Export Citations
Save this search
Please login to be able to save your searches and receive alerts for new content matching your search criteria.
- research-articleJanuary 2025JUST ACCEPTED
AI for DevSecOps: A Landscape and Future Opportunities
ACM Transactions on Software Engineering and Methodology (TOSEM), Just Accepted https://doi.org/10.1145/3712190DevOps has emerged as one of the most rapidly evolving software development paradigms. With the growing concerns surrounding security in software systems, the DevSecOps paradigm has gained prominence, urging practitioners to incorporate security practices ...
- research-articleNovember 2024
DevSecOps practices and tools
International Journal of Information Security (IJOIS), Volume 24, Issue 1https://doi.org/10.1007/s10207-024-00914-zAbstractNowadays, software development happens at a fast pace. At the same time, Information Technology organizations face higher demands and competition while struggling with external threats such as cyberattacks. Therefore, many organizations adopt ...
- research-articleOctober 2024
Automating Cybersecurity Compliance in DevSecOps with Open Information Model for Security as Code
eSAAM '24: Proceedings of the 4th Eclipse Security, AI, Architecture and Modelling Conference on Data SpacePages 93–102https://doi.org/10.1145/3685651.3686700Software development teams meet increasing requirements to implement cybersecurity management in compliance with standards and regulations. However, adopting a compliant cybersecurity management system and DevSecOps practices as part of a software ...
- research-articleOctober 2024
Enhancing DevSecOps practice with Large Language Models and Security Chaos Engineering
International Journal of Information Security (IJOIS), Volume 23, Issue 6Pages 3765–3788https://doi.org/10.1007/s10207-024-00909-wAbstractRecently, the DevSecOps practice has improved companies’ agile production of secure software, reducing problems and improving return on investment. However, overreliance on security tools and traditional security techniques can facilitate the ...
- research-articleNovember 2024
Decoding developer password patterns: A comparative analysis of password extraction and selection practices
AbstractPasswords play a crucial role in authentication, ensuring that only authorised entities can access sensitive information. However, user password choices are often weak and predictable, making them susceptible to cyber-attacks. Additionally, hard-...
-
- research-articleDecember 2024
Integrated Design Method of Development, Operation and Maintenance Security in Public Computing Environment
IPMLP '24: Proceedings of the International Conference on Image Processing, Machine Learning and Pattern RecognitionPages 477–482https://doi.org/10.1145/3700906.3700982The public computing environment is the key technology of the new generation of ship system. The efficiency and quality of its software development will seriously affect the development of combat system. This paper compares the software development ...
- research-articleJuly 2024
A comprehensive analysis on software vulnerability detection datasets: trends, challenges, and road ahead
International Journal of Information Security (IJOIS), Volume 23, Issue 5Pages 3311–3327https://doi.org/10.1007/s10207-024-00888-yAbstractAs society’s dependence on information and communication systems (ICTs) grows, so does the necessity of guaranteeing the proper functioning and use of such systems. In this context, it is critical to enhance the security and robustness of the ...
- research-articleJuly 2024
Identifying the primary dimensions of DevSecOps: A multi-vocal literature review
Journal of Systems and Software (JSSO), Volume 214, Issue Chttps://doi.org/10.1016/j.jss.2024.112063Abstract Context:Security as a key non-functional requirement of software development is often ignored and devalued in DevOps programs, with security seen as an inhibitor to high velocity required in DevOps implementation. Hence, the DevSecOps approach ...
Highlights
- A multivocal literature review on DevSecOps (2012–2022).
- The review of DevSecOps covers Definition, Challenges, Practices, Tools and Metrics.
- Presents a Challenge-Practice-Tool-Metric model for DevSecOps.
- The global dimension ...
- ArticleJune 2024
Training and Security Awareness Under the Lens of Practitioners: A DevSecOps Perspective Towards Risk Management
AbstractCritical infrastructures (CI) extend across various sectors within the economy, relying on a combination of software and hardware technologies to manage the operations of the systems, services, and assets. Risk Management plays a pivotal role in ...
- research-articleJune 2024
Towards People Maturity for Secure Development and Operations: A vision
EASE '24: Proceedings of the 28th International Conference on Evaluation and Assessment in Software EngineeringPages 528–533https://doi.org/10.1145/3661167.3661238DevOps (development and operations) is a set of collaborative practices that automate continuous delivery of new software versions with an aim to reduce the development life cycle and produce quality software products. Security is an important attribute ...
