首页 | 本学科首页   官方微博 | 高级检索  
     

DevSecOps:DevOps下实现持续安全的实践探索
引用本文:戴启铭,毛润丰,黄璜,荣国平,沈海峰,邵栋. DevSecOps:DevOps下实现持续安全的实践探索[J]. 软件学报, 2021, 32(10): 3014-3035
作者姓名:戴启铭  毛润丰  黄璜  荣国平  沈海峰  邵栋
作者单位:计算机软件新技术国家重点实验室(南京大学),江苏 南京 210023;南京大学 软件学院,江苏 南京 210093;Discipline of Information Technology, Peter Faber Business School, Australian Catholic University, Sydney NSW 2060
基金项目:国家自然科学基金(62072227,61802173);国家重点研发计划(2019YFE0105500);江苏省政府间双边创新项目(BZ2020017);南京大学计算机软件新技术国家重点实验室创新项目(ZZKT2019B01)
摘    要:国内外各大软件企业正广泛实施DevOps相关实践,以提高产品交付和部署频率.与此同时,面对日益严峻的网络安全环境,软件系统中的安全问题日益凸显.耗时的安全实践因为快速交付,在软件开发活动中难以得到有效贯彻.也正因如此,在开发和运维流程中有效集成安全控制手段,实现整个软件生命周期的持续安全,已成为各大企业向DevOps转...

关 键 词:DevOps安全  DevSecOps  持续安全  DevSecOps实践
收稿时间:2020-09-15
修稿时间:2020-10-26

DevSecOps: Exploring Practices of Realizing Continuous Security in DevOps
DAI Qi-Ming,MAO Run-Feng,HUANG Huang,RONG Guo-Ping,SHEN Hai-Feng,SHAO Dong. DevSecOps: Exploring Practices of Realizing Continuous Security in DevOps[J]. Journal of Software, 2021, 32(10): 3014-3035
Authors:DAI Qi-Ming  MAO Run-Feng  HUANG Huang  RONG Guo-Ping  SHEN Hai-Feng  SHAO Dong
Affiliation:State Key Laboratory for Novel Software Technology(Nanjing University), Nanjing 210023, China;Software Institute, Nanjing University, Nanjing 210093, China;Discipline of Information Technology, Peter Faber Business School, Australian Catholic University, Sydney NSW 2060
Abstract:DevOps practices have been widely implemented by software companies to increase the frequency of product delivery and deployment. However, faced the increasingly challenging network security, security problems in software systems are becoming prominent. Time-consuming security practices are difficult to be effectively implemented in software development activities because of rapid delivery. Integration of security control measures into software processes to realize continuous security needs to be urgently investigated for companies to transit to DevOps. DevSecOps, a solution to realize continuous security in DevOps, has attracted widespread attention from academia and industry, and has also gradually become a hot research topic in the field of software engineering. In recent years, as DevSecOps research and practice develop rapidly, people have gained a more comprehensive understanding of DevSecOps and more relevant security practices have been introduced. Hence, this paper summarizes the five aspects of background, characteristics, practice, benefits, and challenges, with the aim to introduce the core content of DevSecOps to the software engineering community in China for the first time in detail. Focusing on the latest theoretical research content of DevSecOps and the current state of corporate practice, it is also aimed to provide a reference for practitioners to implement DevSecOps practices. Hopefully, this paper could provide some foundation for researchers to explore DevSecOps and call for more researchers to participate in the research of DevSecOps.
Keywords:DevOps security  DevSecOps  continuous security  DevSecOps practice
本文献已被 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号