期刊文献+

持续集成工具缺陷检测技术研究 被引量:1

Defect-Detecting Technique of Continuous Integration
下载PDF
导出
摘要 持续集成是当今软件开发过程中普遍使用的工具之一。由于管理人员安全意识缺失和错误的安全策略,攻击者可轻松利用缺陷实现用户提权、敏感数据窃取、远程命令执行等目的。在介绍持续集成工具架构和基本组成基础之上,重点分析其存在的缺陷和常见的攻击面,研究攻击者利用这些缺陷所能实现的登陆绕过、远程命令执行、反序列化漏洞等攻击手段。利用缺陷检测技术对这些组件进行检测,集成整合并实现自动化检测平台,呈现出更直观全面的系统安全性评估结果。 Continuous integration is commonly used in today's software development. Due to the lack of security awareness and the wrong security strategy, the attacker can easily exploit defect and achieve higher rights, acquire sensitive data, execute remote command and reach other purposes. Based on introduction of the architecture and basic components of continuous integration tools, this paper focuses on the existing defects and common attack surface of the continuous integration tools, also discusses the password cracking, remote command execution, and Java deserialization vulnerabilities on this platform. By using the defect detection technology to detect these components and achieving integraied integration and implementation of automated testing platform, a more intuitive and comprehensive assessment of system security could be acquired.
出处 《通信技术》 2017年第2期346-352,共7页 Communications Technology
关键词 持续集成 缺陷检测 Jenkins 自动化测试 continuous integration defect detection Jenkins test automation
  • 相关文献

参考文献5

二级参考文献54

  • 1卿斯汉,蒋建春,马恒太,文伟平,刘雪飞.入侵检测技术研究综述[J].通信学报,2004,25(7):19-29. 被引量:234
  • 2赵琪.极限编程初探[J].太原科技,2005(4):72-73. 被引量:3
  • 3谷雨,赵佳枢,张天军,徐宗本.基于免疫多样性的分布式入侵检测算法[J].西安交通大学学报,2006,40(10):1052-1055. 被引量:6
  • 4[1]Beck K.解析极限编程:拥抱变化.北京:中国电力出版社,2003
  • 5[2]Jeffries R.极限编程实施.北京:人民邮电出版社,2002
  • 6[3]Beck K,Fowler M.规划极限编程.北京:人民邮电出版社,2002
  • 7Matrin Fowler,Matthew Foemmel.Continuous Integration[EB/OL].http://www.martinfowler.com/articles/continuousIntegration.html.
  • 8Grady Booch.Object-Oriented Analysis and Design with Application,2E[M].Addison-Wesley,2002
  • 9Steve McConnell.Daily Build and Smoke Test[J].IEEE Software,1996,13 (4)
  • 10Kent Beck.解析极限编程--拥抱变化[M].北京:人民邮电出版社,2002

共引文献54

同被引文献3

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部