A Deep Dive Into the 2023 AI Code Security Report | Predict 2024
AI is advancing at a stunning rate, with new tools and use cases being discovered and announced every week, from writing poems to securing networks. Recent developments in LLM-based engines like ChatGPT and Google’s Bard have turned skeptics into believers as AI’s abilities and outputs move out of the realm of the magical and become tangible. As with all technology, AI raises both opportunities and challenges for security professionals and development teams looking to boost productivity while managing risk.
In this session, Liqian Lim will highlight some of the potential pitfalls AI can bring to secure development, and provide guidance on how security teams can think about both within the context of their programs by highlighting key stats from Snyk’s recently released 2023 State of AI report.
Don’t miss this opportunity to gain a deeper understanding of the dynamic intersection between AI and cybersecurity.
Transcript
Hello. Um, so this is, uh, sneaks deep dive, um, into our 2023 AI code security report. And I'm Leaching Li, uh, I'm senior product marketing manager for AI at Snyk.
I'm going to talk to you a little bit more about the findings of our report and what this means for you today. So that's me again, and, um, here we have the agenda. Uh, today we're going to talk about the first thing.
We're going to talk about the survey that we carried out on AI code security, which gave us some really interesting, useful insights for developers. And then we'll move on to talk about the developer usage and adoption, uh, generative AI concerns, uh, this being the hot topic right now, uh, security mitigations, what you can do to manage the problems that come out of, um, using generative ai. And then finally, learnings and takeaways and some useful resources.
Now about the survey, we're going to talk about, uh, who was involved in the survey, uh, when, where an adoption. So our survey, uh, included over 500 respondents based, uh, in Europe and elsewhere. Uh, their roles covered a variety of different functions, including developer security, and it, we covered a huge range of, uh, companies as well, from startup to enterprise.
And, um, our survey was conducted very recently, uh, between September to October of, uh, 2023. So just some month, uh, a few months ago. You can download it at the link that you see within the slide.
And, um, I, I think everybody already guesses this, but, um, it's nice to see a statistic. 96% of teams use AI coding tools. So this is a very real, um, this is a very real shift where mo most people are using AI coding tools today, as opposed to maybe a year ago when people were still, um, on the fence about AI interested but not really committing to it.
But this is our reality now with 96% of teams using AI coding tools. 2% said yes. So how do we then, uh, or rather how do our respondents verify the security of open source packages brought in through AI suggestions?
So you can see the highest number, uh, comes from code reviews and, um, the second highest number, uh, said that they check the information in a registry or the package manager. Now, 72% said that, uh, AI code suggestions were making them somewhat or much more productive. But, uh, in terms of generative AI concerns, now we know, we know how it can make us productive, but what are the concerns around using generative ai and where should we actually focus our attentions?
Our respondents said that they would rate the security of AI code fixed suggestions as, um, good, the majority of them rated it as good and excellent. 4%, um, saying that they were good or excellent. However, they are also you, you can see that, um, the majority of our respondents are concerned that developers are relying too much on AI code completion tools.
So you've seen, uh, you can see here in the blue portion that 40% of them are very concerned and 46% of them are somewhat concerned. So that's a heavy majority of 86%. And, um, yeah, so you can see 86% of, uh, respondents are concerned about developers being over reliant on AI tooling.
Now, maybe some part of this is, uh, concern around developers losing, uh, their skills. And some part of this, um, might be around developers, uh, over-relying and overtrusting tools that they should be validating despite what they said about, uh, the, uh, quality, uh, uh, that their belief in the quality of the code produced by AI coding tools. Uh, here we go into more details around the issues, um, that our respondents faced when using ai, um, AI code assistance.
So how frequently do you encounter issues due to code suggested by an AI tool? 9% set that sometimes they encounter issues due to, um, code suggested by an AI tool. And so this basically means 56% commonly encounter security issues with the code generated by the AI coding assistance.
We also asked the respondents how concerned they were about the, um, broader security implications of using such, um, AI coding tools. And interestingly, um, a huge majority of them were concerned with about, um, 87% being concerned about, um, AI security. So as you know by now, or as you have a feeling by now, we, uh, there is pressure on developers to use AI coding tools to keep up with the speed of, um, technological changes to keep up with competition.
And so they're using this, uh, these tools to supercharge their speed and development. But this also means, um, a security nightmare for the security teams because, um, the security teams were all already overburdened in the first place. And now not only is code being produced much faster and much higher rate, um, by developers who are now assisted by ai, um, we also know that AI produces more vulnerability in code, um, than if the developers have worked without ai.
And so this has become a compounded, uh, issue for security. We have more code and more vulnerabilities within this code, a higher proportion of vulnerabilities within this code. We also talked to our respondents about, uh, the, their organizations restricting the use of AI coding tools.
