2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP) 2021
DOI: 10.1109/icse-seip52600.2021.00037
|View full text |Cite
|
Sign up to set email alerts
|

Enterprise-Driven Open Source Software: A Case Study on Security Automation

Abstract: Agile and DevOps are widely adopted by the industry. Hence, integrating security activities with industrial practices, such as continuous integration (CI) pipelines, is necessary to detect security flaws and adhere to regulators' demands early.In this paper, we analyze automated security activities in CI pipelines of enterprise-driven open source software (OSS). This shall allow us, in the long-run, to better understand the extent to which security activities are (or should be) part of automated pipelines. In … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
1
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 13 publications
(10 citation statements)
references
References 18 publications
(20 reference statements)
0
1
0
Order By: Relevance
“…There are also research studies on bridging the gap between agile development and security auditing. Angermeir et al analyzed the enterprise-driven open-source software and corresponding security automation on a large scale, indicating that security activities in enterprise-driven OSS are scarce and the protection coverage is low [33]. Türpe et al revealed the isolation between scrum CI/CD framework and security experts [34].…”
Section: Security Of Ci/cd Scriptsmentioning
confidence: 99%
“…There are also research studies on bridging the gap between agile development and security auditing. Angermeir et al analyzed the enterprise-driven open-source software and corresponding security automation on a large scale, indicating that security activities in enterprise-driven OSS are scarce and the protection coverage is low [33]. Türpe et al revealed the isolation between scrum CI/CD framework and security experts [34].…”
Section: Security Of Ci/cd Scriptsmentioning
confidence: 99%
“…Such technologies advocate automation which is considered a backbone of DevSecOps workflow implementation [70]. Automated security has begun to consider the panorama of challenges by bridging the gap between compliance with security standards and the software engineering environment itself [20]. The opportunity to integrate compliance aspects into the DevOps methodology makes the process a matter of automation as well.…”
Section: Managementmentioning
confidence: 99%
“…The use of security tools as an embedded component allows the automation of security testing [43]. Security activities such as Third-Party Vulnerability Scanning, Static/Dynamic Application Security Testing [20], security requirements testing, threat mitigation testing, vulnerability testing, and penetration testing [61] were performed to test for security risks. Security testing itself contributes to the application of compliance testing.…”
Section: Managementmentioning
confidence: 99%
See 2 more Smart Citations