Abstract <p>The problem of detecting potentially malicious activity in CI/CD pipelines during the build process using build agent behavior analysis is considered. The limitations of pipeline security tools related to threat detection during builds and promising approaches for detecting malicious activity are identified. A method for detecting potentially malicious activity in pipelines based on behavioral analysis using eBPF technology for build agent profiling is proposed. The accuracy of threat detection is evaluated on a dataset containing the implementation of malicious scenarios associated with the compromise of the build process. The obtained results can be used to build agent protection tools and for further research in the field of CI/CD pipeline security.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detection of Potentially Malicious Activities in CI/CD Pipelines Based on Build Agent Behavior Analysis

  • E. V. Zhukovskii,
  • V. A. Bugaev,
  • A. A. Lyrchikov

摘要

Abstract

The problem of detecting potentially malicious activity in CI/CD pipelines during the build process using build agent behavior analysis is considered. The limitations of pipeline security tools related to threat detection during builds and promising approaches for detecting malicious activity are identified. A method for detecting potentially malicious activity in pipelines based on behavioral analysis using eBPF technology for build agent profiling is proposed. The accuracy of threat detection is evaluated on a dataset containing the implementation of malicious scenarios associated with the compromise of the build process. The obtained results can be used to build agent protection tools and for further research in the field of CI/CD pipeline security.