Inicio  /  Computers  /  Vol: 8 Par: 4 (2019)  /  Artículo
ARTÍCULO
TITULO

Design and Implementation of SFCI: A Tool for Security Focused Continuous Integration

Michael Lescisin    
Qusay H. Mahmoud and Anca Cioraca    

Resumen

Software security is a component of software development that should be integrated throughout its entire development lifecycle, and not simply as an afterthought. If security vulnerabilities are caught early in development, they can be fixed before the software is released in production environments. Furthermore, finding a software vulnerability early in development will warn the programmer and lessen the likelihood of this type of programming error being repeated in other parts of the software project. Using Continuous Integration (CI) for checking for security vulnerabilities every time new code is committed to a repository can alert developers of security flaws almost immediately after they are introduced. Finally, continuous integration tests for security give software developers the option of making the test results public so that users or potential users are given assurance that the software is well tested for security flaws. While there already exists general-purpose continuous integration tools such as Jenkins-CI and GitLab-CI, our tool is primarily focused on integrating third party security testing programs and generating reports on classes of vulnerabilities found in a software project. Our tool performs all tests in a snapshot (stateless) virtual machine to be able to have reproducible tests in an environment similar to the deployment environment. This paper introduces the design and implementation of a tool for security-focused continuous integration. The test cases used demonstrate the ability of the tool to effectively uncover security vulnerabilities even in open source software products such as ImageMagick and a smart grid application, Emoncms.

 Artículos similares

       
 
João Paulo Oliveira Marum, H. Conrad Cunningham, J. Adam Jones and Yi Liu    
Two recent studies addressed the problem of reducing transitional turbulence in applications developed in C# on .NET. The first study investigated this problem in desktop and Web GUI applications and the second in virtual and augmented reality applicatio... ver más
Revista: Algorithms

 
Padmanabhan Balasubramanian and Nikos E. Mastorakis    
Multiplication is a fundamental arithmetic operation in electronic processing units such as microprocessors and digital signal processors as it plays an important role in various computational tasks and applications. There exist many designs of synchrono... ver más

 
Lucas Schmidt Goecks, Anderson Felipe Habekost, Antonio Maria Coruzzolo and Miguel Afonso Sellitto    
Digital transformations in manufacturing systems confer advantages for enhancing competitiveness and ensuring the survival of companies by reducing operating costs, improving quality, and fostering innovation, falling within the overarching umbrella of I... ver más

 
Liangtian Wang, Jie Zhou, Yuexin Chang and Hao Xu    
In recent years, electrochemical descaling technology has gained widespread attention due to its environmental friendliness and ease of operation. However, its single-pass removal efficiency could be higher, severely limiting its practical application. T... ver más
Revista: Water

 
Hosin Lee, Byungkyu Moon and Jeongbeom Lee    
The need to incorporate sustainability principles and practices is increasing for environmental and economic reasons. It is imperative to identify and operationalize sustainability strategies into core administrative, planning, design, construction, oper... ver más
Revista: Infrastructures