SkyEye: When Your Vision Reaches Beyond IAM Boundary Scope in AWS Cloud
Minh Hoang Nguyen, Anh Minh Ho, Bao Son To

TL;DR
SkyEye is a novel framework that enhances IAM enumeration in AWS, providing comprehensive situational awareness beyond traditional boundaries to improve cloud security and compliance.
Contribution
The paper introduces SkyEye, a cooperative multi-principal IAM enumeration framework that overcomes authorization limitations to reveal complete IAM configurations in AWS.
Findings
Enables full IAM configuration mapping in AWS environments.
Identifies potential security misconfigurations and privilege escalations.
Supports compliance and security posture improvements.
Abstract
In recent years, cloud security has emerged as a primary concern for enterprises due to the increasing trend of migrating internal infrastructure and applications to cloud environments. This shift is driven by the desire to reduce the high costs and maintenance fees associated with traditional on-premise infrastructure. By leveraging cloud capacities such as high availability and scalability, companies can achieve greater operational efficiency and flexibility. However, this migration also introduces new security challenges. Ensuring the protection of sensitive data, maintaining compliance with regulatory requirements, and mitigating the risks of cyber threats are critical issues that must be addressed. Identity and Access Management (IAM) constitutes the critical security backbone of most cloud deployments, particularly within AWS environments. As organizations adopt AWS to scale…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
