{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T22:23:05Z","timestamp":1783549385872,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":54,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,5,13]],"date-time":"2024-05-13T00:00:00Z","timestamp":1715558400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS 19-55228"],"award-info":[{"award-number":["CNS 19-55228"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,5,13]]},"DOI":"10.1145\/3589334.3645436","type":"proceedings-article","created":{"date-parts":[[2024,5,8]],"date-time":"2024-05-08T07:08:13Z","timestamp":1715152093000},"page":"1644-1655","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":15,"title":["GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security Policies"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-9111-6913","authenticated-orcid":false,"given":"Isaac","family":"Polinsky","sequence":"first","affiliation":[{"name":"Department of Computer Science, North Carolina State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2026-5465","authenticated-orcid":false,"given":"Pubali","family":"Datta","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Massachusetts Amherst, Amherst, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1511-4951","authenticated-orcid":false,"given":"Adam","family":"Bates","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Illinois Urbana-Champaign, Champaign, Illinois, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3043-8092","authenticated-orcid":false,"given":"William","family":"Enck","sequence":"additional","affiliation":[{"name":"Department of Computer Science, North Carolina State University, Raleigh, NC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,5,13]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"2019. New Attack Vector - Serverless Crypto Mining. https:\/\/www.puresec.io\/blog\/new-attack-vector-serverless-crypto-mining."},{"key":"e_1_3_2_2_2_1","unstructured":"2021. AWSSupportServiceRolePolicy Informational Update. https:\/\/aws.amazon.com\/security\/security-bulletins\/AWS-2021-007\/."},{"key":"e_1_3_2_2_3_1","unstructured":"2021. Serverless Framework. https:\/\/www.serverless.com\/."},{"key":"e_1_3_2_2_4_1","unstructured":"2021. Serverless IAM Roles Per Function Plugin. https:\/\/github.com\/functionalone\/serverless-iam-roles-per-function."},{"key":"e_1_3_2_2_5_1","unstructured":"2022. AWS Lambda Customer Case Studies. https:\/\/aws.amazon.com\/lambda\/resources\/customer-case-studies\/."},{"key":"e_1_3_2_2_6_1","unstructured":"2022. checkov. https:\/\/www.checkov.io\/."},{"key":"e_1_3_2_2_7_1","unstructured":"2022. Google Cloud Cloud Functions Customers. https:\/\/cloud.google.com\/functions."},{"key":"e_1_3_2_2_8_1","unstructured":"2022. Microsoft Customer Stories. https:\/\/customers.microsoft.com\/en-us\/search'sq=%22Azure%20Functions%22."},{"key":"e_1_3_2_2_9_1","unstructured":"2022. Terraform Cloud. https:\/\/cloud.hashicorp.com\/products\/terraform."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3276488"},{"key":"e_1_3_2_2_11_1","unstructured":"Amazon Web Services. 2020. Identity and access management for AWS Lambda. https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/security-iam.html."},{"key":"e_1_3_2_2_12_1","unstructured":"Amazon Web Services. 2023. IAM Access Analyzer Guides You Toward Least-Privilege Permissions. https:\/\/aws.amazon.com\/iam\/features\/analyze-access\/."},{"key":"e_1_3_2_2_13_1","volume-title":"Stratified Abstraction of Access Control Policies","author":"Backes John","unstructured":"John Backes, Ulises Berrueco, Tyler Bray, Daniel Brim, Byron Cook, Andrew Gacek, Ranjit Jhala, Kasper Luckow, Sean McLaughlin, Madhav Menon, Daniel Peebles, Ujjwal Pugalia, Neha Rungta, Cole Schlesinger, Adam Schodde, Anvesh Tanuku, Carsten Varming, and Deepa Viswanathan. 2020. Stratified Abstraction of Access Control Policies. In Computer Aided Verification, Shuvendu K. Lahiri and Chao Wang (Eds.). Springer International Publishing, Cham, 165--176."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","unstructured":"John Backes Pauline Bolignano Byron Cook Catherine Dodge Andrew Gacek Kasper Luckow Neha Rungta Oksana Tkachuk and Carsten Varming. 2018. Semantic-based Automated Reasoning for AWS Access Policies using SMT. In 2018 Formal Methods in Computer Aided Design (FMCAD). 