Real-time multi-class threat detection and adaptive deception in Kubernetes environments

Kubernetes 环境中的实时多类威胁检测和自适应欺骗

阅读:1

Abstract

Kubernetes has emerged as the backbone of modern cloud-native environments, enabling efficient orchestration of containerized applications. However, its dynamic nature exposes it to sophisticated cyber threats, including privilege escalation, reconnaissance, and denial-of-service attacks. This paper presents a novel framework that combines real-time multi-class threat detection with adaptive deception to enhance Kubernetes security. The framework integrates KServe for scalable machine learning-based threat classification, CICFlowMeter for feature extraction, and KubeDeceive for dynamic deployment of decoys, all governed by the MAPE-K loop for continuous adaptation. Evaluations demonstrate high detection accuracy (up to 91%), efficient resource utilization, and effective attacker engagement, with decoy success rates reaching 93%. The results underscore the framework's ability to proactively mitigate threats, maintain system resilience, and provide actionable intelligence. This unified approach represents a scalable and adaptable defense mechanism for Kubernetes environments, catering to the needs of dynamic and resource-intensive cloud infrastructures.

特别声明

1、本页面内容包含部分的内容是基于公开信息的合理引用;引用内容仅为补充信息,不代表本站立场。

2、若认为本页面引用内容涉及侵权,请及时与本站联系,我们将第一时间处理。

3、其他媒体/个人如需使用本页面原创内容,需注明“来源:[生知库]”并获得授权;使用引用内容的,需自行联系原作者获得许可。

4、投稿及合作请联系:info@biocloudy.com。