Security in Cloud-Native Services: A Survey

T Theodoropoulos, L Rosa, C Benzaid, P Gray… - … of Cybersecurity and …, 2023 - mdpi.com
Cloud-native services face unique cybersecurity challenges due to their distributed
infrastructure. They are susceptible to various threats like malware, DDoS attacks, and Man …

[HTML][HTML] The do's and don'ts of infrastructure code: A systematic gray literature review

I Kumara, M Garriga, AU Romeu, D Di Nucci… - Information and …, 2021 - Elsevier
Abstract Context: Infrastructure-as-code (IaC) is the DevOps tactic of managing and
provisioning software infrastructures through machine-readable definition files, rather than …

The seven sins: Security smells in infrastructure as code scripts

A Rahman, C Parnin, L Williams - 2019 IEEE/ACM 41st …, 2019 - ieeexplore.ieee.org
Practitioners use infrastructure as code (IaC) scripts to provision servers and development
environments. While develo** IaC scripts, practitioners may inadvertently introduce …

Adoption, support, and challenges of infrastructure-as-code: Insights from industry

M Guerriero, M Garriga, DA Tamburri… - … and evolution (ICSME …, 2019 - ieeexplore.ieee.org
Infrastructure-as-code (IaC) is the DevOps tactic of managing and provisioning infrastructure
through machine-readable definition files, rather than physical hardware configuration or …

Within-project defect prediction of infrastructure-as-code using product and process metrics

S Dalla Palma, D Di Nucci, F Palomba… - IEEE Transactions on …, 2021 - ieeexplore.ieee.org
Infrastructure-as-code (IaC) is the DevOps practice enabling management and provisioning
of infrastructure through the definition of machine-readable files, hereinafter referred to as …

Understanding privacy-related questions on stack overflow

M Tahaei, K Vaniea, N Saphra - … of the 2020 CHI conference on human …, 2020 - dl.acm.org
We analyse Stack Overflow (SO) to understand challenges and confusions developers face
while dealing with privacy-related topics. We apply topic modelling techniques to 1,733 …

An empirical study of c++ vulnerabilities in crowd-sourced code examples

M Verdi, A Sami, J Akhondali, F Khomh… - IEEE Transactions …, 2020 - ieeexplore.ieee.org
Software developers share programming solutions in Q&A sites like Stack Overflow, Stack
Exchange, Android forum, and so on. The reuse of crowd-sourced code snippets can …

Gang of eight: A defect taxonomy for infrastructure as code scripts

A Rahman, E Farhana, C Parnin… - Proceedings of the ACM …, 2020 - dl.acm.org
Defects in infrastructure as code (IaC) scripts can have serious consequences, for example,
creating large-scale system outages. A taxonomy of IaC defects can be useful for …

Api-related developer information needs in stack overflow

M Liu, X Peng, A Marcus, S **ng… - IEEE Transactions on …, 2021 - ieeexplore.ieee.org
Stack Overflow (SO) provides informal documentation for APIs in response to questions that
express API related developer needs. Navigating the information available on SO and …

Source code properties of defective infrastructure as code scripts

A Rahman, L Williams - Information and Software Technology, 2019 - Elsevier
Context In continuous deployment, software and services are rapidly deployed to end-users
using an automated deployment pipeline. Defects in infrastructure as code (IaC) scripts can …