首页> 外文会议>International Conference on Computational Science and Computational Intelligence >Detecting Software Security Vulnerability during an Agile Development by Testing the Changes to the Security Posture of Software Systems
【24h】

Detecting Software Security Vulnerability during an Agile Development by Testing the Changes to the Security Posture of Software Systems

机译:通过测试软件系统的安全姿势的更改,在敏捷开发期间检测软件安全漏洞

获取原文

摘要

The purpose of this quantitative quasi-experimental study is to identify the possible correlation between software changes and the likelihood that software releases developed using an agile methodology like DevOps will introduce vulnerabilities into the software application when integrated. There are several scholarly articles that provide details on how Agile development methodologies like scrum and DevOps rely on automated testing for security. The majority of literature on the subject recommend manual security and penetration testing, but there is currently no objective measure to determine when this manual testing should take place. In Agile scrum and in DevOps, manual security testing is usually conducted after a large feature is completed and integrated into production. If a correlation can be found between aspects of software changes and their propensity to introduce vulnerabilities into a software application, then that data can be used to build an objective process for measuring when manual security testing should be performed in Agile development.
机译:该定量准实验研究的目的是识别软件变化与使用像Devops这样的敏捷方法开发的软件发布的可能性将在集成时将漏洞引入软件应用程序。有几个学术文章提供了有关Scrile和DevOps等敏捷开发方法如何依赖于安全性测试的详细信息。大多数文学对主题推荐了手动安全性和渗透测试,但目前没有客观措施确定何时应何时进行此手动测试。在敏捷Scrum和Devops中,手动安全测试通常在完成大功能并融入生产后进行。如果在软件变化的方面和将漏洞引入软件应用程序的倾向之间,则可以使用该数据来构建用于在敏捷开发中执行手动安全测试时的测量的客观过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号