| 本文已被:浏览 3236次 下载 6232次 |
 码上扫一扫! |
|
|
| DevSecOps:DevOps下实现持续安全的实践探索 |
|
戴启铭1,2, 毛润丰1,2, 黄璜1,2, 荣国平1,2, 沈海峰3, 邵栋1,2
|
|
1.计算机软件新技术国家重点实验室(南京大学), 江苏 南京 210023;2.南京大学 软件学院, 江苏 南京 210093;3.Discipline of Information Technology, Peter Faber Business School, Australian Catholic University, Sydney NSW 2060
|
|
| 摘要: |
| 国内外各大软件企业正广泛实施DevOps相关实践,以提高产品交付和部署频率.与此同时,面对日益严峻的网络安全环境,软件系统中的安全问题日益凸显.耗时的安全实践因为快速交付,在软件开发活动中难以得到有效贯彻.也正因如此,在开发和运维流程中有效集成安全控制手段,实现整个软件生命周期的持续安全,已成为各大企业向DevOps转型过程中亟需思考的问题.DevSecOps作为在DevOps下持续解决安全问题的有效方案,因此而受到学术界和工业界的广泛关注,并逐渐成为软件工程领域的研究重点.近年来,随着DevSecOps的研究和实践发展,人们对DevSecOps有了更全面的认识,也引入了更多安全实践.为此,从DevSecOps的背景、特征、实践、裨益和挑战这5个方面进行了归纳和总结,首次向国内软件工程社区全面介绍DevSecOps的核心内容,重点阐述了DevSecOps最新的理论研究和工业界实践现状,进而为从业者实际落地DevSecOps提供参考,也为研究者探索DevSecOps提供便利,并呼吁更多的研究者参与到DevSecOps的研究中来. |
| 关键词: DevOps安全 DevSecOps 持续安全 DevSecOps实践 |
| DOI:10.13328/j.cnki.jos.006276 |
| 分类号:TP311 |
| 基金项目:国家自然科学基金(62072227,61802173);国家重点研发计划(2019YFE0105500);江苏省政府间双边创新项目(BZ2020017);南京大学计算机软件新技术国家重点实验室创新项目(ZZKT2019B01) |
|
| DevSecOps: Exploring Practices of Realizing Continuous Security in DevOps |
|
DAI Qi-Ming1,2, MAO Run-Feng1,2, HUANG Huang1,2, RONG Guo-Ping1,2, SHEN Hai-Feng3, SHAO Dong1,2
|
|
1.State Key Laboratory for Novel Software Technology(Nanjing University), Nanjing 210023, China;2.Software Institute, Nanjing University, Nanjing 210093, China;3.Discipline of Information Technology, Peter Faber Business School, Australian Catholic University, Sydney NSW 2060
|
| Abstract: |
| DevOps practices have been widely implemented by software companies to increase the frequency of product delivery and deployment. However, faced the increasingly challenging network security, security problems in software systems are becoming prominent. Time-consuming security practices are difficult to be effectively implemented in software development activities because of rapid delivery. Integration of security control measures into software processes to realize continuous security needs to be urgently investigated for companies to transit to DevOps. DevSecOps, a solution to realize continuous security in DevOps, has attracted widespread attention from academia and industry, and has also gradually become a hot research topic in the field of software engineering. In recent years, as DevSecOps research and practice develop rapidly, people have gained a more comprehensive understanding of DevSecOps and more relevant security practices have been introduced. Hence, this paper summarizes the five aspects of background, characteristics, practice, benefits, and challenges, with the aim to introduce the core content of DevSecOps to the software engineering community in China for the first time in detail. Focusing on the latest theoretical research content of DevSecOps and the current state of corporate practice, it is also aimed to provide a reference for practitioners to implement DevSecOps practices. Hopefully, this paper could provide some foundation for researchers to explore DevSecOps and call for more researchers to participate in the research of DevSecOps. |
| Key words: DevOps security DevSecOps continuous security DevSecOps practice |