Zum Hauptinhalt springen

Showing 1–4 of 4 results for author: Voggenreiter, M

Searching in archive cs. Search in all archives.
.
  1. Automated Security Findings Management: A Case Study in Industrial DevOps

    Authors: Markus Voggenreiter, Florian Angermeir, Fabiola Moyón, Ulrich Schöpp, Pierre Bonvin

    Abstract: In recent years, DevOps, the unification of development and operation workflows, has become a trend for the industrial software development lifecycle. Security activities turned into an essential field of application for DevOps principles as they are a fundamental part of secure software development in the industry. A common practice arising from this trend is the automation of security tests that… ▽ More

    Submitted 12 January, 2024; originally announced January 2024.

  2. arXiv:2211.11057  [pdf, other

    cs.CL cs.SE

    Semantic Similarity-Based Clustering of Findings From Security Testing Tools

    Authors: Phillip Schneider, Markus Voggenreiter, Abdullah Gulraiz, Florian Matthes

    Abstract: Over the last years, software development in domains with high security demands transitioned from traditional methodologies to uniting modern approaches from software development and operations (DevOps). Key principles of DevOps gained more importance and are now applied to security aspects of software development, resulting in the automation of security-enhancing activities. In particular, it is… ▽ More

    Submitted 20 November, 2022; originally announced November 2022.

    Comments: Accepted to ICNLSP 2022

  3. Using a Semantic Knowledge Base to Improve the Management of Security Reports in Industrial DevOps Projects

    Authors: Markus Voggenreiter, Ulrich Schöpp

    Abstract: Integrating security activities into the software development lifecycle to detect security flaws is essential for any project. These activities produce reports that must be managed and looped back to project stakeholders like developers to enable security improvements. This so-called Feedback Loop is a crucial part of any project and is required by various industrial security standards and models.… ▽ More

    Submitted 19 April, 2022; originally announced April 2022.

    Comments: Preprint

    ACM Class: D.2.0

  4. Enterprise-Driven Open Source Software: A Case Study on Security Automation

    Authors: Florian Angermeir, Markus Voggenreiter, Fabiola Moyón, Daniel Mendez

    Abstract: Agile and DevOps are widely adopted by the industry. Hence, integrating security activities with industrial practices, such as continuous integration (CI) pipelines, is necessary to detect security flaws and adhere to regulators' demands early. In this paper, we analyze automated security activities in CI pipelines of enterprise-driven open source software (OSS). This shall allow us, in the long-r… ▽ More

    Submitted 10 February, 2021; originally announced February 2021.

    Comments: To be published in: Proceedings of the 43rd International Conference on Software Engineering: Software Engineering in Practice (SEIP)

    ACM Class: D.2.0