Framework for Integrating Threat Modeling into a DevOps Pipeline for Enhanced Software Development


연구 분야: Software Development



학회: 2024 International Conference on Software, Telecommunications and Computer Networks (SoftCOM)


초록

In the realm of continuous integration and continuous deployment (CI/CD), safeguarding software systems is crucial. Integrating threat modeling into the DevOps pipeline ensures that security considerations are an integral part of the software development process, helping to prevent vulnerabilities from being introduced into production. This study outlines a detailed framework for embedding threat modeling into a Jenkins DevOps pipeline. The framework involves incorporating threat model results into a database and using this data to perform automated security scans. Three challenges are identified in integration of security in DevOps pipeline and discussed against the proposed framework.


Author Profile
Lyuben Nikolov

Department of Computer Systems Technical University of Sofia Sofia Bulgaria

Bulgaria
Author Profile
Adelina Aleksieva-Petrova

Department of Computer Systems Technical University of Sofia Sofia Bulgaria

Bulgaria

📄 논문 정보

발행 연도 2024년
인용수 1
출판 국가 Bulgaria
사이트 IEEE
좋아요 수 0

연관 논문 목록 (332건)