Enhancing DevSecOps Pipelines with AI-Driven Threat Detection and Response
Semi Yulianto, Gerard Nathaniel Cac Ngo · 2024
DevSecOps incorporates security into the software development lifecycle, enhancing application delivery. This study proposes an AI-driven framework to address traditional security limitations. Partnering with a crypto asset exchange, we tested our framework on 8,000 events, including 15% security incidents. Despite data preparation challenges, our machine learning models-convolutional neural networks, long short-term memory networks, and autoencoders-demonstrated high performance. The framework achieved an average F1-score of 0.92 and increased threat detection accuracy by 25% compared to rule-based methods. These results significantly improve the security posture of DevSecOps environments without compromising development speed. Our research offers a scalable, adaptable approach, laying the foundation for resilient software development practices. Future work will focus on model interpretability and broader security event coverage.