{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T22:40:18Z","timestamp":1785537618232,"version":"3.56.0"},"reference-count":53,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2021,1,20]],"date-time":"2021-01-20T00:00:00Z","timestamp":1611100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSA Science of Security Lablet","award":["H98230-17-D-0080"],"award-info":[{"award-number":["H98230-17-D-0080"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2021,1,31]]},"abstract":"<jats:p>\n            <jats:bold>Context:<\/jats:bold>\n            Security smells are recurring coding patterns that are indicative of security weakness and require further inspection. As infrastructure as code (IaC) scripts, such as Ansible and Chef scripts, are used to provision cloud-based servers and systems at scale, security smells in IaC scripts could be used to enable malicious users to exploit vulnerabilities in the provisioned systems.\n            <jats:bold>Goal:<\/jats:bold>\n            <jats:italic>The goal of this article is to help practitioners avoid insecure coding practices while developing infrastructure as code scripts through an empirical study of security smells in Ansible and Chef scripts.<\/jats:italic>\n            <jats:bold>Methodology:<\/jats:bold>\n            We conduct a replication study where we apply qualitative analysis with 1,956 IaC scripts to identify security smells for IaC scripts written in two languages: Ansible and Chef. We construct a static analysis tool called Security Linter for Ansible and Chef scripts (SLAC) to automatically identify security smells in 50,323 scripts collected from 813 open source software repositories. We also submit bug reports for 1,000 randomly selected smell occurrences.\n            <jats:bold>Results:<\/jats:bold>\n            We identify two security smells not reported in prior work: missing default in case statement and no integrity check. By applying SLAC we identify 46,600 occurrences of security smells that include 7,849 hard-coded passwords. We observe agreement for 65 of the responded 94 bug reports, which suggests the relevance of security smells for Ansible and Chef scripts amongst practitioners.\n            <jats:bold>Conclusion:<\/jats:bold>\n            We observe security smells to be prevalent in Ansible and Chef scripts, similarly to that of the Puppet scripts. We recommend practitioners to rigorously inspect the presence of the identified security smells in Ansible and Chef scripts using (i) code review, and (ii) static analysis tools.\n          <\/jats:p>","DOI":"10.1145\/3408897","type":"journal-article","created":{"date-parts":[[2021,1,20]],"date-time":"2021-01-20T19:18:06Z","timestamp":1611170286000},"page":"1-31","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":67,"title":["Security Smells in Ansible and Chef Scripts"],"prefix":"10.1145","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5056-757X","authenticated-orcid":false,"given":"Akond","family":"Rahman","sequence":"first","affiliation":[{"name":"Tennessee Technological University, Cookeville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Md Rayhanur","family":"Rahman","sequence":"additional","affiliation":[{"name":"NC State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chris","family":"Parnin","sequence":"additional","affiliation":[{"name":"NC State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[{"name":"NC State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,1,20]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.52"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183519.3183549"},{"key":"e_1_2_1_3_1","volume-title":"NASA: Increasing Cloud Efficiency with Ansible and Ansible Tower. Technical Report. Ansible.","year":"2019","unstructured":"Ansible. 2019 . NASA: Increasing Cloud Efficiency with Ansible and Ansible Tower. Technical Report. Ansible. Ansible. 2019. NASA: Increasing Cloud Efficiency with Ansible and Ansible Tower. Technical Report. Ansible."},{"key":"e_1_2_1_4_1","volume-title":"Retrieved","year":"2020","unstructured":"Ansible. 2020 . Ansible Project . Retrieved April 25, 2020 from https:\/\/docs.ansible.com\/. Ansible. 