1--9. https:\/\/doi.org\/10.23919\/FMCAD.2018.8602994","DOI":"10.23919\/FMCAD.2018.8602994"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2014.64"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--981--10--5026--8_1"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3062180"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409728"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00450-019-00413-w"},{"key":"e_1_3_2_2_20_1","unstructured":"Check Point Software. 2019. A Deep Dive into Serverless Attacks SLS-1: Event Injection. https:\/\/www.protego.io\/a-deep-dive-into-serverless-attacks-sls-1-event-injection\/."},{"key":"e_1_3_2_2_21_1","volume-title":"IEEE Symposium on Security and Privacy.","author":"Clark D. D.","unstructured":"D. D. Clark and D. Wilson. 1987. A comparison of military and commercial security policies. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/1045502.1045548"},{"key":"e_1_3_2_2_23_1","unstructured":"Noam Dahan. 2020. Cloud infrastructure is not immune from the SolarWinds Orion breach. https:\/\/securityboulevard.com\/2020\/12\/cloud-infrastructure-is-not-immune-from-the-solarwinds-orion-breach\/."},{"key":"e_1_3_2_2_24_1","unstructured":"Datadog. 2022. The State of Serverless. https:\/\/www.datadoghq.com\/state-of-serverless\/."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380173"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/11814771_51"},{"key":"e_1_3_2_2_28_1","volume-title":"Thoth: Comprehensive Policy Compliance in Data Retrieval Systems. In 25th USENIX Security Symposium (USENIX Security 16)","author":"Elnikety Eslam","year":"2016","unstructured":"Eslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg, and Peter Druschel. 2016. Thoth: Comprehensive Policy Compliance in Data Retrieval Systems. In 25th USENIX Security Symposium (USENIX Security 16). USENIX Association, Austin, TX, 637--654. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/elnikety"},{"key":"e_1_3_2_2_29_1","unstructured":"Frederik Willaert. 2019. AWS Lambda Container Lifetime and Config Refresh. https:\/\/www.linkedin.com\/pulse\/aws-lambda-container-lifetime-config-refresh-frederik-willaert\/."},{"key":"e_1_3_2_2_30_1","unstructured":"Jonathan Greig. 2020. 2020 Cloud Misconfigurations Report. https:\/\/divvycloud.com\/misconfigurations-report-2020\/."},{"key":"e_1_3_2_2_31_1","volume-title":"Linux Conference","volume":"3","author":"Harada Toshiharu","year":"2004","unstructured":"Toshiharu Harada, Takashi Horie, , and Kazuo Tanaka. 2004. Task oriented management obviates your onus on Linux. In Linux Conference, Vol. 3."},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1805874.1805982"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133058.1133063"},{"key":"e_1_3_2_2_34_1","volume-title":"Proceedings of the 12th Conference on USENIX Security Symposium -","volume":"12","author":"Jaeger Trent","year":"2003","unstructured":"Trent Jaeger, Reiner Sailer, and Xiaolan Zhang. 2003. Analyzing Integrity Protection in the SELinux Example Policy. In Proceedings of the 12th Conference on USENIX Security Symposium - Volume 12 (Washington, DC) (SSYM'03). USENIX Association, Berkeley, CA, USA, 5--5. http:\/\/dl.acm.org\/citation.cfm?id=1251353.1251358"},{"key":"e_1_3_2_2_35_1","unstructured":"Deepak Sirone Jegan Liang Wang Siddhant Bhagat Thomas Ristenpart and Michael Swift. 2020. Guarding Serverless Applications with SecLambda. arXiv:2011.05322 [cs.CR]"},{"key":"e_1_3_2_2_36_1","volume-title":"Event Injection: Protecting your Serverless Applications. https:\/\/www.jeremydaly.com\/event-injection-protecting-your-serverless-applications\/.","author":"Daly Jeremy","year":"2020","unstructured":"Jeremy Daly. 2020. Event Injection: Protecting your Serverless Applications. https:\/\/www.jeremydaly.com\/event-injection-protecting-your-serverless-applications\/."},{"key":"e_1_3_2_2_37_1","unstructured":"Rich Jones. 2019. Gone in 60 Milliseconds: Intrusion and Exfiltration in Server-less Architectures. https:\/\/media.ccc.de\/v\/33c3--7865-gone_in_60_milliseconds."},{"key":"e_1_3_2_2_38_1","unstructured":"Andrew Krug and Graham Jones. 2019. Hacking serverless runtimes: Profiling AWS Lambda Azure Functions And more. https:\/\/www.blackhat.com\/us-17\/briefings\/schedule\/#hacking-serverless-runtimes-profiling-aws-lambda-azure-functions-and-more-6434."