An Analysis System to Test Security of Software on Continuous Integration-Continuous Delivery Pipeline

Carmelo Aparo, C. Bernardeschi, G. Lettieri, Fabio Lucattini, Salvatore Montanarella
{"title":"An Analysis System to Test Security of Software on Continuous Integration-Continuous Delivery Pipeline","authors":"Carmelo Aparo, C. Bernardeschi, G. Lettieri, Fabio Lucattini, Salvatore Montanarella","doi":"10.1109/EuroSPW59978.2023.00012","DOIUrl":null,"url":null,"abstract":"This work presents a modular and scalable analysis system to integrate different Applications Security Testing tools inside a Continuous Integration-Continuous Delivery Pipeline. Docker containerization and tools for stateless execution allow parallelism and replication. As a result of the analysis of an application, the system execution produces as output a unique JSON report that contains all the vulnerabilities found by the tools executed, with a risk score associated to each vulnerability. Two Application Security Testing tools, OWASP ZAP and SonarQube, have been integrated using Gitlab Platform to apply DevOps methodology for java web application analysis. Results on the OWASP Benchmark test suite confirm a consistent improvement of the security analysis and allow comparison of tools accuracy by vulnerability category.","PeriodicalId":220415,"journal":{"name":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","volume":"20 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EuroSPW59978.2023.00012","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

This work presents a modular and scalable analysis system to integrate different Applications Security Testing tools inside a Continuous Integration-Continuous Delivery Pipeline. Docker containerization and tools for stateless execution allow parallelism and replication. As a result of the analysis of an application, the system execution produces as output a unique JSON report that contains all the vulnerabilities found by the tools executed, with a risk score associated to each vulnerability. Two Application Security Testing tools, OWASP ZAP and SonarQube, have been integrated using Gitlab Platform to apply DevOps methodology for java web application analysis. Results on the OWASP Benchmark test suite confirm a consistent improvement of the security analysis and allow comparison of tools accuracy by vulnerability category.
基于持续集成的软件安全性测试分析系统——持续交付管道
这项工作提出了一个模块化和可扩展的分析系统,将不同的应用程序安全测试工具集成到一个持续集成-持续交付管道中。Docker容器化和无状态执行工具允许并行和复制。作为应用程序分析的结果,系统执行产生一个唯一的JSON报告作为输出,该报告包含执行的工具发现的所有漏洞,并与每个漏洞相关联的风险评分。两个应用程序安全测试工具,OWASP ZAP和SonarQube,已经集成在Gitlab平台上,应用DevOps方法进行java web应用程序分析。OWASP基准测试套件的结果证实了安全分析的一致改进,并允许按漏洞类别比较工具的准确性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信