Skip to main content
QUICK REVIEW

[논문 리뷰] Challenges and solutions when adopting DevSecOps: A systematic review

Roshan Namal Rajapakse, Mansooreh Zahedi|arXiv (Cornell University)|2021. 03. 15.
Software Engineering Techniques and Practices참고 문헌 42인용 수 15
한 줄 요약

이 체계적 문헌 고찰은 DevSecOps 도입 시 21개의 핵심 과제와 31개의 해결책을 규명하며, 이를 사람, 관행, 도구, 인프라 주제로 분류한다. 연구는 특히 지속적 보안 평가 및 수동 관행 통합 분야에서의 자동화 격차를 부각시키며, 개발자 중심의 도구와 사회기술적 연구의 필요성을 강조하여 DevOps 파이프라인에서 속도와 보안의 균형을 이루도록 당부한다.

ABSTRACT

Context: DevOps has become one of the fastest-growing software development paradigms in the industry. However, this trend has presented the challenge of ensuring secure software delivery while maintaining the agility of DevOps. The efforts to integrate security in DevOps have resulted in the DevSecOps paradigm, which is gaining significant interest from both industry and academia. However, the adoption of DevSecOps in practice is proving to be a challenge. Objective: This study aims to systemize the knowledge about the challenges faced by practitioners when adopting DevSecOps and the proposed solutions reported in the literature. We also aim to identify the areas that need further research in the future. Method: We conducted a Systematic Literature Review of 54 peer-reviewed studies. The thematic analysis method was applied to analyze the extracted data. Results: We identified 21 challenges related to adopting DevSecOps, 31 specific solutions, and the mapping between these findings. We also determined key gap areas in this domain by holistically evaluating the available solutions against the challenges. The results of the study were classified into four themes: People, Practices, Tools, and Infrastructure. Our findings demonstrate that tool-related challenges and solutions were the most frequently reported, driven by the need for automation in this paradigm. Shift-left security and continuous security assessment were two key practices recommended for DevSecOps. Conclusions: We highlight the need for developer-centered application security testing tools that target the continuous practices in DevSecOps. More research is needed on how the traditionally manual security practices can be automated to suit rapid software deployment cycles. Finally, achieving a suitable balance between the speed of delivery and security is a significant issue practitioners face in the DevSecOps paradigm.

연구 동기 및 목표

  • 피어 리뷰된 문헌을 바탕으로 DevSecOps 도입 과제 및 해결책에 대한 지식을 체계화하기 위해.
  • DevOps 파이프라인에 보안을 통합할 때 실무자들이 겪는 주요 장벽을 특정하기 위해.
  • 과제를 제안된 해결책과 연결하고 현재 연구 및 실무의 격차를 드러내기 위해.
  • 특히 사회기술적 요인과 수동 보안 관행의 자동화 분야에서 연구가 부족한 영역을 부각하기 위해.
  • 안정적이고 민첩한 소프트웨어 배포를 위한 도구, 관행, 인프라 분야의 주제적 격차를 식별하여 향후 연구를 안내하기 위해.

제안 방법

  • 선택된 데이터베이스 및 출판사에서 54篇의 피어 리뷰된 논문을 대상으로 체계적 문헌 고찰(SLR)을 수행하였다.
  • 결과 누락을 최소화하기 위해 반복적 검색어 최적화 및 후행/선행 스노우볼링 기법을 적용하였다.
  • 선택 및 추출 편향을 줄이기 위해 사전 정의된 프rotocol를 사용하고 이중 데이터 추출 및 상호 검증을 실시하였다.
  • 주제 분석을 수행하여 과제와 해결책을 사람, 관행, 도구, 인프라의 네 가지 주제로 분류하였다.
  • 과제를 주제별로 해결책과 연결하고, 해결책 커버리지 평가를 통해 연구 격차를 규명하였다.
  • 부정적 결과(예: 도입 과제)의 포함 여부를 기록하여 발표 편향을 평가하고, 결과에 미치는 영향을 감소시켰다.

실험 결과

연구 질문

  • RQ1DevSecOps를 도입할 때 실무자들이 겪는 주요 과제는 무엇인가?
  • RQ2문헌에서 이러한 과제를 해결하기 위해 제안된 해결책(가이드라인, 프레임워크, 도구, 또는 관행)은 무엇인가?
  • RQ3제안된 해결책은 특정 과제와 어떻게 연결되어 있으며, 커버리지에 어떤 격차가 존재하는가?
  • RQ4사람, 관행, 도구, 인프라 주제 중 현재 DevSecOps 연구 및 실무에서 가장 빈도가 높은 주제는 무엇인가?
  • RQ5DevSecOps 도입에 있어 향후 연구에 있어 주요 해결이 필요한 미충족된 필요는 무엇인가?

주요 결과

  • 도구 관련 과제와 해결책이 가장 빈번히 보고되었으며, 이는 DevSecOps 파이프라인에서의 자동화 필요성에서 기인한다.
  • 시프트-레프트 보안 및 지속적 보안 평가는 보안을 조기에 통합하고 지속 가능하게 유지하기 위해 일관되게 권장되는 관행이다.
  • 기존 수동 보안 관행(예: 코드 리뷰, 침투 테스트)의 자동화에 큰 격차가 존재하여 빠른 DevOps 사이클에 통합하는 데 장애가 된다.
  • 문화적 저항과 보안 인식 부족 등의 사람 관련 과제는 핵심적이지만 연구가 부족하여 모든 주제에 걸쳐 도입에 영향을 미친다.
  • 다수의 과제와 해결책이 주제 간 상호연결되어 있어 효과적인 DevSecOps 구현을 위해 통합적이고 다주제적 평가가 필수적임을 시사한다.
  • 특히 컨테이너 기반 및 클라우드 네이티브 환경에서의 빠른 속도와 보안 요구를 충족시키기 위해 하이브리드 또는 IAST 기반 신규 도구의 필요성이 증가하고 있다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.