Warning: Trying to access array offset on value of type bool in /var/www/vhosts/nova8.com.br/httpdocs/2022/wp-content/plugins/elementor-pro/modules/dynamic-tags/tags/post-featured-image.php on line 39

Warning: Trying to access array offset on value of type bool in /var/www/vhosts/nova8.com.br/httpdocs/2022/wp-content/plugins/elementor-pro/modules/dynamic-tags/tags/post-featured-image.php on line 39

Warning: Trying to access array offset on value of type bool in /var/www/vhosts/nova8.com.br/httpdocs/2022/wp-content/plugins/elementor-pro/modules/dynamic-tags/tags/post-featured-image.php on line 39

Warning: Trying to access array offset on value of type bool in /var/www/vhosts/nova8.com.br/httpdocs/2022/wp-content/plugins/elementor-pro/modules/dynamic-tags/tags/post-featured-image.php on line 39
Ir para o conteúdo
  • +55 (11) 3375 0133
  • +55 (11) 96635 2442
  • contato@nova8.com.br
Linkedin-in Facebook-square Instagram Youtube
  • EN-US
  • PT-BR
Nova8
  • Sobre nós
  • Soluções
    • Snyk
    • Upwind
    • Cequence
    • CORO
    • IRONSCALES
    • Checkmarx
    • Acunetix
    • Bright
    • Riskified
    • MazeBolt
    • Mend
  • Serviços
    • Distribuidor
    • Revendas
  • Clientes
  • Blog
  • Materiais
  • Fale Conosco
  • Sobre nós
  • Soluções
    • Snyk
    • Upwind
    • Cequence
    • CORO
    • IRONSCALES
    • Checkmarx
    • Acunetix
    • Bright
    • Riskified
    • MazeBolt
    • Mend
  • Serviços
    • Distribuidor
    • Revendas
  • Clientes
  • Blog
  • Materiais
  • Fale Conosco
Nova8
  • Sobre nós
  • Soluções
    • Snyk
    • Upwind
    • Cequence
    • CORO
    • IRONSCALES
    • Checkmarx
    • Acunetix
    • Bright
    • Riskified
    • MazeBolt
    • Mend
  • Serviços
    • Distribuidor
    • Revendas
  • Clientes
  • Blog
  • Materiais
  • Fale Conosco
  • Sobre nós
  • Soluções
    • Snyk
    • Upwind
    • Cequence
    • CORO
    • IRONSCALES
    • Checkmarx
    • Acunetix
    • Bright
    • Riskified
    • MazeBolt
    • Mend
  • Serviços
    • Distribuidor
    • Revendas
  • Clientes
  • Blog
  • Materiais
  • Fale Conosco
Nova8

Conhecimento especializado

Continuous Security Testing for Microservices

  • flavia
  • 24 de out de 2017
  • Gestão de segurança

Warning: Trying to access array offset on value of type bool in /var/www/vhosts/nova8.com.br/httpdocs/2022/wp-content/plugins/elementor-pro/modules/dynamic-tags/tags/post-featured-image.php on line 39

Being a part of today’s tech-industry, you probably notice all winds blowing towards the implementation of DevOps and CI\CD methodologies, and rightfully so. Today’s software developers face an ever growing need for speedy development-to-production cycles with uncompromising security and reliability. One way of facing the speed versus quality challenge is the introduction ofmicroservices.

 

 

Unlike the classic monolithic approach to developing an application, microservices break the application down to its various components with each component behaving as full a stack as possible. Imagine many mini-apps that together make one unified application. Those mini-apps often revolve around a specific business capability and must be able to communicate and scale seamlessly.

 

Expectedly, there are pros and cons to the adoption of microservices and though we won’t go through them all, there are some worth mentioning:

 

Modularity – Breaking down a large and complex application to its components improves modularity and makes each component easier to understand, develop, modify and test.

 

Independency – One microservice failing doesn’t mean the entire system is affected. Similarly, there is no need to upgrade and test the entire system for just one component.

