Doing more with less? A Study on Models for Intrusion Detection in Microservices

José Flora, Nuno Antunes · 2024

Microservice-based systems are becoming very frequent in many systems, even in business-critical ones. It is only logical that attackers pay more attention to microservices security and attempt to compromise it to achieve their goals. Intrusion detection has been used to increase the security level of these systems but faces significant challenges: namely, effectively processing all the information produced by the services and keeping up with constant modifications and releases. Microservice environments are extremely dynamic, changing by the day or even faster. Although anomaly-based approaches can detect zero-days they require a clear definition of the microservice behavior, which may be cumbersome to obtain without a clear notion of a service’s core behavior. In this paper, we propose three techniques that allow to obtain the core behavior of a microservice into intrusion detection models. The techniques capture a stable model of a microservice core and can be applied across service releases. The models created are evaluated using datasets generated in a representative system with known vulnerabilities through an attack injection methodology with a diverse set of representative attacks. The results show that obtaining the core of a service helps with reusing detection models across several releases, despite some limitations.

Read the paper · More papers on PaperTik