Recommendations for Enhancing Security in Microservice Environment Altered in an Intelligent Way

Tihomir G. Tenev, Simeon Tsvetanov · 2020

The security aspect of designing distributed applications holds a significant part in software development, as they often operate with sensitive information. There is an agile architecture style, mainly used in constructing distributed applications with the advantage of independent partition scalability - Microservice architecture style. For mitigating security threats - such as disclosing or tampering with sensitive information - we suggest using Security patterns. In the current paper, we estimate the issues that exist when designing a secure environment, which microservices often accommodate. The first contribution is in making a vulnerability analysis and discovering the threats in this regard by using STRIDE. The second contribution is in providing recommendations for each security pattern in regard to the place of use, examples of using modern tools for applying patterns solution and the corresponding STRIDE category. The third contribution is in transforming the given recommendations using CIM model. That approach creates common definitions of the security patterns along with their recommendations, which in turn gives opportunities for adapting with various advanced technologies.

Read the paper · More papers on PaperTik