The growing adoption of IT infrastructures determined a high heterogeneity of software systems. As matter of fact, the software is prone to vulnerabilities and cybersecurity problems, which are challenging to manage during the software lifecycle. The situation is further compounded by the growing demand for rapid application development and the widespread diffusion of Agile methodologies and the DevOps culture. This process promotes collaboration within and between the different groups involved in software development. In recent years there has been a spread of new or adapted security-oriented methodologies providing different approaches to identify security problems in the early stages of the software development life cycle (SDLC), thus reducing the costs for the security assessment. SecDevOps is just an example of the integration and promotion of security aspects in DevOps organizations. While these methodologies help to produce more reliable software, on other hand they are difficult to integrate into standard or customized SDLC, or with design evaluation and risk management methodologies. This work analyzes the state of the art and aims at identifying the main activities in a Secure Software Development Life Cycle (SSDLC), by proposing a new secure software development lifecycle meta-model (MetaSEnD). MetaSEnD has also been applied in a continuous integration pipeline of a sample microservices application.

MetaSEnD: A Security Enabled Development Life Cycle Meta-Model / Granata, D.; Rak, M.; Salzillo, G.. - (2022). (Intervento presentato al convegno 17th International Conference on Availability, Reliability and Security, ARES 2022 tenutosi a aut nel 2022) [10.1145/3538969.3544463].

MetaSEnD: A Security Enabled Development Life Cycle Meta-Model

Granata D.;Rak M.;
2022

Abstract

The growing adoption of IT infrastructures determined a high heterogeneity of software systems. As matter of fact, the software is prone to vulnerabilities and cybersecurity problems, which are challenging to manage during the software lifecycle. The situation is further compounded by the growing demand for rapid application development and the widespread diffusion of Agile methodologies and the DevOps culture. This process promotes collaboration within and between the different groups involved in software development. In recent years there has been a spread of new or adapted security-oriented methodologies providing different approaches to identify security problems in the early stages of the software development life cycle (SDLC), thus reducing the costs for the security assessment. SecDevOps is just an example of the integration and promotion of security aspects in DevOps organizations. While these methodologies help to produce more reliable software, on other hand they are difficult to integrate into standard or customized SDLC, or with design evaluation and risk management methodologies. This work analyzes the state of the art and aims at identifying the main activities in a Secure Software Development Life Cycle (SSDLC), by proposing a new secure software development lifecycle meta-model (MetaSEnD). MetaSEnD has also been applied in a continuous integration pipeline of a sample microservices application.
2022
MetaSEnD: A Security Enabled Development Life Cycle Meta-Model / Granata, D.; Rak, M.; Salzillo, G.. - (2022). (Intervento presentato al convegno 17th International Conference on Availability, Reliability and Security, ARES 2022 tenutosi a aut nel 2022) [10.1145/3538969.3544463].
File in questo prodotto:
File Dimensione Formato  
SEC_DEV_OPS_AUTOMA__SSE2022_-3.pdf

non disponibili

Licenza: Non specificato
Dimensione 856.14 kB
Formato Adobe PDF
856.14 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11588/986003
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? 1
social impact