A Novel Approach for Security Analysis in Microservices Using Graph Neural Networks

Chitra Babu, Akil Karthikeyan, Nandakishor Velu, Kaarthik Sivakumar, Abhishek Pathak · 2024

Microservice architectures, as opposed to traditional monolithic ones, require an entirely different approach to iden-tify vulnerabilities, anomalies and other security issues. This is primarily due to the increased attack surface they expose through APIs. A comprehensive analysis of how anomalies in one microservice may affect others requires a detailed understanding of the structure of the entire application. This knowledge can help drive the software architecture to be followed in production applications - particularly those that store and manipulate critical information where vulnerabilities can have a significant business or privacy impact. With this motivation, this paper proposes MicroSecPost (μSecPost), a GNN-based microservice security analysis approach. μSecPost models a microservice based application as a graph that combines data from both static and dynamic analysis, representing each service as a node and service-to-service interactions as edges. μSecPost uses Graph Neural Networks (GNNs) on this graph representation to assign a vulnerability score to each node, predict edge features and score the entire application based on the scores of individual nodes and edges. μSecPost aims to help understand the existing security posture of a microservice-based application and determine where possible improvements can be made.

Read the paper · More papers on PaperTik