Objective. Service-oriented architecture increases technical abilities for attacker to move laterally and maintain multiple pivot points inside of compromised environment. Microservice-based infrastructure brings more challenges for security architect related to internal event visibility and monitoring. Properly implemented logging and audit approach is a baseline for security operations and incident management. The aim of this study is to provide helpful resource to application and product security architects, software and operation engineers on existing architecture patterns to implement trustworthy logging and audit process in microservice-based environments. Method. In this paper, we conduct information security threats modeling and a systematic review of major electronic databases and libraries, security standards and presentations at the major security conferences as well as architecture whitepapers of industry vendors with relevant products. Results and practical relevance. In this work based on research papers and major security conferences presentations analysis, we identified industry best practices in logging audit patterns and its applicability depending on environment characteristic. We provided threat modeling for typical architecture pattern of logging system and identified 8 information security threats. We provided security threat mitigation and as a result of 11 high-level security requirements for audit logging system were identified. High-level security requirements can be used by application security architect in order to secure their products.
翻译:面向服务的结构提高了攻击者在受损环境中横向移动和保持多个支点的技术能力; 以微观服务为基础的基础设施给安全建筑师带来了与内部事件可见度和监测有关的更多挑战; 适当执行的伐木和审计办法是安全行动和事件管理的基线; 这项研究的目的是为应用和产品安全建筑师、软件和操作工程师提供有用的资源,使其了解现有建筑模式,以便在基于微观服务的环境中执行可靠的伐木和审计过程; 方法; 本文对主要电子数据库和图书馆、安全标准和在主要安全会议上的发言以及具有相关产品的行业供应商的建筑白皮书进行信息安全示范和系统审查; 成果和实际相关性; 在这份研究文件和主要安全会议演示分析的基础上,我们查明了伐木审计模式中的行业最佳做法及其根据环境特点的适用性; 我们为典型的伐木系统建筑模式提供了威胁模型,并查明了8项信息安全威胁; 我们为审计伐木系统提供了安全方面的11项高级别安全要求,因此提供了安全缓解。