论文标题

服务网格中的安全问题和挑战 - 一项扩展研究

Security Issues and Challenges in Service Meshes -- An Extended Study

论文作者

Hahn, Dalton A., Davidson, Drew, Bardas, Alexandru G.

论文摘要

服务网站已成为一种有吸引力的DevOps解决方案,用于收集,管理和协调微服务部署。但是,当前的服务网格留下基本的安全机制,缺少或不完整。安全负担意味着服务网格实际上可能会在传统整体系统上为管理员造成额外的工作量和开销。通过评估服务网格工具的有效性和实用性,这项工作为服务网格的可用安全性提供了必要的见解。我们从两个角度评估服务网格:熟练的系统管理员(部署可用安全机制的最佳配置)和默认配置。在这两种模型下,我们考虑了一组全面的对抗场景,并发现了与目标相矛盾的重要设计缺陷,以及在使用服务网格工具中为操作环境采用服务网格工具所遇到的局限性和挑战。

Service meshes have emerged as an attractive DevOps solution for collecting, managing, and coordinating microservice deployments. However, current service meshes leave fundamental security mechanisms missing or incomplete. The security burden means service meshes may actually cause additional workload and overhead for administrators over traditional monolithic systems. By assessing the effectiveness and practicality of service mesh tools, this work provides necessary insights into the available security of service meshes. We evaluate service meshes from two perspectives: skilled system administrators (who deploy optimal configurations of available security mechanisms) and default configurations. Under these two models, we consider a comprehensive set of adversarial scenarios and uncover important design flaws with contradicting goals, as well as the limitations and challenges encountered in employing service mesh tools for operational environments.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源