Efficient secure DevOps using process mining and Attack Defense Trees

Efficient secure DevOps using process mining and Attack Defense Trees
复制标题

使用流程挖掘和攻击防御树实现高效、安全的 DevOps

DOI:
10.1016/j.procs.2022.09.079
复制
发表时间:
2022
期刊:
Procedia Computer Science
影响因子:
--
通讯作者:
Kaiya Haruhiko
Kaiya Haruhiko
中科院分区:
--
文献类型:
--
作者:
Okubo Takao;Kaiya Haruhiko

文献摘要

参考文献

相似文献

在本文中,我们提出了一种通过运维和开发来有效确保DevOps生命周期安全的方法。为了确保DevOps中足够的安全性,在开发期间执行足够的威胁分析是必不可少的。然而,威胁分析通常是一项繁重的任务,很难应用于敏捷过程。此外,现有的技术还不足以提供从Dev到Ops和Ops到Dev的安全反馈,而这是DevOps的重要元素。本文提出了一种利用操作日志异常检测来检测攻击的方法,并利用CAPEC和CWE等信息提取漏洞和候选对策。此外,我们还提出了一种方法,通过将其与之前开发的攻击-防御树进行比较,来确定对策的过剩或不足。通过将我们的建议应用到实际的开发案例中,我们确认了所建议的方法是有效的。
In this paper, we propose a method to efficiently ensure security in the DevOps lifecycle through operations and development. To ensure sufficient security in DevOps, it is essential to perform sufficient threat analysis during development. However, threat analysis is generally a heavy task and difficult to apply to agile processes. In addition, existing technologies are not sufficient for security feedback from Dev to Ops and Ops to Dev, which are important elements of DevOps. In this paper, we propose a method for detecting attacks using anomaly detection from operation logs, and extracting vulnerabilities and candidate countermeasures using information such as CAPEC and CWE. Furthermore, we propose a method to determine the excess or deficiency of the countermeasure by comparing it with the Attack-Defense Trees created in the previous development. By applying our proposal to an actual development case, we confirm that the proposed method works effectively.
DOI: 10.1109/access.2019.2930000
发表时间: 2019-01-01
期刊: IEEE ACCESS
影响因子: 3.9
作者:
Diaz, Jessica;Perez, Jorge E.;Yague, Agustin
通讯作者: Yague, Agustin
持续安全建模:使用云端开源软件 (ADOC) 的自动化 DevSecOps 概念模型
DOI: 10.1016/j.cose.2020.101967
发表时间: 2020
期刊: Comput. Secur.
影响因子: --
作者:
Rakesh Kumar;Rinkaj Goyal
通讯作者: Rinkaj Goyal
一种新颖的设计安全方法:使用定量方法按 SLA 建模和评估安全性
DOI: 10.1016/j.jss.2020.110537
发表时间: 2020
期刊: J. Syst. Softw.
影响因子: --
作者:
V. Casola;Alessandra De Benedictis;M. Rak;Umberto Villano
通讯作者: Umberto Villano
基于深度学习的Web访问日志异常检测
DOI: 10.1145/3451471.3451491
发表时间: 2021
期刊: Proceedings of the 2021 4th International Conference on Software Engineering and Information Management
影响因子: --
作者:
Quan Liu
通讯作者: Quan Liu