Tooling to Expedite Pipeline Based Security Testing (REX)
Tooling to Expedite Pipeline Based Security Testing (REX)
批准号:
69386
负责人:
金额:
$9.54万
依托单位国家:
英国
项目类别:
Feasibility Studies
财政年份:
2020
资助国家:
英国
项目状态:
已结题
起止时间:
2020 至 --
中文摘要
无论是与家人和朋友沟通,支付账单,还是在线订购商品和服务,我们都使用软件;越来越多的是通过智能手机和平板电脑。作为消费者,我们相信这项技术是安全的,经过测试的,对我们来说是安全的,但情况并非总是如此。安全测试不是强制性的,因此由开发人员决定如何进行测试,或者是否愿意进行测试。Digital Interruption不仅是安全方面的专家,我们也是开发人员。我们希望让开发人员更容易进行安全测试,因此我们使用渗透和安全测试中使用的工具,并为软件工程团队开发它们。我们开发了软件工具雷克斯,而不是用于安全测试的复杂手动工具,它允许公司将安全测试集成到他们的开发管道中。我们的工具不是需要对平台有深入了解才能设置和使用的过时的命令行工具,而是具有API的工具,以便管理扫描和开发测试用例。我们创建了一个Web应用程序前端,允许任何人在开发过程的所有阶段轻松执行安全测试,只需将应用程序拖放到雷克斯中。我们还开发了一个Jenkins插件,可以设置为在每次构建Android应用程序时执行安全扫描。使用该插件,Jenkins可以自动使构建失败,通知开发人员存在安全问题。由于扫描是自动的,这意味着软件开发人员可以在每次构建软件时都运行扫描,而不是更传统的安全方法,即每6个月到一年运行一次扫描。这提供了更多的反馈,更好的可见性,并捕捉可能重新引入的问题,从而实现持续的检测和修复,并导致更安全的软件。附加信息:根据用户的反馈,我们扩大了原始项目的范围,包括雷克斯品牌和专用雷克斯网站,以宣传雷克斯并方便购买许可证。该网站还将通过文档、指南和常见问题解答,向用户和潜在客户介绍雷克斯的功能和用途以及相关的安全最佳实践。将提供有关如何使用和集成雷克斯的视频演示。作为修订后的营销和参与战略的一部分,我们将为网站创建一个以安全为重点的内容计划,为开发人员和软件测试人员量身定制,以支持他们将安全嵌入到他们的产品中。该网站还将促进新的雷克斯功能的发布,例如新的集成,我们已经添加到范围中的定制测试用例功能测试,以及我们将作为项目扩展的一部分进行范围扩展的iOS引擎。
英文摘要
Whether it be to communicate with our family and friends, pay our bills, or order goods and services online, we all use software; increasingly this is via smartphones and tablets. As consumers, we trust that this technology is secure, tested and safe for us to use, but this isn't always the case. Security testing isn't mandatory, so it's up to developers to decide how, or indeed if they want to do it.Digital Interruption are not just experts in security, we're also developers. We want to make security testing easier for developers, so we take the tools we use in penetration and security testing and develop them for software engineering teams. Instead of a complex manual tool used for security testing, we've developed software tooling, REX, that allows companies to integrate the security test into their development pipelines. Our tools are not archaic command-line tools that require a deep understanding of the platform to set up and use, but instead they are tools that have APIs in order to manage scanning and develop of test cases.We've created a web application frontend that allows anyone to easily perform a security test at all points in the development process, simply by dragging and dropping the application into REX. We've also developed a Jenkins plugin that can be set up to perform a security scan every time an Android application is built. Using the plugin, Jenkins can automatically fail the build, informing the developer that a security issue is present.As the scans are automated, it means that software developers have the benefit of having the scans run every time the software is built, rather than a more traditional approach to security which is having scans run every 6 months to a year. This gives greater feedback, better visibility and catches issues that may be reintroduced, enabling continuous detection and remediation, and resulting in safer software.Additional Information: Following feedback from users we have increased the scope of our original project to include REX branding and a dedicated REX website, to advertise REX and facilitate purchase of the licence. The website will also educate users and potential customers on REX functionality and uses as well as relevant security best practice through documentation, guides and FAQs. Video walk-throughs will be available on how to use and integrate REX. As part of a revised marketing and engagement strategy we will create a schedule of security focused content for the website, tailored to developers and software testers to support them in embedding security into their products. The website will also facilitate the announcements of new REX features, such as new integrations, the bespoke test cases feature testing that we have also added in to the scope, and the iOS engine that we will be scoping as part of the project extension.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金