Test-suite-guided discovery of least privilege for cloud infrastructure as code
Infrastructure as code (IaC) for the cloud, which automatically configures a system’s cloud environment from source code, is an important practice thanks to its efficient, reproducible provisioning. On a cloud IaC definition (template), developers must carefully manage permission settings to minimize the risk of cyber-attacks. To this end, least privilege on IaC templates, i.e., the assignment of a necessary and sufficient set of permissions, is widely regarded as a best practice. However, the discovery of least privilege can be an error-prone, burdensome task for developers. This is partially because the execution of an action on the cloud sometimes implicitly requires permissions of other services, and since these are difficult to recognize without actual execution, developers are forced to manually iterate the execution of an action and the modification of permissions. In this work, we present an approach to automatically discover least privilege. Our approach utilizes a test suite, which represents what a system should achieve on the cloud, as an indicator of least privilege, and it iterates testing on the cloud and (re)configuration of permissions on the basis of the test results. We also propose a stepwise filtering technique that utilizes the co-occurrences of cloud services/actions and clustering-based pruning to efficiently rule out unnecessary permissions. Our experiments demonstrate that this filtering reduces the number of iterations compared to naive approaches, which directly affects the time and cost to discover least privilege. Moreover, three case studies show that our approach can identify least privilege on Amazon Web Services within a practical time.
Thu 31 OctDisplayed time zone: Pacific Time (US & Canada) change
10:30 - 12:00 | Cloud and Systems Research Papers / Journal-first Papers / Industry Showcase at Carr Chair(s): Amel Bennaceur The Open University, UK | ||
10:30 15mTalk | FaaSConf: QoS-aware Hybrid Resources Configuration for Serverless Workflows Research Papers Yilun Wang Anhui University, Pengfei Chen Sun Yat-sen University, Hui Dou Anhui University, Yiwen Zhang Anhui University, Guangba Yu Sun Yat-sen University, Zilong He Sun Yat-sen University, Haiyu Huang Sun Yat-sen University Pre-print | ||
10:45 15mTalk | Challenges & Opportunities in Automating DBMS: A Qualitative Study Industry Showcase Yifan WANG Orange/ INRIA, Pierre Bourhis University of Lille, Inria, CRIStAL UMR CNRS 9189, Romain Rouvoy University Lille 1 and INRIA, Patrick Royer Orange | ||
11:00 15mTalk | Test-suite-guided discovery of least privilege for cloud infrastructure as code Journal-first Papers DOI | ||
11:15 15mTalk | Microservice Decomposition Techniques: An Independent Tool Comparison Research Papers Yingying Wang University of British Columbia, Sarah Bornais The University of British Columbia, Julia Rubin The University of British Columbia Pre-print | ||
11:30 10mTalk | Towards Long-Term Scientific Model Sustainment at Sandia National Laboratories Industry Showcase Christian Gilbertson Sandia National Labs, Reed Milewicz Sandia National Laboratories, Eric Berquist Sandia National Labs, Aaron Brundage Sandia National Labs, John Engelmann Sandia National Labs, Brian Evans Sandia National Labs, Nicholas Francis Sandia National Labs, Ernest Friedman-Hill Sandia National Labs, Samuel Grayson Sandia National Labs, Evan Harvey Sandia National Labs, Eric Ho Sandia National Labs, Edward Hoffman Sandia National Labs, Kevin Irick Sandia National Labs, Anagha Krishna Sandia National Labs, Aaron Moreno Sandia National Labs, Joshua Teves Sandia National Labs | ||
11:40 10mTalk | Cloud Resource Protection via Automated Security Property Reasoning Industry Showcase Zhixing Xu Amazon Web Services, Shengjian Guo Amazon Web Services, Oksana Tkachuk Amazon Web Services, Saeed Nejati Amazon Web Services, Niloofar Razavi Amazon Web Services, George Argyros Amazon Web Services |