Security Perspective of Open-Source Serverless Platforms: An Empirical Investigation
Hamza, Muhammad; Akbar, Muhammad Azeem; Smolander, Kari; Khan, Arif Ali (2025-12-23)
Publishers version
Hamza, Muhammad
Akbar, Muhammad Azeem
Smolander, Kari
Khan, Arif Ali
23.12.2025
152-161
Association for Computing Machinery
School of Engineering Science
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi-fe202601082004
https://urn.fi/URN:NBN:fi-fe202601082004
Tiivistelmä
Serverless architecture has gained significant traction due to its scal- ability, cost efficiency, and reduced operational overhead. However, despite its advantages, serverless architectures introduce unique security issues that developers encounter when developing applica- tions with open-source serverless platforms. While prior research has explored security concerns in proprietary serverless platforms, there is limited empirical analysis of security issues in open-source serverless platforms based on real-world developer discussions. This study systematically examines 88 security-related issues from GitHub repositories of 10 open-source serverless platforms to iden- tify common security issues, their underlying causes, and potential solutions. Our findings reveal that certificate & encryption, permis- sions & role management, and security & authentication are the most frequently reported issues in the developers’ discussion. The primary causes of these issues include misconfigurations, inade- quate access controls, and dependency-related failures. To address these issues, we identified mitigation strategies such as enhanced security configurations, improved IAM policies, and automated certificate management. The study offers valuable insights for both researchers and practitioners by providing an empirical foundation for improving security practices when developing applications with these open-source serverless platforms.
Lähdeviite
Muhammad Hamza, Muhammad Azeem Akbar, Kari Smolander, and Arif Khan. 2025. Security Perspective of Open-Source Serverless Platforms: An Empirical Investigation. In Proceedings of the 2025 29th International Conference on Evaluation and Assessment in Software Engineering Companion (EASE Companion '25). Association for Computing Machinery, New York, NY, USA, 152–161. https://doi.org/10.1145/3727967.3756839
Alkuperäinen verkko-osoite
https://dl.acm.org/doi/10.1145/3727967.3756839Kokoelmat
- Tieteelliset julkaisut [1836]
