{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T12:09:16Z","timestamp":1766491756345,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":27,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,6,17]]},"DOI":"10.1145\/3727967.3756839","type":"proceedings-article","created":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T11:53:17Z","timestamp":1766490797000},"page":"152-161","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Security Perspective of Open-Source Serverless Platforms: An Empirical Investigation"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1633-9995","authenticated-orcid":false,"given":"Muhammad","family":"Hamza","sequence":"first","affiliation":[{"name":"Lappeenranta-Lahti University of Technology (LUT), Lahti, Finland"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6880-4991","authenticated-orcid":false,"given":"Muhammad Azeem","family":"Akbar","sequence":"additional","affiliation":[{"name":"Lappeenranta-Lahti University of Technology (LUT), Lappeenranta, Finland"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7043-0458","authenticated-orcid":false,"given":"Kari","family":"Smolander","sequence":"additional","affiliation":[{"name":"Lappeenranta University of Technology, Lapeenranta, Finland"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8479-1481","authenticated-orcid":false,"given":"Arif","family":"Khan","sequence":"additional","affiliation":[{"name":"University of Oulu, Oulu, Finland"}]}],"member":"320","published-online":{"date-parts":[[2025,12,23]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338466.3358916"},{"key":"e_1_3_3_1_3_2","unstructured":"Apache OpenWhisk. [n. d.]. Apache OpenWhisk Documentation. https:\/\/openwhisk.apache.org\/documentation.html. Accessed: 2024-10-04."},{"key":"e_1_3_3_1_4_2","unstructured":"AWS Lambda. [n. d.]. AWS Lambda Documentation. https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/welcome.html. Accessed: 2024-10-04."},{"key":"e_1_3_3_1_5_2","unstructured":"Microsoft Azure. [n. d.]. Azure Functions Documentation. url: https:\/\/learn.microsoft.com\/en-us\/azure\/azure-functions\/. Accessed: 2024-11-12."},{"key":"e_1_3_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3210459.3210463"},{"key":"e_1_3_3_1_7_2","unstructured":"Google Cloud. [n. d.]. Cloud Run Functions Documentation. url: https:\/\/cloud.google.com\/functions\/docs\/. Accessed: 2024-11-12."},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3382494.3410690"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"crossref","unstructured":"Simon Eismann Joel Scheuner Erwin Van\u00a0Eyk Maximilian Schwinger Johannes Grohmann Nikolas Herbst Cristina\u00a0L Abad and Alexandru Iosup. 2021. The state of serverless applications: Collection characterization and community consensus. IEEE Transactions on Software Engineering 48 10 (2021) 4152\u20134166.","DOI":"10.1109\/TSE.2021.3113940"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"crossref","unstructured":"Nafise Eskandani and Guido Salvaneschi. 2023. The uphill journey of FaaS in the open-source community. Journal of Systems and Software 198 (2023) 111589.","DOI":"10.1016\/j.jss.2022.111589"},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3593434.3593471"},{"key":"e_1_3_3_1_12_2","first-page":"100","volume-title":"International Conference on Product-Focused Software Process Improvement","author":"Hamza Muhammad","year":"2023","unstructured":"Muhammad Hamza, Muhammad\u00a0Azeem Akbar, and Kari Smolander. 2023. The Journey to Serverless Migration: An Empirical Analysis of Intentions, Strategies, and Challenges. In International Conference on Product-Focused Software Process Improvement. Springer, 100\u2013115."},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"publisher","unstructured":"Muhammad Hamza Muhammad\u00a0Azeem Akbar and Kari Smolander. 2025. Navigating Decision-Making in Serverless Migration: A Socio-Technical Grounded Theory Approach. SSRN Preprint. 