On automated RBAC assessment by constructing a centralized perspective for microservice mesh

8Citations
Citations of this article
22Readers
Mendeley users who have this article in their library.

Abstract

It is important in software development to enforce proper restrictions on protected services and resources. Typically software services can be accessed through REST API endpoints where restrictions can be applied using the Role-Based Access Control (RBAC) model. However, RBAC policies can be inconsistent across services, and they require proper assessment. Currently, developers use penetration testing, which is a costly and cumbersome process for a large number of APIs. In addition, modern applications are split into individual microservices and lack a unified view in order to carry out automated RBAC assessment. Often, the process of constructing a centralized perspective of an application is done using Systematic Architecture Reconstruction (SAR). This article presents a novel approach to automated SAR to construct a centralized perspective for a microservice mesh based on their REST communication pattern. We utilize the generated views from SAR to propose an automated way to find RBAC inconsistencies.

Cite

CITATION STYLE

APA

Das, D., Walker, A., Bushong, V., Svacina, J., Cerny, T., & Matyas, V. (2021). On automated RBAC assessment by constructing a centralized perspective for microservice mesh. PeerJ Computer Science, 7, 1–24. https://doi.org/10.7717/peerj-cs.376

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free