作者
Antonio M Espinoza, Riley Wood, Stephanie Forrest, Mohit Tiwari
发表日期
2022/6/27
研讨会论文
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
页码范围
415-427
出版商
IEEE
简介
Microservices are the dominant architecture used to build internet-scale applications today. Being internet-facing, their most critical attack surfaces are the OWASP top 10 Web Application Security Risks. Many of the top 10 OWASP attack types—injection, cross site scripting, broken access control and security misconfigurations—have persisted for many years despite major investments in code analysis and secure development patterns. Because microservices decompose monolithic applications into components using clean APIs, they lend themselves to practical application of a classic security/resilience principle, N-versioning. The paper introduces RDDR, a principled approach for applying N-versioning to microservices to improve resilience to data leaks. RDDR applies N-versioning to vulnerable microservices, requiring minimal code changes and with low performance impact beyond the cost of replicating …
引用总数
学术搜索中的文章
AM Espinoza, R Wood, S Forrest, M Tiwari - 2022 52nd Annual IEEE/IFIP International Conference …, 2022