詳細検索結果
以下の条件での結果を表示する: 検索条件を変更
クエリ検索: "DevSecOps"
5件中 1-5の結果を表示しています
  • Keita YAMAMOTO, Masaki OYA, Masaki HASHIMOTO, Haruhiko KAIYA, Takao OKUBO
    IEICE Transactions on Information and Systems
    2026年 E109.D 巻 9 号 1358-1370
    発行日: 2026/09/01
    公開日: 2026/09/01
    [早期公開] 公開日: 2026/03/18
    ジャーナル フリー

    Modern software development paradigms, particularly Agile and DevOps methodologies, have compressed development timelines while simultaneously increasing the complexity of security threat landscapes. Traditional threat modeling approaches, notably attack scenario analysis, demand substantial security expertise and extensive time investments that are incompatible with accelerated development cycles. Furthermore, the expanding demand for secure systems has necessitated threat analysis implementation by practitioners lacking comprehensive security backgrounds. This research presents COTTAGE, an automated tool that generates Attack Defense Trees (ADTrees) by leveraging CAPEC and CWE security knowledge repositories, specifically designed to enable effective threat modeling by security non-specialists. Experimental validation involving six participants with limited security expertise revealed that COTTAGE facilitated threat analysis outcomes comparable to expert-level assessment within 30-minute sessions, contrasting with the approximately two-day timeframe typically required by security professionals. Additional validation through DevOps environment case studies confirmed COTTAGE’s capability to support continuous security assessment via automatically generated reference tree structures.

  • 竹房 あつ子
    システム/制御/情報
    2024年 68 巻 5 号 191-196
    発行日: 2024/05/15
    公開日: 2024/11/15
    解説誌・一般情報誌 フリー
  • 倉地 亮
    電子情報通信学会 基礎・境界ソサイエティ Fundamentals Review
    2025年 19 巻 2 号 87-96
    発行日: 2025/10/01
    公開日: 2025/10/01
    ジャーナル フリー

    Software-Defined Vehicle(SDV)は,ソフトウェアによって機能が定義される次世代自動車であり,そのアーキテクチャはゾーン型へと移行しつつある.本稿では,まず従来型車両との構造的な違いと,SDVを支える仮想化,マイクロサービス,OTAといった技術基盤を解説する.次に,コネクティビティの増大やサプライチェーンの複雑化に伴い拡大するサイバー攻撃の脅威を分類し,具体的な攻撃シナリオを論じる.その上で,SBOMによる構成の透明化,Uptaneやin-totoを用いたサプライチェーン全体の信頼性確保,HSM/TEEといったハードウェアセキュリティに至る多層的な対策技術を詳述する.最後に,UN-R155などの国際標準への対応や

    DevSecOps
    体制の構築といった産業的課題と今後の展望を考察する.

  • 日本PDA製薬学会 関西勉強会 デジタルトランスフォーメーション(DX)グループ, 高井 謙次, 峠 茂樹, 集 弘就, 上久木田 務, 落合 宏則, 賀屋 拓郎, 後藤 健太, 白木澤 治, 中島 潤, 外尾 英隆, 山本 和秀, 柳澤 徳雄
    日本PDA学術誌 GMPとバリデーション
    2026年 28 巻 1 号 54-68
    発行日: 2026年
    公開日: 2026/06/30
    ジャーナル フリー

    Proposal for Digital Talent Development to Promote Digital Transformation in Pharmaceutical Manufacturing. Japan’s digital transformation (DX) is considered to be lagging behind Western countries, particularly in pharmaceutical manufacturing, where conservative corporate culture and regulatory complexity hinder progress. This proposal emphasizes human resource development as the key to successful DX implementation. We define seven essential roles—Business Architect, Designer, Data Scientist, Software Engineer, Cybersecurity Specialist, Data Steward, and CSQA (Computer System Quality Assurance)—and outline their responsibilities, tasks, and required skills. By fostering these roles, pharmaceutical companies can enhance DX quality, strengthen global competitiveness, and establish sustainable organizational frameworks. This proposal presents a conceptual framework aimed at providing practical guidance and recommendations for accelerating DX in the pharmaceutical industry.

  • Yuta TAKATA, Hiroshi KUMAGAI, Masaki KAMIZONO
    IEICE Transactions on Information and Systems
    2021年 E104.D 巻 11 号 1828-1838
    発行日: 2021/11/01
    公開日: 2021/11/01
    ジャーナル フリー

    While websites are becoming more and more complex daily, the difficulty of managing them is also increasing. It is important to conduct regular maintenance against these complex websites to strengthen their security and improve their cyber resilience. However, misconfigurations and vulnerabilities are still being discovered on some pages of websites and cyberattacks against them are never-ending. In this paper, we take the novel approach of applying the concept of security governance to websites; and, as part of this, measuring the consistency of software settings and versions used on these websites. More precisely, we analyze multiple web pages with the same domain name and identify differences in the security settings of HTTP headers and versions of software among them. After analyzing over 8,000 websites of popular global organizations, our measurement results show that over half of the tested websites exhibit differences. For example, we found websites running on a web server whose version changes depending on access and using a JavaScript library with different versions across over half of the tested pages. We identify the cause of such governance failures and propose improvement plans.

feedback
Top