Moving Target Defense for Cloud-Native Applications

被引:0
|
作者
Awarkeh, Ali [1 ]
El-Malki, Rim [1 ]
Rebecchi, Filippo [1 ]
机构
[1] Ericsson, Stand & Technol, Massy, France
关键词
MTD; cloud-native; Kubernetes; pods; state-machine;
D O I
10.1109/ICIN60470.2024.10494492
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The proliferation of cloud-native applications has sparked significant interest across various sectors. As these methodologies gain traction, they introduce a transformative shift within the cloud computing landscape. At the forefront of this shift is the synergy between container technology and microservice architecture, promising to significantly enhance both efficiency and agility across industries. Nonetheless, this transformation also adds complexity and enlarges the system attack surface, introducing additional vulnerabilities susceptible to being exploited by well-informed and resourceful attackers, especially in case of static defense techniques. To address these challenges, we propose a Moving Target Defense (MTD) approach, which proactively intervenes on the lifecycle of cloud-native application components. Such dynamicity serves as deterrent to potential adversaries, making persistence harder, lowering the effectiveness of automated attack tools, and increasing overall complexity and cost. We detail a step-by-step path, ranging from simple to advanced MTD techniques, targeting both stateless and stateful applications within a cloud-native environment. We evaluate these strategies and demonstrate that they effectively mitigate different types of attacks (e.g., Denial of service (DoS), lateral movement, reconnaissance, etc.) with minimal resource overhead and without causing service interruptions during normal system operation.
引用
收藏
页码:130 / 137
页数:8
相关论文
共 50 条
  • [1] Cloud-Native Applications and Services
    Kratzke, Nane
    [J]. FUTURE INTERNET, 2022, 14 (12)
  • [2] Benchmarking Scalability of Cloud-Native Applications
    Henning, Sören
    Hasselbring, Wilhelm
    [J]. Lecture Notes in Informatics (LNI), Proceedings - Series of the Gesellschaft fur Informatik (GI), 2023, P-332 : 59 - 60
  • [3] State Management for Cloud-Native Applications
    Szalay, Mark
    Matray, Peter
    Toka, Laszlo
    [J]. ELECTRONICS, 2021, 10 (04) : 1 - 27
  • [4] Approaches for migrating non cloud-native applications to the cloud
    Shastry, Abhigna L.
    Nair, Devika S.
    Prathima, B.
    Ramya, C. P.
    Hallymysore, Phalachandra
    [J]. 2022 IEEE 12TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2022, : 632 - 638
  • [5] Enhancement of Cloud-native applications with Autonomic Features
    Kosinska, Joanna
    Zielinski, Krzysztof
    [J]. JOURNAL OF GRID COMPUTING, 2023, 21 (03)
  • [6] Enriching Cloud-native Applications with Sustainability Features
    Vitali, Monica
    Schmiedmayer, Paul
    Bootz, Valentin
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING, IC2E, 2023, : 21 - 31
  • [7] Autonomic Management Framework for Cloud-Native Applications
    Kosinska, Joanna
    Zielinski, Krzysztof
    [J]. JOURNAL OF GRID COMPUTING, 2020, 18 (04) : 779 - 796
  • [8] Enhancement of Cloud-native applications with Autonomic Features
    Joanna Kosińska
    Krzysztof Zieliński
    [J]. Journal of Grid Computing, 2023, 21
  • [9] Autonomic Management Framework for Cloud-Native Applications
    Joanna Kosińska
    Krzysztof Zieliński
    [J]. Journal of Grid Computing, 2020, 18 : 779 - 796
  • [10] Cloud-Native Applications-The Journey Continues
    Yousif, Mazin
    [J]. IEEE CLOUD COMPUTING, 2017, 4 (05): : 4 - 5