The adoption of containers in complex software systems is rapidly increasing, due to their flexibility that facilitates integration, scalability, and dynamic deployment. However, assessing the security of container-based applications remains challenging in distributed and heterogeneous environments: the scale and diversity of deployment scenarios call for sophisticated security evaluation and verification techniques. In this paper, we present Project SECCO, whose aim is to develop an innovative framework for the systematic integration of security assessment services into the Continuous Integration and Continuous Delivery (CI/CD) DevOps pipeline. The framework orchestrates automatic services to prevent and reduce vulnerabilities in the design, implementation, and deployment phases, and to mitigate runtime attacks. This allows developers and IT operators to focus on integration and delivery, reducing security management tasks. Finally, the paper highlights the main research challenges for realizing this vision.

From Edge to Cloud: Securing Distributed Containerized Applications

Falcone, Alberto;Benedetti, Giacomo;Guarascio, Massimo;Caviglione, Luca;
2025

Abstract

The adoption of containers in complex software systems is rapidly increasing, due to their flexibility that facilitates integration, scalability, and dynamic deployment. However, assessing the security of container-based applications remains challenging in distributed and heterogeneous environments: the scale and diversity of deployment scenarios call for sophisticated security evaluation and verification techniques. In this paper, we present Project SECCO, whose aim is to develop an innovative framework for the systematic integration of security assessment services into the Continuous Integration and Continuous Delivery (CI/CD) DevOps pipeline. The framework orchestrates automatic services to prevent and reduce vulnerabilities in the design, implementation, and deployment phases, and to mitigate runtime attacks. This allows developers and IT operators to focus on integration and delivery, reducing security management tasks. Finally, the paper highlights the main research challenges for realizing this vision.
2025
Istituto di Calcolo e Reti ad Alte Prestazioni - ICAR
979-8-3315-9547-0
Container security
DevSecOps
CI/CD security
Docker
File in questo prodotto:
File Dimensione Formato  
From_Edge_to_Cloud_Securing_Distributed_Containerized_Applications.pdf

solo utenti autorizzati

Tipologia: Versione Editoriale (PDF)
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 596.37 kB
Formato Adobe PDF
596.37 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/552897
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact