Towards Resolving Security Smells in Microservices, Model-Driven

Philip Wizenty, Francisco Ponce, Francisco Ponce, Florian Rademacher, Jacopo Soldani, Hernán Astudillo, Hernán Astudillo, Antonio Brogi, Sabine Sachweh

2023

Abstract

Resolving security issues in microservice applications is crucial, as many IT companies rely on microservices to deliver their core businesses. Security smells denote possible symptoms of such security issues. However, detecting security smells and reasoning on how to resolve them through refactoring is complex and costly, mainly because of the intrinsic complexity of microservice architectures. This paper presents the first idea towards supporting a model-driven resolution of microservices’ security smell. The proposed method relies on LEMMA to model microservice applications by suitably extending LEMMA itself to enable the modeling of microservices’ security aspects. The proposed method then enables processing LEMMA models to automatically detect security smells in modeled microservice applications and recommend the refactorings known to resolve the identified security smells. To assess the feasibility of the proposed method, this paper also introduces a proof-of-concept implementation of the proposed LEMMA-based, automated microservices’ security smell detection and refactoring.

Download


Paper Citation


in Harvard Style

Wizenty P., Ponce F., Rademacher F., Soldani J., Astudillo H., Brogi A. and Sachweh S. (2023). Towards Resolving Security Smells in Microservices, Model-Driven. In Proceedings of the 18th International Conference on Software Technologies - Volume 1: ICSOFT; ISBN 978-989-758-665-1, SciTePress, pages 15-26. DOI: 10.5220/0012049800003538


in Bibtex Style

@conference{icsoft23,
author={Philip Wizenty and Francisco Ponce and Florian Rademacher and Jacopo Soldani and Hernán Astudillo and Antonio Brogi and Sabine Sachweh},
title={Towards Resolving Security Smells in Microservices, Model-Driven},
booktitle={Proceedings of the 18th International Conference on Software Technologies - Volume 1: ICSOFT},
year={2023},
pages={15-26},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012049800003538},
isbn={978-989-758-665-1},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 18th International Conference on Software Technologies - Volume 1: ICSOFT
TI - Towards Resolving Security Smells in Microservices, Model-Driven
SN - 978-989-758-665-1
AU - Wizenty P.
AU - Ponce F.
AU - Rademacher F.
AU - Soldani J.
AU - Astudillo H.
AU - Brogi A.
AU - Sachweh S.
PY - 2023
SP - 15
EP - 26
DO - 10.5220/0012049800003538
PB - SciTePress