XI Commandments of Kubernetes Security: A Systematization of Knowledge Related to Kubernetes Security Practices

XI Commandments of Kubernetes Security: A Systematization of Knowledge Related to Kubernetes Security Practices
复制标题

十一、Kubernetes安全戒律:Kubernetes安全实践相关知识体系化

DOI:
10.1109/secdev45635.2020.00025
复制
发表时间:
2020
期刊:
2020 IEEE Secure Development (SecDev)
影响因子:
--
通讯作者:
A. Rahman
A. Rahman
中科院分区:
--
文献类型:
--
作者:
Md. Shazibul Islam Shamim;Farzana Ahamed Bhuiyan;A. Rahman

文献摘要

被引文献

相似文献

Kubernetes是一个开源软件,用于自动化管理计算机化服务。IBM、Capital One和Adidas等组织使用Kubernetes来部署和管理他们的容器,并报告了与部署频率相关的好处。尽管有报道称,Kubernetes的部署很容易受到安全漏洞的影响,例如2018年特斯拉发生的安全漏洞。Kubernetes安全实践的系统化可以帮助从业者减轻Kubernetes部署中的漏洞。本文的目标是通过系统化与Kubernetes安全实践相关的知识,帮助从业人员保护他们的Kubernetes安装。我们通过对104个互联网工件进行定性分析来系统化知识。我们确定了11种安全实践,包括(i)实现基于角色的访问控制(RBAC)授权以提供最小权限,(ii)应用安全补丁以保持Kubernetes更新,以及(iii)实现pod和网络特定的安全策略。
Kubernetes is an open-source software for automat- ing management of computerized services. Organizations, such as IBM, Capital One and Adidas use Kubernetes to deploy and manage their containers, and have reported benefits related to deployment frequency. Despite reported benefits, Kubernetes deployments are susceptible to security vulnerabilities, such as those that occurred at Tesla in 2018. A systematization of Kubernetes security practices can help practitioners mitigate vulnerabilities in their Kubernetes deployments. The goal of this paper is to help practitioners in securing their Kubernetes installations through a systematization of knowledge related to Kubernetes security practices. We systematize knowledge by applying qualitative analysis on 104 Internet artifacts. We identify 11 security practices that include (i) implementation of role-based access control (RBAC) authorization to provide least privilege, (ii) applying security patches to keep Kubernetes updated, and (iii) implementing pod and network specific security policies.