Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC)

Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over cloud (ADOC)
复制标题

持续安全建模:使用云端开源软件 (ADOC) 的自动化 DevSecOps 概念模型

DOI:
10.1016/j.cose.2020.101967
复制
发表时间:
2020
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Rinkaj Goyal
Rinkaj Goyal
中科院分区:
--
文献类型:
--
作者:
Rakesh Kumar;Rinkaj Goyal

文献摘要

被引文献

相似文献

敏捷软件开发方法和DevOps共同帮助企业实现敏捷性和速度,以交付上市时间的应用程序和服务。开源软件(OSS)和云技术正在将业务创新和DevOps提升到新的高度。然而,在追求敏捷性和速度的过程中,用户数据安全性和隐私保证往往被认为是一项耗时的活动,需要专业人员、流程和技术,因此优先级较低。我们看到这个问题正在通过在DevOps流程中集成安全性来解决。DevOps的安全性已经被制度化为DevSecOps,并针对给定的业务环境进行了实际考虑。在这项工作中,我们提出了一个概念性的安全模型,ADOC,以促进采用DevSecOps的业务流程资本化OSS云。这项工作有助于将持续安全纳入应用程序和服务交付:㈠根据对在云上采用开放源码软件的DevSecOps的挑战进行分析得出的要求,提出持续安全概念框架建议。(ii)一个集成的安全模型,ADOC,基于所提出的持续安全概念框架,通过在云上使用OSS的安全控制自动化来集成开发,安全和运营活动。(iii)一套交互工作的OSS工具,用于自动化ADOC工作流程和实践中的拟议安全控制。(iv)ADOC模型的一组性能度量指标。(v)使用建议的安全控制来映射针对所分析的挑战的解决方案,然后是采用ADOC工作流程和连续实践的用例场景。ADOC通过将安全控制编入自动化交付工作流,将安全性从临时的合规导向活动转变为持续的保证导向活动。它的实际采用使企业能够以经济高效的方式以更快的速度和可持续的敏捷性交付上市时间安全就绪的应用程序和服务。
Agile software development methodology and DevOps, together, have helped the business to achieve agility and velocity in delivering time-to-market applications and services. Open-source software (OSS) and cloud technologies are taking up business innovation and DevOps at new heights. However, in the quest of agility and velocity, user data security and privacy assurance often get lower priority as they are perceived as a time-consuming activity requiring specialized people, process, and technology. We see this problem being addressed by integrating security in DevOps processes. Security for DevOps has been institutionalized as DevSecOps with practical considerations for a given business context. In this work, we proposed a conceptual security model, ADOC, to facilitate adopting DevSecOps for the business processes capitalizing OSS over the cloud. This work contributes towards the following to integrate continuous security in application and service delivery: (i) A continuous security conceptual framework proposal based on the requirements elicited from the analysis of challenges in adopting DevSecOps using OSS over the cloud. (ii) An integrationist security model, ADOC, based on the proposed continuous security conceptual framework, integrating development, security, and operation activities through automation of security controls using OSS over the cloud. (iii) A set of inter-working OSS tools for automation of the proposed security controls in ADOC workflow and practices. (iv) A set of metrics for performance measurement of the ADOC model. (v) Mapping of the solutions for the analyzed challenges using the proposed security controls, followed by a use case scenario to adopt the ADOC workflow and continuous practices. The ADOC transforms security being adhoc compliance-oriented activities into continuous assurance-oriented activities by codifying security controls into an automated delivery workflow. Its practical adoption enables businesses to deliver time-to-market security ready applications and services with accelerated velocity and sustainable agility in a cost-effective way.