Visible to the public With Great Abstraction Comes Great Responsibility: Sealing the Microservices Attack Surface

TitleWith Great Abstraction Comes Great Responsibility: Sealing the Microservices Attack Surface
Publication TypeConference Paper
Year of Publication2019
AuthorsChen, Chien-An
Conference Name2019 IEEE Cybersecurity Development (SecDev)
Date PublishedSept. 2019
PublisherIEEE
ISBN Number978-1-5386-7289-1
Keywordsattack surface, Cloud Native, container, Docker, Kubernetes, Metrics, microservices, pubcrawl, resilience, Resiliency, Scalability
Abstract

While the IT industry is embracing the cloud-native technologies, migrating from monolithic architecture to service-oriented architecture is not a trivial process. It involves a lot of dissection and abstraction. The layer of abstraction designed for simplifying the development quickly becomes the barrier of visibility and the source of misconfigurations. The complexity may give microservices a larger attack surface compared to monolithic applications. This talk presents a microservices threat modeling that uncovers the attack vectors hidden in each abstraction layer. Scenarios of security breaches in microservices platforms are discussed, followed by the countermeasures to close these attack vectors. Finally, a decision-making process for architecting secure microservices is presented.

URLhttps://ieeexplore.ieee.org/document/8901600
DOI10.1109/SecDev.2019.00027
Citation Keychen_great_2019