Creating it from SCRATCh: A Practical Approach for Enhancing the Security of IoT-Systems in a DevOps-enabled Software Development Environment
Simon D Duque Anton, Daniel Fraunholz, Daniel Krohmer, Daniel Reti,, Hans D Schotten, Franklin Selgert, Marcell Marosv\"olgyi, Morten Larsen,, Krishna Sudhakar, Tobias Koch, Till Witt, C\'edric Bassem

TL;DR
This paper presents a practical approach to enhance IoT security within DevOps environments by identifying tooling gaps and proposing solutions developed in the SCRATCh project, addressing challenges of security integration in distributed IoT systems.
Contribution
It introduces a comprehensive overview of DevOps tooling for IoT, identifies security gaps, and proposes solutions tailored for IoT in DevOps workflows, based on the SCRATCh project.
Findings
Identified security gaps in DevOps tooling for IoT
Proposed solutions improve security integration in IoT DevOps processes
Enhanced understanding of IoT-specific challenges in DevOps environments
Abstract
DevOps describes a method to reorganize the way different disciplines in software engineering work together to speed up software delivery. However, the introduction of DevOps-methods to organisations is a complex task. A successful introduction results in a set of structured process descriptions. Despite the structure, this process leaves margin for error: Especially security issues are addressed in individual stages, without consideration of the interdependence. Furthermore, applying DevOps-methods to distributed entities, such as the Internet of Things (IoT) is difficult as the architecture is tailormade for desktop and cloud resources. In this work, an overview of tooling employed in the stages of DevOps processes is introduced. Gaps in terms of security or applicability to the IoT are derived. Based on these gaps, solutions that are being developed in the course of the research…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
