中文

微服务系统安全实践的实证研究

软件工程 2022-11-21 v4 密码学与安全

摘要

尽管微服务系统具有诸多优势,安全性一直是此类系统中的一个关键问题。造成这一困难的因素有多种,包括微服务从业者对如何正确保护微服务系统存在知识缺口。为(部分)弥补该缺口,我们开展了一项实证研究。我们首先手动分析了 861 个微服务安全点,包括来自 10 个 GitHub 开源微服务系统的 567 个问题、9 份文档和 3 个 wiki 页面,以及 306 个关于微服务系统安全的 Stack Overflow 帖子。在本研究中,一个微服务安全点被定义为“包含 5 个或以上微服务安全段落的 GitHub 问题、Stack Overflow 帖子、文档或 wiki 页面”。我们的分析得出了一个包含 28 项微服务安全实践的目录。随后,我们对 74 名微服务从业者进行了调查,以评估这 28 项实践的实用性。我们的发现表明,调查受访者肯定了这 28 项实践的实用性。我们相信该微服务安全实践目录可作为微服务从业者更有效地解决微服务系统安全问题的宝贵资源。它也可向研究界指明开发微服务特定安全实践与工具所需或较少被探索的领域。

关键词

引用

@article{arxiv.2112.14927,
  title  = {An Empirical Study of Security Practices for Microservices Systems},
  author = {Ali Rezaei Nasab and Mojtaba Shahin and Seyed Ali Hoseyni Raviz and Peng Liang and Amir Mashmool and Valentina Lenarduzzi},
  journal= {arXiv preprint arXiv:2112.14927},
  year   = {2022}
}

备注

Preprint accepted for publication in Journal of Systems and Software, 2022