Monday, April 4

MIS603 – Microservices Architecture - Assignment 2

 

 

Table of Contents

Introduction. 3

Issues and Challenges. 3

Privacy issues. 4

Reason for the issues/challenges. 5

Mitigations to overcome the issues. 5

Conclusion. 6

References. 7

 

 

 

 

 

 

 

 

 

 

 

 

 

Microservices Architecture – Privacy and Security Report

Introduction

In the Service Oriented Architecture (SOA) based software development, there are two major classifications. One is monolithic architecture and the other is microservices architecture. Microservices architecture is the approach of software development and deployment into the micro or small pieces and then integrated into an application. The microservices architecture is enabling the efficient computing and helps in building the resilient applications. But there are several challenges and issues while developing the software application with the microservices approach. The microservices is completely new technology and is highly based on cloud computing which might lead to issues. The understanding of microservices based application development along with its issues and challenges is necessary so that an effective application can be developed.

The key concepts that will be discussing in the following report will be like the design complexity, communication issues, security and the privacy issues that may be occurring in the microservices based system. This report will also be discussing the various challenges that might arise in terms of security and privacy that causes issues to the data handled by the applications. It is identified that microservices are facing more complexity and issues when compared with the monolithic applications. The reasons for such challenges and issues are discussed so that it could be rectified easily. Finally, the mitigation plans that will be used to overcome the issues in development and security are discussed.

Issues and Challenges

Complexity in designing

While designing the application in microservices architecture, there are several complexities in designing. The size of each and every microservice, boundaries and the framework used to integrate the services are the challenges. Each and every microservice should be clearly declared, encapsulated and defined in a clear manner. Thus, the logical designing and development in highly critical in microservices based development.

Security issues

Since most of the microservices are deployed in the cloud based environments, the risk involved is high. This is because of the reason that in cloud computing, the loss of control and the lack of visibility will cause serious impacts in security of the microservices (Sudip Sengupta, 2021). The application framework in microservices is distributed and hence maintaining the confidentiality, integrity and privacy of the data is difficult.

Complicated Testing

The complicated testing is another issue in the microservices application development. The prime reason for this is that each and every microservices are loosely coupled and they have to be tested individually and wholly after integration. The dependencies among every services should be understood to test the application. Thus, testing is highly complex as every microservice will be of its own nature and independent behavior (Kaiburr, 2018).

Complex monitoring process

The need of monitoring the microservices of the application is important as to evaluate the performance as well as to identify the underperforming components in it (André Fachat, 2019). The failures that may arise in the future should be predicted well in advance to prevent the system from shutting down. Thus, monitoring every services and integrated application as a whole is complex in nature.

Communication

In the communication between the services there may be arising issues like the increase in the latency and delays in the speed of calling between the various services. The issues may be occurring in the infrastructure layers as the communication may be interrupted due to it. This may lead to face issue in security and privacy of the data handled in the application.

Privacy issues                                                                  

From the above said issues and challenges, it can be identified that there are several challenges in the security and the privacy of the data that are managed in the microservices based applications. Due to the lack of security in cloud computing environment the data that are stored and processed in the applications have several threats. The data transmission is important as each and every services are based on individual containers and the communication may be facing security issues that may result in the loss of privacy (Nera Besic, 2021). The vulnerability that occurs in the system may be exposing all the data in the container and the host OS. The authentication if failed will be causing serious impacts in the data that are handled by the micro services. Thus, the privacy issues in every services will be causing the impacts in the application. The containers with the images, registries, and the orchestration will be under the privacy risk if they are not properly secured. Sensitive data will be processed by every microservice which may be highly vulnerable to attacks. Thus, the microservices are facing several security issues that will be affecting the privacy of the data that are processed in the applications.

Reason for the issues/challenges

There are several reasons for the issues and the challenges that are occurred in the microservices based architecture. The following are some of the reasons,

·         One of the most important reason is that the microservices is still a developing technology and requires some time to avoid the minor issues that are arising.

·         Since the services and the data are loosely coupled, the data that will be flowing in the containers will be lacking in security.

·         The architectural complexity will be another reason that causes the issues and challenges in designing the required application and its development.

·         The security that can be provided to the system will be really complex since the security should be provided at the container level and coupling all the services will be causing serious difficulties.

