No Server, No Cry: the Ups and Downs of Building a Scalable Security Serverless Platform

Aviram (Co-founder and Chief Research and Innovation Officer · JIT)

Cloud Village @ DEF CON 33 · Day 1 · Cloud Village

Overview

In this insightful talk from Cloud Village, Aviram, Co-founder and Chief Research and Innovation Officer at JIT, delves into the complexities and crucial considerations of securing a complete serverless platform. While serverless architectures promise unparalleled scale and simplicity, Aviram emphasizes that security is not an inherent, out-of-the-box feature. Building a robust serverless application requires deliberate and significant investment in security measures, a lesson learned firsthand during the development of JIT's own agentic application security platform.

Watch on YouTube

Visual summary for No Server, No Cry: the Ups and Downs of Building a Scalable Security Serverless Platform by Aviram
Visual summary for No Server, No Cry: the Ups and Downs of Building a Scalable Security Serverless Platform by Aviram

Key moments

  1. 0:00 Introduction: Serverless promises, but security investment is critical
  2. 2:00 Understanding user security responsibilities in serverless architectures
  3. 2:50 Tailoring OWASP Top 10 risks for serverless applications
  4. 6:15 Recommended tools for mitigating broken access control vulnerabilities
  5. 8:00 Best practices to prevent serverless event injection attacks

No Server, No Cry: the Ups and Downs of Building a Scalable Security Serverless Platform

Speakers: Aviram, Co-founder and Chief Research and Innovation Officer, JIT

Conference: Cloud Village

YouTube: https://www.youtube.com/watch?v=mBBnhFo6l1U

Overview

In this insightful talk from Cloud Village, Aviram, Co-founder and Chief Research and Innovation Officer at JIT, delves into the complexities and crucial considerations of securing a complete serverless platform. While serverless architectures promise unparalleled scale and simplicity, Aviram emphasizes that security is not an inherent, out-of-the-box feature. Building a robust serverless application requires deliberate and significant investment in security measures, a lesson learned firsthand during the development of JIT's own agentic application security platform.

The presentation provides a comprehensive exploration of the unique security challenges encountered in a serverless environment and outlines the practical strategies and tools JIT employed to address them. Aviram shares invaluable best practices and recommends specific open-source and AWS-native tools that are essential for any organization venturing into serverless development. The core message is clear: while cloud providers manage much of the underlying infrastructure, the user's responsibility for securing their code, data, and configurations remains paramount, making a proactive and informed security posture indispensable.

Background

▶ Watch: Introduction: Serverless promises, but security investment is critical (0:00)

The shift from traditional cloud models to serverless computing fundamentally alters the shared responsibility model for security. In the classic cloud paradigm, while the cloud provider handles hardware, virtualization, compute, and storage, users are still responsible for the operating system, runtime, network configuration, and application layers. Serverless, however, abstract away even more infrastructure. Cloud providers take charge of the operating system, runtime environment, and network configuration. This increased abstraction can sometimes lead to a false sense of security, where users might assume that most security concerns are offloaded to the provider.

Aviram clarifies that this is a dangerous misconception. Despite the reduced operational overhead, users retain critical security responsibilities. These include securing their own code, protecting customer data, defining robust IAM policies and access configurations, implementing comprehensive logging and monitoring, and managing secrets effectively. Neglecting these areas can expose serverless applications to significant risks.

To systematically approach serverless security, JIT tailored the widely recognized OWASP Top 10 for web application security to fit the serverless context. This adaptation highlights common vulnerabilities that manifest uniquely in event-driven, function-based architectures. Key risks identified include broken access control (e.g., overly permissive IAM roles for Lambda functions), cryptographic failures, injection vulnerabilities (critical given the event-driven nature of serverless), insecure design due to lack of threat modeling, security misconfigurations, reliance on vulnerable and outdated components, and inadequate logging and monitoring. Understanding these specific threat vectors is the first step toward building a truly secure serverless platform.

Key Findings

▶ Watch: Understanding user security responsibilities in serverless architectures (2:00)

The talk's central findings revolve around the critical need for a proactive and tailored security strategy when developing serverless applications, challenging the notion that serverless inherently provides security "out of the box." Aviram underscores that the fundamental shift in responsibility requires developers and security teams to adopt a new mindset, focusing on areas where user control remains significant.

