The article represents a Proof of Concept (PoC) for policy-as-code methodology designed to detect “Privilege Sprawl” in GitLab CI/CD environments and showed how teams can reduce their organisational exposure by 73% and get back into compliance with Least Privilege.
This study investigates security risks in Dock-er-based GitHub Actions workflows and proposes a tailored, DevSecOps-aligned security checklist to mitigate these threats, offering practical protection against supply-chain threats while preserving delivery speed and scalability.
A. Amirova· International Journal of Wir...· 0 citations
A new control approach for PAM known as the Zero-Trust Control Framework, based on behavioural analysis, graph theory, and entropy calculations is proposed, based on behavioural analysis, graph theory, and entropy calculations for enhancing zero trust enforcement in z/OS administration.
R. Shaw· Journal of Intelligent Decis...· 0 citations
Confidential MCP is presented, a set of backward-compatible extensions to MCP that enable standardized, auditable tool calling within and across TEE boundaries and introduces a three-zone enclave-partitioned server topology, a programmable Anonymization Transform Layer (ATL) with formal parameter classification and ent...
Ankur Aggarwal· International journal of com...· 0 citations
CHARGE is an automated framework for generating security properties for unverified RTL modules using CWEs and large language models using CWEs and large language models that leverages the hierarchical nature of CWE entries to improve accuracy when identifying security-critical assets in unverified RTL modules.
This work encodes a bounded policy language's decision function into a fixed-size byte buffer and verify the enforcement code once, proving the validator accepts if and only if the decision function accepts, for every policy, request, and session.
Saranachon Iammongkol, Zhi-Yi Huang, D. Eyers· 0 citations