首页> 外文会议>IEEE International Conference on Software Architecture Companion >Automated Security Analysis for Microservice Architecture
【24h】

Automated Security Analysis for Microservice Architecture

机译:微服务架构的自动安全分析

获取原文

摘要

Designing a software system that applied the microservice architecture style is a challenging task, as its characteristics are vulnerable to various security attacks. Software architect, therefore, needs to pinpoint the security flaws in the design before the implementation can proceed. This task is error-prone as it requires manual analysis on the design model, to identify security threats and trace possible attack scenarios. This paper presents an automated security analysis approach for microservice architecture. Our approach can automatically identify security threats according to a collection of formally defined security characteristics and provide an insightful result that demonstrates how the attack scenarios may happen. A collection of formally defined security characteristics can be extended to support other security characteristics not addressed in this paper.
机译:设计应用微服务架构风格的软件系统是一个具有挑战性的任务,因为它的特性容易受到各种安全攻击的影响。 因此,软件架构师需要在实现可以继续之前确定设计中的安全漏洞。 此任务易于出错,因为它需要在设计模型上进行手动分析,以识别安全威胁和跟踪可能的攻击方案。 本文介绍了微服务架构的自动安全分析方法。 我们的方法可以根据正式定义的安全特性的集合自动识别安全威胁,并提供了展示攻击方案如何发生的识别结果。 可以扩展正式定义的安全特性的集合,以支持本文中未解决的其他安全特性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号