GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security Policies
Isaac Polinsky, Pubali Datta, Adam Bates, William Enck
Abstract
Serverless computing is supplanting past versions of cloud computing as the easiest way to rapidly prototype and deploy applications. However, the reentrant and ephemeral nature of serverless functions only exacerbates the challenge of correctly specifying security policies. Unfortunately, with role-based access control solutions like Amazon Identity and Access Management (IAM) already suffering from pervasive misconfiguration problems, the likelihood of policy failures in serverless applications is high. In this work, we introduce GRASP, a graph-based analysis framework for modeling serverless access control policies as queryable reachability graphs. GRASP generates reusable models that represent the principals of a serverless application and the interactions between those principals. We implement GRASP for Amazon IAM in Prolog, then deploy it on a corpus of 731 open source Amazon Lambda applications. We find that serverless policies tend to be short and highly permissive, e.g., 92% of surveyed policies are comprised of just 10 statements and 30% exhibit full reachability between all application functions and resources. We then use GRASP to identify potential attack vectors permitted by these policies, including hundreds of sensitive access channels, a dozen publicly-exposed resources, and four channels that may permit an attacker to exfiltrate an application's private resources through one of its public resources. These findings demonstrate GRASP's utility as a means of identifying opportunities for hardening application policies and highlighting potential exfiltration channels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2132e051-ff4b-4adc-959b-71c9c5daa336Cited by top-tier papers5
- The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless ApplicationsXunqi Liu, Nanzi Yang, Chang Li, Jinku Li et al.NDSS 2026 · 1 citation
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless FunctionsChanghee Shin, Bom Kim, Seungsoo LeeINFOCOM 2026 · 1 citation
- Skyler: Static Analysis for Predicting API-Driven Costs in Serverless ApplicationsBernardo Ribeiro, Mafalda Ferreira, José Fragoso Santos, Rodrigo Bruno et al.ASPLOS 2026
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad et al.S&P 2025
- PyXray: Practical Cross-Language Call Graph Construction through Object Layout AnalysisGeorgios Alexopoulos, Thodoris Sotiropoulos, Georgios Gousios, Zhendong Su et al.ICSE 2026
Builds on4
- Valve: Securing Function Workflows on Serverless Computing PlatformsPubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace et al.WWW 2020 · 79 citations
- Thoth: Comprehensive Policy Compliance in Data Retrieval SystemsEslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg et al.USENIX Security 2016 · 30 citations
- Block public access: trust safety verification of access control policiesMalik Bouchet, Byron Cook, Bryant Cutler, Anna Druzkina et al.FSE 2020 · 25 citations
- IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social NetworksPaul Marinescu, Chad Parry, Marjori Pomarole, Yuan Tian et al.S&P 2017 · 14 citations
Related papers
- Detecting Multi-Step IAM Attacks in AWS Environments via Model CheckingIlia Shevrin, Oded MargalitUSENIX Security 2023
- ALASTOR: Reconstructing the Provenance of Serverless IntrusionsPubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates et al.USENIX Security 2022
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh et al.OOPSLA 2024 · 11 citations
- CloudFlow: Identifying Security-sensitive Data Flows in Serverless ApplicationsGiuseppe Raffa, Jorge Blasco, Daniel O'Keeffe, Santanu Kumar DashUSENIX Security 2025
- Quantifying Permissiveness of Access Control PoliciesWilliam Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony et al.ICSE 2022 · 15 citations