 

Fast Paced Environments – Microservices’ structure enables a decentralized approach to data management and more importantly, it enables continuous delivery and deployment bringing us back to the first paragraph and the need for speed.

 

That said, microservices are not a one-size-fits-all solution.

Consistency  – It is harder to maintain consistency throughout the system.

 

System Dependencies and Development Roadblocks – Microservices create an increased number of system dependencies and while parallelizing development they also create parallel development roadblocks.

 

Testing – Microservices can create a challenge when it comes to testing as it is hard to get one flow through the entire system.

 

On that last note, microservices present security testing challenges as well:

 

Application security testing (AST) solutions that aim to fit a microservices development method need to offer incremental testing. Solutions that are only able to scan all related binaries at once are not suitable. Such solutions are bound to impose delays on the continuous integration process and present false positives\negatives as they don’t take into consideration each service’s specific logic. When dealing with microservices, it is particularly important to use an AST solution capable of scanning independent segments of code, i.e independent microservices.

 

Shifting security left in the SDLC is ever more valuable when dealing with microservices. Implementing Static Code Analysis (or SAST) for each microservice complements the fast development environment they aim to achieve. Scanning a microservice’s uncompiled code before it is linked to other microservices, is key to pinpointing and remediating vulnerabilities.  That said, the ideal AST solution should also offer Interactive AST (IAST) which will ensure end-to-end security testing – IAST provides high scenario coverage and can detect vulnerabilities that can only be detected on running applications.

 

Microservices present a need for customization. Being the independent units that they are, microservices allow broad technological and design flexibility. Their independency also means each microservice will often require its own set of security tests. AST solutions supporting microservices should allow developers to easily create their own security queries or modify existing ones to better fit the needs of each microservice. This will ensure each service is accurately and thoroughly tested for vulnerabilities.

 

To summarize the above, AST solutions need to keep up with microservices’ modular, flexible and independent nature in order to provide the most accurate vulnerability scanning. They need to ensure developers can easily modify them to better suit their needs, they have to be able to scan independent services and should offer rapid and complete SDLC coverage, from initial coding to the running application.

 

There are many considerations to keep in mind when deciding to shift to microservices. If you wish to learn more about the pros and cons as well as testing implementations, take a look at Checkmarx’s joint whitepaper with Tricentis and Insight Venture Partners.

  • Navegue por assunto:

    • #AppOps
    • #AppSec
    • #cybercrime
    • #cybersecurity
    • #IA
    • #ransomware
    • API Security
    • AppSec
    • Artigos
    • ASPM
    • Auditoria
    • Blog
    • Canais e Revendas
    • Cases
    • Cequence
    • Checkmarx
    • CIOs
    • CloudSecurity
    • Containers
    • Coro
    • CSPM
    • DevSecOps
    • DevSecOps
    • Distribuição de Cibersegurança
    • distribuidor de valor agregado
    • Distribuidores de TI
    • E-commerce
    • E-commerce
    • Ecossistema Nova8
    • Email Phishing
    • Estratégia de Mercado
    • Estratégias de Cibersegurança
    • Ferramentas de Segurança de E-mail
    • Gartner
    • Gartner Market Guide
    • Gestão de segurança
    • GigaOm Radar
    • Glossário
    • GPTW
    • Inovação Tecnológica
    • Ironscales
    • Kubernetes
    • Liderança em TI
    • Malware
    • Materiais
    • Modular Cybersecurity
    • Modular Cybersecurity
    • Notícias
    • Open Source
    • Phishing
    • Planejamento
    • Proteção Cibernética
    • Proteção de Dados
    • SDLC
    • Segurança
    • Segurança Cibernética
    • Segurança de APIs
    • Segurança de e-mails
    • Segurança na Nuvem
    • Sem categoria
    • Snyk
    • Soluções Cloud-Native
    • Soluções Cloud-Native
    • Tecnologia Empresarial
    • Trusted Advisor
    • Upwind
    • Venha trabalhar conosco!
  • Mantenha-se à frente das ameaças cibernéticas​

    Explore nossa seção de Insights e fique por dentro das últimas tendências em cibersegurança.