The primary contributions and discoveries presented by Aviram include:

  1. Shared Responsibility is Not Diminished, But Shifted: While cloud providers handle infrastructure, the user's burden for securing application code, data, IAM, and configurations is substantial. This requires a deep understanding of the attack surface unique to serverless.
  2. OWASP Top 10 Adaptability: The core principles of the OWASP Top 10 remain highly relevant for serverless, but their manifestations and mitigation strategies differ. The talk specifically highlights and deep dives into Broken Access Control, Event Injection, Security Misconfiguration, Vulnerable and Outdated Components, and Security Logging and Monitoring Failures as critical serverless risks.
  3. The "Golden Rules" for Serverless Security: Aviram synthesizes the best practices into a set of actionable "golden rules":
  • Sanitizing Events: All incoming event data must be meticulously validated and sanitized.
  • Least Privilege: Implementing the principle of least privilege for every Lambda function and service is paramount.
  • Dependency Scanning: Continuous scanning for vulnerable third-party components is non-negotiable.
  • Comprehensive Logging and Monitoring: Robust logging of all critical events and proactive monitoring are essential for detection and response.
  • Setting Limits: Defining explicit limits on concurrency and execution timeouts for functions to prevent abuse and control costs.
  • Budget Alerts: Implementing alerts to prevent "denial of wallet" scenarios where malicious activity drives up cloud costs.
  1. Leveraging a Hybrid Tooling Approach: Effective serverless security relies on a combination of AWS-native tools (e.g., IAM Access Analyzer, CloudWatch, CloudTrail, Amazon Detective) and powerful open-source solutions (e.g., pmapper, repoid, Prowler, KICS, OSV-Scanner, npm audit).
  2. Importance of Established Frameworks: Developers don't need to "reinvent the wheel." Adopting existing security frameworks like the OWASP Serverless Top 10, AWS Startup Security Baseline (SSB), CIS Benchmark, and AWS Well-Architected Framework provides a structured approach to baking security into the platform from design to deployment.

These findings collectively emphasize that building a secure serverless platform is an ongoing, multi-faceted effort that demands meticulous attention to detail, continuous vigilance, and the adoption of industry best practices and specialized tooling.

Technical Deep Dive

▶ Watch: Tailoring OWASP Top 10 risks for serverless applications (2:50)

Aviram's talk provides a detailed technical exploration of five critical serverless security domains, outlining specific threats, best practices, and recommended tools.

Broken Access Control

Broken access control is a pervasive risk in serverless, often stemming from overly permissive IAM roles assigned to Lambda functions. If a function is granted more permissions than it strictly needs, an attacker compromising that function could escalate privileges, read, write, or delete sensitive information, or execute unauthorized actions. This risk is amplified if such a function is exposed via a public API.

To mitigate this, the core principle is least privilege. Functions should only have the exact permissions required for their operation. Strong authentication mechanisms and regular monitoring of access logs are also crucial. Aviram recommends several tools:

  • pmapper: An open-source tool specifically for AWS environments, pmapper models IAM roles and attempts to identify potential privilege escalation paths. It helps visualize how an attacker could chain permissions across different IAM entities to gain unauthorized access to resources.
  • repoid: A Netflix-supported open-source tool that analyzes actual service usage data. It helps generate more precise, least-privilege IAM policies by identifying which permissions are genuinely being utilized by a Lambda function and which are superfluous.
  • IAM Access Analyzer: An AWS-native tool that continuously monitors resource policies (including IAM roles) for external access. It helps understand which permissions are actually used by a role, enabling refinement. It also generates findings when it detects overly permissive configurations, such as a Lambda function having administrative-level access.

Event Injection

Serverless applications are inherently reactive and event-driven, relying on triggers from various sources like SNS, SQS, S3 buckets, and DynamoDB streams. This design pattern introduces a significant risk: event injection. If an attacker can craft a malicious event that is not properly validated and sanitized before being processed by a Lambda function, it can lead to severe consequences. These include resource exhaustion, privilege escalation, execution of unauthorized code, and data leakage.

Aviram illustrates this with a compelling example: an innocent Lambda function designed to scan a DynamoDB table based on firstName and lastName parameters. If an attacker provides wildcard characters for these inputs, the function might perform a full table scan. This not only leads to data leakage but also a denial of wallet (DoW) attack, as scanning an entire large table can incur significant costs if no concurrency limits or timeouts are in place.

Best practices for event injection include rigorous validation and sanitization of all data input for every Lambda function, maintaining least privilege, and monitoring functions in runtime. Beyond IAM Access Analyzer for permission analysis, AWS CloudWatch is vital. CloudWatch allows defining and monitoring custom metrics, such as spikes in DynamoDB table scans or unusually large response sizes from a Lambda function, which can indicate an injection attack or data exfiltration attempt.

Security Misconfiguration

Cloud environments, especially serverless ones, present a myriad of configuration options, making security misconfigurations a common vulnerability. Incorrectly configured IAM roles, as discussed, are one aspect, but misconfigurations can also include inadequate network settings, unencrypted storage, or improperly secured API endpoints. These can lead to unauthorized access, denial of service (DoS), denial of wallet (DoW), and even facilitate malware and ransomware attacks or data leakage.

