Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Article . 2024
License: CC BY
Data sources: ZENODO
ZENODO
Article . 2024
License: CC BY
Data sources: Datacite
ZENODO
Article . 2024
License: CC BY
Data sources: Datacite
versions View all 2 versions
addClaim

Securing AI-Assisted Cloud Engineering: Guardrails For Copilot-Generated IaC And CI/CD Changes To Prevent Vulnerability Injection

Authors: Shuaib Ahmed;

Securing AI-Assisted Cloud Engineering: Guardrails For Copilot-Generated IaC And CI/CD Changes To Prevent Vulnerability Injection

Abstract

The quick pace of AI coding assistant adoption in cloud engineering has greatly led to the creation of Infrastructure-as-Code (IaC) and CI/CD pipelines. Nevertheless, AI-generated setting may readily imply security misconfigurations, insecure defaults and violations of the policy that can be transmitted straight into production cloud environments. Such risks are especially acute in those organizations that deal with regulated and high-assurance industries, whose misconfigured resources can cause data breaches, privilege increases, and violation of the rules. Conventional security review procedures are too sluggish and manual to follow through with the AI-assisted development processes, which resulted in a pressing need of automated preventive security mechanisms. The paper presents a recommendation in the form of the AI Guardrailed Cloud Engineering Framework (AGCEF) that is a proactive security model that involves the imposition of guardrails on AI-generated IaC and CI/CD artifacts prior to the deployment. AGCEF combines policy-as-code checking, matching of vulnerability signatures, semantic intent checking with LLM and a quantitative risk scoring system, which identifies and thwart insecure configurations at design time. Through experimental analysis, it is shown that AGCEF is significantly better in comparison to current AI-based methods of vulnerability detection because it offers higher vulnerability prevention, lowers false negatives, less manual review, and enhances the safety of deployment. The framework allows organizations to use AI copilots to enhance productivity and maintain high levels of cloud security and compliance, hence restoring the balance between the speed of AI-assisted development and AI-assisted operations in the cloud.

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green