Serverless Architecture and Security
Marko Harambaša, Karlo Josić and Matej Bašić. Serverless Architecture and Security. Proceedings of the 35th DAAAM International Symposium, 299–305, 2024.
Abstract
This paper explores the serverless architecture, detailing its key components, benefits, and security concerns. It contrasts two main types: Function as a Service (FaaS) and Backend as a Service (BaaS), highlighting how they allow for building applications without the need for managing underlying servers. The paper continues into serverless architecture's operational and financial benefits, such as scalability, reduced maintenance, and cost efficiency. Security challenges unique to serverless computing are examined, stressing the importance of adopting robust security measures like comprehensive monitoring and logging to mitigate risks. The paper discusses the inherent security benefits of serverless computing, including minimised attack surfaces and automated updates. It outlines best practices for ensuring secure serverless environments, such as secure coding, stringent access controls, data encryption, and continuous monitoring.
My contribution
I presented this paper at the 35th DAAAM International Symposium in October 2024, and I built the slide deck and recorded the talk for its virtual edition.