KubeDeceive Unveiling Deceptive Approaches to Protect Kubernetes Clusters
Résumé
Abstract The widespread adoption of containerization platforms such as Kubernetes has revolutionized application deployment and management but also introduced complex security challenges. Deception-based strategies reinforce security by misleading attackers with deceptive resources. This paper proposes deception techniques for Kubernetes, developing a novel security framework, KubeDeceive. KubeDeceive functions as a router, intercepting requests to the Kubernetes API server and redirecting malicious users to decoy components. Its efficacy was tested in a Capture the Flag (CTF) competition, simulating real-world attacks. The competition involved static and dynamic deception methods, including randomized secrets and real-time countermeasures against participants' attempts. KubeDeceive was highly effective, achieving a 100% success rate in preventing any participant from creating a master node pod, and trapping 89% of participants in deception decoys. Moreover, participants spent an average of 160 minutes in their failed attempts in dynamic scenarios, which demonstrates KubeDeceive's roust impact in prolonging attacker engagement and completely thwarting their objectives.
Citer ce document
Accès au document
Texte intégral en lecture en ligne, réservé aux abonnés SPHAERO et aux membres de l'institution. Se connecter
Voir l'article sur le site de la revueStatistiques
Consultations : 1
Téléchargements : 0