Generating Realistic Attack Data for Microservices: Framework and Case Study

被引:0
作者
Castro, Jessica [1 ]
Laranjeiro, Nuno [1 ]
Vieira, Marco [1 ]
机构
[1] Univ Coimbra, CISUC, DEI, Coimbra, Portugal
来源
PROCEEDINGS OF12TH LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE AND SECURE COMPUTING, LADC 2023 | 2023年
关键词
microservices; container; security; DoS attack; testbed;
D O I
10.1145/3615366.3615377
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Microservice applications have gained significant popularity due to their capability to decrease the complexity of developing highly scalable, manageable, and flexible systems. However, the microservices distributed nature, fine service granularity, and large attack surface introduce new security challenges, making it crucial to develop effective mechanisms for protecting those applications at runtime. Nevertheless, developing novel solutions relies on the availability of suitable datasets, which are currently lacking and need to be generated through new research. This research paper presents a comprehensive framework designed to support research on monitoring and analyzing microservices, aiding in the development of novel solutions for detecting attacks in the context of microservice applications. We present an implementation of the framework for generating data for high- and low-volume Denial of Service (DoS) attacks, highlighting its key components and features. Furthermore, we present a series of attack profiles and evaluate the framework's performance in a case study, demonstrating the framework's usefulness for generating data for DoS attacks by presenting a model that successfully detects the attacks.
引用
收藏
页码:60 / 69
页数:10
相关论文
共 50 条
[21]   ICS Security Testbed with Delay Attack Case Study [J].
Korkmaz, Emrah ;
Dolgikh, Andrey ;
Davis, Matthew ;
Skormin, Victor .
MILCOM 2016 - 2016 IEEE MILITARY COMMUNICATIONS CONFERENCE, 2016, :283-288
[22]   A Case Study on Monolith to Microservices Decomposition with Variational Autoencoder-Based Graph Neural Network [J].
Maharjan, Rokin ;
Sooksatra, Korn ;
Cerny, Tomas ;
Rajbhandari, Yudeep ;
Shrestha, Sakshi .
FUTURE INTERNET, 2025, 17 (07)
[23]   Adopting microservices and DevOps in the cyber-physical systems domain: A rapid review and case study [J].
Fritzsch, Jonas ;
Bogner, Justus ;
Haug, Markus ;
da Silva, Ana Cristina Franco ;
Rubner, Carolin ;
Saft, Matthias ;
Sauer, Horst ;
Wagner, Stefan .
SOFTWARE-PRACTICE & EXPERIENCE, 2023, 53 (03) :790-810
[24]   Evaluation framework for automatic privacy auditing tools for hospital data breach detections: A case study [J].
Yesmin, Tahera ;
Carter, Michael W. .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2020, 138
[25]   Resource optimization of container orchestration: a case study in multi-cloud microservices-based applications [J].
Carlos Guerrero ;
Isaac Lera ;
Carlos Juiz .
The Journal of Supercomputing, 2018, 74 :2956-2983
[26]   A big data analytics for DDOS attack detection using optimized ensemble framework in Internet of Things [J].
Ahmad, Ijaz ;
Wan, Zhong ;
Ahmad, Ashfaq .
INTERNET OF THINGS, 2023, 23
[27]   Resource optimization of container orchestration: a case study in multi-cloud microservices-based applications [J].
Guerrero, Carlos ;
Lera, Isaac ;
Juiz, Carlos .
JOURNAL OF SUPERCOMPUTING, 2018, 74 (07) :2956-2983
[28]   Smart City Service System Engineering Based on Microservices Architecture Case Study: Government of Tangerang City [J].
Hidayat, Taufiq ;
Suhardi ;
Kurniawan, Novianto Budi .
2017 INTERNATIONAL CONFERENCE ON ICT FOR SMART SOCIETY (ICISS), 2017,
[29]   The Flooding Attack in Low Power and Lossy Networks: A Case Study [J].
Tanh Nguyen ;
Tri Ngo ;
Tuyen Nguyen ;
Duc Tran ;
Hai Anh Tran ;
Tung Bui .
2018 INTERNATIONAL CONFERENCE ON SMART COMMUNICATIONS IN NETWORK TECHNOLOGIES (SACONET), 2018, :183-187
[30]   Framework for the Assessment of Data Masking Performance Penalties in SQL Database Servers. Case Study: Oracle [J].
Fotache, Marin ;
Munteanu, Adrian ;
Strimbei, Catalin ;
Hrubaru, Ionut .
IEEE ACCESS, 2023, 11 :18520-18541