Skip to main content
QUICK REVIEW

[论文解读] Challenges and solutions when adopting DevSecOps: A systematic review

Roshan Namal Rajapakse, Mansooreh Zahedi|arXiv (Cornell University)|Mar 15, 2021
Software Engineering Techniques and Practices参考文献 42被引用 15
一句话总结

本篇系统性文献回顾识别出DevSecOps采纳过程中的21项关键挑战与31项解决方案,并将其归类为人员(People)、实践(Practices)、工具(Tools)和基础设施(Infrastructure)四大主题。研究揭示了自动化方面的缺口,尤其是在持续安全评估与手动实践集成方面,并呼吁开发面向开发者工具以及开展社会技术研究,以在DevOps流水线中实现速度与安全性的平衡。

ABSTRACT

Context: DevOps has become one of the fastest-growing software development paradigms in the industry. However, this trend has presented the challenge of ensuring secure software delivery while maintaining the agility of DevOps. The efforts to integrate security in DevOps have resulted in the DevSecOps paradigm, which is gaining significant interest from both industry and academia. However, the adoption of DevSecOps in practice is proving to be a challenge. Objective: This study aims to systemize the knowledge about the challenges faced by practitioners when adopting DevSecOps and the proposed solutions reported in the literature. We also aim to identify the areas that need further research in the future. Method: We conducted a Systematic Literature Review of 54 peer-reviewed studies. The thematic analysis method was applied to analyze the extracted data. Results: We identified 21 challenges related to adopting DevSecOps, 31 specific solutions, and the mapping between these findings. We also determined key gap areas in this domain by holistically evaluating the available solutions against the challenges. The results of the study were classified into four themes: People, Practices, Tools, and Infrastructure. Our findings demonstrate that tool-related challenges and solutions were the most frequently reported, driven by the need for automation in this paradigm. Shift-left security and continuous security assessment were two key practices recommended for DevSecOps. Conclusions: We highlight the need for developer-centered application security testing tools that target the continuous practices in DevSecOps. More research is needed on how the traditionally manual security practices can be automated to suit rapid software deployment cycles. Finally, achieving a suitable balance between the speed of delivery and security is a significant issue practitioners face in the DevSecOps paradigm.

研究动机与目标

  • 基于同行评审文献,系统化整理DevSecOps采纳过程中挑战与解决方案的知识。
  • 识别从业者在将安全集成到DevOps流水线时面临的主要障碍。
  • 将挑战与提出的解决方案进行映射,揭示当前研究与实践中的缺口。
  • 突出研究不足的领域,特别是社会技术因素以及手动安全实践的自动化问题。
  • 通过识别工具、实践与基础设施方面在主题上的研究缺口,为未来研究提供指导。

提出的方法

  • 对来自选定数据库和出版商的54篇同行评审研究进行了系统性文献回顾(SLR)。
  • 通过迭代式搜索字符串优化以及前后向滚雪球法,最大限度减少遗漏研究。
  • 采用预定义的协议,实施双人数据提取并交叉核对,以降低选择与提取偏差。
  • 通过主题分析,将挑战与解决方案分类为四大主题:人员、实践、工具与基础设施。
  • 从主题角度对挑战与解决方案进行映射,并评估解决方案的覆盖程度,以识别研究缺口。
  • 通过记录负面结果(如采纳挑战)的纳入情况,评估发表偏倚,降低其对研究发现的影响。

实验结果

研究问题

  • RQ1从业者在采纳DevSecOps时面临的主要挑战是什么?
  • RQ2文献中提出了哪些解决方案——包括指南、框架、工具或实践——以应对这些挑战?
  • RQ3所提出的解决方案如何与已识别的挑战相对应?在哪些方面存在覆盖缺口?
  • RQ4在当前的DevSecOps研究与实践中,哪些主题(人员、实践、工具、基础设施)占据主导地位?
  • RQ5未来DevSecOps采纳研究中存在哪些关键未满足的需求?

主要发现

  • 与工具相关的挑战与解决方案报告频率最高,这源于DevSecOps流水线中对自动化的迫切需求。
  • 持续推行左移安全与持续安全评估被一致推荐,以实现安全的早期嵌入与可持续性。
  • 在自动化传统上依赖人工的安全实践(如代码审查与渗透测试)方面存在显著缺口,这阻碍了其与快速DevOps周期的整合。
  • 与人员相关的挑战——如文化抵制与安全意识不足——虽具关键影响但研究不足,对所有主题的采纳均造成影响。
  • 许多挑战与解决方案在不同主题间相互关联,表明有效实施DevSecOps需要整体性、跨主题的评估。
  • 对新型工具(如混合型或IAST工具)的需求日益增长,以更好地满足现代DevOps对速度与安全性的双重需求,特别是在容器化与云原生环境中。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。