About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 16th EAI International Conference, SecureComm 2020, Washington, DC, USA, October 21-23, 2020, Proceedings, Part I

Research Article

MisMesh: Security Issues and Challenges in Service Meshes

Download(Requires a free EAI acccount)
2 downloads
Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-030-63086-7_9,
        author={Dalton A. Hahn and Drew Davidson and Alexandru G. Bardas},
        title={MisMesh: Security Issues and Challenges in Service Meshes},
        proceedings={Security and Privacy in Communication Networks. 16th EAI International Conference, SecureComm 2020, Washington, DC, USA, October 21-23, 2020, Proceedings, Part I},
        proceedings_a={SECURECOMM},
        year={2020},
        month={12},
        keywords={Service mesh DevOps Containers Consul Istio Linkerdv2},
        doi={10.1007/978-3-030-63086-7_9}
    }
    
  • Dalton A. Hahn
    Drew Davidson
    Alexandru G. Bardas
    Year: 2020
    MisMesh: Security Issues and Challenges in Service Meshes
    SECURECOMM
    Springer
    DOI: 10.1007/978-3-030-63086-7_9
Dalton A. Hahn1,*, Drew Davidson1, Alexandru G. Bardas1
  • 1: EECS Department, ITTC University of Kansas
*Contact email: daltonhahn@ku.edu

Abstract

Service meshes have emerged as an attractive DevOps solution for collecting, managing, and coordinating microservice deployments. However, current service meshes leave fundamental security mechanisms missing or incomplete. The security burden means service meshes may actually cause additional workload and overhead for administrators over traditional monolithic systems. By assessing the effectiveness and practicality of service mesh tools, this work provides necessary insights into the available security of service meshes. We evaluate service meshes under skilled administrators (who deploy optimal configurations of available security mechanisms) and default configurations. We consider a comprehensive set of adversarial scenarios, uncover design flaws contradicting system goals, and present limitations and challenges encountered in employing service mesh tools for operational environments.

Keywords
Service mesh DevOps Containers Consul Istio Linkerdv2
Published
2020-12-12
Appears in
SpringerLink
http://dx.doi.org/10.1007/978-3-030-63086-7_9
Copyright © 2020–2025 ICST
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL