arXiv · 2506.21134
Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations
Abstract
Kubernetes has emerged as the de facto standard for container orchestration. Unfortunately, its increasing popularity has also made it an attractive target for malicious actors. Despite extensive research on securing Kubernetes, little attention has been paid to the impact of network configuration on the security of application deployments. This paper addresses this gap by conducting a comprehensive analysis of network misconfigurations in a Kubernetes cluster with specific reference to lateral movement. Accordingly, we carried out an extensive evaluation of 287 open-source applications belonging to six different organizations, ranging from IT companies and public entities to non-profits. As a result, we identified 634 misconfigurations, well beyond what could be found by solutions in the state of the art. We responsibly disclosed our findings to the concerned organizations and engaged in a discussion to assess their severity. As of now, misconfigurations affecting more than thirty applications have been fixed with the mitigations we proposed.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jacopo Bufalino, Jose Luis Martin-Navarro, Mario Di Francesco, Tuomas Aura. 2025-06-26. Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations. https://doi.org/10.1145/3749220
Cite the original work for its findings. Save a collection to share your selection of sources.