Carmelo Aparo, C. Bernardeschi, G. Lettieri, Fabio Lucattini, Salvatore Montanarella
{"title":"An Analysis System to Test Security of Software on Continuous Integration-Continuous Delivery Pipeline","authors":"Carmelo Aparo, C. Bernardeschi, G. Lettieri, Fabio Lucattini, Salvatore Montanarella","doi":"10.1109/EuroSPW59978.2023.00012","DOIUrl":null,"url":null,"abstract":"This work presents a modular and scalable analysis system to integrate different Applications Security Testing tools inside a Continuous Integration-Continuous Delivery Pipeline. Docker containerization and tools for stateless execution allow parallelism and replication. As a result of the analysis of an application, the system execution produces as output a unique JSON report that contains all the vulnerabilities found by the tools executed, with a risk score associated to each vulnerability. Two Application Security Testing tools, OWASP ZAP and SonarQube, have been integrated using Gitlab Platform to apply DevOps methodology for java web application analysis. Results on the OWASP Benchmark test suite confirm a consistent improvement of the security analysis and allow comparison of tools accuracy by vulnerability category.","PeriodicalId":220415,"journal":{"name":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","volume":"20 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EuroSPW59978.2023.00012","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
This work presents a modular and scalable analysis system to integrate different Applications Security Testing tools inside a Continuous Integration-Continuous Delivery Pipeline. Docker containerization and tools for stateless execution allow parallelism and replication. As a result of the analysis of an application, the system execution produces as output a unique JSON report that contains all the vulnerabilities found by the tools executed, with a risk score associated to each vulnerability. Two Application Security Testing tools, OWASP ZAP and SonarQube, have been integrated using Gitlab Platform to apply DevOps methodology for java web application analysis. Results on the OWASP Benchmark test suite confirm a consistent improvement of the security analysis and allow comparison of tools accuracy by vulnerability category.