Security support in continuous deployment pipeline

Faheem Ullah, Adam Johannes Raft, Mojtaba Shahin, Mansooreh Zahedi, Muhammad Ali Babar

Research output: Chapter in Book/Report/Conference proceedingConference PaperResearchpeer-review

5 Citations (Scopus)


Continuous Deployment (CD) has emerged as a new practice in the software industry to continuously and automatically deploy software changes into production. Continuous Deployment Pipeline (CDP) supports CD practice by transferring the changes from the repository to production. Since most of the CDP components run in an environment that has several interfaces to the Internet, these components are vulnerable to various kinds of malicious attacks. This paper reports our work aimed at designing secure CDP by utilizing security tactics. We have demonstrated the effectiveness of five security tactics in designing a secure pipeline by conducting an experiment on two CDPs- one incorporates security tactics while the other does not. Both CDPs have been analysed qualitatively and quantitatively. We used assurance cases with goal-structured notations for qualitative analysis. For quantitative analysis, we used penetration tools. Our findings indicate that the applied tactics improve the security of the major components (i.e., repository, continuous integration server, main server) of a CDP by controlling access to the components and establishing secure connections.

Original languageEnglish
Title of host publicationProceedings of the 12th International Conference on Evaluation of Novel Approaches to Software Engineering
EditorsErnesto Damiani, George Spanoudakis, Leszek Maciaszek
Place of PublicationPortugal
Number of pages12
ISBN (Electronic)9789897582509
Publication statusPublished - 2017
Externally publishedYes
EventInternational Conference on Evaluation of Novel Approaches to Software Engineering 2017 - Porto, Portugal
Duration: 28 Apr 201729 Apr 2017
Conference number: 12th


ConferenceInternational Conference on Evaluation of Novel Approaches to Software Engineering 2017
Abbreviated titleENASE 2017
Internet address


  • Continuous deployment
  • Continuous deployment pipeline
  • Continuous integration
  • Security

Cite this