{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:01:58Z","timestamp":1782975718361,"version":"3.54.5"},"reference-count":51,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["92467201"],"award-info":[{"award-number":["92467201"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association CAS","doi-asserted-by":"publisher","award":["Y2023047"],"award-info":[{"award-number":["Y2023047"]}],"id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00010","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"1692-1709","source":"Crossref","is-referenced-by-count":0,"title":["C-Verifier: Understanding and Formally Verifying Cross-Service Flaws in AWS Cognito"],"prefix":"10.1109","author":[{"given":"Zhen","family":"Chen","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ze","family":"Jin","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Le","family":"Gong","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kexin","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangyi","family":"Zeng","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qixu","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3579643"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3368454"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1201\/9781439806814"},{"key":"ref4","article-title":"What is Azure identity protection and 7 steps to a seamless setup","author":"Stein","year":"2025","journal-title":"2024, apono Blog."},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.4436"},{"key":"ref6","first-page":"702","article-title":"There\u2019s a hole in that bucket!: A large-scale analysis of misconfigured s3 buckets","volume-title":"in Proceedings of the 34th Annual Computer Security Applications Conference (ACSAC). San Juan","author":"Continella"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4471-2236-4_6"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1080\/08874417.2024.2329985"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00009"},{"key":"ref10","first-page":"175","article-title":"Automated detection of password leakage from public GitHub repositories","volume-title":"in Proceedings of the 44th International Conference on Software Engineering (ICSE). ACM","author":"Feng"},{"issue":"4","key":"ref11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3579639","article-title":"Security Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study","volume":"32","author":"Rahman","year":"2023","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"ref12","first-page":"05","article-title":"Hacking AWS cognito misconfigurations","author":"Yadav","year":"2020","journal-title":"accessed on 2025"},{"key":"ref13","first-page":"05","article-title":"Amazon cognito ratelimit bypass","author":"Uemmelsec","year":"2023","journal-title":"accessed on 2025"},{"key":"ref14","first-page":"483","article-title":"\u201das soon as it\u2019s a risk, i want to require $\\text{MFA}^{\\prime \\prime}$: How administrators configure risk-based authentication,in Eighteenth Symposium on Usable Privacy and Security SOUPS 2022","volume-title":"Boston, MAUSENIX Association","author":"Markert"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.32604\/csse.2022.024854"},{"key":"ref16","article-title":"Leveraging ai planning for detecting cloud security vulnerabilities arXiv preprint","author":"Kazdagli","year":"2024","journal-title":"arXiv:2402.10985"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.36676\/urr.v9.i4.1320"},{"key":"ref18","year":"2025","journal-title":"C-verifier"},{"key":"ref19","article-title":"Cloud market jumped to $ 330 billion in 2024 - genai is now driving half of the growth","author":"Research Group","year":"2025","journal-title":"2024 market shares: AWS 30 %, Azure 21 %, Google 12 %"},{"key":"ref20","first-page":"2025","article-title":"Serverless computing market size, share & trends analysis report, 20252030","author":"View Research","year":"2025","journal-title":"estimates $24.51 billion market in 2024, 14.1% CAGR"},{"key":"ref21","article-title":"The state of serverless 2023","author":"Datadog","year":"2025","journal-title":"over 70% of AWS customers use at least one serverless service"},{"key":"ref22","first-page":"1","article-title":"Identity as a service-towards a service-oriented identity management architecture,\u201d in Dependable and Adaptable Networks and Services: 13th Open European Summer School and IFIP TC6. 