Novel advancements in static analysis of serverless applications
Novel advancements in static analysis of serverless applications
批准号:
2442771
负责人:
金额:
$0.0万
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2020
资助国家:
英国
项目状态:
未结题
起止时间:
2020 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
In recent years, the serverless computing paradigm, which allows developing applications by using cloud services managed by a provider, has become very popular. Companies adopting this approach can focus on the business logic of their software products, thus reducing their costs. Despite this, the tools to secure these applications are still evolving. Static analysis, in particular, remains very challenging because the code that implements the used services is not available to the developer.The chief objective of this PhD project is therefore the development of a novel methodology that allows analysing serverless applications statically, i.e., before their deployment, in order to detect security vulnerabilities. Given their importance, the identification of security-sensitive data flows leading to code injection vulnerabilities and unauthorized disclosure of information should be prioritized.The methodology will have to be implemented and then validated with a set of benchmarks, developed by considering previous research as well as examples of real-world applications. Finally, the prototyped static analysis tool will be used to analyse a large dataset in order to test the effectiveness of the proposed approach and identify its limitations.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金