arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.26699cs.CRcs.SE

KubeCap:一种通过静态分析和大语言模型辅助规则推理实现Kubernetes中能力最小化的框架

KubeCap: A Framework for Capability Minimization in Kubernetes via Static Analysis and LLM-Assisted Rule Inference

Yuhao Liu, Yingnan Zhou, Weijie Liu, Yan Jia, Zheli Liu

首次发表
浏览论文内容

中文总结 AI 辅助

KubeCap是基于静态分析和LLM辅助规则推理的框架,可推断Kubernetes工作负载的最小能力集,平均降低54.97%的能力,优于相关基线,有效实施最小权限原则。

中文摘要 AI 辅助

作为应用最广泛的容器编排平台,Kubernetes允许开发者通过清单文件(manifest files)管理Linux能力,提供灵活的权限配置。但开发者在实践中依赖默认设置或粗粒度安全上下文,违反了最小权限原则,扩大了容器化工作负载的攻击面。现有研究要么检测Kubernetes清单中的脆弱模式,要么为独立Linux程序推断所需能力,但未直接解决Kubernetes中的能力最小化问题。为填补这一空白,我们首先对三个开源数据集开展实证研究,发现74.67%的项目缺乏能力配置。基于观察结果,我们提出KubeCap——一种用于Kubernetes能力最小化的框架。KubeCap将部署规范转换为确定性清单,定位容器入口点,执行可达性引导的系统调用分析,并利用大语言模型(LLM)辅助规则规范从Linux内核代码中推导系统调用-参数-能力关系。基于这些结果,KubeCap推断每个工作负载所需的最小能力集,并自动生成修复后的清单。对10个代表性的基于Go的Kubernetes项目的评估显示,平均能力降低率为54.97%,在保持实用分析成本的同时,优于快速类型分析和类层次分析基线。这些结果证明了KubeCap在Kubernetes中实施最小权限原则的有效性。

英文摘要

As the most widely used container orchestration platform, Kubernetes provides flexible privilege configuration by allowing developers to manage Linux capabilities via manifest files. However, developers rely on default settings or coarse-grained security contexts in practice, violating the principle of least privilege and enlarging the attack surface of containerized workloads. Existing studies either detect vulnerable patterns in Kubernetes manifests or infer required capabilities for standalone Linux programs, but they do not directly address capability minimization in Kubernetes. To bridge this gap, we first conduct an empirical study on three open-source datasets, revealing that 74.67% of projects lack capability configurations. Motivated by our observations, we propose KubeCap, a framework for Kubernetes capability minimization. KubeCap translates deployment specifications into deterministic manifests, locates container entrypoints, performs reachability-guided system call analysis, and leverages LLM-assisted rule specification to derive syscall--parameter--capability relations from Linux kernel code. Based on these results, KubeCap infers the minimal capability set required by each workload and automatically generates repaired manifests. Evaluation on 10 representative Go-based Kubernetes projects shows an average capability reduction rate of 54.97%, outperforming rapid type analysis and class hierarchy analysis baselines while maintaining practical analysis cost. These results demonstrate KubeCap's effectiveness in enforcing least privilege in Kubernetes.

补充信息

↑