论文标题

使用微服务隔离来实现安全和无泄漏的工作流程

Towards Secure and Leak-Free Workflows Using Microservice Isolation

论文作者

Miller, Loïc, Mérindol, Pascal, Gallais, Antoine, Pelsser, Cristel

论文摘要

数据泄漏和漏洞正在上升。它们为电影业等企业带来了巨大的资金损失,以及处理诸如制药行业(例如制药行业)的企业的用户隐私损失。防止数据暴露是具有挑战性的,因为此类事件的原因是各种各样的,从黑客到配置错误的数据库不等。除了数据暴露的激增外,微服务作为范式的最新兴起不仅需要在网络边界处安全流量,而且还需要在内部施加采用新的安全模型(例如零信任)(例如零信任)来保护业务流程。 业务流程可以建模为工作流程,其中风险数据的所有者与承包商相互作用,以实现此数据的一系列任务。在本文中,我们展示了如何在防止数据曝光的同时强制执行这些工作流程。遵循零信托的原则,我们使用微服务架构提供的隔离来开发基础架构,以执行所有者策略。我们表明,我们的基础架构对我们的安全模型中考虑的攻击集有弹性。我们通过公开可用的概念证明,通过基础架构实现了简单但现实的工作流程。然后,我们通过测试违反政策的部署并估算授权的间接成本来验证指定的策略是否可以正确执行。

Data leaks and breaches are on the rise. They result in huge losses of money for businesses like the movie industry, as well as a loss of user privacy for businesses dealing with user data like the pharmaceutical industry. Preventing data exposures is challenging, because the causes for such events are various, ranging from hacking to misconfigured databases. Alongside the surge in data exposures, the recent rise of microservices as a paradigm brings the need to not only secure traffic at the border of the network, but also internally, pressing the adoption of new security models such as zero-trust to secure business processes. Business processes can be modeled as workflows, where the owner of the data at risk interacts with contractors to realize a sequence of tasks on this data. In this paper, we show how those workflows can be enforced while preventing data exposure. Following the principles of zero-trust, we develop an infrastructure using the isolation provided by a microservice architecture, to enforce owner policy. We show that our infrastructure is resilient to the set of attacks considered in our security model. We implement a simple, yet realistic, workflow with our infrastructure in a publicly available proof of concept. We then verify that the specified policy is correctly enforced by testing the deployment for policy violations, and estimate the overhead cost of authorization.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源