ALPS: Automated Least-Privilege Enforcement for Securing Serverless Functions
Changhee Shin, Bom Kim, Seungsoo Lee
Abstract
Serverless computing is increasingly adopted for AI-driven workloads due to its automatic scaling and pay-as-you-go model. However, its function-based architecture creates significant security risks, including excessive privilege allocation and poor permission management. In this paper, we present ALPS, an automated framework for enforcing least privilege in serverless environments. Our system employs serverless-tailored static analysis to extract precise permission requirements from function code and a fine-tuned Large Language Model (LLM) to generate language- and vendor-specific security policies. It also performs real-time monitoring to block unauthorized access and adapt to policy or code changes, supporting heterogeneous cloud providers and programming languages. In an evaluation of 8,322 real-world functions across AWS, Google Cloud, and Azure, ALPS achieved 94.8% coverage for least-privilege extraction, improved security logic generation quality by 220% (BLEU), 124% (ChrF++) and 100% (ROUGE-2), and added minimum performance overhead. These results demonstrate that ALPS provides an effective, practical, and vendor-agnostic solution for securing serverless workloads.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7dc74d0d-3ad9-43fa-9db6-c2f8074aa0d5Builds on9
- Valve: Securing Function Workflows on Serverless Computing PlatformsPubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace et al.WWW 2020 · 79 citations
- Gringotts: Fast and Accurate Internal Denial-of-Wallet Detection for Serverless ComputingJunxian Shen, Han Zhang, Yantao Geng, Jiawei Li et al.CCS 2022 · 19 citations
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 15 citations
- DisProTrack: Distributed Provenance Tracking over Serverless ApplicationsUtkalika Satapathy, Rishabh Thakur, Subhrendu Chattopadhyay, Sandip ChakrabortyINFOCOM 2023 · 15 citations
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh et al.OOPSLA 2024 · 11 citations
Related papers
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad et al.S&P 2025
- CloudFlow: Identifying Security-sensitive Data Flows in Serverless ApplicationsGiuseppe Raffa, Jorge Blasco, Daniel O'Keeffe, Santanu Kumar DashUSENIX Security 2025
- ALASTOR: Reconstructing the Provenance of Serverless IntrusionsPubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates et al.USENIX Security 2022
- ALPS: An Adaptive Learning, Priority OS Scheduler for Serverless FunctionsYuqi Fu, Ruizhe Shi, Haoliang Wang, Songqing Chen et al.USENIX ATC 2024 · 12 citations
- Guarding Serverless Applications with KaliumDeepak Sirone Jegan, Liang Wang, Siddhant Bhagat, Michael M. SwiftUSENIX Security 2023
