Koney: A Cyber Deception Orchestration Framework for Kubernetes

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Kahlhofer, Mario, Golinelli, Matteo, Rass, Stefan
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909676455591936
author Kahlhofer, Mario
Golinelli, Matteo
Rass, Stefan
author_facet Kahlhofer, Mario
Golinelli, Matteo
Rass, Stefan
contents System operators responsible for protecting software applications remain hesitant to implement cyber deception technology, including methods that place traps to catch attackers, despite its proven benefits. Overcoming their concerns removes a barrier that currently hinders industry adoption of deception technology. Our work introduces deception policy documents to describe deception technology "as code" and pairs them with Koney, a Kubernetes operator, which facilitates the setup, rotation, monitoring, and removal of traps in Kubernetes. We leverage cloud-native technologies, such as service meshes and eBPF, to automatically add traps to containerized software applications, without having access to the source code. We focus specifically on operational properties, such as maintainability, scalability, and simplicity, which we consider essential to accelerate the adoption of cyber deception technology and to facilitate further research on cyber deception.
format Preprint
id arxiv_https___arxiv_org_abs_2504_02431
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Koney: A Cyber Deception Orchestration Framework for Kubernetes
Kahlhofer, Mario
Golinelli, Matteo
Rass, Stefan
Cryptography and Security
System operators responsible for protecting software applications remain hesitant to implement cyber deception technology, including methods that place traps to catch attackers, despite its proven benefits. Overcoming their concerns removes a barrier that currently hinders industry adoption of deception technology. Our work introduces deception policy documents to describe deception technology "as code" and pairs them with Koney, a Kubernetes operator, which facilitates the setup, rotation, monitoring, and removal of traps in Kubernetes. We leverage cloud-native technologies, such as service meshes and eBPF, to automatically add traps to containerized software applications, without having access to the source code. We focus specifically on operational properties, such as maintainability, scalability, and simplicity, which we consider essential to accelerate the adoption of cyber deception technology and to facilitate further research on cyber deception.
title Koney: A Cyber Deception Orchestration Framework for Kubernetes
topic Cryptography and Security
url https://arxiv.org/abs/2504.02431