10.2139\/ssrn.5161731","DOI":"10.2139\/ssrn.5161731"},{"key":"e_1_3_3_1_14_2","doi-asserted-by":"publisher","unstructured":"Muhammad Hamza Siamak Farshidi Muhammad\u00a0Azeem Akbar Rafael Capilla et\u00a0al. 2024. A Decision Model for Selecting Serverless Platforms. Preprint. 10.21203\/rs.3.rs-5795769\/v1","DOI":"10.21203\/rs.3.rs-5795769\/v1"},{"key":"e_1_3_3_1_15_2","unstructured":"Eric Jonas Johann Schleier-Smith Vikram Sreekanti Chia-Che Tsai Anurag Khandelwal Qifan Pu Vaishaal Shankar Joao Carreira Karl Krauth and Neeraja Yadwadkar. 2019. Cloud programming simplified: A berkeley view on serverless computing. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1902.03383 (2019)."},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"crossref","unstructured":"Philipp Leitner Erik Wittern Josef Spillner and Waldemar Hummer. 2019. A mixed-method empirical study of Function-as-a-Service software development in industrial practice. Journal of Systems and Software 149 (2019) 340\u2013359.","DOI":"10.1016\/j.jss.2018.12.013"},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"crossref","unstructured":"Xing Li Xue Leng and Yan Chen. 2022. Securing serverless computing: Challenges solutions and opportunities. IEEE Network 37 2 (2022) 166\u2013173.","DOI":"10.1109\/MNET.005.2100335"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"crossref","unstructured":"Eduard Marin Diego Perino and Roberto Di\u00a0Pietro. 2022. Serverless computing: a security perspective. Journal of Cloud Computing 11 1 (2022) 69.","DOI":"10.1186\/s13677-022-00347-w"},{"key":"e_1_3_3_1_19_2","unstructured":"Subrota\u00a0Kumar Mondal Rui Pan HM\u00a0Dipu Kabir Tan Tian and Hong-Ning Dai. 2022. Kubernetes in IT administration and serverless computing: An empirical study and research challenges. The Journal of Supercomputing (2022) 1\u201351."},{"key":"e_1_3_3_1_20_2","doi-asserted-by":"publisher","unstructured":"H. Muhammad. 2025. Security Perspective of Open-Source Serverless Platforms: An Empirical Investigation. 10.5281\/zenodo.15011010[Data set].","DOI":"10.5281\/zenodo.15011010"},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"crossref","unstructured":"Kan Ni Subrota\u00a0Kumar Mondal HM\u00a0Dipu Kabir Tian Tan and Hong-Ning Dai. 2024. Toward security quantification of serverless computing. Journal of Cloud Computing 13 1 (2024) 140.","DOI":"10.1186\/s13677-024-00703-y"},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSC49989.2020.9180214"},{"key":"e_1_3_3_1_23_2","unstructured":"OpenFaaS. [n. d.]. OpenFaaS Documentation. https:\/\/www.openfaas.com\/. Accessed: 2024-10-04."},{"key":"e_1_3_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01701-9_25"},{"key":"e_1_3_3_1_25_2","unstructured":"Shreyansh Surana Smit Detroja and Saurabh Tiwari. 2020. A tool to extract structured data from github. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2012.03453 (2020)."},{"key":"e_1_3_3_1_26_2","unstructured":"The Kubernetes Authors. 2021. Kubernetes Documentation. https:\/\/kubernetes.io\/docs\/."},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468558"},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC.2016.031"}],"event":{"name":"EASE Companion '25: Evaluation and Assessment in Software Engineering","acronym":"EASE Companion '25","location":"Istanbul Turkiye"},"container-title":["Proceedings of the 2025 29th International Conference on Evaluation and Assessment in Software Engineering Companion"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3727967.3756839","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T12:07:15Z","timestamp":1766491635000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3727967.3756839"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,17]]},"references-count":27,"alternative-id":["10.1145\/3727967.3756839","10.1145\/3727967"],"URL":"https:\/\/doi.org\/10.1145\/3727967.3756839","relation":{},"subject":[],"published":{"date-parts":[[2025,6,17]]},"assertion":[{"value":"2025-12-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}