【24h】

Security Support in Continuous Deployment Pipeline

机译:连续部署管道安全支持

获取原文

摘要

Continuous Deployment (CD) has emerged as a new practice in the software industry to continuously and automatically deploy software changes into production. Continuous Deployment Pipeline (CDP) supports CD practice by transferring the changes from the repository to production. Since most of the CDP components run in an environment that has several interfaces to the Internet, these components are vulnerable to various kinds of malicious attacks. This paper reports our work aimed at designing secure CDP by utilizing security tactics. We have demonstrated the effectiveness of five security tactics in designing a secure pipeline by conducting an experiment on two CDPs-one incorporates security tactics while the other does not. Both CDPs have been analysed qualitatively and quantitatively. We used assurance cases with goal-structured notations for qualitative analysis. For quantitative analysis, we used penetration tools. Our findings indicate that the applied tactics improve the security of the major components (i.e., repository, continuous integration server, main server) of a CDP by controlling access to the components and establishing secure connections.
机译:持续部署(CD)已成为软件行业的新实践,以不断,并自动将软件变化部署到生产中。连续部署管道(CDP)通过将更改从存储库转移到生产来支持CD实践。由于大多数CDP组件在对Internet具有多个接口的环境中运行,因此这些组件容易受到各种恶意攻击。本文通过利用安全策略报道我们的工作旨在设计安全CDP。我们通过在两个CDPS-One上进行实验,在设计安全管道时,我们已经证明了五个安全策略的有效性,而另一个没有。两种CDP都经质量和定量分析。我们使用具有目标结构化符号的保证案例进行定性分析。对于定量分析,我们使用了渗透工具。我们的调查结果表明,通过控制对组件的访问并建立安全连接,所应用的策略通过控制CDP的主要组件(即,存储库,连续集成服务器,主服务器)的安全性,并建立安全连接。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号