Serverless Computing: A Security Perspective
Eduard Marin, Diego Perino, Roberto Di Pietro

TL;DR
This paper reviews serverless computing architectures, analyzing their security features and shortcomings, and discusses potential countermeasures and future research directions to address security challenges.
Contribution
It provides a comprehensive security analysis of serverless architectures, highlighting unique vulnerabilities and proposing targeted security countermeasures.
Findings
Identifies security shortcomings in current serverless architectures
Highlights the need for specialized security solutions beyond traditional virtualisation
Suggests research directions for enhancing serverless security
Abstract
Serverless Computing is a virtualisation-related paradigm that promises to simplify application management and to solve the last challenges in the field: scale down and easy to use. The implied cost reduction, coupled with a simplified management of underlying applications, are expected to further push the adoption of virtualisation-based solutions, including cloud-computing or telco-cloud solutions. However, in this quest for efficiency, security is not ranked among the top priorities, also because of the (misleading) belief that current solutions developed for virtualised environments could be applied (as is) to this new paradigm. Unfortunately, this is not the case, due to the highlighted idiosyncratic features of serverless computing. In this paper, we review the current serverless architectures, abstract and categorise their founding principles, and provide an in depth analyse of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCloud Computing and Resource Management · IoT and Edge/Fog Computing · Cloud Data Security Solutions