    Saiba mais
    Samuel Zejger, executivo da Upwind, à esquerda, com fundo azul e logos da Nova8 e Upwind. Ao lado, título: "Upwind e Nova8: Nova geração da segurança em nuvem. Entrevista exclusiva com Samuel Zejger sobre desafios e tendências da cloud security".
    Upwind

    Upwind e Nova8: A nova geração da segurança em nuvem que prioriza o que realmente importa

    • 01 de jul de 2025
    Leia mais
    Fundo azul com elementos gráficos representando segurança digital e proteção de APIs, utilizado no artigo sobre API Abuse da Nova8 e Cequence.
    Soluções Cloud-Native

    API Abuse: Como Proteger APIs do Abuso e Aumentar a Segurança

    • 01 de jul de 2025
    Leia mais
    Aperto de mãos entre um robô e um humano de terno, com fundo escuro repleto de linhas de código, ilustrando o tema “Inteligência Artificial na cibersegurança: aliada ou ameaça?” pela Nova8.
    Upwind

    Inteligência Artificial na cibersegurança: aliada ou ameaça?

    • 27 de jun de 2025
    Leia mais

    Como podemos ajudar?

    Entre em contato para conhecer mais sobre nossas soluções em um atendimento personalizado.
    Fale conosco
    Linkedin-in Facebook-square Instagram Youtube

    Al. Rio Negro, 585 - Torre Jaçarí - 13º andar Conjunto 134 - Alphaville, Barueri - SP, 06454-000

    • +55 (11) 3375 0133
    • +55 (11) 96635 2442
    • contato@nova8.com.br

    Empresa

    • Sobre a Nova8
    • Eventos
    • Serviços
    • Revendas
    • Trabalhe conosco
    • Política de Privacidade
    • Código de Ética

    Soluções

    • Snyk
    • Upwind
    • Cequence
    • CORO
    • IRONSCALES
    • Checkmarx
    • Acunetix
    • Bright
    • Riskified
    • MazeBolt
    • Mend
    • Solicite um orçamento

    Conteúdo

    • Blog Nova8
    • Clientes e Cases
    • Materiais

    Copyright © Nova 8 Cybersecurity - 2025 - Todos os direitos reservados

    Desenvolvido por Tech4Biz

    Pesquisar
    Nova8
    • EN-US
    • PT-BR
    • Sobre nós
    • Soluções
      • Snyk
      • Upwind
      • Cequence
      • CORO
      • IRONSCALES
      • Checkmarx
      • Acunetix
      • Bright
      • Riskified
      • MazeBolt
      • Mend
    • Serviços
      • Distribuidor
      • Revendas
    • Clientes
    • Blog
    • Materiais
    • Fale Conosco
    • Sobre nós
    • Soluções
      • Snyk
      • Upwind
      • Cequence
      • CORO
      • IRONSCALES
      • Checkmarx
      • Acunetix
      • Bright
      • Riskified
      • MazeBolt
      • Mend
    • Serviços
      • Distribuidor
      • Revendas
    • Clientes
    • Blog
    • Materiais
    • Fale Conosco
    • +55 (11) 3375 0133
    • +55 (11) 96635 2442
    • contato@nova8.com.br
    Linkedin-in Facebook-square Instagram Youtube
    Saiba mais
    Pesquisar

    SOLUÇÕES NOVA8

    • Checkmarx
    • Acunetix
    • Bright
    • Whitesource
    • Riskified
    • MazeBolt
    • Ironscales
    • +55 (11) 3375 0133
    • +55 (11) 96635 2442
    • contato@nova8.com.br
    Linkedin-in Facebook-square Instagram Youtube