论文标题

使用seclambda保护无服务器的应用程序

Guarding Serverless Applications with SecLambda

论文作者

Jegan, Deepak Sirone, Wang, Liang, Bhagat, Siddhant, Ristenpart, Thomas, Swift, Michael

论文摘要

作为新兴应用程序范式,无服务器计算吸引了越来越多的攻击者的关注。不幸的是,传统应用程序的安全工具不能轻易移植到无服务器,并且现有的无服务器安全解决方案不足。在本文中,我们提出\ emph {seclambda},这是一个可扩展的安全框架,利用本地函数状态和全局应用程序状态执行复杂的安全任务来保护应用程序。我们展示了如何使用seclambda来实现无服务器应用程序中的控制流程完整性,凭据保护和速率限制。我们使用现实的开源应用程序评估了Seclambda的性能和安全性,我们的结果表明,Seclambda可以减轻几次攻击,同时引入相对较低的性能开销。

As an emerging application paradigm, serverless computing attracts attention from more and more attackers. Unfortunately, security tools for conventional applications cannot be easily ported to serverless, and existing serverless security solutions are inadequate. In this paper, we present \emph{SecLambda}, an extensible security framework that leverages local function state and global application state to perform sophisticated security tasks to protect an application. We show how SecLambda can be used to achieve control flow integrity, credential protection, and rate limiting in serverless applications. We evaluate the performance overhead and security of SecLambda using realistic open-source applications, and our results suggest that SecLambda can mitigate several attacks while introducing relatively low performance overhead.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源