Skip to main navigation Skip to search Skip to main content

Improving Microservices Security

  • Amir Javadpour*
  • , Forough Jafari
  • , Tarik Taleb
  • , Qize Guo
  • , Chafika Benzaid
  • , Luis Rosa
  • , Luis Cordeiro
  • *Corresponding author for this work
  • ICTFicial OY
  • Sharif University of Technology
  • Ruhr University Bochum
  • OneSource
  • University of Oulu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

To support fle xibility and scalability, 5 G networks have embraced microservice-based architectures, which require secure and efficient inter-service communication. This is managed by the service mesh layer, which is now a growing target for cyberattacks. While existing platforms like Istio and NGINX use mutual TLS (mTLS) to secure communications, mTLS imposes considerable resource overhead, undermining the goals of scalability and lightweight operation. To overcome this challenge, we propose an Encryption as a Service (EaaS) framework for Kubernetes that mitigates common attacks such as man-in-the-middle, distributed denial-of-service (DDoS), and eavesdropping. Experimental analysis shows that EaaS significantly improves response time and reduces adversary success compared to traditional microservice-side cryptographic handling, with gains varying across different scenarios and cryptographic/deception configurations. While higher EaaS replication slightly increases CPU and memory usage, it leads to better security outcomes and faster service performance. The successful real-world implementation and deployment of the EaaS framework further corroborated these fin dings.

Original languageEnglish
Title of host publication2025 IEEE Middle East Conference on Communications and Networking, MECOM 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331585877
DOIs
StatePublished - 2025
Externally publishedYes
Event2nd IEEE Middle East Conference on Communications and Networking, MECOM 2025 - Cairo, Egypt
Duration: 4 Nov 20256 Nov 2025

Publication series

Name2025 IEEE Middle East Conference on Communications and Networking, MECOM 2025

Conference

Conference2nd IEEE Middle East Conference on Communications and Networking, MECOM 2025
Country/TerritoryEgypt
CityCairo
Period4/11/256/11/25

Keywords

  • Encryption as a Service (EaaS)
  • Kubernetes
  • Security
  • Service Mesh

Fingerprint

Dive into the research topics of 'Improving Microservices Security'. Together they form a unique fingerprint.

Cite this