Beyond IAM, Aviram stresses the importance of defining max concurrency limits and timeouts for Lambda functions. Max concurrency prevents an overload of the platform by limiting the number of simultaneous executions, while timeouts cap the execution duration, preventing functions from running indefinitely and incurring excessive costs. A practical example provided is a bot generating malicious requests, consuming all available Lambda function resources, leading to a DoS for legitimate users and a DoW due to the increased execution costs.

Two powerful tools for detecting misconfigurations are:

  • Prowler: An open-source tool that runs hundreds of security checks against AWS, GCP, and Azure environments in runtime. It flags misconfigurations across various services, such as publicly exposed S3 buckets or overly permissive security groups.
  • KICS (Keep Infrastructure as Code Secure): Developed by Checkmarx, KICS scans Infrastructure as Code (IaC) templates (e.g., Terraform, CloudFormation, Kubernetes manifests) before deployment. It identifies security vulnerabilities and misconfigurations in the code that defines the cloud infrastructure, such as Lambda functions associated with admin-level permissions or IAM roles defined with wildcards, which are often indicators of overly broad access.

Vulnerable and Outdated Components

Modern serverless applications heavily rely on third-party components and open-source libraries to accelerate development. While beneficial, this introduces the risk of vulnerable and outdated components. These dependencies can contain known security flaws, or worse, be maliciously crafted as part of a supply chain attack. Such vulnerabilities can lead to malware and ransomware attacks, data breaches, and denial of service attacks.

The primary defense is to use Software Composition Analysis (SCA) tools to scan all dependencies for known vulnerabilities by comparing them against public vulnerability databases. Furthermore, it's crucial to keep Lambda function runtimes updated. AWS deprecates older runtime images but does not automatically update functions; this is the user's responsibility.

Aviram recommends several open-source SCA tools:

  • OSV-Scanner: Supported by Google, this tool scans for vulnerabilities across all popular programming languages.
  • npm audit: Specifically for JavaScript projects, integrated with npm.
  • Dependency-Check: Primarily used for Java projects.
  • NC: A tool for Go language dependencies.

A notable example of a supply chain attack cited is the event-stream incident. A popular npm package with millions of weekly downloads was compromised when its maintainer transferred publishing rights to a malicious actor. This attacker introduced a new, unpopular dependency called flatmap-stream with an embedded vulnerability, which event-stream then started using in a minor version update, making it extremely difficult to detect. This led to millions of projects unknowingly installing the malicious code, potentially stealing cryptocurrency keys. An SCA tool would have flagged the flatmap-stream vulnerability upon detection, preventing widespread compromise.

Security Logging and Monitoring Failures

The absence of robust security logging and monitoring mechanisms is a foundational weakness that can render all other security efforts ineffective. Without proper logs, attacks can go undetected, leading to data loss or significantly delayed detection and response. It becomes impossible to understand what happened, how it happened, or how to remediate it.

Best practices include logging all admin events and other critical system events. For AWS, native services are indispensable:

  • Amazon CloudWatch: Collects and monitors logs and metrics from all AWS services, allowing for custom dashboards and alerts.
  • CloudTrail: Provides a record of actions taken by a user, role, or an AWS service in AWS. CloudTrail logs can be used to track API calls, identify unusual activity, and support forensic investigations.
  • Amazon Detective: Automatically collects log data from AWS resources and uses machine learning, statistical analysis, and graph theory to build a linked set of data that enables faster and easier security investigations.

These tools, when properly configured, provide the necessary visibility to detect, investigate, and respond to security incidents in a serverless environment.

Demo / Proof of Concept

▶ Watch: Recommended tools for mitigating broken access control vulnerabilities (6:15)

The talk by Aviram at Cloud Village primarily focused on sharing JIT's experiences, challenges, and best practices in building a secure serverless platform, rather than demonstrating a live technical proof of concept or a specific exploit. While specific tools and their functionalities were discussed in detail, no live demo of these tools in action or a step-by-step walkthrough of exploiting and defending a serverless vulnerability was performed during the presentation. The content served as a comprehensive guide derived from real-world application security development.

Defensive Implications

▶ Watch: Best practices to prevent serverless event injection attacks (8:00)

The insights shared by Aviram provide a clear roadmap for organizations aiming to build and maintain secure serverless applications. Defenders must recognize that the agility and scalability of serverless come with a shifted, not reduced, security responsibility.

