Gringotts: Fast and Accurate Internal Denial-of-Wallet Detection for Serverless Computing
Junxian Shen, Han Zhang, Yantao Geng, Jiawei Li, Jilong Wang, Mingwei Xu
Abstract
Serverless computing, or Function-as-a-Service, is gaining continuous popularity due to its pay-as-you-go billing model, flexibility, and low costs. These characteristics, however, bring additional security risks, such as the Denial-of-Wallet (DoW) attack, to serverless tenants. In this paper, we perform a real-world DoW attack on commodity serverless platforms to evaluate its severity. To identify such attacks, we design, implement, and evaluate Gringotts, an accurate, easy-to-use DoW detection system with a negligible performance overhead. Gringotts addresses the information ambiguity inherent in serverless functions by introducing a well-designed performance metrics collection agent. Then, Gringotts uses the Mahalanobis distance to discover anomalies in the distribution of the metrics. We implement Gringotts as a real system and conduct extensive experiments using a testbed to evaluate the performance of Gringotts. Our results indicate that Gringotts has a performance overhead of less than 1.1%, with an average detection delay of 1.86 seconds and an average accuracy of over 95.75%.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f4bb5591-d4c2-493f-b414-2535e99070a6Cited by top-tier papers3
- The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless ApplicationsXunqi Liu, Nanzi Yang, Chang Li, Jinku Li et al.NDSS 2026 · 1 citation
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless FunctionsChanghee Shin, Bom Kim, Seungsoo LeeINFOCOM 2026 · 1 citation
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che et al.USENIX Security 2023
Related papers
- Warmonger: Inflicting Denial-of-Service via Serverless Functions in the CloudJunjie Xiong, Mingkui Wei, Zhuo Lu, Yao LiuCCS 2021 · 21 citations
- ALASTOR: Reconstructing the Provenance of Serverless IntrusionsPubali Datta, Isaac Polinsky, Muhammad Adil Inam, Adam Bates et al.USENIX Security 2022
- Hierarchical Integration of WebAssembly in Serverless for Efficiency and InteroperabilityMohammadamin Baqershahi, Changyuan Lin, Visal Saosuo, Paul Chen et al.NSDI 2026 · 2 citations
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro et al.NDSS 2026 · 2 citations
- Rampart: Protecting Web Applications from CPU-Exhaustion Denial-of-Service AttacksWei Meng, Chenxiong Qian, Shuang Hao, Kevin Borgolte et al.USENIX Security 2018 · 32 citations
