Observability and Incident Response in Managed Serverless Environments Using Ontology-Based Log Monitoring
Lavi Ben-Shimol, Edita Grolman, Aviad Elyashar, Inbar Maimon, Dudu, Mimran, Oleg Brodt, Martin Strassmann, Heiko Lehmann, Yuval Elovici, Asaf, Shabtai

TL;DR
This paper presents an ontology-based log monitoring framework for fully managed serverless environments, enhancing observability and incident response through a unified activity graph and specialized tools.
Contribution
It introduces a novel three-layer security scheme utilizing serverless logs and a knowledge graph to improve security monitoring and incident response in managed serverless platforms.
Findings
The incident response dashboard improved response accuracy and speed.
The risk assessment framework facilitated better prioritization of security assets.
User study demonstrated effectiveness of the proposed tools.
Abstract
In a fully managed serverless environment, the cloud service provider is responsible for securing the cloud infrastructure, thereby reducing the operational and maintenance efforts of application developers. However, this environment limits the use of existing cybersecurity frameworks and tools, which reduces observability and situational awareness capabilities (e.g., risk assessment, incident response). In addition, existing security frameworks for serverless applications do not generalize well to all application architectures and usually require adaptation, specialized expertise, etc. for use in fully managed serverless environments. In this paper, we introduce a three-layer security scheme for applications deployed in fully managed serverless environments. The first two layers involve a unique ontology based solely on serverless logs which is used to transform them into a unified…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware System Performance and Reliability · Service-Oriented Architecture and Web Services · Network Security and Intrusion Detection
