We've Come
August 09, 2022

Chris Wysopal
Veracode

In the last six months, organizations from Microsoft to the Red Cross have been hit by cybersecurity breaches. Widespread open-source vulnerabilities, such as Log4j and Spring4shell, have also shaken the software industry, reminding us just how entwined source code has become. These recurring incidents raise the question, are we making progress in securing our software?

According to Veracode's latest State of Software Security (SoSS) report, the answer is yes. Now in its 12th year, this annual report looks at more than half a million active software applications spanning multiple business sectors to identify trends, emerging issues, and best practices in application security. The insights shed light on how far we've come in securing our software — and how far we still have to go.


Impact of Emerging Development Trends on Security

In today's digital-first world, increased connectivity, hypercompetitiveness, and the need to innovate constantly are changing the fabric of security. The ability to develop and deploy code quickly is now critical for just about every organization, and this demand has pushed developers to leverage more modern technologies, agile methodologies, and open-source code to accelerate the development process. These trends have had a positive impact on application security.

More apps are being scanned — Organizations are scanning, on average, more than 17 new applications per quarter. This number is more than triple the number of apps scanned per quarter a decade ago.

Apps are being developed with fewer languages — We're also seeing a decrease in applications with multiple languages. Over the past four years, the number of applications developed with multiple languages has decreased by 20%. As each language has its own security strengths and weaknesses, reducing the number and variety of languages makes it easier to find and fix vulnerabilities in code.

Microservices are on the rise — The SoSS research shows an overall decline in application size, most notably in JavaScript, Python, and .NET apps. Combined, these three trends indicate more microservices — smaller, modular applications — are being used today. While the use of microservices speeds up the software development lifecycle, it also introduces new complexities and risks.

Improved AppSec Best Practices

Despite the headlines, application security has improved vastly over the past decade. It's now the norm for security scanning to be integrated into the software development pipeline as part of a continuous testing and integration methodology. Veracode's annual analysis of customers' applications reveals that certain behaviors, such as a regular scanning cadence, can help developers find and fix vulnerabilities in code faster, which is something customers are realizing and prioritizing. This year's SOSS report found a 20x increase in scanning cadence, with most applications being scanned three times a week.

Organizations Are Using Multiple Scan Types

In addition to more frequent scanning, we also found an increase in the use of multiple different security scanning types. Between 2018 and 2021, the use of multiple scan types increased by 31%, and many organizations are now leveraging a combination of static, dynamic, and software composition analysis (SCA) scans for more holistic and comprehensive security scanning.

This growing trend of using multiple scan types builds upon something we saw in SoSS v11 — companies using dynamic and static scanning together remediated 50% of flaws 24 days faster than those using only one scanning type. Adding in software composition analysis to this mix shaves another six days off this remediation time. As organizations learn that more in-depth security scanning leads to faster remediation of flaws, the bar for "good" security practices should continue to rise.

Third-Party Libraries Have Fewer Flaws

We know that organizations rely heavily on third-party libraries. We also know most open-source libraries have flaws. So, it's heartening to see a decline in the overall number of flaws in third-party libraries. In 2017, nearly 35% (on average) of libraries used had a known flaw. This has come down to about 10%. Specific languages demonstrate different degrees of this decline, with JavaScript dropping six%, and Python from about 25% to nearly 10%. Overall, the data indicates a positive trend.

Flaw Prevalence Is Declining

All this data is interesting, sure, but in the end, how does it impact the security of software code? We looked at the percentage of applications with various flaw types, specifically those listed in the OWASP Top 10, CWE/SANS Top 25, and those classified as "High" criticality or above, to see if any trends emerged. Over the years, the percentage of flaw types bounced around a bit, but it's great to see the trend across all applications is a general reduction in flaw prevalence.

Developer Security Training Works

As cybersecurity becomes a business priority at the board level, developers are starting to reap the benefits of better software security training. This year's report found that hands-on security training for developers is a worthwhile investment.

Applications Are Slowly, but Surely, Getting More Secure

As we look back through more than a decade of historical software security data, we can see how far security has come. As speed of development becomes more critical, today's developers are increasingly adopting agile development of small, modular applications and open-source code. Though it's not happening as quickly as we'd like, applications are getting more secure with the help of tools and services like SCA and developer security training. There's still plenty of room for improvement, especially as the threat landscape continues to change, but we're certainly heading in the right direction.

Chris Wysopal is Co-Founder and CTO of Veracode
Share this

Industry News

February 02, 2023

Red Hat announced a multi-stage alliance to offer customers a greater choice of operating systems to run on Oracle Cloud Infrastructure (OCI).

February 02, 2023

Snow Software announced a new global partner program designed to enable partners to support customers as they face complex market challenges around managing cost and mitigating risk, while delivering value more efficiently and effectively with Snow.

February 02, 2023

Contrast Security announced the launch of its new partner program, the Security Innovation Alliance (SIA), which is a global ecosystem of system integrators (SIs), cloud, channel and technology alliances.

February 01, 2023

Red Hat introduced new security and compliance capabilities for the Red Hat OpenShift enterprise Kubernetes platform.

February 01, 2023

Jetpack.io formally launched with Devbox Cloud, a managed service offering for Devbox.

February 01, 2023

Jellyfish launched Life Cycle Explorer, a new solution that identifies bottlenecks in the life cycle of engineering work to help teams adapt workflow processes and more effectively deliver value to customers.

January 31, 2023

Ably announced the Ably Terraform provider.

January 31, 2023

Checkmarx announced the immediate availability of Supply Chain Threat Intelligence, which delivers detailed threat intelligence on hundreds of thousands of malicious packages, contributor reputation, malicious behavior and more.

January 31, 2023

Qualys announced its new GovCloud platform along with the achievement of FedRAMP Ready status at the High impact level, from the Federal Risk and Authorization Management Program (FedRAMP).

January 30, 2023

F5 announced the general availability of F5 NGINXaaS for Azure, an integrated solution co-developed by F5 and Microsoft that empowers enterprises to deliver secure, high-performance applications in the cloud.

January 30, 2023

Tenable announced Tenable Ventures, a corporate investment program.

January 26, 2023

Ubuntu Pro, Canonical’s comprehensive subscription for secure open source and compliance, is now generally available.

January 26, 2023

Mirantis, freeing developers to create their most valuable code, today announced that it has acquired the Santa Clara, California-based Shipa to add automated application discovery, operations, security, and observability to the Lens Kubernetes Platform.

January 25, 2023

SmartBear has integrated the powerful contract testing capabilities of PactFlow with SwaggerHub.

January 25, 2023

Venafi introduced TLS Protect for Kubernetes.