Search Results

Documents authored by Tiemtore, Mohamed Haady


Document
Emerging Results, Vision & Reflection Track Paper
Tools for Detecting Security Issues in Infrastructure-As-Code: A Focused Literature Review

Authors: Mohamed Haady Tiemtore and Frédéric Loulergue

Published in: LIPIcs, Volume 394, 20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)


Abstract
Infrastructure-as-Code (IaC) artefacts such as Puppet manifests, Ansible playbooks, Kubernetes manifests, Helm charts, Terraform configurations, and CloudFormation templates are increasingly used to manage critical infrastructures. Security defects in these artefacts may therefore be propagated rapidly through automated deployment pipelines. This paper reports emerging results from a focused literature review of tools for detecting security issues in IaC artefacts. The current review protocol covers the ACM Digital Library and IEEE Xplore and includes 23 primary studies. We identify the main families of tools captured by this protocol, classify their detection approaches, and analyse how they are evaluated. The review corpus includes rule-based linters, deeper static analyses, graph- and model-based approaches, comparative scanner studies, deployment-oriented analyses, and recent machine-learning and LLM techniques.

Cite as

Mohamed Haady Tiemtore and Frédéric Loulergue. Tools for Detecting Security Issues in Infrastructure-As-Code: A Focused Literature Review. In 20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026). Leibniz International Proceedings in Informatics (LIPIcs), Volume 394, pp. 55:1-55:14, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{tiemtore_et_al:LIPIcs.ESEM.2026.55,
  author =	{Tiemtore, Mohamed Haady and Loulergue, Fr\'{e}d\'{e}ric},
  title =	{{Tools for Detecting Security Issues in Infrastructure-As-Code: A Focused Literature Review}},
  booktitle =	{20th International Symposium on Empirical Software Engineering and Measurement (ESEM 2026)},
  pages =	{55:1--55:14},
  series =	{Leibniz International Proceedings in Informatics (LIPIcs)},
  ISBN =	{978-3-95977-450-5},
  ISSN =	{1868-8969},
  year =	{2026},
  volume =	{394},
  editor =	{Feldt, Robert and Paasivaara, Maria and Mendez, Daniel and Wagner, Stefan and Bar\'{o}n, Marvin Mu\~{n}oz},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.ESEM.2026.55},
  URN =		{urn:nbn:de:0030-drops-280238},
  doi =		{10.4230/LIPIcs.ESEM.2026.55},
  annote =	{Keywords: Infrastructure-as-Code, security tooling, misconfiguration detection, static analysis, empirical software engineering, focused literature review}
}

Any Issues?
X

Feedback on the Current Page

CAPTCHA

Thanks for your feedback!

Feedback submitted to Dagstuhl Publishing

Could not send message

Please try again later or send an E-mail