Return
Full-stack vulnerability analysis of the cloud-native platform
DOI:10.1016/j.cose.2023.103173.png)
Abstract
En 中文
Cloud-native systems have recently emerged as one of the most popular platforms for application devel-opment, providing lightweight virtualization, simplified DevOps procedures, scaling, resource efficiency, monitoring, and more. The typical cloud-native system may include containers, container orchestrators, and service meshes. However, a number of attacks exploit vulnerabilities in different components, lead-ing the attacker to gain control over the cloud-native system. In this paper, we collect, classify, exploit, and mitigate vulnerabilities of different com ponents. Firstly, we choose Docker, Kubernetes, and Istio as the most popular cloud technologies and give each an overview. Secondly, we give an in-depth analysis of the vulnerabilities. We collect cloud-native vulnerabilities over the past five years and propose two classifications of those vulnerabilities. One is based on the architecture of the component, and the other is based on the attack enabled. We exploit vulnerabilities that enable us to discover some insightful find-ings and provide mitigation solutions. Third, we analyze 15 open-source security tools provided for the cloud-native environment. We argue that among all these security tools, none of them covers all features which we will discuss in this paper. We believe that our analysis of cloud security vulnerabilities and open-source security tools can benefit the security of the cloud-native ecosystem.(c) 2023 Elsevier Ltd. All rights reserved.
Keywords:
Cloud -native security
Container security
Vulnerability
Docker
Kubernetes
Istio
CNI
Journal
C
IF:
5.4
Papers:
4.6K
Citations:
1.4W

