International Journal of Network Security & Its Applications (IJNSA) - ERA, WJCI Indexed
ISSN: 0974 - 9330 (Online); 0975 - 2307 (Print)
Webpage URL: https://airccse.org/journal/ijnsa.html
Building a Continuously Integrating System with High Safety
Tuan Nguyen Kim1, Ha Nguyen Hoang2 and Vy Huynh Trieu3, 1Duy Tan University, Viet Nam, 2Hue University, Vietnam, 3Phạm Van Dong University, Viet Nam
Abstract
In this paper, we propose and implement an internal continuous integration system, based on two opensource tools Jenkins and GitLab, taking into account the safety factor for servers in the system. In the proposed system, we use a combination of firewall function and reverse proxy function to protect Jenkins server itself and reduce the risk of this server against attacks on the CVE-2021-44228 security vulnerability, may exist in plugins of Jenkins. This system is highly practical, and it can be applied to immediately protect service servers when a vulnerability in it has been discovered but the corresponding patch has not been found or the condition to update the patch is not allowed yet.
Keywords
Continuous Integration, Continuous Delivery, CI/CD, CVE-2021-44228, Firewalls, Jenkins, Gitlab
Abstract URL: http://aircconline.com/abstract/ijnsa/v15n4/15423ijnsa01.html
Original Source URL: https://aircconline.com/ijnsa/V15N4/15423ijnsa01.pdf
Volume URL: https://airccse.org/journal/jnsa23_current.html
No comments:
Post a Comment