PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 26, 2026Automatic Control and Computer Sciences1 citations

Protection of DevOps Pipelines: Automation of Security within DevSecOps

View Full Paper
SBS. V. BezzateevSaint Petersburg State University of Aerospace and InstrumentationABA. V. BlinovITMO University

Key Points

  • The central aim is to explore automation methods for integrating security into DevOps pipelines within the DevSecOps framework.
  • Conducted a comparative analytical review of modern DevSecOps tools and methodologies.
  • Analyzed literature and industrial practices regarding CI/CD process integration.
  • Assessed the use of AI and machine learning for automating security tasks.
  • Identified barriers to adopting DevSecOps in software development.
  • Automation was found to minimize human error and accelerate vulnerability detection.
  • Key principles for security integration include early vulnerability detection and 'Security as Code'.
  • Identified limitations include integration complexity and a shortage of skilled DevSecOps professionals.
  • Future trends suggest advancements in AI-driven security automation solutions.

Abstract

The research focuses on methods for automating security in DevOps pipelines within the DevSecOps framework, emphasizing the integration of tools, processes, and cultural shifts to enhance the security of software products. The research set the following tasks: analysis of modern DevSecOps methodologies and tools; assess the potential of using artificial intelligence and machine learning to automate information security tasks; identify the main problems and barriers to integrating DevSecOps into continuous integration and delivery (CI/CD) processes; identify promising areas for automation development in the field of security. The study uses a comparative analytical review method, including an analysis of scientific literature, industrial practices and documentation of modern DevSecOps tools, the “Shift-Left Security” and “Security as Code” approaches. Open sources, CI/CD platform documentation, and data on the use of AI in information security were used. The research identifies key principles for integrating security into DevOps: early vulnerability detection, automation of security processes, implementation of “Security as Code,” and enhanced threat monitoring. Modern DevSecOps tools are reviewed, including static and dynamic code analysis, security policy management systems, secret management solutions, and AI-powered proactive threat detection mechanisms. The study finds that automation minimizes human error, accelerates vulnerability detection and remediation processes, and ensures compliance with regulatory requirements. However, certain limitations were also identified, including the complexity of tool integration, a shortage of DevSecOps specialists, and resistance to changes within development and operations teams. Future trends indicate further advancements in AI-driven solutions and automated frameworks for security manage-ment. This research contributes to the field of information security by uncovering methods for automating DevSecOps integration into CI/CD processes and exploring the potential of AI for predictive threat analytics. It highlights key trends in security automation within modern cloud and containerized environments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Bezzateev et al. (2025) studied this question.

synapsesocial.com/papers/699fe39d95ddcd3a253e7adbhttps://doi.org/10.3103/s0146411625701123
Ask AI
Helpful
Bookmark
Share
View Full Paper