Microservices are deployed in the Edge layer of the cloud network for improved latency and cost-effectiveness using containers. Edge layer is resource constrained and requires optimal deployment strategies for efficient use of the resources and to reduce the communication overhead. Containers possess security vulnerabilities across its various layers and this pose security threats to the services deployed in the containers. These vulnerabilities, when exploited, can lead to attacks stopping the services. A system is proposed to demonstrate the effects of exploiting the container runtime vulnerability on an existing microservices architecture. The system is attacked to allow a malicious remote user to gain root privileges onto the container. The user can then perform secondary attacks. This exploit is detected using a generalized model and then mitigated maintaining the optimal deployment metrics to sustain the performance. We conducted an experiment in Kubernetes to evaluate the performance of our approach. Experimental results indicate the performance of the services, including Throughput (reduced by 90%) and Response time (increased by 10%) is affected due to the proposed attack vector which is the rectified back to normal state after mitigation process.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Container Vulnerability Exploitation and Mitigation in Microservices Deployed in Edge Using RSDQL

  • D. P. Bharath Kumar,
  • S. Sri Priyan,
  • Jyotir Aditya Giri,
  • R. Aishwarya,
  • V. Vetriselvi

摘要

Microservices are deployed in the Edge layer of the cloud network for improved latency and cost-effectiveness using containers. Edge layer is resource constrained and requires optimal deployment strategies for efficient use of the resources and to reduce the communication overhead. Containers possess security vulnerabilities across its various layers and this pose security threats to the services deployed in the containers. These vulnerabilities, when exploited, can lead to attacks stopping the services. A system is proposed to demonstrate the effects of exploiting the container runtime vulnerability on an existing microservices architecture. The system is attacked to allow a malicious remote user to gain root privileges onto the container. The user can then perform secondary attacks. This exploit is detected using a generalized model and then mitigated maintaining the optimal deployment metrics to sustain the performance. We conducted an experiment in Kubernetes to evaluate the performance of our approach. Experimental results indicate the performance of the services, including Throughput (reduced by 90%) and Response time (increased by 10%) is affected due to the proposed attack vector which is the rectified back to normal state after mitigation process.