Redirigiendo al acceso original de articulo en 15 segundos...
Inicio  /  Computers  /  Vol: 8 Par: 4 (2019)  /  Artículo
ARTÍCULO
TITULO

Design and Implementation of SFCI: A Tool for Security Focused Continuous Integration

Michael Lescisin    
Qusay H. Mahmoud and Anca Cioraca    

Resumen

Software security is a component of software development that should be integrated throughout its entire development lifecycle, and not simply as an afterthought. If security vulnerabilities are caught early in development, they can be fixed before the software is released in production environments. Furthermore, finding a software vulnerability early in development will warn the programmer and lessen the likelihood of this type of programming error being repeated in other parts of the software project. Using Continuous Integration (CI) for checking for security vulnerabilities every time new code is committed to a repository can alert developers of security flaws almost immediately after they are introduced. Finally, continuous integration tests for security give software developers the option of making the test results public so that users or potential users are given assurance that the software is well tested for security flaws. While there already exists general-purpose continuous integration tools such as Jenkins-CI and GitLab-CI, our tool is primarily focused on integrating third party security testing programs and generating reports on classes of vulnerabilities found in a software project. Our tool performs all tests in a snapshot (stateless) virtual machine to be able to have reproducible tests in an environment similar to the deployment environment. This paper introduces the design and implementation of a tool for security-focused continuous integration. The test cases used demonstrate the ability of the tool to effectively uncover security vulnerabilities even in open source software products such as ImageMagick and a smart grid application, Emoncms.

 Artículos similares

       
 
Liangtian Wang, Jie Zhou, Yuexin Chang and Hao Xu    
In recent years, electrochemical descaling technology has gained widespread attention due to its environmental friendliness and ease of operation. However, its single-pass removal efficiency could be higher, severely limiting its practical application. T... ver más
Revista: Water

 
Hosin Lee, Byungkyu Moon and Jeongbeom Lee    
The need to incorporate sustainability principles and practices is increasing for environmental and economic reasons. It is imperative to identify and operationalize sustainability strategies into core administrative, planning, design, construction, oper... ver más
Revista: Infrastructures

 
WoonSeong Jeong, ByungChan Kong and Sang-Guk Yum    
The demand for compact housing is on the rise, driven by the need for floor plans that accommodate stakeholders? preferences. However, clients frequently struggle to convey their spatial needs to professionals, such as architects, due to a lack of means ... ver más
Revista: Applied Sciences

 
João P. Ferreira, Vinicius C. Ferreira, Sérgio L. Nogueira, João M. Faria and José A. Afonso    
The sharing of mobile network infrastructure has become a key topic with the introduction of 5G due to the high costs of deploying such infrastructures, with neutral host models coupled with features such as network function virtualization (NFV) and netw... ver más
Revista: Information

 
Romeu Sequeira, Arsénio Reis, Paulo Alves and Frederico Branco    
Higher education institutions (HEIs) make decisions in several domains, namely strategic and internal management, without using systematized data that support these decisions, which may jeopardize the success of their actions or even their efficiency. Th... ver más
Revista: Information