Microservices gained momentum in enterprise IT, as they enable building cloud-native applications. At the same time, they come with new security challenges, including security smells, viz., symptoms of bad (though often unintentional) design decisions that might affect application security. This study aims to explore the impacts of microservice security smells- and of the refactorings known to mitigate their effects-beyond security. In particular, we systematically elicit possible impacts of smells and refactorings on applications' maintainability, performance efficiency, and adherence to microservices' key design principles. We then validate the elicited impacts by means of an online survey targeting experienced practitioners and researchers. Our main contributions include 35 validated impacts, and a discussion of the survey results geared towards analyzing the (mis)alignment between practitioners and researchers.

To Security and Beyond: On The Impacts of Microservice Security Smells and Refactorings

Soldani J.
Secondo
;
Brogi A.
Ultimo
2023-01-01

Abstract

Microservices gained momentum in enterprise IT, as they enable building cloud-native applications. At the same time, they come with new security challenges, including security smells, viz., symptoms of bad (though often unintentional) design decisions that might affect application security. This study aims to explore the impacts of microservice security smells- and of the refactorings known to mitigate their effects-beyond security. In particular, we systematically elicit possible impacts of smells and refactorings on applications' maintainability, performance efficiency, and adherence to microservices' key design principles. We then validate the elicited impacts by means of an online survey targeting experienced practitioners and researchers. Our main contributions include 35 validated impacts, and a discussion of the survey results geared towards analyzing the (mis)alignment between practitioners and researchers.
2023
979-8-3503-1887-6
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11568/1220132
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 3
  • ???jsp.display-item.citation.isi??? ND
social impact