The rise of containerized environments and microservices architectures has revolutionized application development, offering scalability and efficiency. This shift also introduces significant security challenges, including vulnerabilities in container images, inter-service communication risks, and misconfigurations in orchestration platforms. The SecCO-OC project addresses these challenges by embedding security workflows into the CI/CD pipeline, a critical component of the DevOps paradigm. These workflows include static and dynamic threat analysis, runtime enforcement of security policies, and secure container publication. Stack4Things, a distributed platform for IoT resource management, serves as a foundational testbed for SecCO-OC. Its modular and containerized architecture provides a realistic environment for refining these workflows. Key innovations in SecCO-OC include advancements in containerization, such as enhanced virtualization techniques and hardware pass-through, ensuring robust security guarantees. The project also introduces security services directly within containers, achieving a balance between flexibility, functionality, and security. This paper explores how SecCO-OC’s strategies, developed by using Stack4Things, align with modern security standards and enhance the security maturity of containerized microservices while maintaining agility and scalability.

SecCO-OC: Security Strategies for Containerized Microservices Architecture

Giacobbe, Maurizio
;
Zanafi, Sarah;Olana, Jiregna A.;Puliafito, Antonio
2025-01-01

Abstract

The rise of containerized environments and microservices architectures has revolutionized application development, offering scalability and efficiency. This shift also introduces significant security challenges, including vulnerabilities in container images, inter-service communication risks, and misconfigurations in orchestration platforms. The SecCO-OC project addresses these challenges by embedding security workflows into the CI/CD pipeline, a critical component of the DevOps paradigm. These workflows include static and dynamic threat analysis, runtime enforcement of security policies, and secure container publication. Stack4Things, a distributed platform for IoT resource management, serves as a foundational testbed for SecCO-OC. Its modular and containerized architecture provides a realistic environment for refining these workflows. Key innovations in SecCO-OC include advancements in containerization, such as enhanced virtualization techniques and hardware pass-through, ensuring robust security guarantees. The project also introduces security services directly within containers, achieving a balance between flexibility, functionality, and security. This paper explores how SecCO-OC’s strategies, developed by using Stack4Things, align with modern security standards and enhance the security maturity of containerized microservices while maintaining agility and scalability.
2025
9783031877773
9783031877780
File in questo prodotto:
Non ci sono file associati a questo prodotto.
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11570/3333573
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact