Workflow Integration Alleviates Identity and Access Management in Serverless Computing

Workflow Integration Alleviates Identity and Access Management in Serverless Computing
复制标题

DOI:
10.1145/3427228.3427665
复制
发表时间:
2020-12
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
A. Sankaran;Pubali Datta;Adam Bates
A. Sankaran;Pubali Datta;Adam Bates
中科院分区:
其他
文献类型:
--
作者:
A. Sankaran;Pubali Datta;Adam Bates

文献摘要

被引文献

相似文献

随着无服务器计算不断革新Web服务的设计和部署,它已成为攻击者越来越有吸引力的目标。这些对手正在开发新的策略,以规避无服务器功能的短暂性,利用容器重用优化,并通过合法的无服务器工作流提供的“生活在陆地上”来实现横向移动。不幸的是,云提供商目前提供的传统安全控制措施不足以应对这些新威胁。在这项工作中,我们提出了will. iam,1一个工作流感知的访问控制模型和引用监视器,满足无服务器计算范式的功能需求。will.iam将无服务器应用程序的保护状态编码为描述其工作流的可允许转换的许可图,根据基于图的标记状态将Web请求与入口点处的许可集相关联。通过主动强制下游工作流组件的权限要求,will.iam能够避免部分处理未授权请求的成本,并减少应用程序的攻击面。我们在Go语言中实现了will.iam框架,并将其性能与最近的相关工作进行了比较,并与Nordstrom“Hello,Retail!”应用程序.我们证明了will.iam对请求的负担最小,在代表性的工作流中平均开销为0.51%,但在处理未经授权的请求时(例如,DDoS攻击)与过去的解决方案相比。因此,will.iam展示了无服务器范例中授权的有效且实用的替代方案。
As serverless computing continues to revolutionize the design and deployment of web services, it has become an increasingly attractive target to attackers. These adversaries are developing novel tactics for circumventing the ephemeral nature of serverless functions, exploiting container reuse optimizations and achieving lateral movement by “living off the land” provided by legitimate serverless workflows. Unfortunately, the traditional security controls currently offered by cloud providers are inadequate to counter these new threats. In this work, we propose will.iam,1 a workflow-aware access control model and reference monitor that satisfies the functional requirements of the serverless computing paradigm. will.iam encodes the protection state of a serverless application as a permissions graph that describes the permissible transitions of its workflows, associating web requests with a permissions set at the point of ingress according to a graph-based labeling state. By proactively enforcing the permissions requirements of downstream workflow components, will.iam is able to avoid the costs of partially processing unauthorized requests and reduce the attack surface of the application. We implement the will.iam framework in Go and evaluate its performance as compared to recent related work against the well-established Nordstrom “Hello, Retail!” application. We demonstrate that will.iam imposes minimal burden to requests, averaging 0.51% overhead across representative workflows, but dramatically improves performance when handling unauthorized requests (e.g., DDoS attacks) as compared to past solutions. will.iam thus demonstrates an effective and practical alternative for authorization in the serverless paradigm.