Security represents one of the crucial concerns when it comes to DevOps methodology-empowered software development and service delivery process. Considering the adoption of Infrastructure as Code (IaC), even minor flaws could potentially cause fatal consequences, especially in sensitive domains such as healthcare and maritime applications. However, most of the existing solutions tackle either Static Application Security Testing (SAST) or run-time behavior analysis distinctly. In this paper, we propose a) IaC Scan Runner, an open-source solution developed in Python for inspecting a variety of state-of-the-art IaC languages in application design time and b) the run time anomaly detection tool called LOMOS. Both tools work in synergy and prov...
Developers make use of automation to perform repetitive and potentially error- prone tasks. One such...
Infrastructure-as-code (IaC) is the DevOps practice enabling management and provisioning of infrastr...
Context: Security is a growing concern in many organizations. Industries developing software systems...
Security represents one of the crucial concerns when it comes to De- vOps methodology-empowered soft...
One of main benefits enabled by DevOps ideology is to automatize activities and operations related t...
The increasing use of Infrastructure as Code (IaC) in DevOps leads to benefits in speed and reliabil...
This paper examines how adding security tools to a software pipeline affect the build time. Soft...
Software assurance is of paramount importance given the increasing impact of software on our lives. ...
With the rising number of servers used in productions, virtualization technology engineers needed a ...
DevSecOps is the extension of DevOps with security aspects and tools throughout all the stages of th...
Abstract—Security vulnerabilities plague modern systems be-cause writing secure systems code is hard...
This paper presents a methodology which combines static analysis and runtime assertion checking in o...
DeVAIC (Detection of Vulnerabilities in AI-generated Code) is a static analysis tool for Python, abl...
In the digital transformation era, where cybersecurity is paramount, we present a machine learning-b...
Infrastructure-as-code (IaC) is the DevOps practice enabling management and provisioning of infrastr...
Developers make use of automation to perform repetitive and potentially error- prone tasks. One such...
Infrastructure-as-code (IaC) is the DevOps practice enabling management and provisioning of infrastr...
Context: Security is a growing concern in many organizations. Industries developing software systems...
Security represents one of the crucial concerns when it comes to De- vOps methodology-empowered soft...
One of main benefits enabled by DevOps ideology is to automatize activities and operations related t...
The increasing use of Infrastructure as Code (IaC) in DevOps leads to benefits in speed and reliabil...
This paper examines how adding security tools to a software pipeline affect the build time. Soft...
Software assurance is of paramount importance given the increasing impact of software on our lives. ...
With the rising number of servers used in productions, virtualization technology engineers needed a ...
DevSecOps is the extension of DevOps with security aspects and tools throughout all the stages of th...
Abstract—Security vulnerabilities plague modern systems be-cause writing secure systems code is hard...
This paper presents a methodology which combines static analysis and runtime assertion checking in o...
DeVAIC (Detection of Vulnerabilities in AI-generated Code) is a static analysis tool for Python, abl...
In the digital transformation era, where cybersecurity is paramount, we present a machine learning-b...
Infrastructure-as-code (IaC) is the DevOps practice enabling management and provisioning of infrastr...
Developers make use of automation to perform repetitive and potentially error- prone tasks. One such...
Infrastructure-as-code (IaC) is the DevOps practice enabling management and provisioning of infrastr...
Context: Security is a growing concern in many organizations. Industries developing software systems...