2020. Ansible Project. Retrieved April 25, 2020 from https:\/\/docs.ansible.com\/."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1469-1809.1939.tb02219.x"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635880"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS\u201911)","author":"Bugiel Sven","year":"2011","unstructured":"Sven Bugiel , Stefan Nurnberger , Thomas Poppelmann , Ahmad-Reza Sadeghi , and Thomas Schneider . 2011 . Amazon IA: When elasticity snaps back . In Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS\u201911) . ACM, New York, NY, 389--400. DOI:https:\/\/doi.org\/10.1145\/ 2046707.2046753 10.1145\/2046707.2046753 Sven Bugiel, Stefan Nurnberger, Thomas Poppelmann, Ahmad-Reza Sadeghi, and Thomas Schneider. 2011. Amazon IA: When elasticity snaps back. In Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS\u201911). ACM, New York, NY, 389--400. DOI:https:\/\/doi.org\/10.1145\/2046707.2046753"},{"key":"e_1_2_1_9_1","unstructured":"Chef. 2018. Sitemap-Chef Docs. Retrieved July 4 2019 from https:\/\/docs.chef.io\/.  Chef. 2018. Sitemap-Chef Docs. Retrieved July 4 2019 from https:\/\/docs.chef.io\/."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.15"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1177\/001316446002000104"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48285-7_26"},{"key":"e_1_2_1_13_1","unstructured":"Albert Endres and H. Dieter Rombach. 2003. A Handbook of Software and Systems Engineering: Empirical Observations Laws and Theories. Pearson Education.  Albert Endres and H. Dieter Rombach. 2003. A Handbook of Software and Systems Engineering: Empirical Observations Laws and Theories. Pearson Education."},{"key":"e_1_2_1_14_1","volume-title":"Refactoring: Improving the Design of Existing Code","author":"Fowler Martin","year":"1999","unstructured":"Martin Fowler and Kent Beck . 1999 . Refactoring: Improving the Design of Existing Code . Addison-Wesley Professional . Martin Fowler and Kent Beck. 1999. Refactoring: Improving the Design of Existing Code. Addison-Wesley Professional."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3022671.2984000"},{"key":"e_1_2_1_16_1","volume-title":"Continuous Delivery: Reliable Software Releases Through Build, Test, and Deployment Automation","author":"Humble Jez","year":"2010","unstructured":"Jez Humble and David Farley . 2010 . Continuous Delivery: Reliable Software Releases Through Build, Test, and Deployment Automation ( 1 st ed.). Addison-Wesley Professional . Jez Humble and David Farley. 2010. Continuous Delivery: Reliable Software Releases Through Build, Test, and Deployment Automation (1st ed.). Addison-Wesley Professional.","edition":"1"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-45065-5_19"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2015.12"},{"key":"e_1_2_1_19_1","volume-title":"G\u00f3mez","author":"Juristo Natalia","year":"2010","unstructured":"Natalia Juristo and Omar S . G\u00f3mez . 2010 . Replication of software engineering experiments. In Empirical Software Engineering and Verification. Springer , 60--88. Natalia Juristo and Omar S. G\u00f3mez. 2010. Replication of software engineering experiments. In Empirical Software Engineering and Verification. Springer, 60--88."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/0164-1212(92)90089-3"},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 1st International Workshop on Replication in Empirical Software Engineering Research.","author":"Jonathan","unstructured":"Jonathan L. Krein and Charles D. Knutson. 2010. A case for replication: Synthesizing research methodologies in software engineering . In Proceedings of the 1st International Workshop on Replication in Empirical Software Engineering Research. Jonathan L. Krein and Charles D. Knutson. 2010. A case for replication: Synthesizing research methodologies in software engineering. In Proceedings of the 1st International Workshop on Replication in Empirical Software Engineering Research."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183519.3183548"},{"key":"e_1_2_1_23_1","volume-title":"Borsa Istanbul: Improving Efficiency and Reducing Costs to Manage a Growing Infrastructure. Technical Report. Puppet.","author":"Labs Puppet","year":"2018","unstructured":"Puppet Labs . 