inklap

TESTING-BASED PREVENTION OF MISCONFIGURATION THREATS IN AWS INFRASTRUCTURE AS CODE

Ivan Parkhomenko, Mykhailo Savonik · Cybersecurity: Education, Science, Technique · 2025

Misconfigured cloud infrastructure has emerged as a prevalent and impactful threat vector in cybersecurity. In particular, organizations deploying services on Amazon Web Services (AWS) often face significant security risks due to incorrectly configured access controls, insufficient logging, weak network segmentation, and the absence of critical protections such as Web Application Firewalls (WAF). Despite the widespread adoption of Infrastructure as Code (IaC) tools (e.g., Terraform, AWS CloudFormation) to enforce predictable, version-controlled deployments, these IaC configurations typically undergo little to no systematic security testing. Unlike application code—which routinely undergoes unit, integration, and security testing—infrastructure code is seldom tested beyond basic static analysis or post-deployment monitoring. As a result, critical security misconfigurations can remain undetected until they are exploited by attackers. To address this gap, this paper proposes a novel approach termed "Infrastructure as Tested Code." By applying proven software testing techniques—such as test assertions and continuous integration workflows—to IaC, our framework enables pre-deployment val

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً