Valve: Securing Function Workflows on Serverless Computing Platforms
Pubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace, Amir Rahmati, Adam Bates
Abstract
Serverless Computing has quickly emerged as a dominant cloud computing paradigm, allowing developers to rapidly prototype eventdriven applications using a composition of small functions that each perform a single logical task. However, many such application workflows are based in part on publicly-available functions developed by third-parties, creating the potential for functions to behave in unexpected, or even malicious, ways. At present, developers are not in total control of where and how their data is flowing, creating significant security and privacy risks in growth markets that have embraced serverless (e.g., IoT). As a practical means of addressing this problem, we present Valve, a serverless platform that enables developers to exert complete finegrained control of information flows in their applications. Valve enables workflow developers to reason about function behaviors, and specify restrictions, through auditing of network-layer information flows. By proxying network requests and propagating taint labels across network flows, Valve is able to restrict function behavior without code modification. We demonstrate that Valve is able defend against known serverless attack behaviors including container reuse-based persistence and data exfiltration over cloud platform APIs with less than 2.8% runtime overhead, 6.25% deployment overhead and 2.35% teardown overhead. CCS CONCEPTS • Security and privacy → Access control; Distributed systems security; Information flow control.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 703fb5fe-8be9-423f-b7b6-e464ffe97a7cCited by top-tier papers16
- SandTrap: Securing JavaScript-driven Trigger-Action PlatformsMohammad M. Ahmadpanah, Daniel Hedin, Musard Balliu, Lars Eric Olsson et al.USENIX Security 2021 · 31 citations
- Warmonger: Inflicting Denial-of-Service via Serverless Functions in the CloudJunjie Xiong, Mingkui Wei, Zhuo Lu, Yao LiuCCS 2021 · 21 citations
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 15 citations
- SPES: Towards Optimizing Performance-Resource Trade-Off for Serverless FunctionsCheryl Lee, Zhouruixin Zhu, Tianyi Yang, Yintong Huo et al.ICDE 2024 · 13 citations
- LinkLab 2.0: A Multi-tenant Programmable IoT Testbed for Experimentation with Edge-Cloud IntegrationWei Dong, Borui Li, Haoyu Li, Hao Wu et al.NSDI 2023 · 9 citations
Builds on2
Related papers
- CloudFlow: Identifying Security-sensitive Data Flows in Serverless ApplicationsGiuseppe Raffa, Jorge Blasco, Daniel O'Keeffe, Santanu Kumar DashUSENIX Security 2025
- Guarding Serverless Applications with KaliumDeepak Sirone Jegan, Liang Wang, Siddhant Bhagat, Michael M. SwiftUSENIX Security 2023
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad et al.S&P 2025
- LeakLess: Selective Data Protection against Memory Leakage Attacks for Serverless PlatformsMaryam Rostamipoor, Seyedhamed Ghavamnia, Michalis PolychronakisNDSS 2025
- DataFlower: Exploiting the Data-flow Paradigm for Serverless Workflow OrchestrationZijun Li, Chuhao Xu, Quan Chen, Jieru Zhao et al.ASPLOS 2023 · 28 citations
