Securing Serverless Computing: Challenges, Solutions, and Opportunities

被引:12
作者
Li, Xing [3 ]
Leng, Xue [1 ,2 ]
Chen, Yan [4 ]
机构
[1] Xidian Univ, Hangzhou Inst Technol, Xian, Peoples R China
[2] Xidian Univ, Sch Cyber Engn, Xian, Peoples R China
[3] Zhejiang Univ, Hangzhou, Peoples R China
[4] Northwestern Univ, Evanston, IL USA
来源
IEEE NETWORK | 2023年 / 37卷 / 02期
关键词
Security; Serverless computing; Containers; Computational modeling; Virtualization; Monitoring; Task analysis;
D O I
10.1109/MNET.005.2100335
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Serverless computing is a new cloud service model that reduces both cloud providers' and consumers' costs through agile development, operation, and charging mechanisms. It has been widely applied since its emergence. Nevertheless, some characteristics of serverless computing, such as fragmented application boundaries, have raised new security challenges. Considerable literature has been committed to addressing these challenges. Commercial and open-source serverless platforms implement many security measures to enhance serverless environments. This article presents the first survey of serverless security that considers both the literature and industrial security measures. We summarize the primary security challenges, analyze corresponding solutions from the literature and industry, and identify potential research opportunities. Then, we conduct a gap analysis of the academic and industrial solutions, as well as commercial and open- source serverless platforms' security capabilities. Finally, we present a complete picture of current serverless security research.
引用
收藏
页码:166 / 173
页数:8
相关论文
共 15 条
[1]  
Agache A, 2020, PROCEEDINGS OF THE 17TH USENIX SYMPOSIUM ON NETWORKED SYSTEMS DESIGN AND IMPLEMENTATION, P419
[2]   VALVE: Securing Function Workflows on Serverless Computing Platforms [J].
Datta, Pubali ;
Kumar, Prabuddha ;
Morris, Tristan ;
Grace, Michael ;
Rahmati, Amir ;
Bates, Adam .
WEB CONFERENCE 2020: PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE (WWW 2020), 2020, :939-950
[3]  
Jonas Eric, 2019, arXiv, DOI DOI 10.48550/ARXIV.1902.03383
[4]   Confidential Serverless Made Efficient with Plug-In Enclaves [J].
Li, Mingyu ;
Xia, Yubin ;
Chen, Haibo .
2021 ACM/IEEE 48TH ANNUAL INTERNATIONAL SYMPOSIUM ON COMPUTER ARCHITECTURE (ISCA 2021), 2021, :306-318
[5]  
Li ZJ, 2022, PROCEEDINGS OF THE 2022 USENIX ANNUAL TECHNICAL CONFERENCE, P53
[6]   Tracking Causal Order in AWS Lambda Applications [J].
Lin, Wei-Tsung ;
Krintz, Chandra ;
Wolski, Rich ;
Zhang, Michael ;
Cai, Xiaogang ;
Li, Tongjun ;
Xu, Weijin .
2018 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2018), 2018, :50-60
[7]  
MarketsandMarkets, 2020, Serverless Architecture Market Size, Share and Global Market Forecast to 2025
[8]  
Nam J, 2020, PROCEEDINGS OF THE 2020 USENIX ANNUAL TECHNICAL CONFERENCE, P81
[9]  
Obetz M., 2019, P 11 USENIX WORKSH H
[10]   Se-Lambda: Securing Privacy-Sensitive Serverless Applications Using SGX Enclave [J].
Qiang, Weizhong ;
Dong, Zezhao ;
Jin, Hai .
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2018, PT I, 2018, 254 :451-470