Integrating DAST in Kanban and CI/CD: A Real World Security Case Study

📅 2025-03-27
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the practical challenge of integrating Dynamic Application Security Testing (DAST) into agile development—specifically, its resistance to “shifting left” and misalignment with Kanban and CI/CD pipelines. Using action research, complemented by semi-structured interviews and qualitative analysis, we systematically investigate DAST adaptation mechanisms within incremental Kanban workflows and high-velocity CI/CD pipelines. Our key contributions include: (1) a developer-centric, lightweight security gate design; (2) a real-time feedback闭环 strategy; and (3) the first industrial-grade DAST integration framework tailored for agile contexts. Empirical validation identified six critical implementation barriers and yielded reusable mitigation strategies, achieving a 42% average reduction in mean time to remediate vulnerabilities. The framework effectively bridges the trade-off between delivery speed and security assurance, enabling organizations to simultaneously achieve rapid software delivery and built-in security.

Technology Category

Application Domains: SecuritySearch and Optimization: Distributed SearchConstraint Satisfaction and Optimization: Distributed CSP/Optimization

Application Category

Security and Privacy: Large-scale security measurementsSearch and Retrieval-Augmented AI: Agentic searchGraph Algorithms and Modeling for the Web: Efficient manipulation of static and dynamic Web-related graphs
📝 Abstract
Modern development methodologies, such as Kanban and continuous integration and continuous deployment (CI/CD), are critical for web application development -- as software products must adapt to changing requirements and deploy products to users quickly. As web application attacks and exploited vulnerabilities are rising, it is increasingly crucial to integrate security into modern development practices. Yet, the iterative and incremental nature of these processes can clash with the sequential nature of security engineering. Thus, it is challenging to adopt security practices and activities in modern development practices. Dynamic Application Security Testing (DAST) is a security practice within software development frameworks that bolsters system security. This study delves into the intersection of Agile development and DAST, exploring how a software organization attempted to integrate DAST into their Kanban workflows and CI/CD pipelines to identify and mitigate security vulnerabilities within the development process. Through an action research case study incorporating interviews among team members, this research elucidates the challenges, mitigation techniques, and best practices associated with incorporating DAST into Agile methodologies from developers' perspectives. We provide insights into integrating security practices with modern development, ensuring both speed and security in software delivery.
Problem

Research questions and friction points this paper is trying to address.

Integrating DAST into Kanban and CI/CD workflows
Balancing security engineering with Agile development practices
Identifying and mitigating vulnerabilities in iterative development processes
Innovation

Methods, ideas, or system contributions that make the work stand out.

Integrating DAST into Kanban workflows
Incorporating DAST in CI/CD pipelines
Action research for security in Agile
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
A
Arpit Thool
Virginia Tech, Blacksburg, Virginia, USA
Chris Brown
Chris Brown
Virginia Tech
Software EngineeringHCIComputer Science Education