Better Left Shift Security! Framework for Secure Software Development

Abdallah Dawoud, Sören Finster, Nicolas Coppik, Virendra Ashiwal · 2024

The concept of security left-shifting focuses on integrating security processes, traditionally occurring later in the Software Development Life Cycle, into the early development phase. This approach is beneficial in mitigating security issues early on, before they manifest in released products, where the remediation cost is higher. In this study, we scrutinize the shift left approach from a security standpoint. We derive a set of criteria that, if satisfied, provide higher guarantees of successful left-shifting. We showcase the significance of these criteria in forming the shift left decision, showcased by left-shifting the software fuzzing operation. A holistic view of the shift left approach reveals several overarching challenges. We address these challenges in a prototypical framework that provides the basic building blocks for successfully integrating security processes into the development phase. Thus, this paper tackles several conceptual and technical challenges associated with left-shifting, forming a foundation for future works to build upon.

Read the paper · More papers on PaperTik