Ir para o conteúdo
  • +55 (11) 3375 0133
  • contato@nova8.com.br
Linkedin-in Facebook-square Instagram Youtube Whatsapp
  • EN-US
  • PT-BR
  • ES-MX
Nova8
  • #Nova8é10!
  • Portfólio

    Checkmarx

    Segurança de Aplicações (AppSec) de Ponta a Ponta​

    Cequence

    Proteção Contra Fraudes e Bots com Segurança de APIs​

    Snyk

    Segurança Dev-First para Desenvolvimento Seguro e Ágil

    IRONSCALES

    Antiphishing Inteligente com IA Adaptativa e Generativa​

    Upwind

    Segurança em Tempo Real para Ambientes em Nuvem e Containers

    CORO

    Cibersegurança Simples e Modular para Empresas Enxutas

    Invicti

    Segurança web com detecção de vulnerabilidades

    Conheça o portfólio completo
  • Serviços

    VAD

    Única Distribuidora de Valor Agregado (VAD) de cibersegurança da América Latina citada no Gartner Market Guide

    Centro de Excelência Nova8 em Cibersegurança

    Acelere sua capacitação técnica e estratégica com o hub de inovação da Nova8.

    Consultoria Nova8 em Cibersegurança

    Estratégia, eficiência e proteção real para aplicações e dados críticos.

  • Cases
  • Blog & Materiais
Fale Conosco
Nova8
  • Home
  • Blog

Continuous Security Testing for Microservices

  • Nova8 Security Research Team
  • outubro 24, 2017
  • Gestão de segurança

Being a part of today’s tech-industry, you probably notice all winds blowing towards the implementation of DevOps and CI\CD methodologies, and rightfully so. Today’s software developers face an ever growing need for speedy development-to-production cycles with uncompromising security and reliability. One way of facing the speed versus quality challenge is the introduction ofmicroservices.

 

 

Unlike the classic monolithic approach to developing an application, microservices break the application down to its various components with each component behaving as full a stack as possible. Imagine many mini-apps that together make one unified application. Those mini-apps often revolve around a specific business capability and must be able to communicate and scale seamlessly.

 

Expectedly, there are pros and cons to the adoption of microservices and though we won’t go through them all, there are some worth mentioning:

 

Modularity – Breaking down a large and complex application to its components improves modularity and makes each component easier to understand, develop, modify and test.

 

Independency – One microservice failing doesn’t mean the entire system is affected. Similarly, there is no need to upgrade and test the entire system for just one component.

 

Fast Paced Environments – Microservices’ structure enables a decentralized approach to data management and more importantly, it enables continuous delivery and deployment bringing us back to the first paragraph and the need for speed.

 

That said, microservices are not a one-size-fits-all solution.

Consistency  – It is harder to maintain consistency throughout the system.

 

System Dependencies and Development Roadblocks – Microservices create an increased number of system dependencies and while parallelizing development they also create parallel development roadblocks.

 

Testing – Microservices can create a challenge when it comes to testing as it is hard to get one flow through the entire system.

 

On that last note, microservices present security testing challenges as well:

 

Application security testing (AST) solutions that aim to fit a microservices development method need to offer incremental testing. Solutions that are only able to scan all related binaries at once are not suitable. Such solutions are bound to impose delays on the continuous integration process and present false positives\negatives as they don’t take into consideration each service’s specific logic. When dealing with microservices, it is particularly important to use an AST solution capable of scanning independent segments of code, i.e independent microservices.

 

Shifting security left in the SDLC is ever more valuable when dealing with microservices. Implementing Static Code Analysis (or SAST) for each microservice complements the fast development environment they aim to achieve. Scanning a microservice’s uncompiled code before it is linked to other microservices, is key to pinpointing and remediating vulnerabilities.  That said, the ideal AST solution should also offer Interactive AST (IAST) which will ensure end-to-end security testing – IAST provides high scenario coverage and can detect vulnerabilities that can only be detected on running applications.