2018 . Borsa Istanbul: Improving Efficiency and Reducing Costs to Manage a Growing Infrastructure. Technical Report. Puppet. Puppet Labs. 2018. Borsa Istanbul: Improving Efficiency and Reducing Costs to Manage a Growing Infrastructure. Technical Report. Puppet."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.2307\/2529310"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23418"},{"key":"e_1_2_1_27_1","volume-title":"CWE-Common Weakness Enumeration. Retrieved","author":"MITRE.","year":"2019","unstructured":"MITRE. 2018. CWE-Common Weakness Enumeration. Retrieved July 2, 2019 from https:\/\/cwe.mitre.org\/index.html. MITRE. 2018. CWE-Common Weakness Enumeration. Retrieved July 2, 2019 from https:\/\/cwe.mitre.org\/index.html."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9512-6"},{"key":"e_1_2_1_29_1","unstructured":"Pars Mutaf. 1999. Defending against a Denial-of-Service Attack on TCP. In Recent Advances in Intrusion Detection.  Pars Mutaf. 1999. Defending against a Denial-of-Service Attack on TCP. In Recent Advances in Intrusion Detection."},{"key":"e_1_2_1_30_1","volume-title":"Security and Privacy Controls for Federal Information Systems and Organizations. Retrieved","author":"National Institute of Standards and Technology. 2014.","year":"2019","unstructured":"National Institute of Standards and Technology. 2014. Security and Privacy Controls for Federal Information Systems and Organizations. Retrieved July 4, 2019 from https:\/\/www.nist.gov\/publications\/security-and-privacy-controls-federal-information-systems-and-organizations-including-0. National Institute of Standards and Technology. 2014. Security and Privacy Controls for Federal Information Systems and Organizations. Retrieved July 4, 2019 from https:\/\/www.nist.gov\/publications\/security-and-privacy-controls-federal-information-systems-and-organizations-including-0."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3278142.3278149"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380409"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09841-8"},{"key":"e_1_2_1_36_1","volume-title":"A systematic mapping study of infrastructure as code research. Inf. Softw. Technol. 108, 4","author":"Rahman Akond","year":"2018","unstructured":"Akond Rahman , Rezvan Mahdavi-Hezaveh , and Laurie Williams . 2018. A systematic mapping study of infrastructure as code research. Inf. Softw. Technol. 108, 4 ( 2018 ). DOI:https:\/\/doi.org\/10.1016\/j.infsof.2018.12.004 10.1016\/j.infsof.2018.12.004 Akond Rahman, Rezvan Mahdavi-Hezaveh, and Laurie Williams. 2018. A systematic mapping study of infrastructure as code research. Inf. Softw. Technol. 108, 4 (2018). DOI:https:\/\/doi.org\/10.1016\/j.infsof.2018.12.004"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00033"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/3105398.3105404"},{"key":"#cr-split#-e_1_2_1_39_1.1","unstructured":"Akond Rahman M. Rahman Chris Parnin and Laurie Williams. 2020. Dataset for security smells for ansible and chef scripts used in DevOps. DOI:https:\/\/doi.org\/10.6084\/m9.figshare.8085755 10.6084\/m9.figshare.8085755"},{"key":"#cr-split#-e_1_2_1_39_1.2","doi-asserted-by":"crossref","unstructured":"Akond Rahman M. Rahman Chris Parnin and Laurie Williams. 2020. Dataset for security smells for ansible and chef scripts used in DevOps. DOI:https:\/\/doi.org\/10.6084\/m9.figshare.8085755","DOI":"10.1145\/3408897"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2018.00014"},{"key":"e_1_2_1_41_1","volume-title":"Source code properties of defective infrastructure as code scripts. Inf. Softw. Technol. 112, 11","author":"Rahman Akond","year":"2019","unstructured":"Akond Rahman and Laurie Williams . 2019. Source code properties of defective infrastructure as code scripts. Inf. Softw. Technol. 112, 11 ( 2019 ). DOI:https:\/\/doi.org\/10.1016\/j.infsof.2019.04.013 10.1016\/j.infsof.2019.04.013 Akond Rahman and Laurie Williams. 2019. Source code properties of defective infrastructure as code scripts. Inf. Softw. Technol. 