Overcoming Security Obstacles in Serverless Function as-a-Service (FaaS) for Healthcare Insurance

Sanjeev Kumar · International Journal of Computer Trends and Technology · 2024

In recent years, serverless computing, particularly FaaS, has gained much popularity as a method by which developers can develop and publish their code without having to manage any underlying infrastructure. With these conveniences and scalability opportunities come a particular set of security challenges: function-level vulnerabilities, insecure APIs, data leakage risks, improper resource permissions, and bad monitoring practices. Furthermore, the stateless nature of FaaS combined with shared environments in the cloud increases the number of attack vectors, which include injection attacks, DoS, and privilege escalation. This paper searches for general security challenges of serverless applications, especially FaaS, and provides a detailed review of best practices available to mitigate the risks. The studies are analyzed based on case study data, and the findings from security testing tools, such as OWASP ZAP and Burp Suite, which have identified the vulnerabilities of the application and measured the effectiveness of various security practices, are considered. These tools are applied in a simulated FaaS environment, and the findings are drawn from the attack frequency impact of security measures on system performance, so demonstrating how best practices such as least privilege access, API security, and encryption can really make a difference in security outcomes. Risks will be reduced, and compliance with modern security standards will be upheld by adopting a holistic, security-first approach to the design of serverless applications. This paper provides an overall roadmap for building secure and efficient FaaS with real-world examples and empirical evidence.

Read the paper · More papers on PaperTik