Companies that update their software once a month may struggle to keep pace with how quickly vulnerabilities are being found, according to Amazon Web Services (AWS).

“Most businesses are still operating on a monthly patch cadence,” Bryce Boland, head of Security Solutions Architecture, APJC, at AWS, said during a virtual ASEAN security briefing.

He also noted that AI tools can examine large amounts of code and identify multiple weaknesses at once. He said attackers can also use AI to develop ways to exploit those weaknesses more quickly.

He said about 48,000 software vulnerabilities were publicly reported last year, up 20% from the year before. This year, he said, the monthly number grew from about 5,000 in the first quarter to about 10,000 in the third quarter.

The growing volume poses a practical problem for companies: security teams must work out which weaknesses affect their systems, which are most urgent, and how to fix them. Boland said firms may need to update their processes as well as their tools.

AWS is offering one possible approach through Continuum, a service previously called AWS Security Agent. Boland said it can examine system designs and software code for weaknesses and run penetration tests, which check whether a flaw can be exploited.

Its threat modeling, design review, and code review capabilities are in preview. The penetration testing capability is generally available.

Boland cited results from two customers. He said Japanese software-as-a-service security company HENNGE reduced penetration testing time from weeks to hours. At AWS partner LG CNS, tests took three days instead of five when security engineers checked the agent’s work, with costs falling 30%. Boland said testing took one day and costs fell 70% when LG CNS used the agent independently.

The service’s results also depend on what a company can tell it about its systems. Asked by Back End News whether Continuum can work with older systems that have incomplete documentation or disorganized code, Boland said: “It works with whatever you can provide it. The more context you can provide, the more accurate and reliable it can be.”

He said LG CNS improved the reliability of one assessment from 60% to 90% by supplying more information about account permissions. That helped remove incorrect findings.

For companies with older systems, Boland’s answer leaves a basic task alongside faster testing: gathering enough information about what they have built for the results to be useful.

By Marlet Salazar

Marlet Salazar is a technology writer focusing on cybersecurity. In 2018, driven by her passion for the tech industry, she founded Back End News through bootstrapped funding. She honed her writing skills at the Philippine Daily Inquirer, rising from proofreader to desk editor through the years.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading