A DevOps Approach to the Mitigation of Security Vulnerabilities in Runtime Environments
Stefan Throner, Sebastian Abeck, Patrick Petrovic, Heiko Hütter · 2023
External sources, such as libraries and packages, are often used to accelerate software development. Whereas in-house developed code is frequently revised, dependencies to external sources or already delivered software systems often remain unchanged if the functionality fulfills the requirements. This can lead to vulnerabilities in individual components of the system over time, which can compromise the security of the entire system. The issue of outdated libraries and components increases with the number of running environments and the number of individual software modules common in cloud-native environments. Current vulnerability scanners detect a variety of known vulnerabilities, but often have problems fixing them due to a lack of integration into the developer's workflow. To prevent this, we present an approach that automatically detects known security vulnerabilities in running systems and supports the developer in closing the vulnerabilities and re-delivering the hardened software with a DevOps approach, by providing a feedback loop from the operation environments towards the development artifacts of the system.