Security audit logging in microservice-based systems: survey of architecture patterns
Alexander Barabanov, Denis Makrushin

TL;DR
This paper surveys architecture patterns for security audit logging in microservice systems, providing threat models, best practices, and security requirements to enhance security and monitoring capabilities.
Contribution
It offers a systematic review of logging architecture patterns, threat modeling, and security requirements specifically tailored for microservice-based environments.
Findings
Identified 8 security threats in logging architectures.
Proposed 11 high-level security requirements for audit logging.
Mapped best practices to different environment characteristics.
Abstract
Objective. Service-oriented architecture increases technical abilities for attacker to move laterally and maintain multiple pivot points inside of compromised environment. Microservice-based infrastructure brings more challenges for security architect related to internal event visibility and monitoring. Properly implemented logging and audit approach is a baseline for security operations and incident management. The aim of this study is to provide helpful resource to application and product security architects, software and operation engineers on existing architecture patterns to implement trustworthy logging and audit process in microservice-based environments. Method. In this paper, we conduct information security threats modeling and a systematic review of major electronic databases and libraries, security standards and presentations at the major security conferences as well as…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware System Performance and Reliability · Network Security and Intrusion Detection · Cloud Computing and Resource Management
