GLITCH: Automated Polyglot Security Smell Detection in Infrastructure as Code
Nuno Saavedra, João F. Ferreira
摘要
Infrastructure as Code (IaC) is the process of managing IT infrastructure via programmable configuration files (also called IaC scripts). Like other software artifacts, IaC scripts may contain security smells, which are coding patterns that can result in security weaknesses. Automated analysis tools to detect security smells in IaC scripts exist, but they focus on specific technologies such as Puppet, Ansible, or Chef. This means that when the detection of a new smell is implemented in one of the tools, it is not immediately available for the technologies supported by the other tools -the only option is to duplicate the effort. This paper presents an approach that enables consistent security smell detection across different IaC technologies. We conduct a large-scale empirical study that analyzes security smells on three large datasets containing 196,755 IaC scripts and 12,281,251 LOC. We show that all categories of security smells are identified across all datasets and we identify some smells that might affect many IaC projects. To conduct this study, we developed GLITCH, a new technology-agnostic framework that enables automated polyglot smell detection by transforming IaC scripts into an intermediate representation, on which different security smell detectors can be defined. GLITCH currently supports the detection of nine different security smells in scripts written in Ansible, Chef, or Puppet. We compare GLITCH with state-of-the-art security smell detectors. The results obtained not only show that GLITCH can reduce the effort of writing security smell analyses for multiple IaC technologies, but also that it has higher precision and recall than the current state-of-the-art tools. CCS CONCEPTS • Software and its engineering → Software configuration management and version control systems; Software maintenance tools; • Security and privacy → Software and application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- When Your Infrastructure Is a Buggy Program: Understanding Faults in Infrastructure as Code EcosystemsGeorgios-Petros Drosos, Thodoris Sotiropoulos, Georgios Alexopoulos, Dimitris Mitropoulos 等OOPSLA 2024 · 被引用 14 次
- State Reconciliation Defects in Infrastructure as CodeMd. Mahadi Hassan, John Salvador, Shubhra Kanti Karmaker Santu, Akond RahmanFSE 2024 · 被引用 8 次
- Unfulfilled Promises: LLM-Based Detection of OS Compatibility Issues in Infrastructure as CodeGeorgios-Petros Drosos, Georgios Alexopoulos, Thodoris Sotiropoulos, Dimitris Mitropoulos 等FSE 2026
它引用的顶会 Paper3
- Gang of eight: a defect taxonomy for infrastructure as code scriptsAkond Rahman, Effat Farhana, Chris Parnin, Laurie A. WilliamsICSE 2020 · 被引用 58 次
- What helped, and what did not? An Evaluation of the Strategies to Improve Continuous IntegrationXianhao Jin, Francisco ServantICSE 2021 · 被引用 26 次
- Practical fault detection in puppet programsThodoris Sotiropoulos, Dimitris Mitropoulos, Diomidis SpinellisICSE 2020 · 被引用 22 次
相关 Paper
- Leveraging Practitioners' Feedback to Improve a Security LinterSofia Reis, Rui Abreu, Marcelo d'Amorim, Daniel FortunatoASE 2022 · 被引用 16 次
- Configuration smells in continuous delivery pipelines: a linter and a six-month study on GitLabCarmine Vassallo, Sebastian Proksch, Anna Jancso, Harald C. Gall 等FSE 2020 · 被引用 43 次
- Your Build Scripts Stink: The State of Code Smells in Build ScriptsMahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski 等ASE 2025 · 被引用 1 次
- An Empirical Study and Benchmark of Kubernetes Misconfiguration ScannersHaeun Eom, Bohyun Suk, Sungjae HwangISSTA 2026
- The Smelly Eight: An Empirical Study on the Prevalence of Code Smells in Quantum ComputingQihong Chen, Rúben Câmara, José Campos, André Souto 等ICSE 2023 · 被引用 23 次