  1. Embrace Security by Design: Integrate security considerations from the very initial design phases of serverless applications. This includes conducting thorough threat modeling to identify potential vulnerabilities unique to event-driven architectures and designing with least privilege in mind.
  2. Strict Least Privilege Implementation: This is non-negotiable. Every Lambda function, every IAM role, and every service interaction must adhere to the principle of least privilege. Utilize tools like pmapper and repoid during development and IAM Access Analyzer in production to continuously audit and refine permissions.
  3. Comprehensive Input Validation and Sanitization: Given the event-driven nature of serverless, every incoming event, regardless of its source (SNS, SQS, S3, API Gateway), must be meticulously validated and sanitized to prevent injection attacks. Implement robust data validation libraries and frameworks.
  4. Continuous Configuration and Code Scanning: Implement automated scanning tools throughout the CI/CD pipeline. Use KICS for Infrastructure as Code (IaC) scanning to catch misconfigurations before deployment. Deploy Prowler for continuous runtime security assessment of your AWS, GCP, or Azure environments.
  5. Robust Software Composition Analysis (SCA): Integrate SCA tools like OSV-Scanner, npm audit, Dependency-Check, or NC into your development workflow to automatically detect and remediate known vulnerabilities in third-party libraries and dependencies. Regularly update these dependencies and Lambda runtimes.
  6. Proactive Logging, Monitoring, and Alerting: Establish a centralized logging strategy using services like Amazon CloudWatch and CloudTrail. Define custom metrics and alerts for suspicious activities, such as unusual spikes in DynamoDB scans, large response sizes, or excessive function invocations. Leverage Amazon Detective for deeper security investigations.
  7. Implement Resiliency and Cost Controls: Configure max concurrency limits and timeouts for all Lambda functions to prevent Denial of Service (DoS) and Denial of Wallet (DoW) attacks. Set up budget alerts within your cloud provider's billing console to be notified of unexpected cost increases.
  8. Leverage Established Security Frameworks: Do not start from scratch. Adopt and adapt recognized security frameworks and guidelines such as the OWASP Serverless Top 10, the AWS Startup Security Baseline (SSB), CIS Benchmarks, or the AWS Well-Architected Framework to guide your serverless security strategy. These provide a structured approach and proven best practices.

By systematically applying these defensive strategies, organizations can significantly strengthen their security posture in serverless environments, transforming potential vulnerabilities into resilient, secure applications.

Key Takeaways

  • Serverless security is a shared responsibility, with significant user obligations. While cloud providers handle much of the infrastructure, users are fully accountable for securing their code, data, IAM policies, and configurations.
  • The principle of least privilege is paramount for all serverless functions. Granting only the necessary permissions, validated by tools like pmapper, repoid, and IAM Access Analyzer, is critical to prevent privilege escalation and unauthorized access.
  • Rigorous input validation and sanitization are essential for event-driven architectures. All events triggering Lambda functions must be thoroughly checked to prevent injection vulnerabilities that could lead to data leakage, resource exhaustion, or denial of wallet attacks.
  • Comprehensive security scanning across the entire lifecycle is non-negotiable. This includes scanning Infrastructure as Code (IaC) with tools like KICS pre-deployment, continuous runtime scanning with Prowler, and Software Composition Analysis (SCA) with OSV-Scanner for third-party dependencies.
  • Robust logging, monitoring, and setting limits protect against abuse and financial costs. Utilizing Amazon CloudWatch, CloudTrail, and Amazon Detective for visibility, alongside setting max concurrency and timeout limits, is vital for detecting and preventing DoS/DoW attacks.
  • Leverage existing security frameworks and tools to build security into serverless platforms. Organizations should adopt guidelines like the OWASP Serverless Top 10, AWS Startup Security Baseline, or CIS Benchmarks to avoid reinventing the wheel and ensure a structured, industry-aligned security approach.

About the Speaker(s)

Aviram is a seasoned cybersecurity professional and a co-founder and Chief Research and Innovation Officer at JIT, an agentic application security platform. With a career spanning over 25 years, Aviram has deep expertise in both offensive and defensive cybersecurity. He identifies himself as a software engineer at heart, having dedicated many years to development and research. His extensive experience includes contributing to cutting-edge technologies at prominent cybersecurity companies such as CyberArk and SentinelOne, bringing a wealth of practical knowledge to the discussion of building secure serverless platforms.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A vendor founder walks through serverless security 101 — shared responsibility model, OWASP Top 10 adapted for Lambda, a tool parade of Prowler/KICS/IAM Access Analyzer — and calls it research. Nothing here is original, the 'event-stream' supply chain example is years old, and the whole thing reads like a JIT product onboarding deck with the logo swapped out.

Heather Calloway (CISO) — WEAK

Competent serverless security primer from a practitioner who clearly knows the terrain, but this is a developer-level checklist dressed up as security strategy. It names the right tools and the right principles, but never crosses into governance, accountability, or organizational decision-making — and the audience that most needs to act on serverless risk isn't in the room.

→ Top-rated talks at Cloud Village @ DEF CON 33

All talks from Cloud Village @ DEF CON 33