Моніторинг вразливостей безсерверних функцій із використанням адаптивного сигнатурного аналізу та стандартів OWASP
Анотації
У роботі розглянуто проблему забезпечення кібербезпеки безсерверних функцій у хмарних середовищах. The paper considers the problem of ensuring cybersecurity of serverless functions in cloud environments. It is established that traditional vulnerability detection methods, including SAST, DAST, IAST, SCA, and CSPM, have significant limitations in Function as a Service environments due to the ephemeral nature of execution environments, event-driven architecture, and lack of access to the operating system. An approach to the development of an automated vulnerability monitoring system is proposed, combining lightweight middleware, an event collection module, an analytical core, and an adaptive signature database. The system is focused on detecting attacks according to relevant OWASP categories, including broken access control, event injection, security misconfiguration, and Denial of Wallet attacks.
URI:
https://ir.lib.vntu.edu.ua/handle/123456789/53124

