Log2Policy: An Approach to Generate Fine-Grained Access Control Rules for Microservices from Scratch

被引:3
|
作者
Xu, Shaowen [1 ,2 ]
Zhou, Qihang [1 ]
Huang, Heqing [1 ]
Jia, Xiaoqi [1 ,2 ]
Du, Haichao [1 ]
Chen, Yang [1 ,2 ]
Xie, Yamin [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Microservice; Access Control; Access Log; Machine Learning;
D O I
10.1145/3627106.3627137
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Microservice application architecture is one of the most widely used service architectures in the industry. To prevent a compromised microservice from abusing other microservices, authorization policy is applied to regulate the access among them. However, configuring access control policy manually is challenging due to the complexity and dynamic nature of microservice applications. In this paper, we present Log2Policy, a novel approach to generate microservice authorization policy based on access logs. Our approach consists of three fundamental techniques: (1) a log-based topological graph generation mechanism that automatically infers the invocation logic among microservices, (2) a machine learning based attributes mining method that extracts the relevant attributes of requests, and (3) a policy upgrade mechanism based on traffic management that can significantly reduce the upgrade time. We have implemented a prototype of Log2Policy on mainstream microservice infrastructures and have evaluated it with several microservice applications. The results show that Log2Policy can generate fine-grained and effective access control rules and upgrade them with negligible overhead.
引用
收藏
页码:229 / 240
页数:12
相关论文
共 50 条
  • [41] Efficient CCA2 Secure Flexible and Publicly-Verifiable Fine-Grained Access Control in Fog Computing
    Li, Dawei
    Liu, Jianwei
    Wu, Qianhong
    Guan, Zhenyu
    IEEE ACCESS, 2019, 7 : 11688 - 11697
  • [42] Oblivious Transfer with Fine Grained Access Control from Ciphertext Policy Attribute Based Encryption in the Standard Model
    Fu, Xingbing
    Li, Fagen
    Zeng, Shengke
    INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2016, 9 (01): : 285 - 302
  • [43] F2AC: A Lightweight, Fine-Grained, and Flexible Access Control Scheme for File Storage in Mobile Cloud Computing
    Ren, Wei
    Zeng, Lingling
    Liu, Ran
    Cheng, Chi
    MOBILE INFORMATION SYSTEMS, 2016, 2016
  • [44] DET-ABE: A Java']Java API for Data Confidentiality and Fine-Grained Access Control from Attribute Based Encryption
    Morales-Sandoval, Miguel
    Diaz-Perez, Arturo
    INFORMATION SECURITY THEORY AND PRACTICE, WISTP 2015, 2015, 9311 : 104 - 119
  • [45] P2GT: Fine-Grained Genomic Data Access Control With Privacy-Preserving Testing in Cloud Computing
    Huang, Qinlong
    Yue, Wei
    Yang, Yixian
    Chen, Lixuan
    IEEE-ACM TRANSACTIONS ON COMPUTATIONAL BIOLOGY AND BIOINFORMATICS, 2022, 19 (04) : 2385 - 2398
  • [46] A Key-Policy Searchable Attribute-Based Encryption Scheme for Efficient Keyword Search and Fine-Grained Access Control over Encrypted Data
    Yin, Hui
    Xiong, Yinqiao
    Zhang, Jixin
    Ou, Lu
    Liao, Shaolin
    Qin, Zheng
    ELECTRONICS, 2019, 8 (03)
  • [47] Fine-Grained Access Control for Cloud Data Sharing by Secure and Efficient Attribute-Revocable Ciphertext-Policy Attribute-Based Encryption
    Vaanchig, Nyamsuren
    Chen, Wei
    Qin, Zhiguang
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (10): : 303 - 319
  • [48] Ciphertext Policy-Attribute Based Homomorphic Encryption (CP-ABHER-LWE) Scheme: A Fine-Grained Access Control on Outsourced Cloud Data Computation
    Tan, Soo-Fun
    Samsudin, Azman
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2017, 33 (03) : 675 - 694
  • [49] SGD2 : Secure Group-based Device-to-Device Communications with Fine-grained Access Control for IoT in 5G
    Hsu, Ruei-Hau
    Fan, Hsiang-Shian
    Wang, Lu-Chin
    2021 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2021,
  • [50] Fine-grained rock fabric facies classification and its control on shale oil accumulation: a case study from the Paleogene Kong 2 Member, Bohai Bay Basin
    Wenzhong Han
    Xianzheng Zhao
    Xiugang Pu
    Shiyue Chen
    Hu Wang
    Yan Liu
    Zhannan Shi
    Wei Zhang
    Jiapeng Wu
    Frontiers of Earth Science, 2021, 15 : 423 - 437