论文标题
使用语义知识库来改善工业DevOps项目中安全报告的管理
Using a Semantic Knowledge Base to Improve the Management of Security Reports in Industrial DevOps Projects
论文作者
论文摘要
将安全活动集成到软件开发生命周期中以检测安全缺陷对于任何项目都至关重要。这些活动产生的报告必须管理并循环回到像开发人员这样的项目利益相关者,以实现安全性改进。这种所谓的反馈回路是任何项目的关键部分,是各种工业安全标准和模型所要求的。但是,此循环的操作提出了各种挑战。这些挑战范围从确保反馈数据具有足够的质量,而不是为不同的利益相关者提供所需的信息来管理报告。在本文中,我们提出了一种新颖的方法,用于将安全活动报告中的发现视为对知识库(KB)的信念。通过利用持续的逻辑推断,我们得出了从业者必要的信息,并应对行业中现有的挑战。目前,使用持续安全测试的数据在工业DevOps项目中评估了此方法。
Integrating security activities into the software development lifecycle to detect security flaws is essential for any project. These activities produce reports that must be managed and looped back to project stakeholders like developers to enable security improvements. This so-called Feedback Loop is a crucial part of any project and is required by various industrial security standards and models. However, the operation of this loop presents a variety of challenges. These challenges range from ensuring that feedback data is of sufficient quality over providing different stakeholders with the information they need to the enormous effort to manage the reports. In this paper, we propose a novel approach for treating findings from security activity reports as belief in a Knowledge Base (KB). By utilizing continuous logical inferences, we derive information necessary for practitioners and address existing challenges in the industry. This approach is currently evaluated in industrial DevOps projects, using data from continuous security testing.