Knowledgebase

Securing Internal Service Communication Print

  • 0

Trust inside the network.

WHAT THE OLD ASSUMPTION WAS

Inside the network is safe.

WHY IT NO LONGER HOLDS

One compromised component otherwise reaches everything.

WHAT TO IMPLEMENT

Authentication between services Authorisation for what each may do Encryption in transit

WHAT SERVICE AUTHENTICATION USUALLY USES

Mutual certificates, or short-lived tokens issued centrally.

WHAT SHORT-LIVED MEANS

Minutes or hours, renewed automatically.

WHY

A leaked credential expires quickly.

WHAT TO AVOID

Long-lived shared secrets in configuration files One credential used by every service

WHY

It removes any ability to limit or attribute.

WHAT TO SCOPE

Each service to the specific calls it needs.

WHAT TO LOG

Every inter-service call, with the correlation identifier.

WHAT TO MONITOR

Calls that should not be happening.

WHY

They indicate either a defect or a compromise.

WHAT TO RESTRICT AT THE NETWORK LEVEL

Which services may reach which.

WHY BOTH NETWORK AND APPLICATION CONTROLS

Either alone fails eventually.

WHAT TO ROTATE

Everything, automatically.

WHAT TO TEST

That a service cannot call what it should not.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot