Denial of wallet-Defining a looming threat to serverless computing

被引:16
作者
Kelly, Daniel [1 ]
Glavin, Frank G. [1 ]
Barrett, Enda [1 ]
机构
[1] Natl Univ Ireland, Sch Comp Sci, Galway NUIG, Galway, Ireland
关键词
Serverless computing; Cloud computing; Cloud security; Denial-of-wallet; Function-as-a-service; DEFENSE-MECHANISMS;
D O I
10.1016/j.jisa.2021.102843
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Serverless computing is the latest paradigm in cloud computing, offering a framework for the development of event driven, pay-as-you-go functions in a highly scalable environment. While these traits offer a powerful new development paradigm, they have also given rise to a new form of cyber-attack known as Denial of Wallet (forced financial exhaustion). In this work, we define and identify the threat of Denial of Wallet and its potential attack patterns. Also, we demonstrate how this new form of attack can potentially circumvent existing mitigation systems developed for a similar style of attack, Denial of Service. Our goal is twofold. Firstly, we will provide a concise and informative overview of this emerging attack paradigm. Secondly, we propose this paper as a starting point to enable researchers and service providers to create effective mitigation strategies. We include some simulated experiments to highlight the potential financial damage that such attacks can cause and the creation of an isolated test bed for continued safe research on these attacks.
引用
收藏
页数:10
相关论文
共 26 条
[1]  
Akiwatkar R., 10 AWS LAMBDA USE CA
[2]   Twitter turing test: Identifying social machines [J].
Alarifi, Abdulrahman ;
Alsaleh, Mansour ;
Al-Salman, AbdulMalik .
INFORMATION SCIENCES, 2016, 372 :332-346
[3]  
[Anonymous], 2014, XML Schema, DTD, and Entity Attacks
[4]  
Aslam S, 2020, OMNICORE
[5]  
AWS, AMAZON API GATEWAY Q
[6]  
Barna C., 2012, 2012 7th International Symposium on Software Engineering for Adaptive and Self-Managing Systems, P119, DOI 10.1109/SEAMS.2012.6224398
[7]  
Cao Q., 2012, P 9 USENIX S NETWORK, P15
[8]   VALVE: Securing Function Workflows on Serverless Computing Platforms [J].
Datta, Pubali ;
Kumar, Prabuddha ;
Morris, Tristan ;
Grace, Michael ;
Rahmati, Amir ;
Bates, Adam .
WEB CONFERENCE 2020: PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE (WWW 2020), 2020, :939-950
[9]  
Dooley D, 2019, SERVERLESS SHADOW AP
[10]   DDoS attacks and defense mechanisms: classification and state-of-the-art [J].
Douligeris, C ;
Mitrokotsa, A .
COMPUTER NETWORKS, 2004, 44 (05) :643-666