首页> 外文期刊>Computers & Security >Security in microservice-based systems: A Multivocal literature review
【24h】

Security in microservice-based systems: A Multivocal literature review

机译:基于MicroService的系统中的安全性:多因素文献综述

获取原文
获取原文并翻译 | 示例

摘要

Microservices define an architectural style that conceives systems as a suite of modular, independent and scalable services. While application design is now simpler, designing secure applications is in general harder than for monolithic applications and the current literature offers little orientation to architects and developers regarding solutions. This article describes the design and results of a multivocal literature review of the security solutions that have been proposed for microservice-based systems. The study yielded 370 academic articles and 620 grey literature; duplicates removal and the application of exclusion criteria left 36 from the academic literature and 34 from the grey literature. The security solution(s) proposed in each article were classified into variations of standard security mechanisms (e.g., Access Control) and scopes (Info Management, Threat Modeling, etc), and were associated to security contexts (detect, mitigate/stop, react, recover from attack). Our research questions addressed frequency of publications, research methodologies, security mechanisms, and security contexts. Key findings were that (1) both kinds of literature differ in their preferred empirical research strategies (examples, experiments and case studies); (2) The solutions proposed in the 70 selected articles correspond to 15 classifications of security mechanisms and analyses; (3) the most mentioned security mechanisms are Authentication and Authorization; (4) around 2/3 of solutions focused on Mitigate/Stop attacks, but none on reacting and recovering from them, and (5) the methodologies used are mostly block diagrams and code, with little use of models or analysis. These findings hold for both grey and academic literature. This study is a first step towards providing secure software researchers and practitioners a comprehensive catalog of security solutions and mechanisms, and where the clear identification of the most used security solutions will simplify their reuse to address security problems while designing microservice-based systems.
机译:微服务定义了一种架构风格,可以将系统视为模块化,独立和可扩展的服务套件。虽然应用设计现在更简单,但设计安全应用程序通常比单片应用更难,而目前的文献对建筑师和开发人员提供了很少的方向,而是关于解决方案的方向。本文介绍了对基于微服务的系统提出的安全解决方案的多元素文献综述的设计和结果。该研究产生了370个学术文章和620个灰色文学;重复删除和应用排除标准从学术文献中留下36,从灰色文献中的34。每篇文章中提出的安全解决方案被分类为标准安全机制(例如,访问控制)和范围(INFO管理,威胁建模等)的变体,并与安全上下文相关联(检测,减轻/停止,反应从攻击中恢复)。我们的研究问题解决了出版物的频率,研究方法,安全机制和安全环境。主要发现是(1)两种文献在其首选经验研究策略中有所不同(实例,实验和案例研究); (2)70种所选物品中提出的解决方案对应于安全机制和分析的15分类; (3)最提到的安全机制是认证和授权; (4)大约2/3的解决方案专注于减缓/停止攻击,但没有关于反应和从它们恢复的影响,(5)所用方法主要是块图和代码,几乎没有使用模型或分析。这些调查结果适用于灰色和学术文献。本研究是为安全解决方案和机制的全面目录提供安全软件研究人员和从业者的第一步,以及最清晰的安全解决方案的清晰识别将简化其重用以在设计基于微服务的系统时解决安全问题。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号