Security Gap in Microservices: A Systematic Literature Review

被引:0
|
作者
Hutasuhut, Nurman Rasyid Panusunan [1 ]
Amri, Mochamad Gani [1 ]
Aji, Rizal Fathoni [1 ]
机构
[1] Univ Indonesia, Fac Comp Sci, Jakarta, Indonesia
关键词
-Microservice security; cyber-attacks; container; security standards; access control;
D O I
10.14569/IJACSA.2024.0151218
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The growing importance of microservices architecture has raised concerns about its security despite a rise in publications addressing various aspects of microservices. Security issues are particularly critical in microservices due to their complex and distributed nature, which makes them vulnerable to various types of cyber-attacks. This study aims to fill the gap in systematic investigations into microservice security by reviewing current state-of-the-art solutions and models. A total of 487 papers were analyzed, with the final selection refined to 87 relevant articles using a snowball method. This approach ensures that the focus remains on security issues, particularly those identified post- 2020. However, there is still a significant lack of dedicated security standards or comprehensive models specifically designed for microservices. Key findings highlight the vulnerabilities of container-based applications, the evolving nature of cyber-attacks, and the critical need for effective access control. Moreover, a substantial knowledge gap exists between academia and industry practitioners, which compounds the challenges of securing microservices. This study emphasizes the need for more focused research on security models and guidelines to address the unique vulnerabilities of microservices and facilitate their secure integration into critical applications across various domains.
引用
收藏
页码:165 / 171
页数:7
相关论文
共 50 条
  • [31] On the Security Aspects of Internet of Things: A Systematic Literature Review
    Macedo, Evandro L. C.
    de Oliveira, Egberto A. R.
    Silva, Fabio H.
    Mello Jr, Rui R.
    Franca, Felipe M. G.
    Delicato, Flavia C.
    de Rezende, Jose F.
    de Moraes, Luis F. M.
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2019, 21 (05) : 444 - 457
  • [32] Information Security Policy Compliance: Systematic Literature Review
    Angraini
    Alias, Rose Alinda
    Okfalisa
    FIFTH INFORMATION SYSTEMS INTERNATIONAL CONFERENCE, 2019, 161 : 1216 - 1224
  • [33] Systematic literature review on security misconfigurations in web applications
    Martins, Samuel Luna
    Cruz, Felipe Mendes da
    Araújo, Rogério Pontes de
    Silva, Carlo Marcelo Revoredo da
    International Journal of Computers and Applications, 2024, 46 (10) : 840 - 852
  • [34] A systematic literature review of mitigating cyber security risk
    Kamarudin S.
    Tang L.
    Bolong J.
    Adzharuddin N.A.
    Quality & Quantity, 2024, 58 (4) : 3251 - 3273
  • [35] Security Issues in Fog Environment: A Systematic Literature Review
    Kaur, Jasleen
    Agrawal, Alka
    Khan, Raees Ahmad
    INTERNATIONAL JOURNAL OF WIRELESS INFORMATION NETWORKS, 2020, 27 (03) : 467 - 483
  • [36] Security testing for web applications: A Systematic Literature Review
    Dominguez-Garcia, Antonio de Jesus
    Limon, Xavier
    Ocharan-Hernandez, Jorge Octavio
    Perez-Arriaga, Juan Carlos
    2023 11TH INTERNATIONAL CONFERENCE IN SOFTWARE ENGINEERING RESEARCH AND INNOVATION, CONISOFT 2023, 2023, : 82 - 91
  • [37] Software supply chain security: a systematic literature review
    Reichert, Beatriz M.
    Obelheiro, Rafael R.
    International Journal of Computers and Applications, 2024, 46 (10) : 853 - 867
  • [38] Dynamic Security Analysis on Android: A Systematic Literature Review
    Sutter, Thomas
    Kehrer, Timo
    Rennhard, Marc
    Tellenbach, Bernhard
    Klein, Jacques
    IEEE ACCESS, 2024, 12 : 57261 - 57287
  • [39] A systematic literature review of indicators measuring food security
    Manikas, Ioannis
    Ali, Beshir M.
    Sundarakani, Balan
    AGRICULTURE & FOOD SECURITY, 2023, 12 (01):
  • [40] Trends for the DevOps Security. A Systematic Literature Review
    Leppanen, Tiina
    Honkaranta, Anne
    Costin, Andrei
    BUSINESS MODELING AND SOFTWARE DESIGN, BMSD 2022, 2022, 453 : 200 - 217