USENIX Security2023Top-tier venue
Detecting Multi-Step IAM Attacks in AWS Environments via Model Checking
Ilia Shevrin, Oded Margalit
Abstract
Cloud services enjoy a surging popularity among IT professionals, owing to their rapid provision of virtual infrastructure on demand. Hand-in-hand with the growing usage, there is also a growing concern about potential security vulnerabilities arising from misconfigurations, exposing resources or allowing malicious actors to escalate privileges. Model checking is a known method for verifying that a finite-state Boolean model of a system satisfies certain properties, where the model and the properties are described in formal logic. In case it doesn't, a finite trace leading to a violating state can be generated. In this paper, we present an approach to construct a finitestate Boolean model from the Identity and Access Management (IAM) component of Amazon Web Services (AWS), and a property from an attack target, e.g., read a classified S3 bucket object. We run a model checker that detects whether some initial setup allows an attacker to escalate privileges and reach the target in one or more steps by applying IAM manipulating actions. We show that our approach can discover existing misconfigurations in real AWS environments, and that it can detect multi-step attacks in setups containing tens of AWS accounts with hundreds of resources in under a minute.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- Fixing Privilege Escalations in Cloud Access Control with MaxSAT and Graph Neural NetworksYang Hu, Wenxi Wang, Sarfraz Khurshid, Kenneth L. McMillan et al.ASE 2023 · 4 citations
- An Empirical Study of Observability Limits in Advanced Software Supply Chain AttacksZhuoran Tan, Wenbo Guo, Jiewen Luo, Taylor Brierley et al.CCS 2026 · 3 citations
- The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless ApplicationsXunqi Liu, Nanzi Yang, Chang Li, Jinku Li et al.NDSS 2026 · 1 citation
- Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud ServicesYizhe Shi, Zhemin Yang, Dingyi Liu, Kangwei Zhong et al.NDSS 2026
- CloudFlow: Identifying Security-sensitive Data Flows in Serverless ApplicationsGiuseppe Raffa, Jorge Blasco, Daniel O'Keeffe, Santanu Kumar DashUSENIX Security 2025
Related papers
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 15 citations
- C-Verifier: Understanding and Formally Verifying Cross-Service Flaws in AWS CognitoZhen Chen, Ze Jin, Le Gong, Kexin Chen et al.S&P 2026
- Quantifying Permissiveness of Access Control PoliciesWilliam Eiers, Ganesh Sankaran, Albert Li, Emily O'Mahony et al.ICSE 2022 · 15 citations
- Quantitative Policy Repair for Access Control on the CloudWilliam Eiers, Ganesh Sankaran, Tevfik BultanISSTA 2023 · 7 citations
- Automatically Reducing Privilege for Access Control PoliciesLoris D'Antoni, Shuo Ding, Amit Goel, Mathangi Ramesh et al.OOPSLA 2024 · 11 citations
