secure sdlc

Designs and implements processes, policies, and automated tooling that integrate security throughout the software development lifecycle (SDLC). This work produces secure design artifacts and standards, CI/CD security gates and automated security tests for code, dependencies, and configurations, plus metrics and remediation workflows, and analyzes SDLC pipelines to reduce vulnerabilities and ensure consistent security controls.

securesdlc

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.99
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$203K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

To address the challenges of identifying static security vulnerabilities in proprietary and open-source software, unclear vulnerability remediation priorities, and escalating software supply chain risks, this paper proposes an end-to-end, customizable Static Application Security Testing (SAST) workflow. The workflow enables multi-tool orchestration, iterative scanning, and seamless DevSecOps integration, incorporating AI-driven vulnerability prioritization and automated remediation governance as key innovations. Leveraging a generalized process design with environment-adaptive configuration, it significantly improves detection coverage and remediation efficiency. Experimental evaluation in industrial settings demonstrates that the approach reduces source-code-level vulnerabilities by 32.7%, mitigates third-party component–introduced risks by 41.5%, and ensures backward compatibility with legacy systems while supporting scalable deployment across heterogeneous environments.

Creating configurable DevSecOps workflow for prioritized vulnerability remediationDeveloping adaptable process for scanning proprietary and open-source software vulnerabilitiesReducing source code vulnerabilities and supply chain risks in SDLC

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines

Jun 06, 2025
SD
Sowmiya Dhandapani
🏛️ Independent Cyber Security Researcher

This paper addresses the insufficient identification and mitigation of software supply chain security risks throughout the CI/CD pipeline lifecycle. We propose a structured threat modeling methodology grounded in the STRIDE framework, applied incrementally across core infrastructure components—including GitHub, Jenkins, Docker, and Kubernetes—to cover all phases from source code management to production deployment. A novel integration of STRIDE with the SLSA maturity model enables quantitative assessment of how specific security controls elevate SLSA compliance levels. By unifying Security as Code principles with the “Shift Left–Shield Right” paradigm, our approach realizes threat-driven, automated security enforcement. The outcomes include a structured threat–control mapping matrix and an actionable CI/CD security hardening roadmap, directly supporting DevSecOps adoption and progressive SLSA compliance advancement.

Analyzing vulnerabilities from source code to deployment with GitHub, Jenkins, Docker, KubernetesEnhancing CI/CD security via NIST, OWASP, and SLSA-based controls and toolchain integrationIdentifying and mitigating risks in CI/CD pipelines using STRIDE threat modeling

An Exploratory Study on the Engineering of Security Features

Jan 20, 2025
KH
Kevin Hermann
🏛️ Ruhr University Bochum | XITASO GmbH | Chalmers University of Technology | University of Gothenburg

Prior security development research lacks empirical grounding, particularly regarding engineers’ practical challenges in industrially engineering and maintaining security features (e.g., encryption, access control). Method: We conducted a qualitative study involving semi-structured interviews with 26 experienced practitioners, followed by thematic coding to empirically validate and refine four prevalent industry assumptions. Contribution/Results: We identify three core challenges: (1) ambiguous security trade-off decisions, (2) severe documentation deficits, and (3) excessive maintenance burden during system evolution. We further characterize recurring code patterns and maintenance bottlenecks associated with security features. This work fills a critical gap in empirical security engineering research and provides actionable, evidence-based insights for designing security tools, IDE plugins, and engineering guidelines—thereby bridging the theory–practice divide in secure software development.

Practical ApplicationSecurity FeaturesSoftware Developers

This study addresses the significant abstraction gap between security-by-design specifications—typically expressed in domain-specific languages (DSLs)—and code-level analyzers, which impedes the traceability of design intent to implementation vulnerabilities. It presents the first large-scale empirical investigation, examining 559 security checks across 36 analyzers and 66 security design DSLs. The authors introduce SecLan, a unified model that captures shared security concepts between these two layers, and validate its structure through expert evaluation involving 22 practitioners and qualitative interviews with 9 additional experts. The findings reveal a pronounced mismatch between security concepts at the design and implementation levels, with existing analyzer checks often relying on overly broad vulnerability descriptions, leading to ambiguous mappings. This work provides both an empirical foundation and a modeling framework to bridge the gap between security design and implementation.

