返回
Toward security quantification of serverless computing
DOI:10.1186/s13677-024-00703-y.png)
摘要
En 中文
Serverless computing is one of the recent compelling paradigms in cloud computing. Serverless computing can quickly run user applications and services regardless of the underlying server architecture. Despite the availability of several commercial and open-source serverless platforms, there are still some open issues and challenges to address. One of the key concerns in serverless computing platforms is security. Therefore, in this paper, we present a multi-layer abstract model of serverless computing for an security investigation. We conduct a quantitative analysis of security risks for each layer. We observe that the Attack Tree and Attack-Defense Tree methodologies are viable approaches in this regard. Consequently, we make use of the Attack Tree and the Attack-Defense Tree to quantify the security risks and countermeasures of serverless computing. We also propose a novel measure called the Relative Risk Matrix (RRM) to quantify the probability of attack success. Stakeholders including application developers, researchers, and cloud providers can potentially apply these findings and implications to better understand and further enhance the security of serverless computing.
Keyword:
Serverless computing
FaaS
Security
Quantification
Attack Tree
Attack-Defense Tree
Risk matrix
期刊
J
IF:
4.3
论文数:
756
被引数:
2.2K
机构
引用论文
Vinyl polymers containing amido and carboxylic groups as side substituents: I. Synthesis of N-acryloyl-glycine and N-acryloyl-6-caproic acid and their grafting on cellulose membranes
Polymer
IF0
Clinical Significance of SERPINA1 Gene and Its Encoded Alpha1-antitrypsin Protein in NSCLC
Cancers
IF0
Improvement of Kafka Streaming Using Partition and Multi-Threading in Big Data Environment
SENSORS
IF3.5

