Ir directamente a la navegación principal Ir directamente a la búsqueda Ir directamente al contenido principal

Enhancing DevSecOps practice with Large Language Models and Security Chaos Engineering

    Producción científica: Contribución a revistaArtículo de Investigaciónrevisión exhaustiva

    Resumen

    Recently, the DevSecOps practice has improved companies’ agile production of secure software, reducing problems and improving return on investment. However, overreliance on security tools and traditional security techniques can facilitate the implementation of vulnerabilities in different stages of the software lifecycle. Thus, this paper proposes the integration of a Large Language Model to help automate threat discovery at the design stage and Security Chaos Engineering to support the identification of security flaws that may be undetected by security tools. A specific use case is described to demonstrate how our proposal can be applied to a retail company that has the business need to produce rapidly secure software.

    Idioma originalInglés estadounidense
    PublicaciónInternational Journal of Information Security
    DOI
    EstadoEn prensa - 2024

    Áreas temáticas de ASJC Scopus

    • Software
    • Sistemas de información
    • Seguridad, riesgos, fiabilidad y calidad
    • Redes de ordenadores y comunicaciones

    Huella

    Profundice en los temas de investigación de 'Enhancing DevSecOps practice with Large Language Models and Security Chaos Engineering'. En conjunto forman una huella única.

    Citar esto