The paper explains how to integrate the artificial intelligence (AI) and machine learning (ML) techniques into the DevSecOps pipeline to automate the security compliance checks, vulnerability testing, and threat detection in cloud-native systems. The proposed model incorporates also the use of AI-based security automation in the continuous integration/continuous deployment (CI/CD) pipelines, such that compliance control and interactive vulnerability scanners can be automated and do not need human intervention. Based on historical and real-time data, the AI algorithms are capable of identifying security gaps and vulnerabilities and the possible threats and anticipating them within the system. The architecture makes use of compliance-as-code, which applies security policies to the whole development life cycle and ascertains all deployments conform to regulatory and security standards. Threat modelling and vulnerability detection are used in the pipeline so that the possible risks can be viewed at the first step of the development process and automated remediation mechanisms are provided to make sure that the security issues will be addressed as soon as possible. Cloud security posture management is also one of the tools of the platform, where they constantly scan and evaluate the environment to ensure best practices and organizational security policies are upheld. The manual load of these major processes will be automated to improve the security status quo of the entire framework to be compliant, resilient, and secure against the upcoming threats, and ensure that cloud-native applications are compliant.
Paper
Full text
AI-Enhanced DevSecOps: Automating Security Compliance in Cloud-Native Pipelines
Semantic Scholar · 2024
Abstract
The paper explains how to integrate the artificial intelligence (AI) and machine learning (ML) techniques into the DevSecOps pipeline to automate the security compliance checks, vulnerability testing, and threat detection in cloud-native systems. The proposed model incorporates also the use of AI-based security automation in the continuous integration/continuous deployment (CI/CD) pipelines, such that compliance control and interactive vulnerability scanners can be automated and do not need human intervention. Based on historical and real-time data, the AI algorithms are capable of identifying security gaps and vulnerabilities and the possible threats and anticipating them within the system. The architecture makes use of compliance-as-code, which applies security policies to the whole development life cycle and ascertains all deployments conform to regulatory and security standards. Threat modelling and vulnerability detection are used in the pipeline so that the possible risks can be viewed at the first step of the development process and automated remediation mechanisms are provided to make sure that the security issues will be addressed as soon as possible. Cloud security posture management is also one of the tools of the platform, where they constantly scan and evaluate the environment to ensure best practices and organizational security policies are upheld. The manual load of these major processes will be automated to improve the security status quo of the entire framework to be compliant, resilient, and secure against the upcoming threats, and ensure that cloud-native applications are compliant.