Security Gap in Microservices: A Systematic Literature Review

被引:0
|
作者
Hutasuhut, Nurman Rasyid Panusunan [1 ]
Amri, Mochamad Gani [1 ]
Aji, Rizal Fathoni [1 ]
机构
[1] Univ Indonesia, Fac Comp Sci, Jakarta, Indonesia
关键词
-Microservice security; cyber-attacks; container; security standards; access control;
D O I
10.14569/IJACSA.2024.0151218
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The growing importance of microservices architecture has raised concerns about its security despite a rise in publications addressing various aspects of microservices. Security issues are particularly critical in microservices due to their complex and distributed nature, which makes them vulnerable to various types of cyber-attacks. This study aims to fill the gap in systematic investigations into microservice security by reviewing current state-of-the-art solutions and models. A total of 487 papers were analyzed, with the final selection refined to 87 relevant articles using a snowball method. This approach ensures that the focus remains on security issues, particularly those identified post- 2020. However, there is still a significant lack of dedicated security standards or comprehensive models specifically designed for microservices. Key findings highlight the vulnerabilities of container-based applications, the evolving nature of cyber-attacks, and the critical need for effective access control. Moreover, a substantial knowledge gap exists between academia and industry practitioners, which compounds the challenges of securing microservices. This study emphasizes the need for more focused research on security models and guidelines to address the unique vulnerabilities of microservices and facilitate their secure integration into critical applications across various domains.
引用
收藏
页码:165 / 171
页数:7
相关论文
共 50 条
  • [1] A Systematic Literature Review on Microservices
    Vural, Hulya
    Koyuncu, Murat
    Guney, Sinem
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2017, PT VI, 2017, 10409 : 203 - 217
  • [2] Smells and refactorings for microservices security: A multivocal literature review
    Ponce, Francisco
    Soldani, Jacopo
    Astudillo, Hernan
    Brogi, Antonio
    JOURNAL OF SYSTEMS AND SOFTWARE, 2022, 192
  • [3] Energy Consumption in Microservices Architectures: A Systematic Literature Review
    Araujo, Gabriel
    Barbosa, Vandirleya
    Lima, Luiz Nelson
    Sabino, Arthur
    Brito, Carlos
    Fe, Iure
    Rego, Paulo
    Choi, Eunmi
    Min, Dugki
    Nguyen, Tuan Anh
    Silva, Francisco Airton
    IEEE ACCESS, 2024, 12 : 186710 - 186729
  • [4] The pains and gains of microservices: A Systematic grey literature review
    Soldani, Jacopo
    Tamburri, Damian Andrew
    Van Den Heuvel, Willem-Jan
    JOURNAL OF SYSTEMS AND SOFTWARE, 2018, 146 : 215 - 232
  • [5] Authentication and Authorization in Microservices Architecture: A Systematic Literature Review
    de Almeida, Murilo Goes
    Canedo, Edna Dias
    APPLIED SCIENCES-BASEL, 2022, 12 (06):
  • [6] Monitoring tools for DevOps and microservices: A systematic grey literature review
    Giamattei, L.
    Guerriero, A.
    Pietrantuono, R.
    Russo, S.
    Malavolta, I.
    Islam, T.
    Dinga, M.
    Koziolek, A.
    Singh, S.
    Armbruster, M.
    Gutierrez-Martinez, J. M.
    Caro-Alvaro, S.
    Rodriguez, D.
    Weber, S.
    Henss, J.
    Vogelin, E. Fernandez
    Panojo, F. Simon
    JOURNAL OF SYSTEMS AND SOFTWARE, 2024, 208
  • [7] A Systematic Literature Review on Migration to Microservices: a Quality Attributes perspective
    Capuano, Roberta
    Muccini, Henry
    2022 IEEE 19TH INTERNATIONAL CONFERENCE ON SOFTWARE ARCHITECTURE COMPANION (ICSA-C 2022), 2022, : 120 - 123
  • [8] Research Opportunities in Microservices Quality Assessment: A Systematic Literature Review
    Tapia, Veronica C.
    Gaona, Carlos M.
    JOURNAL OF ADVANCES IN INFORMATION TECHNOLOGY, 2023, 14 (05) : 991 - 1002
  • [9] Exploring the Potential of Microservices in Internet of Things: A Systematic Review of Security and Prospects
    El Akhdar, Abir
    Baidada, Chafik
    Kartit, Ali
    Hanine, Mohamed
    Garcia, Carlos Osorio
    Lara, Roberto Garcia
    Ashraf, Imran
    SENSORS, 2024, 24 (20)
  • [10] Understanding and addressing quality attributes of microservices architecture: A Systematic literature review
    Li, Shanshan
    Zhang, He
    Jia, Zijia
    Zhong, Chenxing
    Zhang, Cheng
    Shan, Zhihao
    Shen, Jinfeng
    Babar, Muhammad Ali
    Information and Software Technology, 2021, 131