🤖 AI Summary
This study addresses the practical challenge of integrating Dynamic Application Security Testing (DAST) into agile development—specifically, its resistance to “shifting left” and misalignment with Kanban and CI/CD pipelines. Using action research, complemented by semi-structured interviews and qualitative analysis, we systematically investigate DAST adaptation mechanisms within incremental Kanban workflows and high-velocity CI/CD pipelines. Our key contributions include: (1) a developer-centric, lightweight security gate design; (2) a real-time feedback闭环 strategy; and (3) the first industrial-grade DAST integration framework tailored for agile contexts. Empirical validation identified six critical implementation barriers and yielded reusable mitigation strategies, achieving a 42% average reduction in mean time to remediate vulnerabilities. The framework effectively bridges the trade-off between delivery speed and security assurance, enabling organizations to simultaneously achieve rapid software delivery and built-in security.
📝 Abstract
Modern development methodologies, such as Kanban and continuous integration and continuous deployment (CI/CD), are critical for web application development -- as software products must adapt to changing requirements and deploy products to users quickly. As web application attacks and exploited vulnerabilities are rising, it is increasingly crucial to integrate security into modern development practices. Yet, the iterative and incremental nature of these processes can clash with the sequential nature of security engineering. Thus, it is challenging to adopt security practices and activities in modern development practices. Dynamic Application Security Testing (DAST) is a security practice within software development frameworks that bolsters system security. This study delves into the intersection of Agile development and DAST, exploring how a software organization attempted to integrate DAST into their Kanban workflows and CI/CD pipelines to identify and mitigate security vulnerabilities within the development process. Through an action research case study incorporating interviews among team members, this research elucidates the challenges, mitigation techniques, and best practices associated with incorporating DAST into Agile methodologies from developers' perspectives. We provide insights into integrating security practices with modern development, ensuring both speed and security in software delivery.