Teaching DevOps Security Education with Hands-on Labware: Automated Detection of Security Weakness in Python

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Akter, Mst Shapna, Rodriguez-Cardenas, Juanjose, Rahman, Md Mostafizur, Shahriar, Hossain, Rahman, Akond, Wu, Fan
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911827039879168
author Akter, Mst Shapna
Rodriguez-Cardenas, Juanjose
Rahman, Md Mostafizur
Shahriar, Hossain
Rahman, Akond
Wu, Fan
author_facet Akter, Mst Shapna
Rodriguez-Cardenas, Juanjose
Rahman, Md Mostafizur
Shahriar, Hossain
Rahman, Akond
Wu, Fan
contents The field of DevOps security education necessitates innovative approaches to effectively address the ever-evolving challenges of cybersecurity. In adopting a student-centered ap-proach, there is the need for the design and development of a comprehensive set of hands-on learning modules. In this paper, we introduce hands-on learning modules that enable learners to be familiar with identifying known security weaknesses, based on taint tracking to accurately pinpoint vulnerable code. To cultivate an engaging and motivating learning environment, our hands-on approach includes a pre-lab, hands-on and post lab sections. They all provide introduction to specific DevOps topics and software security problems at hand, followed by practicing with real world code examples having security issues to detect them using tools. The initial evaluation results from a number of courses across multiple schools show that the hands-on modules are enhancing the interests among students on software security and cybersecurity, while preparing them to address DevOps security vulnerabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2311_16944
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Teaching DevOps Security Education with Hands-on Labware: Automated Detection of Security Weakness in Python
Akter, Mst Shapna
Rodriguez-Cardenas, Juanjose
Rahman, Md Mostafizur
Shahriar, Hossain
Rahman, Akond
Wu, Fan
Cryptography and Security
The field of DevOps security education necessitates innovative approaches to effectively address the ever-evolving challenges of cybersecurity. In adopting a student-centered ap-proach, there is the need for the design and development of a comprehensive set of hands-on learning modules. In this paper, we introduce hands-on learning modules that enable learners to be familiar with identifying known security weaknesses, based on taint tracking to accurately pinpoint vulnerable code. To cultivate an engaging and motivating learning environment, our hands-on approach includes a pre-lab, hands-on and post lab sections. They all provide introduction to specific DevOps topics and software security problems at hand, followed by practicing with real world code examples having security issues to detect them using tools. The initial evaluation results from a number of courses across multiple schools show that the hands-on modules are enhancing the interests among students on software security and cybersecurity, while preparing them to address DevOps security vulnerabilities.
title Teaching DevOps Security Education with Hands-on Labware: Automated Detection of Security Weakness in Python
topic Cryptography and Security
url https://arxiv.org/abs/2311.16944