- research-articleAugust 2024
On DevSecOps and Risk Management in Critical Infrastructures: Practitioners' Insights on Needs and Goals
EnCyCriS/SVM '24: Proceedings of the 2024 ACM/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE/ACM Second International Workshop on Software VulnerabilityPages 45–52https://doi.org/10.1145/3643662.3643954Risk management is essential for ensuring the sustained viability of organizations over the long term. It plays a pivotal role in business by helping identify potential threats and vulnerabilities, enabling well-informed decision-making. Within the ...
- research-articleMay 2024
Industrial Challenges in Secure Continuous Development
ICSE-SEIP '24: Proceedings of the 46th International Conference on Software Engineering: Software Engineering in PracticePages 309–311https://doi.org/10.1145/3639477.3639736The intersection between security and continuous software engineering has been of great interest since the early years of the agile development movement, and it remains relevant as software development processes are more frequently guided by agility and ...
- short-paperOctober 2023
PIACERE Integrated Development Environment
eSAAM '23: Proceedings of the 3rd Eclipse Security, AI, Architecture and Modelling Conference on Cloud to Edge ContinuumPages 62–66https://doi.org/10.1145/3624486.3624507This article presents a model-driven engineering (MDE) integrated development environment (IDE) to assist the DevSecOps (Development Security and Operations) process. This tool has been developed within the PIACERE H2020 project, which proposes a ...
- research-articleAugust 2023
Experiences with Secure Pipelines in Highly Regulated Environments
ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and SecurityArticle No.: 57, Pages 1–9https://doi.org/10.1145/3600160.3605466In this experiential paper, we present observations from our collaborative efforts with multiple entities operating in highly regulated environments that enabled or disrupted the construction, use, and sustainment of secure CI/CD pipelines as part of a ...
- research-articleAugust 2023
SecCo: Automated Services to Secure Containers in the DevOps Paradigm
RACS '23: Proceedings of the 2023 International Conference on Research in Adaptive and Convergent SystemsArticle No.: 10, Pages 1–6https://doi.org/10.1145/3599957.3606222Containers are core building blocks for creating applications based on the microservice paradigm. However, assessing their security is complex, especially when deployed in distributed and heterogeneous scenarios. Moreover, developers and IT operators ...
- short-paperJune 2023
Full Spec Software via Platform Engineering: Transition from Bolting-on to Building-in
EASE '23: Proceedings of the 27th International Conference on Evaluation and Assessment in Software EngineeringPages 172–175https://doi.org/10.1145/3593434.3593440The complexity of delivering enterprise-grade software, especially as-a-service, keeps getting more sophisticated even with the large set of open-source and commercial helper tools. Every single commit by the developers must go through a large group of ...
- research-articleApril 2023
From DevOps to DevSecOps is not enough. CyberDevOps: an extreme shifting-left architecture to bring cybersecurity within software security lifecycle pipeline
Software Quality Journal (KLU-SQJO), Volume 31, Issue 2Pages 619–654https://doi.org/10.1007/s11219-023-09619-3AbstractSoftware engineering is evolving quickly leading to an urgency to discover more efficient development models. DevOps and its security-oriented extension DevSecOps promised to speed up the development process while ensuring more robust code. ...
- short-paperApril 2023
Security in DevSecOps: Applying Tools and Machine Learning to Verification and Monitoring Steps
ICPE '23 Companion: Companion of the 2023 ACM/SPEC International Conference on Performance EngineeringPages 201–205https://doi.org/10.1145/3578245.3584943Security represents one of the crucial concerns when it comes to DevOps methodology-empowered software development and service delivery process. Considering the adoption of Infrastructure as Code (IaC), even minor flaws could potentially cause fatal ...
- short-paperNovember 2022
Engram: the one security platform for modern software supply chain risks
WoC '22: Proceedings of the Eighth International Workshop on Container Technologies and Container CloudsPages 7–12https://doi.org/10.1145/3565384.3565889In the light of recent increase in the number of cybersecurity incidents affecting organizations of different kinds and sizes, security of software supply chain is becoming mission critical. At the core, supply chain security is a multi-disciplinary ...
- research-articleSeptember 2022
Open source software: an approach to controlling usage and risk in application ecosystems
SPLC '22: Proceedings of the 26th ACM International Systems and Software Product Line Conference - Volume APages 154–163https://doi.org/10.1145/3546932.3547000The Open Source Software movement has been growing exponentially for a number of years with no signs of slowing. Driving this growth is the wide-spread availability of libraries and frameworks that provide many functionalities. Developers are saving ...