DevSecOps:DevOps下实现持续安全的实践探索
作者:
作者单位:

作者简介:

戴启铭(1996-),男,学士,CCF学生会员,主要研究领域为软件过程改进,DevSec Ops,软件安全.
毛润丰(1996-),男,学士,CCF学生会员,主要研究领域为软件过程改进,DevSec Ops.
黄璜(1996-),男,学士,CCF学生会员,主要研究领域为软件工程中的人与社会方面.
荣国平(1977-),男,博士,副研究员,CCF专业会员,主要研究领域为软件过程实证软件工程.
沈海峰(1971-),男,博士,教授,博士生导师,主要研究领域为Software Engineering, Human Computer Interaction, Human-Centered Artificial Intelligence, Simulation and Visualization.
邵栋(1976-),男,副教授,CCF专业会员,主要研究领域为软件过程,高科技市场理论,敏捷软件开发,软件工程教育.

通讯作者:

邵栋,E-mail:dongshao@nju.edu.cn

基金项目:

国家自然科学基金(62072227,61802173);国家重点研发计划(2019YFE0105500);江苏省政府间双边创新项目(BZ2020017);南京大学计算机软件新技术国家重点实验室创新项目(ZZKT2019B01)


DevSecOps: Exploring Practices of Realizing Continuous Security in DevOps
Author:
Affiliation:

Fund Project:

National Natural Science Foundation of China (62072227, 61802173); National Key Research and Development Program of China (2019YFE0105500); Intergovernmental Bilateral Innovation Project of Jiangsu Province of China (BZ2020017); Innovation Project of State Key Laboratory for Novel Software Technology (Nanjing University) (ZZKT2019B01)

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
    摘要:

    国内外各大软件企业正广泛实施DevOps相关实践,以提高产品交付和部署频率.与此同时,面对日益严峻的网络安全环境,软件系统中的安全问题日益凸显.耗时的安全实践因为快速交付,在软件开发活动中难以得到有效贯彻.也正因如此,在开发和运维流程中有效集成安全控制手段,实现整个软件生命周期的持续安全,已成为各大企业向DevOps转型过程中亟需思考的问题.DevSecOps作为在DevOps下持续解决安全问题的有效方案,因此而受到学术界和工业界的广泛关注,并逐渐成为软件工程领域的研究重点.近年来,随着DevSecOps的研究和实践发展,人们对DevSecOps有了更全面的认识,也引入了更多安全实践.为此,从DevSecOps的背景、特征、实践、裨益和挑战这5个方面进行了归纳和总结,首次向国内软件工程社区全面介绍DevSecOps的核心内容,重点阐述了DevSecOps最新的理论研究和工业界实践现状,进而为从业者实际落地DevSecOps提供参考,也为研究者探索DevSecOps提供便利,并呼吁更多的研究者参与到DevSecOps的研究中来.

    Abstract:

    DevOps practices have been widely implemented by software companies to increase the frequency of product delivery and deployment. However, faced the increasingly challenging network security, security problems in software systems are becoming prominent. Time-consuming security practices are difficult to be effectively implemented in software development activities because of rapid delivery. Integration of security control measures into software processes to realize continuous security needs to be urgently investigated for companies to transit to DevOps. DevSecOps, a solution to realize continuous security in DevOps, has attracted widespread attention from academia and industry, and has also gradually become a hot research topic in the field of software engineering. In recent years, as DevSecOps research and practice develop rapidly, people have gained a more comprehensive understanding of DevSecOps and more relevant security practices have been introduced. Hence, this paper summarizes the five aspects of background, characteristics, practice, benefits, and challenges, with the aim to introduce the core content of DevSecOps to the software engineering community in China for the first time in detail. Focusing on the latest theoretical research content of DevSecOps and the current state of corporate practice, it is also aimed to provide a reference for practitioners to implement DevSecOps practices. Hopefully, this paper could provide some foundation for researchers to explore DevSecOps and call for more researchers to participate in the research of DevSecOps.

    参考文献
    相似文献
    引证文献
引用本文

戴启铭,毛润丰,黄璜,荣国平,沈海峰,邵栋. DevSecOps:DevOps下实现持续安全的实践探索.软件学报,2021,32(10):3014-3035

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
历史
  • 收稿日期:2020-09-15
  • 最后修改日期:2020-10-26
  • 录用日期:
  • 在线发布日期: 2021-01-15
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号