Score
Designs and implements processes, policies, and automated tooling that integrate security throughout the software development lifecycle (SDLC). This work produces secure design artifacts and standards, CI/CD security gates and automated security tests for code, dependencies, and configurations, plus metrics and remediation workflows, and analyzes SDLC pipelines to reduce vulnerabilities and ensure consistent security controls.
本文针对软件开发过程中早期识别和修复安全漏洞的问题,提出了一种将静态应用安全测试工具输出集成到CI/CD流水线及问题跟踪软件中的自动化方法。
To address the challenges of identifying static security vulnerabilities in proprietary and open-source software, unclear vulnerability remediation priorities, and escalating software supply chain risks, this paper proposes an end-to-end, customizable Static Application Security Testing (SAST) workflow. The workflow enables multi-tool orchestration, iterative scanning, and seamless DevSecOps integration, incorporating AI-driven vulnerability prioritization and automated remediation governance as key innovations. Leveraging a generalized process design with environment-adaptive configuration, it significantly improves detection coverage and remediation efficiency. Experimental evaluation in industrial settings demonstrates that the approach reduces source-code-level vulnerabilities by 32.7%, mitigates third-party component–introduced risks by 41.5%, and ensures backward compatibility with legacy systems while supporting scalable deployment across heterogeneous environments.
This paper addresses the insufficient identification and mitigation of software supply chain security risks throughout the CI/CD pipeline lifecycle. We propose a structured threat modeling methodology grounded in the STRIDE framework, applied incrementally across core infrastructure components—including GitHub, Jenkins, Docker, and Kubernetes—to cover all phases from source code management to production deployment. A novel integration of STRIDE with the SLSA maturity model enables quantitative assessment of how specific security controls elevate SLSA compliance levels. By unifying Security as Code principles with the “Shift Left–Shield Right” paradigm, our approach realizes threat-driven, automated security enforcement. The outcomes include a structured threat–control mapping matrix and an actionable CI/CD security hardening roadmap, directly supporting DevSecOps adoption and progressive SLSA compliance advancement.
Prior security development research lacks empirical grounding, particularly regarding engineers’ practical challenges in industrially engineering and maintaining security features (e.g., encryption, access control). Method: We conducted a qualitative study involving semi-structured interviews with 26 experienced practitioners, followed by thematic coding to empirically validate and refine four prevalent industry assumptions. Contribution/Results: We identify three core challenges: (1) ambiguous security trade-off decisions, (2) severe documentation deficits, and (3) excessive maintenance burden during system evolution. We further characterize recurring code patterns and maintenance bottlenecks associated with security features. This work fills a critical gap in empirical security engineering research and provides actionable, evidence-based insights for designing security tools, IDE plugins, and engineering guidelines—thereby bridging the theory–practice divide in secure software development.
This study addresses the significant abstraction gap between security-by-design specifications—typically expressed in domain-specific languages (DSLs)—and code-level analyzers, which impedes the traceability of design intent to implementation vulnerabilities. It presents the first large-scale empirical investigation, examining 559 security checks across 36 analyzers and 66 security design DSLs. The authors introduce SecLan, a unified model that captures shared security concepts between these two layers, and validate its structure through expert evaluation involving 22 practitioners and qualitative interviews with 9 additional experts. The findings reveal a pronounced mismatch between security concepts at the design and implementation levels, with existing analyzer checks often relying on overly broad vulnerability descriptions, leading to ambiguous mappings. This work provides both an empirical foundation and a modeling framework to bridge the gap between security design and implementation.
本文探讨了通过整合数据工程和软件工程实践(如DataOps、MLOps等)来重塑面向数据和AI系统的软件开发生命周期,以应对传统SDLC在处理这些系统时遇到的挑战。
This work addresses the fragility, inefficiency, and strong platform coupling commonly found in CI/CD pipelines for legacy COBOL systems, which often result in high maintenance costs and vendor lock-in. To overcome these challenges, the authors propose a portable CI/CD architecture tailored for highly secure and compliance-driven environments. The approach leverages OCI-compliant container images preloaded with COBOL toolchains, introduces a platform abstraction layer, integrates multiple repositories, and employs Groovy script refactoring to achieve platform-agnostic continuous integration and delivery. Empirical evaluation demonstrates that the proposed solution significantly enhances efficiency—reducing pipeline execution time by 82%—while simultaneously improving system portability, security, and maintainability. This architecture offers a reusable paradigm for modernizing legacy COBOL applications within regulated domains.
This work addresses the limitations of existing large language models, which are typically confined to isolated tasks and struggle to integrate into industrial-scale, multi-stage security workflows. To bridge this gap, the authors propose the first role-based multi-agent framework tailored to the entire vulnerability lifecycle, incorporating specialized agents—Planner, Analyzer, Fixer, and Verifier—augmented with CodeQL static analysis for enhanced precision. By introducing a role-oriented multi-agent architecture into end-to-end vulnerability management, this approach effectively aligns the capabilities of large models with real-world security engineering demands. Evaluated on 25 real-world C/C++ vulnerabilities, the system achieves a detection accuracy of 44%—comparable to GPT-5.5—and a repair accuracy of 19%, offering a practical and collaborative paradigm for intelligent security operations.
This study addresses the limitation of existing evaluations that focus solely on final code while overlooking safety risks in the intermediate processes of LLM-based coding agents. To this end, it proposes "Safety Debt Line Integral," a novel trajectory-level metric. By integrating Static Application Security Testing (SAST) with Common Weakness Enumeration (CWE) classification, this method dynamically correlates code evolution with static scanning results to quantify the cumulative risk incurred as agents improve test pass rates. Empirical analyses on benchmarks such as SWE-bench reveal low agreement among multiple detection tools and demonstrate that the proposed metric effectively tracks both development progress and safety debt simultaneously. Ultimately, this work offers a new perspective for the safety-aligned steering of autonomous coding agents.
This study addresses the challenge of identifying security weaknesses during the requirements and design phases prior to implementation by proposing a threat modeling framework based on multi-agent large language models. The framework parses system architecture diagrams to generate attack trees, analyzes trust boundaries and data flows, and recommends mitigation strategies. Its core innovation lies in eliminating reliance on conventional CWE retrieval; instead, it employs misuse cases to correlate components and attack paths while introducing an iterative validation loop to enhance traceability and practical applicability. Experimental evaluations conducted on Microsoft reference scenarios and open systems demonstrate that the proposed approach significantly outperforms existing baselines in review quality, effectiveness, and attack tree construction.