KubeDeceive Unveiling Deceptive Approaches to Protect Kubernetes Clusters
Abdelrahman Aly, Mahmoud Fayez, Mirvat Al-Qutt, Ahmed Mahmoud Hamad · Research Square · 2023
Abstract The widespread adoption of containerization platforms such as Kubernetes has revolutionized application deployment and management but also introduced complex security challenges. Deception-based strategies reinforce security by misleading attackers with deceptive resources. This paper proposes deception techniques for Kubernetes, developing a novel security framework, KubeDeceive. KubeDeceive functions as a router, intercepting requests to the Kubernetes API server and redirecting malicious users to decoy components. Its efficacy was tested in a Capture the Flag (CTF) competition, simulating real-world attacks. The competition involved static and dynamic deception methods, including randomized secrets and real-time countermeasures against participants' attempts. KubeDeceive was highly effective, achieving a 100% success rate in preventing any participant from creating a master node pod, and trapping 89% of participants in deception decoys. Moreover, participants spent an average of 160 minutes in their failed attempts in dynamic scenarios, which demonstrates KubeDeceive's roust impact in prolonging attacker engagement and completely thwarting their objectives.