Software Security in DevOps: Synthesizing Practitioners’ Perceptions and Practices

Software Security in DevOps: Synthesizing Practitioners’ Perceptions and Practices
复制标题

DevOps 中的软件安全:综合从业者的看法和实践

DOI:
10.1145/2896941.2896946
复制
发表时间:
2016
期刊:
2016 IEEE/ACM International Workshop on Continuous Software Evolution and Delivery (CSED)
影响因子:
--
通讯作者:
L. Williams
L. Williams
中科院分区:
--
文献类型:
--
作者:
A. Rahman;L. Williams

文献摘要

被引文献

相似文献

在使用DevOps实践的组织中,每天部署软件更改的速度最快可达500次或更多。如果没有安全团队的充分参与,快速部署的软件更改由于缺乏足够的审查,更有可能包含漏洞。本文的目标是通过总结在DevOps环境中使用安全实践的经验,帮助软件从业者集成安全和DevOps。我们分析了一组选定的互联网产品,并对使用DevOps的九个组织的代表进行了调查,以系统地探索利用安全实践的经验。我们观察到,大多数软件从业者都表达了常见的DevOps活动的潜力,例如自动监控,以提高系统的安全性。此外,集成DevOps和安全的组织还利用其他安全活动,例如安全需求分析和执行安全配置。此外,这些团队还在安全团队与开发和运营团队之间建立了协作。
In organizations that use DevOps practices, software changes can be deployed as fast as 500 times or more per day. Without adequate involvement of the security team, rapidly deployed software changes are more likely to contain vulnerabilities due to lack of adequate reviews. The goal of this paper is to aid software practitioners in integrating security and DevOps by summarizing experiences in utilizing security practices in a DevOps environment. We analyzed a selected set of Internet artifacts and surveyed representatives of nine organizations that are using DevOps to systematically explore experiences in utilizing security practices. We observe that the majority of the software practitioners have expressed the potential of common DevOps activities, such as automated monitoring, to improve the security of a system. Furthermore, organizations that integrate DevOps and security utilize additional security activities, such as security requirements analysis and performing security configurations. Additionally, these teams also have established collaboration between the security team and the development and operations teams.