Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bufalino, Jacopo, Martin-Navarro, Jose Luis, Di Francesco, Mario, Aura, Tuomas
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909770057777152
author Bufalino, Jacopo
Martin-Navarro, Jose Luis
Di Francesco, Mario
Aura, Tuomas
author_facet Bufalino, Jacopo
Martin-Navarro, Jose Luis
Di Francesco, Mario
Aura, Tuomas
contents Kubernetes has emerged as the de facto standard for container orchestration. Unfortunately, its increasing popularity has also made it an attractive target for malicious actors. Despite extensive research on securing Kubernetes, little attention has been paid to the impact of network configuration on the security of application deployments. This paper addresses this gap by conducting a comprehensive analysis of network misconfigurations in a Kubernetes cluster with specific reference to lateral movement. Accordingly, we carried out an extensive evaluation of 287 open-source applications belonging to six different organizations, ranging from IT companies and public entities to non-profits. As a result, we identified 634 misconfigurations, well beyond what could be found by solutions in the state of the art. We responsibly disclosed our findings to the concerned organizations and engaged in a discussion to assess their severity. As of now, misconfigurations affecting more than thirty applications have been fixed with the mitigations we proposed.
format Preprint
id arxiv_https___arxiv_org_abs_2506_21134
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations
Bufalino, Jacopo
Martin-Navarro, Jose Luis
Di Francesco, Mario
Aura, Tuomas
Cryptography and Security
Networking and Internet Architecture
Kubernetes has emerged as the de facto standard for container orchestration. Unfortunately, its increasing popularity has also made it an attractive target for malicious actors. Despite extensive research on securing Kubernetes, little attention has been paid to the impact of network configuration on the security of application deployments. This paper addresses this gap by conducting a comprehensive analysis of network misconfigurations in a Kubernetes cluster with specific reference to lateral movement. Accordingly, we carried out an extensive evaluation of 287 open-source applications belonging to six different organizations, ranging from IT companies and public entities to non-profits. As a result, we identified 634 misconfigurations, well beyond what could be found by solutions in the state of the art. We responsibly disclosed our findings to the concerned organizations and engaged in a discussion to assess their severity. As of now, misconfigurations affecting more than thirty applications have been fixed with the mitigations we proposed.
title Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2506.21134