[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82700-en":3,"doc-seo-82700-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82700,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Overprivilege Analysis of Security Policies in Serverless Cloud Applications","Serverless computing adoption is growing, yet the security impact of its service-oriented programming model remains insufficiently understood. Modular, distributed, and heterogeneous serverless apps make precise security policy specification difficult, while role-based access control frequently suffers misconfiguration. Excess permissions enlarge the attack surface and expose sensitive cloud resources. A large-scale measurement on 689 AWS Lambda applications (1,293 functions) introduces PrivLess to statically derive function-to-resource interactions and quantify overprivilege.","Overprivilege Analysis of Security Policies in Serverless Cloud Applications  \nElvis Yeboah-Duako  \nUniversity of Massachusetts, Amherst [eyeboahduako@umass.edu](eyeboahduako@umass.edu)  \nPubali Datta  \nUniversity of Massachusetts, Amherst [pdatta@umass.edu](pdatta@umass.edu)  \narXiv :2607 .02875v 1 [ cs .CR] 3 Jul 2026  \nAbstract—Serverless computing has seen rapid adoption in cloud deployments, yet the security implications of its service-oriented programming model remain poorly understood. Distributed, modular, and heterogeneous applications complicate the specification of precise security policies. Role-based access control solutions such as Identity and Access Management (IAM) already exhibit pervasive misconfiguration problems, and the multiplicity of functions, services, and resources in serverless applications, together with frequent permission model changes by cloud providers, greatly increases the likelihood of policy misconfigurations. Consequently, policies are often overprivileged, thereby enlarging the attack surface and exposing sensitive cloud resources to compromise.  \nWe present a large-scale measurement study of overprivilege in real-world serverless applications, analyzing a curated dataset of 689 AWS Lambda applications comprised of 1,293 functions. To enable this study, we develop PrivLess, a static policy analysis framework that extracts function-to-resource interactions from application source code, derives an interactionpermission mapping, and reconciles inferred interactions with declared policies to quantify overprivilege. Our measurement reveals that overprivilege is systemic and severe across the serverless ecosystem: 47.7% of applications carry excess permissions with a significant privilege reduction potential of 99.65% . Applications with wildcard-defined permissions exhibited an average overprivilege ratio 274 × higher than those without. More critically, the excess permissions enable concrete attack vectors: 18.8% of applications hold unnecessary Privilege Escalation capabilities, and 12 applications had Defense Evasion permissions they did not need.  \nIndex Terms—Access Control, Security Policy Analysis, Serverless cloud security  \nI. Introduction  \nIdentity and Access Management (IAM) frameworks (e.g., AWS IAM [4], Google IAM [27], Microsoft IAM [42]) enable developers to specify security policies for cloud applications. However, writing correct policies remains difficult, and developers frequently introduce misconfigurations and excessive privileges. This problem is exacerbated in serverless environments, where modular, eventdriven, stateless functions [54] must access many auxiliary services (e.g., data stores, messaging queues, logging), that makes least-privilege specification harder and expands the attack surface [39] . Over-privileged policies have contributed to high-impact breaches (e.g., SolarWinds [20])  \nand widespread incidents, with roughly 82% of enterprises reporting security problems from misconfigured policies [38], [51] and aggregate financial losses exceeding USD 5 trillion [29] .  \nCloud platforms offer hundreds of services, each with numerous actions and resources requiring precise permission specifications. The ever-evolving nature of IAM permissions framework [32], [43], opaque service dependencies, and inadequate documentation for correlating policy components [25] complicate correct policy definition. Moreover, in serverless applications, each function acts as a distinct security principal requiring specific authorizations. This function-level granularity compounds policy complexity even further. Consequently, developers resort to coarse-grained policies with wildcards to expedite deployment. Moreover, even initially secure policies can become overprivileged as cloud providers introduce finergrained permissions for their services over time. Updating application policies to adopt these refined permissions is labor-intensive and often neglected, leaving existing polici","cbCaiiLCgLEYSemB","https://ap.wps.com/l/cbCaiiLCgLEYSemB","pdf",1324994,4,1,16,"English","en",105,"# Introduction\n## Background and Problem Motivation\n## Study Approach and PrivLess Framework\n## Key Findings","[{\"question\":\"Why are serverless security policies more likely to become overprivileged?\",\"answer\":\"Serverless apps consist of many modular, event-driven, stateless functions that must access numerous auxiliary services. Frequent permission-model changes and coarse-grained use of wildcards further increase the likelihood that declared policies contain excess privileges.\"},{\"question\":\"What is PrivLess and how does it quantify overprivilege?\",\"answer\":\"PrivLess is a static policy analysis framework that extracts function-to-resource interactions from application source code. It derives an interaction-to-permission mapping, reconciles inferred interactions with declared policies, and then quantifies overprivilege.\"},{\"question\":\"What results does the measurement study report about overprivilege in AWS Lambda?\",\"answer\":\"Overprivilege is described as systemic and severe: 47.7% of applications carry excess permissions. Wildcard-defined permissions correlate with much higher overprivilege ratios, and the excess permissions enable concrete attack vectors such as privilege escalation capabilities.\"}]",1784182373,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"overprivilege-analysis-of-security-policies-in-serverless-cloud-applications","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/overprivilege-analysis-of-security-policies-in-serverless-cloud-applications/82700/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why are serverless security policies more likely to become overprivileged?","Question",{"text":75,"@type":76},"Serverless apps consist of many modular, event-driven, stateless functions that must access numerous auxiliary services. Frequent permission-model changes and coarse-grained use of wildcards further increase the likelihood that declared policies contain excess privileges.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is PrivLess and how does it quantify overprivilege?",{"text":80,"@type":76},"PrivLess is a static policy analysis framework that extracts function-to-resource interactions from application source code. It derives an interaction-to-permission mapping, reconciles inferred interactions with declared policies, and then quantifies overprivilege.",{"name":82,"@type":73,"acceptedAnswer":83},"What results does the measurement study report about overprivilege in AWS Lambda?",{"text":84,"@type":76},"Overprivilege is described as systemic and severe: 47.7% of applications carry excess permissions. Wildcard-defined permissions correlate with much higher overprivilege ratios, and the excess permissions enable concrete attack vectors such as privilege escalation capabilities.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]