Serverless computing is the latest paradigm in cloud computing, offering a framework for the development of event driven, pay-as-you-go functions in a highly scalable environment. While these traits offer a powerful new development paradigm, they have also given rise to a new form of cyber-attack known as Denial of Wallet (forced financial exhaustion). In this work, we define and identify the threat of Denial of Wallet and its potential attack patterns. Also, we demonstrate how this new form of attack can potentially circumvent existing mitigation systems developed for a similar style of attack, Denial of Service. Our goal is twofold. Firstly, we will provide a concise and informative overview of this emerging attack paradigm. Secondly, we propose this paper as a starting point to enable researchers and service providers to create effective mitigation strategies. We include some simulated experiments to highlight the potential financial damage that such attacks can cause and the creation of an isolated test bed for continued safe research on these attacks.
翻译:无服务器计算是云计算中的最新范例,为在高度可扩展的环境中发展事件驱动的现收现付功能提供了一个框架。这些特征提供了强有力的新发展模式,但它们也产生了一种新的网络攻击形式,称为拒绝钱包(强迫财政枯竭 ) 。 在这项工作中,我们定义和确定否认钱包的威胁及其潜在的攻击模式。此外,我们还展示了这种新形式的攻击可能如何绕过为类似攻击类型“拒绝服务”而开发的现有减缓系统。我们的目标是双重的。首先,我们将对这一新出现的攻击模式提供一个简明而翔实的概览。第二,我们提出这份文件作为起点,使研究人员和服务提供者能够制定有效的减轻战略。我们包括一些模拟实验,以突出这种攻击可能造成的潜在财政损失,并为继续安全研究这些攻击建立一个孤立的试验床。