On automated RBAC assessment by constructing a centralized perspective for microservice mesh

Author:

Das Dipta1ORCID,Walker Andrew1,Bushong Vincent1ORCID,Svacina Jan1ORCID,Cerny Tomas1ORCID,Matyas Vashek2

Affiliation:

1. Department of Computer Science, Baylor University, Waco, TX, USA

2. Faculty of Informatics, Masaryk University, Brno, Czech Republic

Abstract

It is important in software development to enforce proper restrictions on protected services and resources. Typically software services can be accessed through REST API endpoints where restrictions can be applied using the Role-Based Access Control (RBAC) model. However, RBAC policies can be inconsistent across services, and they require proper assessment. Currently, developers use penetration testing, which is a costly and cumbersome process for a large number of APIs. In addition, modern applications are split into individual microservices and lack a unified view in order to carry out automated RBAC assessment. Often, the process of constructing a centralized perspective of an application is done using Systematic Architecture Reconstruction (SAR). This article presents a novel approach to automated SAR to construct a centralized perspective for a microservice mesh based on their REST communication pattern. We utilize the generated views from SAR to propose an automated way to find RBAC inconsistencies.

Funder

National Science Foundation

Red Hat Research

Publisher

PeerJ

Subject

General Computer Science

Reference53 articles.

1. Role-based authorization constraints specification;Ahn;ACM Transactions on Information and System Security,2000

2. Towards micro service architecture recovery: An empirical study;Alshuqayran,2018

3. Dynamic enforcement of abstract separation of duty constraints;Basin,2009

Cited by 7 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. From static code analysis to visual models of microservice architecture;Cluster Computing;2024-04-24

2. Software Architecture Reconstruction for Microservice Systems Using Static Analysis via GraalVM Native Image;2024 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER);2024-03-12

3. Catalog and detection techniques of microservice anti-patterns and bad smells: A tertiary study;Journal of Systems and Software;2023-12

4. Roadmap to Reasoning in Microservice Systems: A Rapid Review;Applied Sciences;2023-01-31

5. Towards Security-Aware Microservices: On Extracting Endpoint Data Access Operations to Determine Access Rights;Proceedings of the 13th International Conference on Cloud Computing and Services Science;2023

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3