ASE 2024
Sun 27 October - Fri 1 November 2024 Sacramento, California, United States
Thu 31 Oct 2024 11:00 - 11:15 at Carr - Cloud and Systems Chair(s): Amel Bennaceur

Infrastructure as code (IaC) for the cloud, which automatically configures a system’s cloud environment from source code, is an important practice thanks to its efficient, reproducible provisioning. On a cloud IaC definition (template), developers must carefully manage permission settings to minimize the risk of cyber-attacks. To this end, least privilege on IaC templates, i.e., the assignment of a necessary and sufficient set of permissions, is widely regarded as a best practice. However, the discovery of least privilege can be an error-prone, burdensome task for developers. This is partially because the execution of an action on the cloud sometimes implicitly requires permissions of other services, and since these are difficult to recognize without actual execution, developers are forced to manually iterate the execution of an action and the modification of permissions. In this work, we present an approach to automatically discover least privilege. Our approach utilizes a test suite, which represents what a system should achieve on the cloud, as an indicator of least privilege, and it iterates testing on the cloud and (re)configuration of permissions on the basis of the test results. We also propose a stepwise filtering technique that utilizes the co-occurrences of cloud services/actions and clustering-based pruning to efficiently rule out unnecessary permissions. Our experiments demonstrate that this filtering reduces the number of iterations compared to naive approaches, which directly affects the time and cost to discover least privilege. Moreover, three case studies show that our approach can identify least privilege on Amazon Web Services within a practical time.

Thu 31 Oct

Displayed time zone: Pacific Time (US & Canada) change

10:30 - 12:00
Cloud and Systems Research Papers / Journal-first Papers / Industry Showcase at Carr
Chair(s): Amel Bennaceur The Open University, UK
10:30
15m
Talk
FaaSConf: QoS-aware Hybrid Resources Configuration for Serverless Workflows
Research Papers
Yilun Wang Anhui University, Pengfei Chen Sun Yat-sen University, Hui Dou Anhui University, Yiwen Zhang Anhui University, Guangba  Yu Sun Yat-sen University, Zilong He Sun Yat-sen University, Haiyu Huang Sun Yat-sen University
Pre-print
10:45
15m
Talk
Challenges & Opportunities in Automating DBMS: A Qualitative Study
Industry Showcase
Yifan WANG Orange/ INRIA, Pierre Bourhis University of Lille, Inria, CRIStAL UMR CNRS 9189, Romain Rouvoy University Lille 1 and INRIA, Patrick Royer Orange
11:00
15m
Talk
Test-suite-guided discovery of least privilege for cloud infrastructure as code
Journal-first Papers
Ryo Shimizu Hitachi Ltd., Yuna Nunomura Hitachi, Ltd., Hideyuki Kanuka Hitachi, Ltd.
DOI
11:15
15m
Talk
Microservice Decomposition Techniques: An Independent Tool Comparison
Research Papers
Yingying Wang University of British Columbia, Sarah Bornais The University of British Columbia, Julia Rubin The University of British Columbia
Pre-print
11:30
10m
Talk
Towards Long-Term Scientific Model Sustainment at Sandia National Laboratories
Industry Showcase
Christian Gilbertson Sandia National Labs, Reed Milewicz Sandia National Laboratories, Eric Berquist Sandia National Labs, Aaron Brundage Sandia National Labs, John Engelmann Sandia National Labs, Brian Evans Sandia National Labs, Nicholas Francis Sandia National Labs, Ernest Friedman-Hill Sandia National Labs, Samuel Grayson Sandia National Labs, Evan Harvey Sandia National Labs, Eric Ho Sandia National Labs, Edward Hoffman Sandia National Labs, Kevin Irick Sandia National Labs, Anagha Krishna Sandia National Labs, Aaron Moreno Sandia National Labs, Joshua Teves Sandia National Labs
11:40
10m
Talk
Cloud Resource Protection via Automated Security Property Reasoning
Industry Showcase
Zhixing Xu Amazon Web Services, Shengjian Guo Amazon Web Services, Oksana Tkachuk Amazon Web Services, Saeed Nejati Amazon Web Services, Niloofar Razavi Amazon Web Services, George Argyros Amazon Web Services