Novel advancements in static analysis of serverless applications

Lead Research Organisation: Royal Holloway University of London
Department Name: Information Security

Abstract

In recent years, the serverless computing paradigm, which allows developing applications by using cloud services managed by a provider, has become very popular. Companies adopting this approach can focus on the business logic of their software products, thus reducing their costs. Despite this, the tools to secure these applications are still evolving. Static analysis, in particular, remains very challenging because the code that implements the used services is not available to the developer.

The chief objective of this PhD project is therefore the development of a novel methodology that allows analysing serverless applications statically, i.e., before their deployment, in order to detect security vulnerabilities. Given their importance, the identification of security-sensitive data flows leading to code injection vulnerabilities and unauthorized disclosure of information should be prioritized.

The methodology will have to be implemented and then validated with a set of benchmarks, developed by considering previous research as well as examples of real-world applications. Finally, the prototyped static analysis tool will be used to analyse a large dataset in order to test the effectiveness of the proposed approach and identify its limitations.

Planned Impact

People. The most obvious impact of RHUL's cyber security CDT will be its production of 50 PhD-level graduates during its lifetime. CDT graduates will be "industry-ready": through industry placements, they will have exposure to real-world cyber security problems and working environments; because of the breadth of our training programme, they will gain exposure to cyber security in all its forms; through involvement of our external partners at all stages of the CDT, the students will be exposed to the language and culture of industry, government and other sectors. At the same time, they will benefit from generic skills training, equipping them with a broad set of skills that will be of use in their subsequent workplaces. They will also engage in PhD-level research projects that will lead to them developing deep topic-specific knowledge as well as general analytical skills. There is a growing demand for graduates with these skill-sets. While RHUL already has demonstrably close relationships with key external players, our CDT represents an opportunity for us to enhance our existing links and develop new ones. Moreover, our own research will be strengthened by working with the best external researchers.

Economy. The nature of our cyber security research and the planned industrial involvement in influencing the selection of research topics means that there will be significant commercialisation opportunities arising from the research produced by this CDT. RHUL cyber security researchers have more than 80 years of experience working in industry, either in research, development or customer-facing environments, and are named inventors on more than 30 patents. We are closely supported by the Royal Holloway Enterprise Centre, who have expertise in business development, securing venture capital funding, and IPR protection. RHUL's Institute for Cyber Security Innovation provides business research and training support. We also have an on-campus incubation centre which has hosted a number of spin-out companies. We are thus thoroughly prepared to identify and exploit commercialisation opportunities arising from the CDT.

Knowledge. The CDT will make substantial and original contributions to knowledge in cyber security. Following institutional policy, all research is made available to the public for free in some form, either through open access publishing,the institution's research repository or via subject-specific on-line archives. The research will also published in conference venues which, by their nature, are regularly attended by large numbers of delegates from outside of academia. Other impact routes for our knowledge include Industry Fora (RHUL is an active academic member of the I4 and ISF organisations, which are influential industry fora), Business Events (RHUL researchers regularly speak at events such as InfoSec London, RSA Conference), Standards Bodies (several staff are active in international standards bodies), Consulting (staff have consulted for more than 100 organisations in the last 30 years), Industry-focused Events (RHUL hosts several external facing events each year, including the annual CDT Showcase, HP Colloquium, and ISG Open Day).

Society. One of the longer-term impacts of our research is to provide mechanisms that help to enhance confidence and trust in the on-line society for ordinary citizens, leading in turn to quality of life enhancement. Our work on the socio-technical dimensions of security and privacy gives us a means to influence government policy to the betterment of society at large. We work closely with government departments such as the Cabinet Office to provide advice on privacy, security and design issues. We also communicate research findings through more widely accessible media, press engagement, speaking at public events, and working with schools (CDT students will take part in the annual Smallpeice Trust Cyber Security residential for Year 9 students).

Publications

10 25 50

Studentship Projects

Project Reference Relationship Related To Start End Student Name
EP/S021817/1 01/10/2019 31/03/2028
2442771 Studentship EP/S021817/1 01/10/2020 22/12/2024 Giuseppe Raffa