{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T02:13:17Z","timestamp":1773713597366,"version":"3.50.1"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Ministry of Industry and Information Technology of China"},{"name":"National Key Research and Development Program of China","award":["2023YFB3307500"],"award-info":[{"award-number":["2023YFB3307500"]}]},{"name":"NSFC Program","award":["6212780016"],"award-info":[{"award-number":["6212780016"]}]},{"name":"NSFC Program","award":["62076146"],"award-info":[{"award-number":["62076146"]}]},{"name":"NSFC Program","award":["62021002"],"award-info":[{"award-number":["62021002"]}]},{"name":"NSFC Program","award":["U20A6003"],"award-info":[{"award-number":["U20A6003"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1109\/tdsc.2025.3628339","type":"journal-article","created":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T18:47:44Z","timestamp":1762195664000},"page":"2599-2616","source":"Crossref","is-referenced-by-count":0,"title":["ERINYES: Request-Level Provenance Analysis for Serverless Attacks"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-5071-5306","authenticated-orcid":false,"given":"Hao","family":"Xi","sequence":"first","affiliation":[{"name":"School of Software, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9608-5808","authenticated-orcid":false,"given":"Hai","family":"Wan","sequence":"additional","affiliation":[{"name":"School of Software, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6168-7016","authenticated-orcid":false,"given":"Xibin","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Software, Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8972-8094","authenticated-orcid":false,"given":"Mohsen","family":"Guizani","sequence":"additional","affiliation":[{"name":"Mohamed bin Zayed University of Artificial Intelligence, Masdar City, UAE"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"What is serverless?","author":"Hat","year":"2022"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1186\/s13677-022-00347-w"},{"key":"ref3","article-title":"Security risks and challenges in the serverless world","year":"2021"},{"key":"ref4","article-title":"A deep dive into serverless attacks, sls-1: Event injection","author":"Labs","year":"2019"},{"key":"ref5","article-title":"Securing serverless: Attacking an aws account via a lambda function","author":"Segal","year":"2018"},{"key":"ref6","article-title":"CVE-2019-5736: RunC container breakout","year":"2019"},{"key":"ref7","first-page":"2443","article-title":"$\\lbrace${ALASTOR$\\rbrace$}: Reconstructing the provenance of serverless intrusions","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Datta"},{"key":"ref8","first-page":"373","article-title":"$\\lbrace${AIRTAG$\\rbrace$}: Towards automated attack investigation by unsupervised learning with log texts","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Ding"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24445"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24270"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"ref12","article-title":"High accuracy attack provenance via binary-based execution partition","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Lee"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2022.3166553"},{"key":"ref14","article-title":"Making the most of AWS lambda - navigating its limitations for better results","author":"Schmidt","year":"2023"},{"key":"ref15","article-title":"Aws X-ray","year":"2024"},{"key":"ref16","article-title":"View metrics and quotas","author":"Cloud","year":"2024"},{"key":"ref17","article-title":"Azure monitor overview","author":"Azure","year":"2024"},{"key":"ref18","article-title":"Agentless monitoring and error detection for serverless","year":"2024"},{"key":"ref19","article-title":"Application monitoring built for containers and serverless","year":"2024"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427665"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380173"},{"key":"ref22","first-page":"3989","article-title":"$\\lbrace${CLARION$\\rbrace$}: Sound and clear provenance tracking for microservice deployments","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Chen"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM53939.2023.10228884"},{"key":"ref24","article-title":"What is AWS lambda?","year":"2024"},{"key":"ref25","article-title":"Create new functions","year":"2024"},{"key":"ref26","article-title":"Function identity","author":"Cloud","year":"2024"},{"key":"ref27","article-title":"Hello, retail!","author":"Technology","year":"2017"},{"key":"ref28","article-title":"How aws lambda reuses containers","author":"Pfisterer","year":"2021"},{"key":"ref29","article-title":"Finding azurescape\u2013cross-account container takeover in azure container instances","author":"Avrahami","year":"2021"},{"key":"ref30","article-title":"Gone in 60 milliseconds: Intrusion and exfiltration in serverless architectures","author":"Jones","year":"2019"},{"key":"ref31","article-title":"Container escape: Service account token with risky permissions","author":"Security","year":"2022"},{"key":"ref32","article-title":"Going serverless with node.js: Benefits, use cases, and how to get started","year":"2024"},{"key":"ref33","article-title":"AWS lambda vs azure functions: A comprehensive comparison","year":"2024"},{"key":"ref34","article-title":"Side channel attack - an overview| sciencedirect topics","year":"2024"},{"key":"ref35","article-title":"Cybersecurity hardware: Shielding your critical infrastructure","year":"2024"},{"key":"ref36","article-title":"Defending against in-memory attacks with endpoint security and memory threat protection","year":"2023"},{"key":"ref37","article-title":"Fileless malware: What is it and how does it work?","year":"2024"},{"key":"ref38","article-title":"Cloud programming simplified: A berkeley view on serverless computing","author":"Jonas","year":"2019"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E65552.2025.00032"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00064"},{"key":"ref41","article-title":"AWS lambda documentation","year":"2025"},{"key":"ref42","article-title":"Google cloud functions documentation","year":"2025"},{"key":"ref43","article-title":"SAS top 10","year":"2023"},{"key":"ref44","first-page":"4087","article-title":"Guarding serverless applications with kalium","volume-title":"Proc. 32nd USENIX Secur. Symp","author":"Jegan"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645436"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3459616"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE62328.2024.00047"},{"key":"ref48","article-title":"Analyze and debug production, distributed applications","year":"2019"},{"key":"ref49","article-title":"Azure application insights","year":"2019"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23141"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11434575\/11224542.pdf?arnumber=11224542","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T01:16:16Z","timestamp":1773710176000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11224542\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":50,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3628339","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3]]}}}