Exploring Microservice Security

Tetiana Yarygina · NORA - Norwegian Open Research Archives · 2018

Due to rapid transitioning towards digitalized society and extended reliance on interconnected digital systems, computer security is a field of growing importance. Software that we build should be secure, resilient and reliable both against accidents and targeted attacks. The microservice architecture, or concisely microservices, is a recent trend in software engineering and system design. Microservices are a way to build scalable and flexible distributed applications as a collection of loosely coupled services communicating over a network. In this thesis, we study the microservice architectural style from a security perspective. The contributions are as follows. We show that microservice architecture has inherent security benefits in terms of isolation and diversity. We explore how these inherent security benefits of microservices can be improved even further by maximizing interface security, avoiding unnecessary node relationships, introducing asymmetric node strength, and using N-version programming. We design a taxonomy of microservice security giving an overview of the existing security threats and mitigations. In this thesis, we argue that the defense in depth principle should be adopted for microservices. We discuss several prominent microservice security trends in industry. Furthermore, we present an open source prototype security framework for microservices. We take the defense in depth principle even further by focusing our attention on the self-protection and adaptive security properties. Also, we propose an architecture of an automated intrusion response system for microservices that uses gametheoretic approach. Finally, we analyze the security properties of the REST style, the most typical microservice integration solution.

Read the paper · More papers on PaperTik