{"id":77,"date":"2023-09-25T15:24:23","date_gmt":"2023-09-25T14:24:23","guid":{"rendered":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/?p=77"},"modified":"2025-05-19T10:36:09","modified_gmt":"2025-05-19T09:36:09","slug":"uwe-bristol-researchers-conduct-first-longitudinal-study-on-evolving-vulnerabilities-in-cloud-and-application-security","status":"publish","type":"post","link":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/uwe-bristol-researchers-conduct-first-longitudinal-study-on-evolving-vulnerabilities-in-cloud-and-application-security\/","title":{"rendered":"UWE Bristol researchers conduct first longitudinal study on evolving vulnerabilities in cloud and application security\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A team of UWE Bristol researchers have conducted a major new study into the evolving security landscape of modern cloud infrastructures.&nbsp;The study, recently published in the Computers and Security journal, investigates container security for over 400 applications and services over a 9-month period, to assess what the security vulnerabilities of these services are, and the frequency of when these vulnerabilities are resolved.&nbsp;The findings show many cases where&nbsp;vulnerabilities remain&nbsp;persistent&nbsp;even when updated versions of the application are released. However, we also investigate the real-world nature of these vulnerabilities, to assess the true risk of utilising these&nbsp;services in both local and remote settings, recognising that whilst some security scans may highlight a vulnerability, the vulnerability can not actually be exploited given the use case of the application.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/people.uwe.ac.uk\/Person\/AlanMills\">Alan Mills<\/a>, lead author of the study says\u00a0<em>&#8220;Container security is a growing area of concern, with the increasing use of micro-services we need to ensure that cyber security keeps pace, while avoiding common pit falls around vulnerability assessment. By assessing container security over an extended time-period and analysing our results from multiple areas, all with a focus on real world risk, we present findings which inform further academic studies and industry-based decision making.&#8221; <\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The study was conducted in collaboration with <a href=\"https:\/\/eur01.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fpeople.uwe.ac.uk%2FPerson%2FJonathan6White&amp;data=05%7C01%7CAnna6.Jones%40uwe.ac.uk%7C1f4bb93714d74f492cdd08dbbdc7bce1%7C07ef1208413c4b5e9cdd64ef305754f0%7C0%7C0%7C638312437781636854%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=AHroRg12SMSPPE%2B7kMxVUQYfL3dtGb2DNgMSY9QsUT8%3D&amp;reserved=0\">Jonathan White<\/a> and <a href=\"https:\/\/eur01.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fpeople.uwe.ac.uk%2FPerson%2FPhilLegg&amp;data=05%7C01%7CAnna6.Jones%40uwe.ac.uk%7C1f4bb93714d74f492cdd08dbbdc7bce1%7C07ef1208413c4b5e9cdd64ef305754f0%7C0%7C0%7C638312437781636854%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=oRbCg57A2CQEQcEuQohm%2B%2FWfB1vQuSQ6EOmob7rVCXo%3D&amp;reserved=0\">Professor Phil Legg<\/a>. Alan is currently a Lecturer in Cyber Security studying for a part-time DPhil on the topic of container and cloud security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The paper, <a href=\"https:\/\/eur01.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.sciencedirect.com%2Fscience%2Farticle%2Fpii%2FS0167404823003887&amp;data=05%7C01%7CAnna6.Jones%40uwe.ac.uk%7C1f4bb93714d74f492cdd08dbbdc7bce1%7C07ef1208413c4b5e9cdd64ef305754f0%7C0%7C0%7C638312437781636854%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=qrr%2BI3Gqap7NuJYy27%2BiY0JINA03zp4a6OxB6Vc%2BXFI%3D&amp;reserved=0\">Longitudinal risk-based security assessment of docker software container images,<\/a>&nbsp;is now available as Open Access from the Computers and Security journal.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A team of UWE Bristol researchers have conducted a major new study into the evolving security landscape of modern cloud infrastructures.&nbsp;The study, recently published in the Computers and Security journal, investigates container security for over 400 applications and services over a 9-month period, to assess what the security vulnerabilities of these services are, and the &hellip; <a href=\"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/uwe-bristol-researchers-conduct-first-longitudinal-study-on-evolving-vulnerabilities-in-cloud-and-application-security\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;UWE Bristol researchers conduct first longitudinal study on evolving vulnerabilities in cloud and application security\u00a0&#8220;<\/span><\/a><\/p>\n","protected":false},"author":39,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":4,"footnotes":""},"categories":[4],"tags":[6,7,13],"class_list":["post-77","post","type-post","status-publish","format-standard","hentry","category-cyber-security","tag-cyber-crime","tag-cyber-security","tag-uwe-bristol-research"],"_links":{"self":[{"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/posts\/77","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/comments?post=77"}],"version-history":[{"count":3,"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/posts\/77\/revisions"}],"predecessor-version":[{"id":108,"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/posts\/77\/revisions\/108"}],"wp:attachment":[{"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/media?parent=77"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/categories?post=77"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.uwe.ac.uk\/cyber-security-cyber-crime\/wp-json\/wp\/v2\/tags?post=77"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}