Integrating Continuous Security Assessments in Microservices and Cloud Native Applications

Integrating Continuous Security Assessments in Microservices and Cloud Native Applications
复制标题

在微服务和云原生应用程序中集成持续安全评估

DOI:
10.1145/3147213.3147229
复制
发表时间:
2017
期刊:
Proceedings of the10th International Conference on Utility and Cloud Computing
影响因子:
--
通讯作者:
C. Meinel
C. Meinel
中科院分区:
--
文献类型:
--
作者:
K. Torkura;M. Sukmana;C. Meinel

文献摘要

被引文献

相似文献

云本地应用(Cloud Native Applications,CNA)由多个协同工作的微服务实例组成,它们为了共同的目标而共同工作。这些微服务利用底层云基础设施来实现多个属性,如可伸缩性和弹性。CNA是复杂的分布式应用程序,容易受到影响微服务和基于云的传统应用程序的几个安全问题的影响。例如,每个微服务实例可以使用不同的技术开发,例如编程语言和数据库。这种技术的多样性增加了微服务中安全漏洞的可能性。此外,中央通讯社(CNA)快节奏的开发周期增加了开发管道中安全测试不足的可能性,从而增加了易受攻击的微服务的部署。此外,云本地环境是短暂的,微服务是动态启动和注销的,这一因素给传统的安全评估技术带来了可发现性的挑战。因此,这种环境中的安全评估需要专门适应和整合CNA的新方法。事实上,这样的技术应该是云本地的,即很好地集成到云的结构中。在本文中,我们通过引入一种新的安全控制概念-安全网关来应对上述挑战。为了支持安全网关概念,还提出了另外两个概念:动态文档存储和安全健康端点。我们使用本地云设计模式实施了这些概念,并将其集成到CNA工作流程中。我们的实验评估验证了我们的建议的有效性,安全网关的时间开销最小,漏洞检测率超过了传统的安全评估方法。因此,我们的建议可用于确保基于CNA和微服务的实施。
Cloud Native Applications (CNA) consists of multiple collaborating microservice instances working together towards common goals. These microservices leverage the underlying cloud infrastructure to enable several properties such as scalability and resiliency. CNA are complex distributed applications, vulnerable to several security issues affecting microservices and traditional cloud-based applications. For example, each microservice instance could be developed with different technologies e.g. programming languages and databases. This diversity of technologies increases the chances for security vulnerabilities in microservices. Moreover, the fast-paced development cycles of (CNA) increases the probability of insufficient security tests in the development pipelines, and consequent deployment of vulnerable microservices. Furthermore, cloud native environments are ephemeral, microservices are dynamically launched and de-registered, this factor creates a discoverability challenge for traditional security assessment techniques. Hence, security assessments in such environments require new approaches which are specifically adapted and integrated to CNA. In fact, such techniques are to be cloud native i.e. well integrated into the cloud's fabric. In this paper, we tackle the above-mentioned challenges through the introduction of a novel Security Control concept - the Security Gateway. To support the Security Gateway concept, two other concepts are proposed: dynamic document store and security health endpoints. We have implemented these concepts using cloud-native design patterns and integrated them into the CNA workflow. Our experimental evaluations validate the efficiency of our proposals, the time overhead due to the security gateway is minimal and the vulnerability detection rate surpasses that of traditional security assessment approaches. Our proposal can therefore be employed to secure CNA and microservice-based implementations.