Efficient secure DevOps using process mining and Attack Defense Trees
Efficient secure DevOps using process mining and Attack Defense Trees
复制标题
使用流程挖掘和攻击防御树实现高效、安全的 DevOps
DOI:
10.1016/j.procs.2022.09.079
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Kaiya Haruhiko
中科院分区:
文献类型:
--
作者:
Okubo Takao;Kaiya Haruhiko
In this paper, we propose a method to efficiently ensure security in the DevOps lifecycle through operations and development. To ensure sufficient security in DevOps, it is essential to perform sufficient threat analysis during development. However, threat analysis is generally a heavy task and difficult to apply to agile processes. In addition, existing technologies are not sufficient for security feedback from Dev to Ops and Ops to Dev, which are important elements of DevOps. In this paper, we propose a method for detecting attacks using anomaly detection from operation logs, and extracting vulnerabilities and candidate countermeasures using information such as CAPEC and CWE. Furthermore, we propose a method to determine the excess or deficiency of the countermeasure by comparing it with the Attack-Defense Trees created in the previous development. By applying our proposal to an actual development case, we confirm that the proposed method works effectively.
登录
查看更多内容
影响因子:
3.9
作者:
Diaz, Jessica;Perez, Jorge E.;Yague, Agustin
通讯作者:
Yague, Agustin
DOI:
10.1016/j.cose.2020.101967
发表时间:
2020
期刊:
Comput. Secur.
影响因子:
--
作者:
Rakesh Kumar;Rinkaj Goyal
通讯作者:
Rinkaj Goyal
DOI:
10.1016/j.jss.2020.110537
发表时间:
2020
期刊:
J. Syst. Softw.
影响因子:
--
作者:
V. Casola;Alessandra De Benedictis;M. Rak;Umberto Villano
通讯作者:
Umberto Villano
DOI:
10.1145/3451471.3451491
发表时间:
2021
期刊:
Proceedings of the 2021 4th International Conference on Software Engineering and Information Management
影响因子:
--
作者:
Quan Liu
通讯作者:
Quan Liu