6 Workshop EUNICE 2007, Enschede, The Netherlands","volume-title":"Proceedings 13. Springer","author":"Emig","year":"2007"},{"key":"ref23","article-title":"Identity as a service market size (2026 2032)","author":"Market Research","year":"2025","journal-title":"values IDaaS at $3.01 billion in 2024, 20.13% CAGR;"},{"key":"ref24","article-title":"Authentication service \u2013 customer iam (amazon cognito)","author":"Web Services","year":"2025","journal-title":"states \u201cmore than 100 billion authentications per month\u201d"},{"key":"ref25","article-title":"Amazon cognito pricing","year":"2025","journal-title":"free tier: 10,000 MAU for direct sign-in;"},{"key":"ref26","article-title":"Quotas in amazon cognito","year":"2025","journal-title":"default quota supports up to two million MAU per account;"},{"key":"ref27","article-title":"Amazon cognito - features","year":"2025","journal-title":"low-code UI, multi-framework SDKs;"},{"key":"ref28","article-title":"Everything you need to know about aws cognito","author":"CloudOptimo","year":"2025","journal-title":"overview of developer benefits;"},{"key":"ref29","article-title":"Control access to rest apis using amazon cognito user pools","author":"Web Services","year":"2025","journal-title":"aPI Gateway authorizer integration;"},{"key":"ref30","article-title":"Building fine-grained authorization using amazon cognito, api gateway, and iam","author":"Lovan","year":"2025","journal-title":"aWS Security Blog;"},{"key":"ref31","article-title":"Serverless api security, authentication, and authorization on aws","author":"Web Services","year":"2025","journal-title":"discusses Cognito user-pool protection for serverless APIs;"},{"key":"ref32","article-title":"Leveraging aws cognito with serverless for user authentication and data management","author":"Builders","year":"2025","journal-title":"step-by-step guide;"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00067"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.23919\/FMCAD.2018.8602994"},{"key":"ref35","first-page":"06","article-title":"Google gemini","year":"2025","journal-title":"[Online]. Available:"},{"key":"ref36","first-page":"05","article-title":"AWS Access Analyzer - identify and refine access to your aws resources","author":"Web Services","year":"2025","journal-title":"official documentation and information;"},{"key":"ref37","first-page":"05","article-title":"Cloudsplaining: An aws iam least privilege tool","author":"Salesforce","year":"2025","journal-title":"gitHub repository;"},{"key":"ref38","first-page":"05","article-title":"Prowler: Cloud security tool to perform aws, azure and gcp security assessments","author":"Community","year":"2025","journal-title":"gitHub repository;"},{"key":"ref39","author":"Services","year":"2025","journal-title":"Access analyzer concepts"},{"key":"ref40","author":"Adamson","year":"2025","journal-title":"Zero trust 2.0 Advances, challenges, and future directions in zta"},{"key":"ref41","article-title":"The overlooked six I AWS security blind spots","author":"Magee","year":"2025","journal-title":"sentinelOne"},{"key":"ref42","article-title":"Bucket monopoly: Breaching AWS accounts through shadow resources","author":"Geva","year":"2025","journal-title":"2023 lightspin Blog (now part of Cisco). Original research by Lightspin; link change or redirect over time"},{"key":"ref43","article-title":"Critical Azure vulnerability (AzNFS): Unauthenticated attacker can gain root privilege on customer VMs and cross tenant boundaries","author":"Threat Research","year":"2025","journal-title":"2024 varonis Blog"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3253572"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670366"},{"key":"ref46","article-title":"Automated vulnerability scanning of kubernetes during the ci\/cd process","volume-title":"Ph.D. dissertation, University of Applied Sciences Technikum Wien","author":"Wende","year":"2024"},{"key":"ref47","author":"Friman","year":"2024","journal-title":"Agile and devsecops oriented vulnerability detection and mitigation on public cloud"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1186\/s13677-024-00697-7"},{"key":"ref49","first-page":"281","article-title":"Block public access: trust safety verification of access control policies","volume-title":"in Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ser. ESEC\/FSE","author":"Bouchet","year":"2020"},{"issue":"1","key":"ref50","first-page":"21","article-title":"Quantifying Permissiveness of Access Control Policies. Association for Computing Machinery","volume-title":"publication Title: 44th International Conference on Software Engineering (ICSE \u201922)","volume":"1","author":"Eiers","year":"2022"},{"key":"ref51","first-page":"6025","article-title":"Detecting multi-step iam attacks in aws environments via model checking","volume-title":"in 32nd USENIX Security Symposium (USENIX Security 23)","author":"Shevrin","year":"2023"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573417.pdf?arnumber=11573417","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:35:29Z","timestamp":1782970529000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573417\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00010","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}