https://www.mdu.se/

mdu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
CyberSecurity in a DevOps environment: From requirements to monitoring
SOFTEAM Ivry-sur-Seine, France.
Åbo Akademi University, Turku, Finland.
Montimage, Paris, France.
Montimage, Paris, France.
Show others and affiliations
2023 (English)Book (Other academic)
Abstract [en]

This book provides an overview of software security analysis in a DevOps cycle including requirements formalisation, verification and continuous monitoring. It presents an overview of the latest techniques and tools that help engineers and developers verify the security requirements of large-scale industrial systems and explains novel methods that enable a faster feedback loop for verifying security-related activities, which rely on techniques such as automated testing, model checking, static analysis, runtime monitoring, and formal methods. The book consists of three parts, each covering a different aspect of security engineering in the DevOps context. The first part, "Security Requirements", explains how to specify and analyse security issues in a formal way. The second part, "Prevention at Development Time", offers a practical and industrial perspective on how to design, develop and verify secure applications. The third part, "Protection at Operations", eventually introduces tools for continuous monitoring of security events and incidents. Overall, it covers several advanced topics related to security verification, such as optimizing security verification activities, automatically creating verifiable specifications from security requirements and vulnerabilities, and using these security specifications to verify security properties against design specifications and generate artifacts such as tests or monitors that can be used later in the DevOps process. The book aims at computer engineers in general and does not require specific knowledge. In particular, it is intended for software architects, developers, testers, security professionals, and tool providers, who want to define, build, test, and verify secure applications, Web services, and industrial systems.

Place, publisher, year, edition, pages
Springer Nature , 2023. p. 1-324
Series
CyberSecur. in a DevOps Environ.: From Requir. to Monit.
Keywords [en]
Cybersecurity, DevOps, Intrusion Detection, Requirements Engineering, Security-attack Detection, Software Testing, Software Verification
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:mdh:diva-69537DOI: 10.1007/9783031422126Scopus ID: 2-s2.0-85195006946ISBN: 9783031422126 (print)OAI: oai:DiVA.org:mdh-69537DiVA, id: diva2:1920855
Available from: 2024-12-12 Created: 2024-12-12 Last updated: 2025-10-10Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Seceleanu, Cristina

Search in DiVA

By author/editor
Seceleanu, Cristina
By organisation
Embedded Systems
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 57 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf