课题基金 / 基金详情

Tooling to Expedite Pipeline Based Security Testing (REX)

Tooling to Expedite Pipeline Based Security Testing (REX)
加快基于管道的安全测试 (REX) 的工具
批准号:
69386
负责人:
金额:
$9.54万
依托单位国家:
英国
项目类别:
Feasibility Studies
财政年份:
2020
资助国家:
英国
项目状态:
已结题
起止时间:
2020 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Whether it be to communicate with our family and friends, pay our bills, or order goods and services online, we all use software; increasingly this is via smartphones and tablets. As consumers, we trust that this technology is secure, tested and safe for us to use, but this isn't always the case. Security testing isn't mandatory, so it's up to developers to decide how, or indeed if they want to do it.Digital Interruption are not just experts in security, we're also developers. We want to make security testing easier for developers, so we take the tools we use in penetration and security testing and develop them for software engineering teams. Instead of a complex manual tool used for security testing, we've developed software tooling, REX, that allows companies to integrate the security test into their development pipelines. Our tools are not archaic command-line tools that require a deep understanding of the platform to set up and use, but instead they are tools that have APIs in order to manage scanning and develop of test cases.We've created a web application frontend that allows anyone to easily perform a security test at all points in the development process, simply by dragging and dropping the application into REX. We've also developed a Jenkins plugin that can be set up to perform a security scan every time an Android application is built. Using the plugin, Jenkins can automatically fail the build, informing the developer that a security issue is present.As the scans are automated, it means that software developers have the benefit of having the scans run every time the software is built, rather than a more traditional approach to security which is having scans run every 6 months to a year. This gives greater feedback, better visibility and catches issues that may be reintroduced, enabling continuous detection and remediation, and resulting in safer software.Additional Information: Following feedback from users we have increased the scope of our original project to include REX branding and a dedicated REX website, to advertise REX and facilitate purchase of the licence. The website will also educate users and potential customers on REX functionality and uses as well as relevant security best practice through documentation, guides and FAQs. Video walk-throughs will be available on how to use and integrate REX. As part of a revised marketing and engagement strategy we will create a schedule of security focused content for the website, tailored to developers and software testers to support them in embedding security into their products. The website will also facilitate the announcements of new REX features, such as new integrations, the bespoke test cases feature testing that we have also added in to the scope, and the iOS engine that we will be scoping as part of the project extension.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金