 

Microservices present a need for customization. Being the independent units that they are, microservices allow broad technological and design flexibility. Their independency also means each microservice will often require its own set of security tests. AST solutions supporting microservices should allow developers to easily create their own security queries or modify existing ones to better fit the needs of each microservice. This will ensure each service is accurately and thoroughly tested for vulnerabilities.

 

To summarize the above, AST solutions need to keep up with microservices’ modular, flexible and independent nature in order to provide the most accurate vulnerability scanning. They need to ensure developers can easily modify them to better suit their needs, they have to be able to scan independent services and should offer rapid and complete SDLC coverage, from initial coding to the running application.

 

There are many considerations to keep in mind when deciding to shift to microservices. If you wish to learn more about the pros and cons as well as testing implementations, take a look at Checkmarx’s joint whitepaper with Tricentis and Insight Venture Partners.

Navegue por tema

  • Segurança
  • Gestão de segurança
  • #cybersecurity
  • Notícias
  • Upwind
  • Cequence
  • #cybercrime
  • #IA
  • Segurança na Nuvem
  • Checkmarx

Navegue por solução

  • Snyk
  • Upwind
  • Cequence
  • Coro
  • Ironscales
  • Checkmarx

Segurança começa pelo Colaborador

Mantenha-se à frente das ameaças cibernéticas

Explore nossos materiais ricos em insights como e-books, whitepapers, artigos e conteúdos do blog para saber tudo sobre as tendências de cibersegurança.

Veja mais
Nova8 é 10! - Banner
  • maio 19, 2026
  • Trusted Advisor

Nova8 é 10: 10 anos como VAD em cibersegurança

Entenda por que a Nova8 é 10: uma década como VAD em cibersegurança, menção no Gartner Market Guide, ISO/IEC 27001, GPTW, Centro de Excelência e portfólio global.
Leia mais
Nova8 Checkmarx (3)
  • maio 14, 2026
  • Soluções

Vibe coding e AppSec: como proteger código gerado por IA

Entenda como o código gerado por IA muda o risco em AppSec e como a Checkmarx ajuda a escalar governança no SDLC.
Leia mais
Snyk Agent Fix por que a correção segura de código virou o novo desafio da AppSec com IA
  • maio 14, 2026
  • Soluções

Snyk Agent Fix e AppSec com IA: correção segura de código no fluxo dev

Entenda como o Snyk Agent Fix usa arquitetura agêntica para acelerar a remediação segura de código no fluxo de desenvolvimento.
Leia mais

Linkedin-in Facebook-square Instagram Youtube

Al. Rio Negro, 585 - Torre Jaçarí - 13º andar Conjunto 134 - Alphaville, Barueri - SP, 06454-000

  • +55 (11) 3375 0133
  • contato@nova8.com.br
  • Fale com a Nova8 pelo WhatsApp

Empresa

  • #Nova8é10!
  • Eventos
  • VAD
  • Centro de Excelência
  • Consultoria
  • Trabalhe conosco
  • Política de Privacidade
  • Código de Ética

Portfólio

  • Checkmarx
  • Upwind
  • Cequence
  • CORO
  • Snyk
  • IRONSCALES
  • Invicti
  • Bright
  • Riskified
  • MazeBolt
  • Mend
  • Solicite um orçamento

Conteúdo

  • Blog Nova8
  • Clientes e Cases
  • Materiais

Copyright © Nova 8 Cybersecurity - 2026 - Todos os direitos reservados

Pesquisar
Nova8
  • EN-US
  • PT-BR
  • ES-MX
  • #Nova8é10!
  • Sobre nós
  • Portfólio
  • Serviços
    • Consultoria em Cibersegurança
    • Centro de excelência
    • Distribuidora de Cibersegurança de Valor Agregado
  • Cases
  • Blog & Materiais
  • Fale Conosco
  • #Nova8é10!
  • Sobre nós
  • Portfólio
  • Serviços
    • Consultoria em Cibersegurança
    • Centro de excelência
    • Distribuidora de Cibersegurança de Valor Agregado
  • Cases
  • Blog & Materiais
  • Fale Conosco
  • +55 (11) 3375 0133
  • contato@nova8.com.br
Linkedin-in Facebook-square Instagram Youtube
Saiba mais
Pesquisar