arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

利用并保护Docker容器和Kubernetes Pod免受中间人攻击

Exploiting and Securing Docker containers and Kubernetes pods from a MitM attack

Henry Kabuye, Ismail Khalid Kazmi, Chunyan Mu, Paolo Modesti

arXiv 2609.16253首次发表:更新:

发表机构

School of Computing, Engineering and Digital Technologies(计算、工程与数字技术学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过系统综述和设计-创建方法,提出结合概念模型、AnBxJ库及第7层容器防火墙的框架,并应用零信任架构,以有效保护Docker和Kubernetes免受中间人攻击。

AI 中文摘要

目的——容器中的工作负载,如Docker容器和Kubernetes Pod,容易受到与非容器环境中工作负载相同的许多攻击,包括网络钓鱼、应用程序漏洞利用和网络入侵。本系统综述和设计-创建研究探讨了保护基于容器的操作系统免受中间人(MitM)攻击的技术。所提出的框架使用一个概念模型来表示通信和密码学原语,并结合AnBxJ Java安全库和运行在OSI模型第7层的容器防火墙。该研究解决了以下问题:如何有效保护基于容器的操作系统免受中间人攻击?它旨在通过系统化安全实践和应用零信任架构,支持从业者保护Docker和Kubernetes部署。方法——本研究采用基于系统评价和荟萃分析首选报告项目(PRISMA)的系统综述(SR),汇集了针对同一研究主题的研究证据。发现——确定了成功因素,并在基于容器的操作系统场景中成功实施了一种安全机制。价值——研究结果可能通过系统化容器安全实践并为基于容器的操作系统提供零信任架构,帮助从业者保护Kubernetes和Docker安装。

英文摘要

PURPOSE - Workloads in containers, such as Docker containers and Kubernetes pods, are vulnerable to many of the same attacks as workloads in non-container environments, including phishing, application exploits and network intrusions. This systematic review and design-and-creation study explores techniques for securing containerised-based operating systems against Man-in-the-Middle (MitM) attacks. The proposed framework uses a conceptual model for representing communication and cryptographic primitives, together with the AnBxJ Java security library and container firewalls operating at layer 7 of the OSI model. The study addresses the question: How can containerised-based operating systems be effectively secured from Man-in-the-Middle attacks? It aims to support practitioners in protecting Docker and Kubernetes deployments by systematising security practices and applying a zero trust architecture. METHODOLOGY - The research uses a Systematic Review (SR) based on the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA), bringing together evidence from studies addressing the same research topic. FINDINGS - Success factors were identified, and a security mechanism was successfully implemented in a containerised-based operating system scenario. VALUE - The findings may help practitioners protect Kubernetes and Docker installations by systematising container security practices and providing a zero trust architecture for containerised-based operating systems.

CommentsThis work was submitted in partial requirements for the degree of Msc Cybersecurity at Teesside University

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