Self-Service Cybersecurity Monitoring as Enabler for DevSecOps

Self-Service Cybersecurity Monitoring as Enabler for DevSecOps
复制标题

DOI:
10.1109/access.2019.2930000
复制
发表时间:
2019-01-01
期刊:
影响因子:
3.9
通讯作者:
Yague, Agustin
Yague, Agustin
中科院分区:
计算机科学3区
文献类型:
--
作者:
Diaz, Jessica;Perez, Jorge E.;Yague, Agustin

文献摘要

被引文献

相似文献

当前的物联网系统是高度分布式的系统,根据智能和处理能力的分配情况,集成了云、边缘和雾计算方法。这种分布和异构性使得开发和部署管道非常复杂,并且在硬件之上有多个交付端点。这一事实阻碍了快速开发,并使生产系统的操作和监控成为一项困难而繁琐的任务,包括网络安全事件监控。DevSecOps可以被定义为一种文化方法,通过使开发/安全/运营团队的协作有效来改善和加速业务价值的交付。本文重点介绍自助式网络安全监控,将其作为在DevOps环境中引入安全实践的推动因素。为此,我们定义并正式化了一项活动,通过提供灵活的监控基础设施来支持“从运营到开发的快速持续反馈”,以便团队可以根据其标准(您构建、运行,现在您监控)配置其监控和警报服务,从而从运营中获得快速持续的反馈,从而在执行生产部署时更好地预测问题。OMG使用软件和系统过程工程元模型对该活动进行了形式化,并通过案例研究对其实例化进行了描述,该案例研究通过虚拟化和容器化技术展示了网络安全监控基础设施(监控即代码)的版本化和可重复配置。这种自助式监控/警报允许通过开放对关键安全指标的访问来打破开发、运营和证券交易团队之间的孤岛,从而实现共享文化和持续改进。
Current IoT systems are highly distributed systems that integrate cloud, edge, and fog computing approaches depending on where intelligence and processing capabilities are allocated. This distribution and heterogeneity make development and deployment pipelines very complex and fragmented with multiple delivery endpoints above hardware. This fact prevents rapid development and makes the operation and monitoring of production systems a difficult and tedious task, including cybersecurity event monitoring. The DevSecOps can be defined as a cultural approach to improve and accelerate the delivery of business value by making dev/sec/ops teams' collaboration effective. This paper focuses on self-service cybersecurity monitoring as an enabler to introduce security practices in a DevOps environment. To that end, we have defined and formalized an activity that supports 'Fast and Continuous Feedback from Ops to Dev' by providing a flexible monitoring infrastructure so that teams can configure their monitoring and alerting services according to their criteria (you build, you run, and now you monitor) to obtain fast and continuous feedback from the operation and thus, better anticipate problems when a production deployment is performed. This activity has been formalized using the Software & Systems Process Engineering Metamodel by OMG and its instantiation is described through a case study that shows the versioned and repeatable configuration of a cybersecurity monitoring infrastructure (Monitoring as Code) through virtualization and containerization technology. This self-service monitoring/alerting allows breaking silos between dev, ops, and sec teams by opening access to key security metrics, which enables a sharing culture and continuous improvement.