·         The fault tolerance is a reason where microservice based application will not entirely shut down even if a service fails to work. In such cases, there are chances of occurring issues in the system.

·         In monolithic testing, the entire application will be tested for its features and functions and any issues will cause to fail. But, testing the microservice based application is highly difficult since every service has to be individually tested and then the entire application that is integrated should be tested.

Mitigations to overcome the issues

Encrypting the data communications

To overcome the microservices issues it is must that every organization makes the encryption process towards data communication process. Encrypting the personal data process is the better outcome, this could manage the data that are transferred between one device to another will provide the effective protection system against (kong, 2020) the interception of the communication for all the third parties those transfers the data.

Container level security

The other mitigation process is an container security measure, it is the process of initiating the security tools and needed policies in organization for making sure that all the container data are processed well, including the protection system, software supply chain and runtime progress management in the organization.

API Gateway

The API gateway is apt for the mitigation process once the issues are emerged from the microservice system. If the organization initiates the API gateway inside the environment then it could normally validates the access token through the server of authorization. The token of JWT, will be containing the users claim, and then it will be passed over the backend microservice with more protection schemas. After that the backend microservice will use the information over the JWT token for the authorization purposes.

Isolation

The isolation method will mitigate the issues once it occurred in organization, isolating components and features from the risks could give the better management system throughout the process. In case one service get crashes, through isolation process it can quite other application without affecting, hence this process makes the risk avoidance in microservice.

Authentication and Access Control

Initiate the authentication and access control for privacy of data in the organization, authentication is the method of system verification and it would identify the users of authorized and unauthorized those wishes to access the (Besic, 2021) system. The access control will be based on the users request from the resource access, and this could prevent the hackers to stop from the attacks.

Conclusion

Thus the report is summarized with the microservice concepts towards the organization. Given report induce the challenges and issues that are raised through the microservice architecture for the software development. Some of the risk mitigation plan was also identified that could be applied on the issues that are found towards the micro-service architecture environment. The microservice complexity was high when compared with the monolithic architecture. The organization faces the issues due to the microservice structure which comprises with many privacy issues. As per the findings the organization can adopt the mitigation plan towards the processing system so that the issues can be easily avoided. The organization those initiates the microservice structure has to make sure all the risk (Schofmann, 2016) avoidance plans are induced before the implementation progress. So the organization can find various types of issues or risks that are made by the microservice through this report, as well the management of organization team can use this mitigation plan towards the application development. The isolation process is the best mitigation plans that are identified through the mitigation plan; this can be very well suitable for the organization in isolating each component with risk mitigation plan, hence the organization can use these methods.

References

André Fachat. (2019, January 30). Challenges and benefits of the microservice architectural style, Part 1. Retrieved from IBM Developer: https://developer.ibm.com/articles/challenges-and-benefits-of-the-microservice-architectural-style-part-1/

Besic. (2021, May 28). Microservices Security: Challenges and Best Practices. Retrieved from Neuralegion: https://www.neuralegion.com/blog/microservices-security/

Kaiburr. (2018, October 11). Kaiburr. Retrieved from Challenges in implementing microservices: https://www.kaiburr.com/blog/challenges-in-implementing-microservices/

kong. (2020, May 18). 10 Ways Microservices Create New Security Challenges. Retrieved from konghq website: https://konghq.com/blog/10-ways-microservices-create-new-security-challenges/

Nera Besic. (2021, May 28). Microservices Security: Challenges and Best Practices. Retrieved from Neuralegion: https://www.neuralegion.com/blog/microservices-security/

Schofmann, M. (2016, January 14). Security Challenges in Microservice Implementations. Retrieved from Blog web site: https://blog.container-solutions.com/security-challenges-in-microservice-implementations

Sudip Sengupta. (2021, January 20). Challenges of Microservices & When To Avoid Them. Retrieved from BMC blogs: https://www.bmc.com/blogs/microservices-challenges-when-to-avoid/

 

 

 

No comments:

Post a Comment

ITC506 - Topics in Information Technology Ethics - Assessment item 3

  Table of Contents Task 1: Argument Visualization . 3 Task 2 . 3 Introduction . 3 Utilitarianism Theory . 4 Deontology...