Denis Makrushin
  • Blog
  • Research
Denis Makrushin
  • Academynew
  • About
Research

Authentication and authorization in microservice-based systems

by Denis Makrushin October 27, 2020

https://arxiv.org/abs/2009.02114

Authentication, Authorization, and Audit (AAA) in microservice-based architecture is a cornerstone for any scale applications. Multiple “best practices” by technology leaders, multiple recommendations by industry influencers. What is relevant to your product design and should be implemented?

We published the survey deliver the AAAnswers with the criteria for choosing the right one for your application security architecture: “Authentication and authorization in microservice-based systems: survey of architecture patterns.”

Objective: the aim of this study is to provide a helpful resource to application security architect and developers on existing architecture patterns to implement authentication and authorization in microservices-based systems.

October 27, 2020
TwitterLinkedinVKTelegramThreadsBluesky
Blog

“Dev, Sec, Oops” principles (Infoshare 2020 Online talk)

by Denis Makrushin August 27, 2020

You know that product security strategy, if properly integrated into DevOps process, can improve the product. But do you know, how product security can destroy the product?

Join my talk on Security Stage at the upcoming @infosharepl 2020 Online, where I will speak about “Dev, Sec, Oops” principles.

Let’s meet on 23-25 and 28-30 September 2020. Book a ticket using promo code “is20-dmakrushin” to get 10% off.  Register: https://infoshare.pl/is-register/

August 27, 2020
TwitterLinkedinVKTelegramThreadsBluesky
Blog

Проект Red Team: роли и области экспертизы

by Denis Makrushin June 22, 2020

Красная команда имитирует действия атакующего, чтобы помочь оценить эффективность защитных мер и улучшить безопасность. В этой статье я разберу, как устроены такие команды и какие нужны области экспертизы для успешной реализации kill chain и демонстрации результатов.

В прошлый раз мы познакомились с ключевыми целями и показателями эффективности Red Team для процессов ИБ и бизнеса в целом. Мы рассмотрели особенности взаимодействия экспертов наступательной безопасности c Blue Team, нюансы ведения проектов и коммуникации во время работ. При этом мы практически не коснулись внутренней структуры красной команды. Пора исправить это!

Continue Reading
June 22, 2020
TwitterLinkedinVKTelegramThreadsBluesky
Load More Posts

Join Telegram Channel

  • Twitter
  • Linkedin
  • Vk
  • Telegram

@ 2009. Denis Makrushin


Back To Top
Denis Makrushin
  • Blog
  • Research
Denis Makrushin
  • Academynew
  • About