A Risk Adaptive Access Control Model for the Service Mesh Architecture

Rami Alboqmi, Sharmin Jahan, Rose Gamble · 2024

Microservice architecture (MSA) applications can be built with a service mesh infrastructure layer that manages service-to-service communications through features, such as access control (AC) that is enforced statically and manually. Attackers attempt to exploit vulnerabilities in services to compromise the entire MSA application. The AC feature of the service mesh needs to be adaptive and capable of enforcing an emerging model called Risk-Adaptive Access Control (RAdAC). As found in the literature, RAdAC adjusts AC policies based on the assessed potential risk of access requests and the operational needs required to maintain the deployed application functionality. This paper introduces an architecture, called SMAAC, to add the self-adaptive AC features to the service mesh while maintaining and enhancing the RAdAC model. SMAAC houses runtime trust evaluation to assess the trustworthiness of a service based on behavioral patterns and quantifying it with a trust metric. In addition, SMAAC houses early threat intelligence sharing to enable threat data sharing in the service mesh. New for this work is enabling SMAAC with access policy generation (APG) that introduces self-adaptation to AC policies when the trust metric of the service request initiator falls below an acceptable level. APG considers the requesting service's impact levels on confidentiality, integrity, and availability that define service sensitivity within the MSA application. The paper introduces SMAAC and provides an initial demonstration of its potential using a third-party MSA application, Bench, that is deployed on the Istio service mesh platform with Kubernetes as the orchestration solution.

Read the paper · More papers on PaperTik