- Library Home /
- Search Collections /
- Open Collections /
- Browse Collections /
- UBC Theses and Dissertations /
- A developer-centric compliance tool for serverless...
Open Collections
UBC Theses and Dissertations
UBC Theses and Dissertations
A developer-centric compliance tool for serverless applications Gupta, Praveen Kumar
Abstract
Serverless computing has emerged as a new paradigm that offers developers a streamlined approach to building and deploying cloud-native applications. These applications are characterized by ephemeral, stateless functions written in heterogeneous programming languages and relying on diverse cloud services for storage and communication. Although serverless computing reduces the burden of managing and scaling the infrastructure for cloud tenants, it makes it challenging to protect the application data from inadvertent leaks due to bugs, misconfiguration, and human errors. Existing cloud security tools, such as Identity and Access Management (IAM), lack observability into application-level data flows, while state-of-the-art dataflow tracking tools often require extensive platform modifications and impose substantial runtime overheads. This work presents Growlithe, a developer-centric tool for serverless applications to enable continuous compliance with data policies by design. Growlithe allows declarative specification of access and data flow control policies over a language- and platform-independent dataflow graph abstraction of a serverless application. Growlithe enforces these policies efficiently using a hybrid approach of static and runtime checks. We demonstrate that Growlithe can provide efficient policy enforcement without requiring changes to the underlying cloud platform or incurring significant performance penalties. We used Growlithe with applications using serverless functions in Python and JavaScript on Amazon Web Services and Google Cloud Platform and empirically demonstrated that Growlithe is portable, efficient, and enables developers to adapt their applications and policies to evolving requirements.
Item Metadata
Title |
A developer-centric compliance tool for serverless applications
|
Creator | |
Supervisor | |
Publisher |
University of British Columbia
|
Date Issued |
2024
|
Description |
Serverless computing has emerged as a new paradigm that offers developers a streamlined approach to building and deploying cloud-native applications. These applications are characterized by ephemeral, stateless functions written in heterogeneous programming languages and relying on diverse cloud services for storage and communication. Although serverless computing reduces the burden of managing and scaling the infrastructure for cloud tenants, it makes it challenging to protect the application data from inadvertent leaks due to bugs, misconfiguration, and human errors. Existing cloud security tools, such as Identity and Access Management (IAM), lack observability into application-level data flows, while state-of-the-art dataflow tracking tools often require extensive platform modifications and impose substantial runtime overheads. This work presents Growlithe, a developer-centric tool for serverless applications to enable continuous compliance with data policies by design. Growlithe allows declarative specification of access and data flow control policies over a language- and platform-independent dataflow graph abstraction of a serverless application. Growlithe enforces these policies efficiently using a hybrid approach of static and runtime checks. We demonstrate that Growlithe can provide efficient policy enforcement without requiring changes to the underlying cloud platform or incurring significant performance penalties. We used Growlithe with applications using serverless functions in Python and JavaScript on Amazon Web Services and Google Cloud Platform and empirically demonstrated that Growlithe is portable, efficient, and enables developers to adapt their applications and policies to evolving requirements.
|
Genre | |
Type | |
Language |
eng
|
Date Available |
2024-12-12
|
Provider |
Vancouver : University of British Columbia Library
|
Rights |
Attribution-NonCommercial-NoDerivatives 4.0 International
|
DOI |
10.14288/1.0447498
|
URI | |
Degree | |
Program | |
Affiliation | |
Degree Grantor |
University of British Columbia
|
Graduation Date |
2025-05
|
Campus | |
Scholarly Level |
Graduate
|
Rights URI | |
Aggregated Source Repository |
DSpace
|
Item Media
Item Citations and Data
Rights
Attribution-NonCommercial-NoDerivatives 4.0 International