Towards a Blockchain-Based CI/CD Framework to Enhance Security in Cloud Environments
By: Sabbir M Saleh, Nazim Madhavji, John Steinbacher
Potential Business Impact:
Secures software updates using a tamper-proof digital ledger.
Security is becoming a pivotal point in cloud platforms. Several divisions, such as business organisations, health care, government, etc., have experienced cyber-attacks on their infrastructures. This research focuses on security issues within Continuous Integration and Deployment (CI/CD) pipelines in a cloud platform as a reaction to recent cyber breaches. This research proposes a blockchain-based solution to enhance CI/CD pipeline security. This research aims to develop a framework that leverages blockchain's distributed ledger technology and tamper-resistant features to improve CI/CD pipeline security. The goal is to emphasise secure software deployment by integrating threat modelling frameworks and adherence to coding standards. It also aims to employ tools to automate security testing to detect publicly disclosed vulnerabilities and flaws, such as an outdated version of Java Spring Framework, a JavaScript library from an unverified source, or a database library that allows SQL injection attacks in the deployed software through the framework.
Similar Papers
A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud Computing
Software Engineering
Makes apps safer when put online.
Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines
Software Engineering
Makes software building safer from hackers.
Software Supply Chain Security of Web3
Cryptography and Security
Secures online money from hackers and mistakes.