[PDF][PDF] Knowledge base driven pipelines for security enforcement

A Trajković, M Stojkov, M Simić, G Sladić - 2023 - eventiotic.com
A Trajković, M Stojkov, M Simić, G Sladić
2023eventiotic.com
A lack of security controls in the system may be a potential point of attack to exploit the
system's vulnerability. Unfortunately, security controls are added as an afterthought when all
functionalities are implemented, which leads to difficulties adapting to the software's rigid
policies, decreased performance, and increased costs. Furthermore, even after adjusting
those policies, using an application that only partially fulfills some desired security
requirements is difficult. The solution for decreasing time on adapting security mechanisms …
Abstract
A lack of security controls in the system may be a potential point of attack to exploit the system's vulnerability. Unfortunately, security controls are added as an afterthought when all functionalities are implemented, which leads to difficulties adapting to the software's rigid policies, decreased performance, and increased costs. Furthermore, even after adjusting those policies, using an application that only partially fulfills some desired security requirements is difficult. The solution for decreasing time on adapting security mechanisms and minimizing weak points in the system becomes integrating security as a building block of development and maintenance, known as the DevSecOps concept. In this paper, we illustrate the importance of continuously providing protection in containers and reducing the risk of unwanted application attacks by integrating a secure pipeline in the earliest stage. The proposal is to automate the pipeline by combining security tools with database knowledge in a development process. The database knowledge will provide security policies that can be applied to a specific pipeline stage. This paper presents an approach to minimize vulnerabilities and code flaws by practicing DevSecOps, which also requires collaboration and communication between development, security, and operations teams, which increases the software's overall development efficiency.
eventiotic.com
以上显示的是最相近的搜索结果。 查看全部搜索结果