Jul 2026· 2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET)· pp. 1-6· 0 citations· 13 references
Abstract
The rapid expansion of the life cycle for software deployment has required a move from traditional, manual security analysis to automated and integrated assurance frameworks. This study examines the effectiveness of integrating assurance, real-time threat detection, and automated certification gates right into the Continuous Integration and Continuous Deployment pipeline. The analysis is based on a synthetic dataset comprising values from 429 different builds, which is used to study the agreement between automated gating mechanisms and lower vulnerability escape rates. We used a standard tool chain consisting of Jenkins for orchestration, SonarQube for static analysis, and Splunk for log aggregation to emulate a high-velocity enterprise environment. The system seeks to reduce technical debt and potential security risks without impeding deployment velocity by enforcing stringent quality gates that prevent non-compliant artifacts from being promoted. The study highlights the quantitative effects of these controls on success build rates and on the exposure of hidden threats during staging. The results reveal that, despite an initial slowdown in delivery velocity, the incorporation of automated certification gates considerably reduces critical severity incident rates. Implications: The results indicate how to make system changes in response to data for those attempting to put DevSecOps into practice while maintaining the speed and integrity of their systems.
Large Language Models (LLMs) are now deployed at an unprecedented scale across many critical sectors, rapidly transitioning from experimental AI tools to embedded components of production software systems. This accelerated adoption, often enabled by low-code integrations, has lowered technical barriers while simultaneously expanding the attack surface of modern applications, particularly when deployments occur without sufficient domain-specific security expertise. In many cases, security maturity has not progressed at the same pace as capability expansion, creating systemic exposure across confidentiality, integrity, and availability dimensions. To provide structured clarity amid this rapid growth, this paper presents a comparative and standards-aligned analysis of LLM security risks and defense mechanisms grounded in the OWASP GenAI Top-10 (2025). We systematically examine each vulnerability class, map representative attack patterns to primary mitigation strategies, evaluate their security property impact, and analyze practical limitations and implementation trade-offs. In addition, we introduce a severity-based assessment to prioritize risks according to operational and systemic impact, offering a quantitative perspective on defensive readiness. Our findings indicate that current mitigation strategies are predominantly reactive, concentrated at inference time, and unevenly distributed across the LLM lifecycle. Controls addressing training pipelines, supplychain dependencies, and autonomous system behaviors remain comparatively less mature and less standardized. By integrating vulnerability classification, defense mapping, severity prioritization, and trade-off analysis within a unified framework, this study provides actionable guidance for strengthening secure, resilient, and standards-driven LLM deployment in high-stakes environments.
Md Abdul Barek, Md Bajlur Rashid, A. K. I. Riad et al.· Annual International Compute...· 0 citations
This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.
Topicality. The rapid proliferation of web applications across enterprise ecosystems has intensified the demand for comprehensive, automated vulnerability detection mechanisms. Existing standalone scanning tools exhibit inherent limitations in coverage scope, reporting standardization, and CI/CD pipeline integration, necessitating the development of unified orchestration platforms. The subject of study in this article is the architectural design and implementation of a modular, Python-based integrated vulnerability scanner that consolidates multiple open-source security testing utilities into a cohesive automation framework. The purpose of the article is to develop and validate an extensible platform capable of orchestrating reconnaissance, dynamic application security testing (DAST), static configuration analysis, and information leak detection through unified command-line interface and consolidated HTML reporting. The following results were obtained. A modular scanner architecture was designed, integrating industry-standard tools including Nuclei (template-based vulnerability detection), Burp Suite (proxy-based traffic analysis), Feroxbuster (directory fuzzing), Subfinder/DNSX (subdomain enumeration), Katana (URL crawling), and auxiliary modules for WAF detection (CDNCheck), 403 bypass (byp4xx), Postman collection leak analysis (Postleaks), and exposed configuration discovery (LeakIX). Conclusion. The developed platform achieves enhanced scanning coverage through multi-tool orchestration and generates structured HTML reports with categorized findings. The modular architecture enables rapid integration of emerging security tools, making the framework adaptable to evolving threat landscapes in modern web application security testing.
O.I. Fediushyn, Hlib Khivrenko, Nataliia Popova et al.· Terra security· 0 citations
Enterprise IT infrastructure has grown increasingly complex, which places simultaneous demands on operations teams to maintain high availability and to defend against a growing array of cyber threats. Historically, uptime assurance and security monitoring have operated as discrete organizational functions with separate toolsets, personnel and objectives. This siloed approach creates operational blind spots that threat actors and system failures exploit with equal consequence. This article presents a structured methodology for integrating security monitoring into uptime assurance workflows within enterprise data center environments. Drawing on frameworks established by the National Institute of Standards and Technology (NIST), the Information Technology Infrastructure Library (ITIL) and peer-reviewed scholarship published between 2015 and 2025, the study identifies key convergence points between availability management and threat detection, proposes an integrated operational model and examines the organizational and technological prerequisites for sustainable implementation. The methodology addresses log correlation, alert triage, incident classification and cross-functional escalation protocols. The findings indicated that integration produces measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR) while reducing alert fatigue and redundant infrastructure costs. This article concludes with recommendations for enterprise IT leaders seeking to unify security and availability operations under a coherent governance structure.
Keywords: Uptime Assurance, Security Monitoring, Enterprise IT Infrastructure, IT Operations, Availability Management, Threat Detection, ITIL, NIST, Integrated Operations, Incident Response.
Oladele Adekunle Awonusi· Computer Science & IT Re...· 0 citations
HawkEye is introduced, a modular, web-based vulnerability auditing platform designed to streamline security analysis by integrating multiple scanning tools within a unified dashboard and illustrates how consolidated reporting improves vulnerability prioritization for development teams.
D. R. Patil, Varad Salgare, Devaj Arya et al.· International Journal for Re...· 0 citations
Empirical evidence is provided that generative AI can effectively support security requirements engineering when embedded within human-centered workflows and organizational governance structures, offering practical insights for adoption in regulated software development contexts.
F. Martins, Elaine Venson· SIGSOFT FSE Companion· 0 citations