Despite the numerous benefits of microservices systems, security has been a critical issue in such systems. Several factors explain this difficulty, including a knowledge gap among microservices practitioners on properly securing a microservices system. To (partially) bridge this gap, we conducted an empirical study. We first manually analyzed 861 microservices security points, including 567 issues, 9 documents, and 3 wiki pages from 10 GitHub open-source microservices systems and 306 Stack Overflow posts concerning security in microservices systems. In this study, a microservices security point is referred to as "a GitHub issue, a Stack Overflow post, a document, or a wiki page that entails 5 or more microservices security paragraphs". Our analysis led to a catalog of 28 microservices security practices. We then ran a survey with 74 microservices practitioners to evaluate the usefulness of these 28 practices. Our findings demonstrate that the survey respondents affirmed the usefulness of the 28 practices. We believe that the catalog of microservices security practices can serve as a valuable resource for microservices practitioners to more effectively address security issues in microservices systems. It can also inform the research community of the required or less explored areas to develop microservices-specific security practices and tools.
翻译:尽管微型服务系统有许多好处,但安全一直是这些系统中的一个关键问题。有几个因素解释了这种困难的原因,包括微型服务从业人员在适当确保微观服务系统方面的知识差距。(部分)为了弥补这一差距,我们进行了一项经验研究。我们首先人工分析了861个微观服务安全点,包括567个问题、9份文件和10个GitHub开放源微观服务系统和306 Stack Soverflow 员额的3维基页,涉及微型服务系统安全的问题。在本研究中,一个微观服务安全点被称为“GitHub问题、一个堆积过大后柱、一个文件或一个wiki网页,包含5个或更多微观服务安全段落”。我们的分析产生了28个微观服务安全做法的目录。我们随后与74个微观服务从业人员进行了调查,以评估这28种做法的效用。我们的研究结果表明,调查对象肯定了28种做法的效用。我们认为,微观服务安全做法目录可以作为微观服务从业人员的宝贵资源,用以更有效地解决微观服务安全方面需要的系统或系统开发的更小的系统。