Security challenges in serverless architectures: Vulnerabilities and penetration testing approaches for AWS Lambda and Google Cloud Functions
Main Article Content
Abstract
This study examines the evolving security landscape of serverless computing, specifically focusing on AWS Lambda and Google Cloud Functions. While serverless architectures offer significant scalability and cost advantages, their event-driven nature introduces unique vulnerabilities that traditional infrastructure-based security measures often fail to address. To identify these risks, a multi-methodological approach was employed, involving systematic literature mapping, platform benchmarking, and threat modeling using the STRIDE framework. The research specifically analyzed the "blast radius" of compromised functions and the efficacy of current penetration testing methodologies. Results indicate that Identity and Access Management (IAM) misconfigurations are the primary driver of cloud breaches, accounting for 42% of critical vulnerabilities, while traditional network scanning yielded zero actionable detection data. Furthermore, simulation data revealed that unthrottled "Denial-of-Wallet" attacks can cause catastrophic financial loss within minutes. Based on these findings, a five-layer defense-in-depth framework is proposed, integrating secure secret management, automated dependency scanning, and identity-centric governance. The study concludes that securing serverless environments requires a paradigm shift from network-level protection to granular application logic validation and continuous observability. These measures are essential for maintaining data integrity in decentralized cloud-native environments.
Article Details
Section

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All articles published in this journal are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0).
Authors retain copyright and grant the journal the right of first publication.
This license allows others to share, copy, redistribute, and adapt the work for any purpose, even commercially, provided that appropriate credit is given to the original author(s) and the source. Any derivative works must be distributed under the same license as the original.