112, 11 (2019). DOI:https:\/\/doi.org\/10.1016\/j.infsof.2019.04.013"},{"key":"e_1_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Eric Rescorla. 2000. Http over tls. (2000). http:\/\/dret.net\/biblio\/reference\/rfc2818.  Eric Rescorla. 2000. Http over tls. (2000). http:\/\/dret.net\/biblio\/reference\/rfc2818.","DOI":"10.17487\/rfc2818"},{"key":"e_1_2_1_43_1","volume-title":"The Coding Manual for Qualitative Researchers","author":"Saldana Johnny","unstructured":"Johnny Saldana . 2015. The Coding Manual for Qualitative Researchers . Sage . Johnny Saldana. 2015. The Coding Manual for Qualitative Researchers. Sage."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1037\/a0015108"},{"key":"e_1_2_1_46_1","volume-title":"Code Smell Detection in Infrastructure as Code. Retrieved","author":"Schwarz Julian","year":"2019","unstructured":"Julian Schwarz . 2017. Code Smell Detection in Infrastructure as Code. Retrieved July 2, 2019 from https:\/\/www.swc.rwth-aachen.de\/thesis\/code-smell-detection-infrastructure-code\/. Julian Schwarz. 2017. Code Smell Detection in Infrastructure as Code. Retrieved July 2, 2019 from https:\/\/www.swc.rwth-aachen.de\/thesis\/code-smell-detection-infrastructure-code\/."},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the 2018 11th International Conference on the Quality of Information and Communications Technology (QUATIC\u201918)","author":"Schwarz J.","year":"2018","unstructured":"J. Schwarz , A. Steffens , and H. Lichter . 2018. Code smells in infrastructure as code . In Proceedings of the 2018 11th International Conference on the Quality of Information and Communications Technology (QUATIC\u201918) . 220--228. DOI:https:\/\/doi.org\/10.1109\/QUATIC. 2018 .00040 10.1109\/QUATIC.2018.00040 J. Schwarz, A. Steffens, and H. Lichter. 2018. Code smells in infrastructure as code. In Proceedings of the 2018 11th International Conference on the Quality of Information and Communications Technology (QUATIC\u201918). 220--228. DOI:https:\/\/doi.org\/10.1109\/QUATIC.2018.00040"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2901761"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1083142.1083147"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368088.1368123"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294276"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330206"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1007\/11426639_2"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.5555\/2349018"},{"key":"e_1_2_1_55_1","volume-title":"Retrieved","author":"Brikman Yevgeniy","year":"2016","unstructured":"Yevgeniy Brikman . 2016 . Why we use Terraform and not Chef, Puppet, Ansible, SaltStack, or CloudFormation . Retrieved April 24, 2020 from https:\/\/blog.gruntwork.io\/why-we-use-terraform-and-not-chef-puppet-ansible-saltstack-or-cloudformation-7989dad2865c. Yevgeniy Brikman. 2016. Why we use Terraform and not Chef, Puppet, Ansible, SaltStack, or CloudFormation. Retrieved April 24, 2020 from https:\/\/blog.gruntwork.io\/why-we-use-terraform-and-not-chef-puppet-ansible-saltstack-or-cloudformation-7989dad2865c."},{"key":"e_1_2_1_56_1","doi-asserted-by":"crossref","unstructured":"Tatu Ylonen and Chris Lonvick. 2006. The secure shell (SSH) protocol architecture. (2006). https:\/\/tools.ietf.org\/html\/rfc4251.  Tatu Ylonen and Chris Lonvick. 2006. The secure shell (SSH) protocol architecture. (2006). https:\/\/tools.ietf.org\/html\/rfc4251.","DOI":"10.17487\/rfc4251"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3408897","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3408897","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:47:58Z","timestamp":1750193278000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3408897"}},"subtitle":["A Replication Study"],"short-title":[],"issued":{"date-parts":[[2021,1,20]]},"references-count":53,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,1,31]]}},"alternative-id":["10.1145\/3408897"],"URL":"https:\/\/doi.org\/10.1145\/3408897","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,20]]},"assertion":[{"value":"2020-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-06-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-01-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}