AUTOMATED SECURITY WEAKNESS DETECTION IN CONTINUOUS INTEGRATION PIPELINES USING PREDICTIVE MODELS

Authors

  • Mariana Coelho Author

Abstract

Continuous Integration (CI) pipelines have become essential components of modern software development by enabling rapid code integration, automated testing, and frequent software releases. However, accelerated development cycles also introduce security challenges, as vulnerabilities and security weaknesses may propagate into production environments if not detected early. Traditional security testing approaches often depend on static rules, manual reviews, and isolated vulnerability scanning, limiting their ability to identify complex security issues during continuous development workflows. This paper proposes an Automated Security Weakness Detection Framework in Continuous Integration Pipelines Using Predictive Models by integrating machine learning, predictive analytics, DevSecOps practices, automated testing, and intelligent security monitoring. The proposed framework analyzes source code changes, software metrics, dependency information, testing outcomes, and historical vulnerability patterns to predict potential security weaknesses. Predictive models classify security risks and provide early warnings during CI execution. Experimental evaluation demonstrates improvements in weakness detection accuracy, security automation, vulnerability prevention, and continuous software delivery reliability.

Downloads

Published

2024-06-29