2023 · 12 citations · 10 references
Microservice architectures decompose web applications into loosely-coupled, distributed components that interact with each other to provide an overall service. While this popular software architecture paradigm has many advantages in development and deployment, it also introduces a wider attack surface that is vulnerable to both internal and external attackers. Potentially malicious third-party services or software packages, as well as increased communication endpoints, introduce a wide array of security concerns. To improve the resiliency of microservice-based applications, many of which store sensitive data, we propose a novel, path-based anomaly detection and access control infrastructure that requires no modifications to existing software. We propose leveraging trusted proxies deployed alongside each service for request inspection, anomaly detection and signed token propagation for end-user path validation. Our approach reduces the trusted computing base away from the microservices to a smaller set of components that allow for less trust and a smaller attack surface.
10
Proceedings of the 24th USENIX Conference on Security Symposium
Jaeyeon Jung · 2015 · 466 citations
Microservices in Practice, Part 1: Reality Check and Service Design
Cesare Pautasso, Olaf Zimmermann, Mike Amundsen et al. · IEEE Software · 2017 · 118 citations
A Novel Graph-based Mechanism for Identifying Traffic Vulnerabilities in Smart Home IoT
Yizhen Jia, Yinhao Xiao, Jiguo Yu et al. · 2018 · 54 citations