Arif Tuba, Jo Byunghyun, Park Jong Hyuk
Department of Computer Science and Engineering, Seoul National University of Science and Technology (SeoulTech), Seoul 01811, Republic of Korea.
Sensors (Basel). 2025 Apr 8;25(8):2350. doi: 10.3390/s25082350.
Cloud-native architecture is becoming increasingly popular in today's digital environment, driving the demand for robust security precautions to protect infrastructure and applications. This paper examines a variety of privacy-enhancing and trust-centric tools and techniques intended to meet the unique security requirements within cloud-native environments. Specifically, a variety of solutions are covered, such as runtime protection platforms for real-time threat detection and responses, cloud-native endpoint security solutions for ensuring trust and resilience in dynamic contexts, and service mesh technologies for secure service-to-service communication. Furthermore, we examine the roles of cloud-native encryption, cloud-native identity and access management, and container image scanning technologies in protecting containerized applications and preserving data privacy in transit and at rest. The importance of threat detection and response systems, cloud-native security information and event management (SIEM) solutions, and network security are also covered to strengthen trust and transparency in cloud-native security. We also present a thorough case study that demonstrates how security measures are applied across multiple layers, including application, network, infrastructure, and security, and compliance, to ensure holistic security in a cloud-native architecture. By investigating these privacy-enhancing methods and technologies, organizations may improve the security posture of their cloud-native implementations, reducing risks and ensuring the trustworthiness of their information and applications in the ever-changing ecosystem of today's digital landscape.
在当今的数字环境中,云原生架构越来越受欢迎,这推动了对强大安全防范措施的需求,以保护基础设施和应用程序。本文研究了各种旨在满足云原生环境中独特安全要求的增强隐私和以信任为中心的工具及技术。具体而言,涵盖了多种解决方案,例如用于实时威胁检测和响应的运行时保护平台、用于在动态环境中确保信任和弹性的云原生端点安全解决方案,以及用于安全的服务到服务通信的服务网格技术。此外,我们研究了云原生加密、云原生身份和访问管理以及容器镜像扫描技术在保护容器化应用程序以及保护传输中和静止时的数据隐私方面的作用。还涵盖了威胁检测和响应系统、云原生安全信息和事件管理(SIEM)解决方案以及网络安全的重要性,以增强云原生安全中的信任和透明度。我们还提供了一个全面的案例研究,展示了安全措施如何跨多个层面应用,包括应用程序、网络、基础设施以及安全和合规性,以确保云原生架构中的整体安全性。通过研究这些增强隐私的方法和技术,组织可以改善其云原生实施的安全态势,降低风险,并确保其信息和应用程序在当今数字领域不断变化的生态系统中的可信度。