An Analysis System to Test Security of Software on Continuous Integration-Continuous Delivery Pipeline


연구 분야: Analysis



학회: 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)


초록

This work presents a modular and scalable analysis system to integrate different Applications Security Testing tools inside a Continuous Integration-Continuous Delivery Pipeline. Docker containerization and tools for stateless execution allow parallelism and replication. As a result of the analysis of an application, the system execution produces as output a unique JSON report that contains all the vulnerabilities found by the tools executed, with a risk score associated to each vulnerability. Two Application Security Testing tools, OWASP ZAP and SonarQube, have been integrated using Gitlab Platform to apply DevOps methodology for java web application analysis. Results on the OWASP Benchmark test suite confirm a consistent improvement of the security analysis and allow comparison of tools accuracy by vulnerability category.


Author Profile
Cinzia Bernardeschi

Department of Information Engineering University of Pisa Pisa Italy

Italy
Author Profile
Giuseppe Lettieri

Department of Information Engineering University of Pisa Pisa Italy

Italy
Author Profile
Carmelo Aparo

Desys s.r.l. Viareggio Lucca Italy

Italy

📄 논문 정보

발행 연도 2023년
인용수 2
출판 국가 Italy
사이트 IEEE
좋아요 수 0

연관 논문 목록 (38건)