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.33"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.47"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.12"},{"key":"e_1_3_2_2_42_1","volume-title":"Proceedings of the 11th USENIX Conference on Hot Topics in Cloud Computing","author":"Obetz Matthew","year":"2019","unstructured":"Matthew Obetz, Stacy Patterson, and Ana Milanova. 2019. Static Call Graph Construction in AWS Lambda Serverless Applications. In Proceedings of the 11th USENIX Conference on Hot Topics in Cloud Computing (Renton, WA, USA) (HotCloud'19). USENIX Association, USA, 20."},{"key":"e_1_3_2_2_43_1","volume-title":"Securing Serverless: Attacking an AWS Account via a Lambda Function. https:\/\/www.darkreading.com\/cloud\/securing-serverless-attacking-an-aws-account-via-a-lambda-function\/a\/d-id\/1333047.","author":"Segal Ory","year":"2019","unstructured":"Ory Segal. 2019. Securing Serverless: Attacking an AWS Account via a Lambda Function. https:\/\/www.darkreading.com\/cloud\/securing-serverless-attacking-an-aws-account-via-a-lambda-function\/a\/d-id\/1333047."},{"key":"e_1_3_2_2_44_1","unstructured":"PureSec. 2019. Hacking a Serverless Application: Demo. https:\/\/www.youtube.com\/watch?v=TcN7wHuroVw."},{"key":"e_1_3_2_2_45_1","unstructured":"Nathaniel Quist. 2021. Unit 42 Cloud Threat Report Update: Cloud Security Weakens as More Organizations Fail to Secure IAM. https:\/\/unit42.paloaltonetworks.com\/iam-misconfigurations\/."},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.241422"},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427665"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.28"},{"key":"e_1_3_2_2_49_1","unstructured":"Serverless Inc. 2023. Serverless Infrastructure Providers. https:\/\/www.serverless.com\/framework\/docs\/providers."},{"key":"e_1_3_2_2_50_1","volume-title":"Proceedings of the IASTED International Conference on Communication, Network, and Information Security, M.H. Hamza (Ed.). 79--84","author":"Sueyasu Katsuya","year":"2003","unstructured":"Katsuya Sueyasu, Toshihiro Tabata, and Kouichi Sakurai. 2003. On the security of SELinux with a simplified policy. In Proceedings of the IASTED International Conference on Communication, Network, and Information Security, M.H. Hamza (Ed.). 79--84."},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/2414456.2414500"},{"key":"e_1_3_2_2_52_1","volume-title":"Peeking Behind the Curtains of Serverless Platforms. In 2018 USENIX Annual Technical Conference (USENIX ATC 18)","author":"Wang Liang","year":"2018","unstructured":"Liang Wang, Mengyuan Li, Yinqian Zhang, Thomas Ristenpart, and Michael Swift. 2018. Peeking Behind the Curtains of Serverless Platforms. In 2018 USENIX Annual Technical Conference (USENIX ATC 18). USENIX Association, Boston, MA, 133--146. https:\/\/www.usenix.org\/conference\/atc18\/presentation\/wang-liang"},{"key":"e_1_3_2_2_53_1","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Wang Ruowen","unstructured":"Ruowen Wang, William Enck, Douglas Reeves, Xinwen Zhang, Peng Ning, Ding-bang Xu, Wu Zhou, and Ahmed M. Azab. 2015. EASEAndroid: Automatic Policy Analysis and Refinement for Security Enhanced Android via Large-Scale Semi-Supervised Learning. In 24th USENIX Security Symposium (USENIX Security 15). USENIX Association, Washington, D.C., 351--366. https:\/\/www.usenix.org\/conference\/usenixsecurity15\/technical-sessions\/presentation\/wang-ruowen"},{"key":"e_1_3_2_2_54_1","unstructured":"Yan Cui. 2021. Many-faced threats to Serverless security. https:\/\/hackernoon.com\/many-faced-threats-to-serverless-security-519e94d19dba."}],"event":{"name":"WWW '24: The ACM Web Conference 2024","location":"Singapore Singapore","acronym":"WWW '24","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2024"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3645436","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3589334.3645436","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:30:43Z","timestamp":1755822643000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3645436"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,13]]},"references-count":54,"alternative-id":["10.1145\/3589334.3645436","10.1145\/3589334"],"URL":"https:\/\/doi.org\/10.1145\/3589334.3645436","relation":{},"subject":[],"published":{"date-parts":[[2024,5,13]]},"assertion":[{"value":"2024-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}