Threat Intelligence Sharing Component in the Service Mesh Architecture

Rami Alboqmi, Sharmin Jahan, Rose Gamble · 2023

The service mesh is a dedicated infrastructure layer in a microservice architecture (MSA) to handle service-to-service communication through application programming interface (API) calls. The service mesh employs features for continuous monitoring and ensuring delivery of service requests among services securely and reliably. The service mesh should enable threat intelligence sharing among the services at runtime as a part of continuous monitoring so that services are aware of potential threats and adapt to mitigate the threats. Threat intelligence contains detailed descriptions of attack tactics, techniques, and procedures (TTP) that are analyzed for countermeasure deployment. In this paper, we introduce threat intelligence sharing (TIS) into the control plane of the service mesh to enable the sharing of threat intelligence among services in an automated manner. It requires a structured format to specify threat intelligence and a well-defined protocol for sharing intelligence. We adopt a structured threat information expression (STIX) schema to specify threat intelligence and use the trusted automated exchange of intelligence information (TAXII) as a defined protocol to share threat intelligence as STIX documents. The advantage of including a TIS component in the service mesh is that it can generate threat intelligence using available telemetry data and enable sharing among the services without forcing services to modify their functionalities to support the process. We experiment with the TIS component’s effectiveness using an open-source MSA application called Online Boutique, which uses the service mesh platform, Istio, and Kubernetes as the orchestration solution.

Read the paper · More papers on PaperTik