We wanted to understand what would the reasons behind these restrictions be. And, uh, the vast majority of our respondents, uh, over 50% stated that, uh, this was down to security concerns, uh, followed by data privacy concerns. That's not really very much of a surprise with the data privacy.
I'm sure you'll all remember the case of, um, uh, Samsung where, uh, their employees, um, use chat GBT and leaked organizational, um, private or organizational information. We also ask respondents, how often, um, do developers bypass security policies in order to use AI code completion tool? 8% mentioned most of the time.
Finally, 25% mentioned some of the time, so 80% of our respondents bypass sec, uh, uh, 80% of our respondents mentioned that, uh, developers bypass security policies to use, um, AI coding assistance. And this basically means that you need another layer of security on top of your policies. Um, you really need an integrated approach to, uh, to security for your code.
So this takes us round to security mitigations. Um, how good are we at containing the risk of our generative AI adoption? 1%.
And then we followed on to ask if, uh, the AppSec or security teams are struggling to adapt to the speed of development due to this, um, to the use of AI code completion tools. And, uh, a good majority of them said that they were struggling significantly. 2%.
So that's 59% in total of AppSec teams struggling to keep up, which, um, is not a surprise. 1% of respondents consider AI code completion tools to be part of their, um, software development cycle, but yet despite that, we can see that under 10% actually have 76 to a hundred percent of their security scanning automated. So this is, this presents a high security risk, and we ask respondents, uh, whether they're, or how the organization has, um, changed their software security practices as a result of incorporating AI coding tools in that into their practices or into their normal, um, software development cycle.
Uh, and you can see a vast majority, over 50% said that they have not made any changes, which is very concerning. Um, and the second, um, the second highest number over 40% have said that they incorporated more frequent code audits. Now, this is promising, but the question is whether these, uh, more frequent code audits are human or AI power, whether they can keep up with the speed of, uh, AI assisted developers.
So these are now our learnings and takeaways, uh, and how we beliefs, how snyk beliefs that, um, developers and, uh, security teams should approach AI assisted development. So after key takeaways, you have seen that 56% of respondents say, um, that insecure AI suggestions are common, but very few have actually improved their security processes, and 80% are very high concerning 80% bypass policies to use AI tools. Um, and 80, 87%, uh, but yet only 87% are concerned about AI security.
So this, um, indicates cognitive dissonance to us because it's, it's quite ironic that despite, um, being concerned about AI security, they still bypass security, uh, policies to use ai. Uh, we've seen that AI is considered part of the software supply chain, but very few companies have actually changed their practices, their security practices specifically, and we've seen that 59% of AppSec teams are struggling to keep up, uh, despite only starting the organization's AI journey. So this is only at the start as AI ramps up.
As more AI tools are, um, incorporated, uh, AppSec teams will struggle even more. Now in terms of our, uh, secure AI takeaways, we, we should be looking at education and awareness. Uh, as you've seen, cognitive dissonance indicates that developers and security teams need more education around, um, AI and good AI practices.
One of the things you can do is to write up policies and company guidelines. You can focus on security vulnerabilities, um, sensitive data and IP and human interaction with these AI tools. And you can make educational, uh, education actionable, uh, and make sure that, uh, that repeatable steps can be taken.
Um, writing the these into your policies and company guidelines. Most importantly, don't trust, uh, these AI code completion tools. AI tools are meant to augment developers and not to replace developers.
So treat AI code like, um, it's created by, it was created by an, um, inexperienced developer or AppSec engineer. Um, treat your tools as such as well always check your code, um, test and validate everything and have, uh, additional layers of security. So don't just, um, have humans validate the code.
Also pair your chat, GPT copilot code whisperer or whatever AI coding assistant you, you plan on using, or you are using with, um, a security tool within the IDE like snyk. So have a tool that's fast enough that can keep up with these, um, AI coding assistance in real time and that don't develop, uh, don't disrupt developer workflows. Um, so the best thing to do to would be to have such a tool run within the IDE so you can remediate early.
Um, this, these are just some additional useful resources for you. Uh, you can consider, uh, 10 best practices for secure securely developing with ai. Or on the right hand side, you can see the top considerations for addressing risks in the O OSP top 10 for lms.
So these are just, um, best practices if you're developing, if you're planning on developing your own ai, we have links with, uh, at the bottom of the page for we have links at the bottom of the page, um, for you to refer to. And, um, go on to this link to try sneak code for free, uh, just experiments, play with it yourself and see how we can actually remediate your code, uh, help you to scan and remediate your code in real time. 4 times faster than other solutions on average.
And, um, we allow you to automatically fix your, uh, vulnerabilities as well from within your IDE be a secure developer code securely. Thank you very much.





