Efficient secure DevOps using process mining and Attack Defense Trees
Takao Okubo, Haruhiko Kaiya · Procedia Computer Science · 2022
In this paper, we propose a method to efficiently ensure security in the DevOps lifecycle through operations and development. To ensure sufficient security in DevOps, it is essential to perform sufficient threat analysis during development. However, threat analysis is generally a heavy task and difficult to apply to agile processes. In addition, existing technologies are not sufficient for security feedback from Dev to Ops and Ops to Dev, which are important elements of DevOps. In this paper, we propose a method for detecting attacks using anomaly detection from operation logs, and extracting vulnerabilities and candidate countermeasures using information such as CAPEC and CWE. Furthermore, we propose a method to determine the excess or deficiency of the countermeasure by comparing it with the Attack-Defense Trees created in the previous development. By applying our proposal to an actual development case, we confirm that the proposed method works effectively.