检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:戴启铭 毛润丰 黄璜 荣国平 沈海峰[3] 邵栋 DAI Qi-Ming;MAO Run-Feng;HUANG Huang;RONG Guo-Ping;SHEN Hai-Feng;SHAO Dong(State Key Laboratory for Novel Software Technology(Nanjing University),Nanjing 210023,China;Software Institute,Nanjing University,Nanjing 210093,China;Discipline of Information Technology,Peter Faber Business School,Australian Catholic University,Sydney NSW 2060)
机构地区:[1]计算机软件新技术国家重点实验室(南京大学),江苏南京210023 [2]南京大学软件学院,江苏南京210093 [3]Discipline of Information Technology,Peter Faber Business School,Australian Catholic University,Sydney NSW 2060
出 处:《软件学报》2021年第10期3014-3035,共22页Journal of Software
基 金:国家自然科学基金(62072227,61802173);国家重点研发计划(2019YFE0105500);江苏省政府间双边创新项目(BZ2020017);南京大学计算机软件新技术国家重点实验室创新项目(ZZKT2019B01)。
摘 要:国内外各大软件企业正广泛实施DevOps相关实践,以提高产品交付和部署频率.与此同时,面对日益严峻的网络安全环境,软件系统中的安全问题日益凸显.耗时的安全实践因为快速交付,在软件开发活动中难以得到有效贯彻.也正因如此,在开发和运维流程中有效集成安全控制手段,实现整个软件生命周期的持续安全,已成为各大企业向DevOps转型过程中亟需思考的问题.DevSecOps作为在DevOps下持续解决安全问题的有效方案,因此而受到学术界和工业界的广泛关注,并逐渐成为软件工程领域的研究重点.近年来,随着DevSecOps的研究和实践发展,人们对DevSecOps有了更全面的认识,也引入了更多安全实践.为此,从DevSecOps的背景、特征、实践、裨益和挑战这5个方面进行了归纳和总结,首次向国内软件工程社区全面介绍DevSecOps的核心内容,重点阐述了DevSecOps最新的理论研究和工业界实践现状,进而为从业者实际落地DevSecOps提供参考,也为研究者探索DevSecOps提供便利,并呼吁更多的研究者参与到DevSecOps的研究中来.DevOps practices have been widely implemented by software companies to increase the frequency of product delivery and deployment.However,faced the increasingly challenging network security,security problems in software systems are becoming prominent.Time-consuming security practices are difficult to be effectively implemented in software development activities because of rapid delivery.Integration of security control measures into software processes to realize continuous security needs to be urgently investigated for companies to transit to DevOps.DevSecOps,a solution to realize continuous security in DevOps,has attracted widespread attention from academia and industry,and has also gradually become a hot research topic in the field of software engineering.In recent years,as DevSecOps research and practice develop rapidly,people have gained a more comprehensive understanding of DevSecOps and more relevant security practices have been introduced.Hence,this paper summarizes the five aspects of background,characteristics,practice,benefits,and challenges,with the aim to introduce the core content of DevSecOps to the software engineering community in China for the first time in detail.Focusing on the latest theoretical research content of DevSecOps and the current state of corporate practice,it is also aimed to provide a reference for practitioners to implement DevSecOps practices.Hopefully,this paper could provide some foundation for researchers to explore DevSecOps and call for more researchers to participate in the research of DevSecOps.
关 键 词:DevOps安全 DevSecOps 持续安全 DevSecOps实践
分 类 号:TP311[自动化与计算机技术—计算机软件与理论]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.148.247.50