A DevOps framework for quality-driven self-protection in web software systems
Nasim Beigi-Mohammadi, Marin Litoiu, Mahsa Emami-Taba, Ladan Tahvildari, Marios Fokaefs, Ettore Merlo, Iosif-Viorel Onut · PolyPublie (École Polytechnique de Montréal) · 2018
Modern software is developed, deployed and operates continuously. At the same time, cyberattacks are on the rise. The continuity of development and operations and the constant threat of attacks requires novel approaches to identify, analyze and address potential security vulnerabilities. In this continuous and volatile execution environment, factors like security, performance, cost and functionality may not be able to be guaranteed in the same degree at the same time. In this work, we propose a DevOps framework for security adaptation that enables the development and operations teams to collaborate and address security vulnerabilities. The proposed framework spans across the different phases of software (development, operations, maintenance) and considers all other factors (performance, cost, functionality), when deciding for security adaptations. We demonstrate the approach on a prototype tool that shows how teams work together to tackle security concerns.