Permissions on the Loose: Measuring Overprivilege in Real-World Serverless Applications
cs.CR
Submitted: 2026-07-03
Updated: 2026-09-08
Comments: Added functionality tests and revised topic
Code: https://github.com/boto/boto
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Guarding Serverless Applications with SecLambda
- Quantifying Azure RBAC Wildcard Overreach
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless Functions
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs