Attack methods and defenses on Kubernetes

Attack methods and defenses on Kubernetes
复制标题

Kubernetes的攻击方式与防御

DOI:
--
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Panagiotis Mytilinakis
Panagiotis Mytilinakis
中科院分区:
--
文献类型:
--
作者:
Παναγιώτης Μυτιληνάκης;Panagiotis Mytilinakis

文献摘要

被引文献

相似文献

容器和容器编排在云计算和内部部署中的采用速度越来越快,这引发了许多关于其安全性的问题。到目前为止,Kubernetes与Docker的结合是实现容器化工作负载最常用的解决方案。Kubernetes分为两个平面:控制平面和数据平面。控制平面包括Kubernetes运行和管理集群状态所需的组件,而数据平面包括负责实际工作负载的组件。此外,Kubernetes还包括一些描述集群所需状态所必需的对象。在本文中,具体的攻击是针对Kubernetes集群进行的,它可以分为四类。(a)对Kubernetes引擎和组件的攻击。(b)对Kubernetes网络层的攻击,在这种情况下可能进行MITM和DNS欺骗攻击。(c)涉及pod内容器以及攻击者如何在容器注册表或具有一个或多个可被利用的漏洞的容器上注入恶意代码并上传的攻击。(d)最后,基于基础设施的攻击是恶意行为者可以利用的代码漏洞。与攻击相对应的是,根据每个攻击可能发生的层,推荐了许多防御措施作为对策。对于涉及Kubernetes引擎的攻击,推荐使用kube-bench作为检测错误配置和攻击者可以利用的入口点的工具。为了保护网络层,与典型的基础设施相比,网络策略正在取代第3层防火墙,此外还使用在第7层运行的服务网格。在将容器上传到注册表之前,可以扫描pod中的容器。在这篇论文中,克莱尔扫描仪被用于他的目的。最终,Pod Security策略被用来阻止易受攻击的代码被部署。
The increasing rate of adoption of containers and container orchestration in cloud computing and on premise arises a number of questions about their security. Kubernetes combined with Docker is by far the most frequently adopted solution for implementing containerized workloads. Kubernetes is divided on two planes the control plane and the data plane. The control plane includes the components that are required for Kubernetes to function and manage the cluster state while the data plane the components that are responsible for the actual workloads. Furthermore, Kubernetes includes several objects that are necessary for describing the cluster’s desired state. In this thesis, specific attacks were conducted into a Kubernetes cluster, that can be divided into four categories. (a) Attacks on a Kubernetes engine and components. (b) Attacks on Kubernetes network layer where MITM and DNS spoofing attacks are possible under circumstances. (c) Attacks that concern the containers inside a pod and how an attacker can inject malicious code and upload it, on a container registry or a container with one or more vulnerabilities that can be exploited. (d) Finally, attacks that are bases on Infrastructure as code vulnerabilities that a malicious actor can take advantage of. Correspondingly to the attacks a number of defenses where recommended as countermeasures depending on the layer that each of the attacks can take place. For the attacks that concern the Kubernetes engine, kube-bench was recommended as a tool that detects misconfigurations and entry points that an attacker can take advantage of. In order for network layer to be protected, network policies are taking the place of a layer 3 firewall compared to a typical infrastructure in addition with the use of service meshes that are operating in layer 7. Containers inside pods can be scanned before being upload on a registry. On this thesis Clair scanner was used for his purpose. Eventually, Pod Security policies were used to block vulnerable code from being deployed.