节点文献
面向Serverless应用的跨函数行为分析与约束技术
Cross-Function Behavior Analysis and Constraint Technology for Serverless Applications
【摘要】 无服务器计算中的应用被分解为函数运行于不同容器中,由于具有轻量化优势被广泛应用,但是也带来了安全风险。这种架构使程序内部接口暴露于网络,增加了攻击面以及越权访问等安全风险,威胁控制流和数据流的完整性。而现有的安全检测方法难以同时保护无服务器计算中容器(函数)间的控制流和数据流完整性。因此,文章提出一种面向Serverless应用的跨函数行为分析与约束技术,研究基于静态分析的函数间完整业务访问模型提取方法,实现实时的跨函数访问安全检测。实验结果表明,文章所提方法的异常控制流与数据流检出率分别达到97.54%和92.87%,并将监控误报率降低了10%以上,能够提升无服务器计算安全性。
【Abstract】 Applications in Serverless computing are decomposed into functions and run in different containers,they have the advantage of being lightweight and was widely used,but they also brings security risks.This architecture exposes the internal interfaces of the program to the network,increases the attack surface and security risks such as unauthorized access,and threatens the integrity of the control flow and data flow.However,existing security monitoring methods are difficult to protect the integrity of the control flow and data flow between containers (or functions) in Serverless computing.As a result,this paper proposed a cross-function behavior analysis and constraint technology for Serverless applications,by studying the extraction method of the complete access model between functions based on static analysis,real-time access control across functions was performed.Experimental results show that the method achieves an average of 97.54% as well as 92.87% for the anomalous control flow and data flow identification rate,and reduces the monitoring false alarms by more than 10%,which is able to improve the security of Serverless computing.
- 【文献出处】 信息网络安全 ,Netinfo Security , 编辑部邮箱 ,2025年09期
- 【分类号】TP393.08
- 【下载频次】13