What occurs while you add AI to SAST

Practically a 12 months in the past, I wrote an article titled “How you can decide the appropriate SAST device.” It was a have a look at the professionals and cons of two totally different generations of static utility safety testing (SAST):

  • Conventional SAST (first era): Deep scans for the very best protection, however creates huge friction on account of future occasions.
  • Guidelines-based SAST (second era): Prioritized developer expertise by way of sooner, customizable guidelines, however protection was restricted to explicitly outlined guidelines.

At the moment, these two approaches had been actually the one choices. And to be sincere, neither choice was all that nice. Mainly, each generations had been created to alert for code weaknesses which have principally been solved in different methods (i.e., enhancements in compilers and frameworks eradicated entire courses of CWEs), and the instruments haven’t developed on the identical tempo as fashionable utility improvement. They depend on syntactic sample matching, often enhanced with intraprocedural taint evaluation. However fashionable purposes are way more complicated and infrequently use middleware, frameworks, and infrastructure to deal with dangers.

So whereas accountability for weaknesses shifted to different components of the stack (because of reminiscence security, frameworks, and infrastructure), SAST instruments spew out false positives (FPs) discovered on the granular, code stage. Whether or not you’re utilizing first or second era SAST, 68% to 78% of findings are FPs. That’s lots of handbook triaging by the safety workforce. Worse, right now’s code weaknesses usually tend to come from logic flaws, abuse of reliable options, and contextual misconfigurations. Sadly, these aren’t issues a regex-based SAST can meaningfully perceive. So along with FPs, you even have excessive charges of false negatives (FNs). And as organizations undertake AI code assistants at excessive volumes, we are able to additionally anticipate extra logic and structure flaws that SASTs can’t catch.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles