Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations
Fuente:
arXiv
Saved in:
| Main Authors: | , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866909770057777152 |
|---|---|
| author | Bufalino, Jacopo Martin-Navarro, Jose Luis Di Francesco, Mario Aura, Tuomas |
| author_facet | Bufalino, Jacopo Martin-Navarro, Jose Luis Di Francesco, Mario Aura, Tuomas |
| contents | Kubernetes has emerged as the de facto standard for container orchestration. Unfortunately, its increasing popularity has also made it an attractive target for malicious actors. Despite extensive research on securing Kubernetes, little attention has been paid to the impact of network configuration on the security of application deployments. This paper addresses this gap by conducting a comprehensive analysis of network misconfigurations in a Kubernetes cluster with specific reference to lateral movement. Accordingly, we carried out an extensive evaluation of 287 open-source applications belonging to six different organizations, ranging from IT companies and public entities to non-profits. As a result, we identified 634 misconfigurations, well beyond what could be found by solutions in the state of the art. We responsibly disclosed our findings to the concerned organizations and engaged in a discussion to assess their severity. As of now, misconfigurations affecting more than thirty applications have been fixed with the mitigations we proposed. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2506_21134 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations Bufalino, Jacopo Martin-Navarro, Jose Luis Di Francesco, Mario Aura, Tuomas Cryptography and Security Networking and Internet Architecture Kubernetes has emerged as the de facto standard for container orchestration. Unfortunately, its increasing popularity has also made it an attractive target for malicious actors. Despite extensive research on securing Kubernetes, little attention has been paid to the impact of network configuration on the security of application deployments. This paper addresses this gap by conducting a comprehensive analysis of network misconfigurations in a Kubernetes cluster with specific reference to lateral movement. Accordingly, we carried out an extensive evaluation of 287 open-source applications belonging to six different organizations, ranging from IT companies and public entities to non-profits. As a result, we identified 634 misconfigurations, well beyond what could be found by solutions in the state of the art. We responsibly disclosed our findings to the concerned organizations and engaged in a discussion to assess their severity. As of now, misconfigurations affecting more than thirty applications have been fixed with the mitigations we proposed. |
| title | Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations |
| topic | Cryptography and Security Networking and Internet Architecture |
| url | https://arxiv.org/abs/2506.21134 |