Securing Serverless Computing: Challenges, Solutions, and Opportunities

被引:8
|
作者
Li, Xing [3 ]
Leng, Xue [1 ,2 ]
Chen, Yan [4 ]
机构
[1] Xidian Univ, Hangzhou Inst Technol, Xian, Peoples R China
[2] Xidian Univ, Sch Cyber Engn, Xian, Peoples R China
[3] Zhejiang Univ, Hangzhou, Peoples R China
[4] Northwestern Univ, Evanston, IL USA
来源
IEEE NETWORK | 2023年 / 37卷 / 02期
关键词
Security; Serverless computing; Containers; Computational modeling; Virtualization; Monitoring; Task analysis;
D O I
10.1109/MNET.005.2100335
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Serverless computing is a new cloud service model that reduces both cloud providers' and consumers' costs through agile development, operation, and charging mechanisms. It has been widely applied since its emergence. Nevertheless, some characteristics of serverless computing, such as fragmented application boundaries, have raised new security challenges. Considerable literature has been committed to addressing these challenges. Commercial and open-source serverless platforms implement many security measures to enhance serverless environments. This article presents the first survey of serverless security that considers both the literature and industrial security measures. We summarize the primary security challenges, analyze corresponding solutions from the literature and industry, and identify potential research opportunities. Then, we conduct a gap analysis of the academic and industrial solutions, as well as commercial and open- source serverless platforms' security capabilities. Finally, we present a complete picture of current serverless security research.
引用
收藏
页码:166 / 173
页数:8
相关论文
共 50 条
  • [1] Serverless Computing: State-of-the-Art, Challenges and Opportunities
    Li, Yongkang
    Lin, Yanying
    Wang, Yang
    Ye, Kejiang
    Xu, Chengzhong
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (02) : 1522 - 1539
  • [2] Serverless Computing: A Survey of Opportunities, Challenges, and Applications
    Shafiei, Hossein
    Khonsari, Ahmad
    Mousavi, Payam
    ACM COMPUTING SURVEYS, 2022, 54 (11S)
  • [3] VALVE: Securing Function Workflows on Serverless Computing Platforms
    Datta, Pubali
    Kumar, Prabuddha
    Morris, Tristan
    Grace, Michael
    Rahmati, Amir
    Bates, Adam
    WEB CONFERENCE 2020: PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE (WWW 2020), 2020, : 939 - 950
  • [4] Kubernetes in IT administration and serverless computing: An empirical study and research challenges
    Mondal, Subrota Kumar
    Pan, Rui
    Kabir, H. M. Dipu
    Tian, Tan
    Dai, Hong-Ning
    JOURNAL OF SUPERCOMPUTING, 2022, 78 (02) : 2937 - 2987
  • [5] Kubernetes in IT administration and serverless computing: An empirical study and research challenges
    Subrota Kumar Mondal
    Rui Pan
    H M Dipu Kabir
    Tan Tian
    Hong-Ning Dai
    The Journal of Supercomputing, 2022, 78 : 2937 - 2987
  • [6] Security in cloud computing: Opportunities and challenges
    Ali, Mazhar
    Khan, Samee U.
    Vasilakos, Athanasios V.
    INFORMATION SCIENCES, 2015, 305 : 357 - 383
  • [7] An Empirical Study on Challenges of Application Development in Serverless Computing
    Wen, Jinfeng
    Chen, Zhenpeng
    Liu, Yi
    Lou, Yiling
    Ma, Yun
    Huang, Gang
    Jin, Xin
    Liu, Xuanzhe
    PROCEEDINGS OF THE 29TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '21), 2021, : 416 - 428
  • [8] Serverless computing: a security perspective
    Marin, Eduard
    Perino, Diego
    Di Pietro, Roberto
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2022, 11 (01):
  • [9] A survey on the scheduling mechanisms in serverless computing: a taxonomy, challenges, and trends
    Ghorbian, Mohsen
    Ghobaei-Arani, Mostafa
    Esmaeili, Leila
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (05): : 5981 - 5993
  • [10] Serverless computing: a security perspective
    Eduard Marin
    Diego Perino
    Roberto Di Pietro
    Journal of Cloud Computing, 11