作者
Pandu Ranga Reddy Konala, Vimal Kumar, David Bainbridge
发表日期
2023/7/31
研讨会论文
2023 IEEE International Conference on Cyber Security and Resilience (CSR)
页码范围
281-288
出版商
IEEE
简介
This SoK paper presents findings from a survey conducted on the current state of tools and techniques used in the static configuration analysis of Infrastructure as Code (IaC). Our findings highlight the increasing importance of ensuring the quality of IaC scripts through techniques such as detecting code and security smells. Our findings reveal that regular expressions are widely used, but this may not be a long-term or fully automated solution for detecting smells. Additionally, our study found that the majority of the tools and techniques are developed for infrastructure provisioning, rather than configuration management and image building. This raises concerns because configuring software is a high-risk task, with malicious actors constantly targeting software systems. Therefore, it is crucial for researchers to develop efficient and advanced techniques for detecting defects in configuration management and image …
引用总数
学术搜索中的文章
PRR Konala, V Kumar, D Bainbridge - 2023 IEEE International Conference on Cyber Security …, 2023