abstraction gapcode analyzersdomain-specific languages

Latest Papers

What's happening recently
View more

本文探讨了通过整合数据工程和软件工程实践(如DataOps、MLOps等)来重塑面向数据和AI系统的软件开发生命周期,以应对传统SDLC在处理这些系统时遇到的挑战。

AI-enabled systemsdata-intensive systemsDataOps

This work addresses the fragility, inefficiency, and strong platform coupling commonly found in CI/CD pipelines for legacy COBOL systems, which often result in high maintenance costs and vendor lock-in. To overcome these challenges, the authors propose a portable CI/CD architecture tailored for highly secure and compliance-driven environments. The approach leverages OCI-compliant container images preloaded with COBOL toolchains, introduces a platform abstraction layer, integrates multiple repositories, and employs Groovy script refactoring to achieve platform-agnostic continuous integration and delivery. Empirical evaluation demonstrates that the proposed solution significantly enhances efficiency—reducing pipeline execution time by 82%—while simultaneously improving system portability, security, and maintainability. This architecture offers a reusable paradigm for modernizing legacy COBOL applications within regulated domains.

CI/CDCOBOLlegacy systems

This work addresses the limitations of existing large language models, which are typically confined to isolated tasks and struggle to integrate into industrial-scale, multi-stage security workflows. To bridge this gap, the authors propose the first role-based multi-agent framework tailored to the entire vulnerability lifecycle, incorporating specialized agents—Planner, Analyzer, Fixer, and Verifier—augmented with CodeQL static analysis for enhanced precision. By introducing a role-oriented multi-agent architecture into end-to-end vulnerability management, this approach effectively aligns the capabilities of large models with real-world security engineering demands. Evaluated on 25 real-world C/C++ vulnerabilities, the system achieves a detection accuracy of 44%—comparable to GPT-5.5—and a repair accuracy of 19%, offering a practical and collaborative paradigm for intelligent security operations.

LLM-based securityrole-based agentic architecturesecure software engineering

This study addresses the limitation of existing evaluations that focus solely on final code while overlooking safety risks in the intermediate processes of LLM-based coding agents. To this end, it proposes "Safety Debt Line Integral," a novel trajectory-level metric. By integrating Static Application Security Testing (SAST) with Common Weakness Enumeration (CWE) classification, this method dynamically correlates code evolution with static scanning results to quantify the cumulative risk incurred as agents improve test pass rates. Empirical analyses on benchmarks such as SWE-bench reveal low agreement among multiple detection tools and demonstrate that the proposed metric effectively tracks both development progress and safety debt simultaneously. Ultimately, this work offers a new perspective for the safety-aligned steering of autonomous coding agents.

intermediate code statesLLM coding agentssecurity debt

This study addresses the challenge of identifying security weaknesses during the requirements and design phases prior to implementation by proposing a threat modeling framework based on multi-agent large language models. The framework parses system architecture diagrams to generate attack trees, analyzes trust boundaries and data flows, and recommends mitigation strategies. Its core innovation lies in eliminating reliance on conventional CWE retrieval; instead, it employs misuse cases to correlate components and attack paths while introducing an iterative validation loop to enhance traceability and practical applicability. Experimental evaluations conducted on Microsoft reference scenarios and open systems demonstrate that the proposed approach significantly outperforms existing baselines in review quality, effectiveness, and attack tree construction.

Attack TreesDesign-Time SecuritySecurity Analysis

Hot Scholars

SD

Sagar Dasgupta

University of Alabama
ITSCPSTransportation Digital TwinGNSS
CM

Chris M. Ward

Fire Mountain Labs
Computer VisionAI SecurityAI Red Teaming
JH

Josh Harguess

Fire Mountain Labs
AI & Machine Learning SecurityComputer VisionPattern RecognitionMachine Learning
MR

Md Rayhanur Rahman

Assistant Professor, University of Alabama
Software securitycyberthreat intelligencemachine learning
CI

Clemente Izurieta

Professor of Computer Science, Software Engineering and Cybersecurity Lab, Montana State University
software engineeringdesign patternstechnical debtempirical methods