Resilient Cloud cluster with DevSecOps security model, automates a data analysis, vulnerability search and risk calculation
Abed Saif Ahmed Alghawli, Tamara Radivilova

TL;DR
This paper presents a resilient cloud cluster integrated with DevSecOps practices that automates vulnerability detection, risk assessment, and real-time threat modeling to enhance security in web application development.
Contribution
It introduces an automated risk assessment algorithm based on FAIR methodology, integrated into a cloud cluster deployment using Terraform and Jenkins, for continuous security monitoring.
Findings
Automated vulnerability detection during development
Real-time risk assessment with quantitative metrics
Enhanced security through continuous monitoring and adjustment
Abstract
Automated, secure software development is an important task of digitalization, which is solved with the DevSecOps approach. An important part of the DevSecOps approach is continuous risk assessment, which is necessary to identify and evaluate risk factors. Combining the development cycle with continuous risk assessment creates synergies in software development and operation and minimizes vulnerabilities. The article presents the main methods of deploying web applications, ways to increase the level of information security at all stages of product development, compares different types of infrastructures and cloud computing providers, and analyzes modern tools used to automate processes. The cloud cluster was deployed using Terraform and the Jenkins pipeline, which is written in the Groovy programming language, which checks program code for vulnerabilities and allows you to fix violations…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
