Least-Privilege Calls to Amazon Web Services

被引:1
|
作者
Gill, Puneet [1 ]
Dietl, Werner [1 ]
Tripunitara, Mahesh [1 ]
机构
[1] Univ Waterloo, Dept Elect & Comp Engn, Waterloo, ON N2L 3G1, Canada
关键词
Cloud computing; Security; Web services; Databases; Documentation; Context; Syntactics; Computer security; amazon web services; least-privilege;
D O I
10.1109/TDSC.2022.3171740
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We address least-privilege in a particular context of public cloud computing: calls to Amazon Web Services (AWS) Application Programming Interfaces (APIs). AWS is, by far, the largest cloud provider, and therefore an important context in which to consider the fundamental security design principle of least-privilege, which states that a thread of execution should possess only those privileges it needs. There have been reports of over-privilege being a root cause of attacks against AWS cloud applications, and a least-privilege set for an API call is a necessary building-block in devising a least-privilege policy for a cloud application. We observe that accurate information on a least-privilege set for an invoker of a method to possess is simply not available for most such methods in AWS. We provide a meaningful characterization of least-privilege in this context. We then propose techniques to determine such sets, and discuss a black-box process we have devised and carried out to identify such sets for all 707 API methods we are able to invoke across five AWS services. We discuss a number of interesting discoveries we have made, some of which are surprising and some alarming, that we have reported to AWS. Our work has resulted in a database of least-privilege sets for API calls to AWS, which we make available publicly. Developers can consult our database when configuring security policies for their cloud applications, and we welcome contributors that augment our database. Also, we discuss example uses of our database via an assessment of two repositories and two full-fledged serverless applications that are available publicly and have policies published alongside. We observe that the vast majority of policies are over-privileged. Our work contributes constructively to securing cloud applications in the largest cloud provider.
引用
收藏
页码:2085 / 2096
页数:12
相关论文
共 50 条
  • [21] Least privilege and more
    Schneider, FB
    COMPUTER SYSTEMS: THEORY, TECHNOLOGY AND APPLICATIONS: A TRIBUTE TO ROGER NEEDHAM, 2004, : 253 - 258
  • [22] Least privilege and more
    Cornell University
    不详
    不详
    IEEE Security and Privacy, 2003, 1 (05): : 55 - 59
  • [23] Application of Cloud Computing in Astrophysics - The case of Amazon Web Services
    Landoni, M.
    Genoni, M.
    Riva, M.
    Bianco, A.
    Corina, A.
    SOFTWARE AND CYBERINFRASTRUCTURE FOR ASTRONOMY V, 2018, 10707
  • [24] The Quality Attibutes and Architectural Tactics of Amazon Web Services (AWS)
    Milhem, Hind
    Harrison, Neil B.
    2022 INTERMOUNTAIN ENGINEERING, TECHNOLOGY AND COMPUTING (IETC), 2022,
  • [25] D-MASON on the Cloud: An Experience with Amazon Web Services
    Carillo, Michele
    Cordasco, Gennaro
    Serrapica, Flavio
    Spagnuolo, Carmine
    Szufel, Przemysaw
    Vicidomini, Luca
    EURO-PAR 2016: PARALLEL PROCESSING WORKSHOPS, 2017, 10104 : 322 - 333
  • [26] Bidding Application in Amazon Web Services for the Sales of Agricultural Products
    Madhumathi, R.
    RadhaKrishnan, R.
    Kumar, Suresh S.
    Abineshkumar, K.
    Karthi, M.
    ManojKrishna, M.
    2016 5TH INTERNATIONAL CONFERENCE ON RECENT TRENDS IN INFORMATION TECHNOLOGY (ICRTIT), 2016,
  • [27] Cloud Enabled Media Streaming using Amazon Web Services
    Kumar, V. D. Ambeth
    Kumar, V. D. Ashok
    Divakar, H.
    Gokul, R.
    2017 IEEE INTERNATIONAL CONFERENCE ON SMART TECHNOLOGIES AND MANAGEMENT FOR COMPUTING, COMMUNICATION, CONTROLS, ENERGY AND MATERIALS (ICSTM), 2017, : 195 - 198
  • [28] Student Research Abstract: Least Privilege Persistent-Storage Access in Web Browsers
    Kancherla, Gayatri Priyadarsini
    39TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2024, 2024, : 1797 - 1799
  • [29] Pregnancy Companion Chatbot Using Alexa and Amazon Web Services
    Sadavarte, Sanket Sanjay
    Bodanese, Eliane
    2019 IEEE PUNE SECTION INTERNATIONAL CONFERENCE (PUNECON), 2019,
  • [30] Digital Media Distribution Platform Using Amazon Web Services
    Dinca, Marius Alexandru
    Angelescu, Nicoleta
    Dragomir, Radu
    Puchianu, Dan Constantin
    Caciula, Ion
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTERS AND ARTIFICIAL INTELLIGENCE (ECAI-2019), 2019,