A Mutation-Enabled Proactive Defense Against Service-Oriented Man-in-The-Middle Attack in Kubernetes

A Mutation-Enabled Proactive Defense Against Service-Oriented Man-in-The-Middle Attack in Kubernetes
复制标题

DOI:
10.1109/tc.2023.3238125
复制
发表时间:
2023-07
影响因子:
3.7
通讯作者:
Tengchao Ma;Changqiao Xu;Shujie Yang;Yiting Huang;Qingzhao An;Xiaohui Kuang;L. Grieco
Tengchao Ma;Changqiao Xu;Shujie Yang;Yiting Huang;Qingzhao An;Xiaohui Kuang;L. Grieco
中科院分区:
计算机科学2区
文献类型:
--
作者:
Tengchao Ma;Changqiao Xu;Shujie Yang;Yiting Huang;Qingzhao An;Xiaohui Kuang;L. Grieco

文献摘要

相似文献

Kubernetes (k8)已经成为云原生应用程序的核心技术。然而,k8外部IP的设计缺陷导致了面向服务的中间人攻击。现有的解决方案(例如,脚本监视器)试图被动地解决这个问题,这使得攻击者有足够的分析时间来绕过这些静态规则审查。不同的是,我们提出了一种突变激活的主动防御机制,旨在改变攻击者和防御者之间的不对称。它包括地址突变(即网络识别)模块和连接ID突变(即通信识别)模块。在前一个模块中,我们分析了突变约束,并证明了相应的突变分组问题是np困难的。然后,提出了一种最大颜色驱动的突变分组算法。由于地址分配时间随服务规模线性增长,我们设计了一种预取地址分配算法。在设计了模块间的交互流程后,提出了模块间的随机化算法。因此,我们的机制不影响面向其他攻击的方法。最终,它可以通过增量更新k8和传输层协议来持续中断攻击并保持服务连接。在阿里云上的实验表明,它可以在可接受的性能损失下有效防御攻击。
Kubernetes (K8s) has become a core technology for cloud-native applications. However, a design flaw of the external IP in K8s leads to the service-oriented man-in-the-middle attack. Existing solutions (e.g., script monitor) attempt to address it passively, which allows attackers enough analysis time to bypass these static rule reviews. Differently, we propose a mutation-enabled proactive defense mechanism, aiming to change the asymmetry between attackers and defenders. It involves the address mutation (i.e., network identification) module and the connection ID (i.e., communication identification) mutation module. In the former module, we analyze mutation constraints and prove the corresponding mutation grouping problem to be NP-hard. Then, a maximally coloring-driven mutation grouping algorithm is developed. Since the address allocation time grows linearly with the service size, we design a prefetched address allocation algorithm. After designing the interaction flow between modules, we present a randomized algorithm in the latter module. Thus our mechanism does not affect methods oriented to other attacks. Eventually, it can continuously interrupt the attack and keep the service connection by incrementally updating K8s and the transport layer protocol. Experiments in the Alibaba cloud demonstrate that it can effectively defend against the attack with an acceptable performance loss.