arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

无服务器云应用中安全策略的过度授权分析

Permissions on the Loose: Measuring Overprivilege in Real-World Serverless Applications

Elvis Yeboah-Duako, Pubali Datta

arXiv 2607.02875首次发表:更新:

发表机构

University of Massachusetts, Amherst(马萨诸塞大学阿默斯特分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究无服务器云应用安全策略过度授权问题,通过PrivLess框架从代码提取交互,推导映射并量化过度授权。发现该问题在无服务器生态系统中严重且普遍,部分应用有多余权限及攻击能力。

AI 中文摘要

无服务器计算在云部署中迅速采用,但其面向服务编程模型的安全影响尚不清楚。分布式、模块化和异构应用使精确安全策略规范复杂化。基于角色的访问控制解决方案存在普遍配置错误问题,无服务器应用中功能、服务和资源的多样性以及云提供商频繁的权限模型更改,大大增加了策略配置错误的可能性。因此,策略往往过度授权,从而扩大了攻击面并使敏感云资源面临被破坏的风险。我们对实际无服务器应用中的过度授权进行了大规模测量研究,分析了一个由689个AWS Lambda应用组成的精选数据集,其中包括1293个函数。为了进行这项研究,我们开发了PrivLess,这是一个静态策略分析框架,它从应用程序源代码中提取函数到资源的交互,推导交互-权限映射,并将推断的交互与声明的策略进行协调,以量化过度授权。我们的测量表明,过度授权在无服务器生态系统中是系统性的且严重的:47.7%的应用程序具有多余的权限,具有99.65%的显著权限降低潜力。具有通配符定义权限的应用程序的平均过度授权率比没有通配符定义权限的应用程序高274倍。更关键的是,多余的权限启用了具体的攻击向量:18.8%的应用程序拥有不必要的权限提升能力,12个应用程序拥有它们不需要的防御规避权限。

英文摘要

Serverless computing has seen rapid adoption in cloud deployments, yet the security implications of its service-oriented programming model remain poorly understood. Distributed, modular, and heterogeneous applications complicate the specification of precise security policies. Role-based access control solutions such as Identity and Access Management (IAM) already exhibit pervasive misconfiguration problems, and the multiplicity of functions, services, and resources in serverless applications, together with frequent permission model changes by cloud providers, greatly increases the likelihood of policy misconfigurations. Consequently, policies are often overprivileged, thereby enlarging the attack surface and exposing sensitive cloud resources to compromise. We present a large-scale measurement study of overprivilege in real-world serverless applications, analyzing a curated dataset of 789 AWS Lambda applications comprised of 1,293 functions. To enable this study, we develop PrivLess, a static policy analysis framework that extracts function-to-resource interactions from application source code, derives an interaction-permission mapping, and reconciles inferred interactions with declared policies to quantify overprivilege. Our measurement reveals that overprivilege is systemic and severe across the serverless ecosystem: 47.7% of applications carry excess permissions with a significant privilege reduction potential of 99.65%. Applications with wildcard-defined permissions exhibited an average overprivilege ratio 274x higher than those without. More critically, the excess permissions enable concrete attack vectors: 18.8% of applications hold unnecessary Privilege Escalation capabilities, and 12 applications had Defense Evasion permissions they did not need.

CommentsAdded functionality tests and revised topic

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