Learning Serverless Security: Hacking and Securing Serverless Cloud Applications on Aws, Azure, and Google Cloud
暫譯: 學習無伺服器安全:在 AWS、Azure 和 Google Cloud 上駭客攻擊與保護無伺服器雲端應用程式

Lat, Joshua Arvin

  • 出版商: O'Reilly
  • 出版日期: 2026-03-24
  • 售價: $2,400
  • 貴賓價: 9.8$2,352
  • 語言: 英文
  • 頁數: 531
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1098149017
  • ISBN-13: 9781098149017
  • 相關分類: Serverless
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Despite the increased adoption of serverless computing services around the world, a big gap still exists when it comes to serverless security knowledge and expertise. This gap comes with a steep price: the increased risk of data breaches as more companies store their data in the cloud.

This practical guide covers the relevant offensive and defensive security techniques to audit and secure serverless applications running on AWS, Azure, and Google Cloud. You'll learn how to attack and defend a variety of vulnerable serverless applications using the step-by-step instructions. By the end of this book, you'll have a solid understanding on how to prevent a variety of serverless application attacks and privilege escalation techniques.

Author Joshua Arvin Lat, chief technology officer at NuWorks Interactive Labs and AWS AI Hero, shows you how to:

  • Identify and address vulnerabilities within modern serverless applications
  • Dive deeper into serverless security risks and threats
  • Explore privilege escalation techniques within vulnerable-by-design serverless lab environments
  • Configure authentication and identity services properly on AWS, Azure, and Google Cloud
  • Implement security strategies and best practices to prevent a variety of serverless application attacks
  • Audit serverless function code using various security tools and strategies

商品描述(中文翻譯)

儘管全球對無伺服器計算服務的採用日益增加,但在無伺服器安全知識和專業技能方面仍存在著一個巨大的差距。這個差距帶來了高昂的代價:隨著越來越多的公司將數據存儲在雲端,數據洩露的風險也隨之增加。

本實用指南涵蓋了相關的攻擊和防禦安全技術,以審核和保護在 AWS、Azure 和 Google Cloud 上運行的無伺服器應用程序。您將學習如何使用逐步指導來攻擊和防禦各種易受攻擊的無伺服器應用程序。在本書結束時,您將對如何防止各種無伺服器應用程序攻擊和特權提升技術有一個扎實的理解。

作者 Joshua Arvin Lat,NuWorks Interactive Labs 的首席技術官及 AWS AI Hero,將向您展示如何:
- 識別並解決現代無伺服器應用程序中的漏洞
- 更深入地探討無伺服器安全風險和威脅
- 探索在設計上易受攻擊的無伺服器實驗室環境中的特權提升技術
- 正確配置 AWS、Azure 和 Google Cloud 上的身份驗證和身份服務
- 實施安全策略和最佳實踐,以防止各種無伺服器應用程序攻擊
- 使用各種安全工具和策略審核無伺服器函數代碼