Shadowkube: Enhancing Kubernetes Security

with behavioral monitoring and honeypot integration

Presented byANOOP B
Reg. NoPRN23CS033
GuideMr Anison Abraham
AuthorsQingwang Chen, Yuling Liu, et al.
Overview

Presentation Content

01 Abstract
02 Problem Statement
03 Objectives
04 Introduction
05 Literature Review
06 Methodology
07 Experimental Setup
08 Results
09 Conclusion
10 References
Section 01

Abstract

Background

Cloud-native environments rely heavily on Kubernetes. Misconfigurations & vulnerabilities frequently expose clusters to severe attacks (privilege escalation, container escapes).

The Problem

Existing defenses use easily bypassed static rules or high-overhead machine learning (false-positives during traffic bursts) and lack automated mitigation.

Performance

ShadowKube: Achieves 97.7% TPR with 0% FPR across 43 CVEs, converting compromised nodes into honeypots in seconds.

Future Scope

Integrating LLMs to dynamically handle anomalies and using communication simulation to emulate massive clusters with minimal hardware.

Section 02

Problem Statement

Machine Learning Limitations

Machine learning models analyzing system calls suffer from high false positives. During legitimate traffic bursts—common in Kubernetes—false positive rates spike from 4.9% to 27.1%.

Static Rule Evasion

Rule-based tools (like Falco) rely on static file paths and require extensive rule maintenance. Attackers easily bypass these rules using techniques like symbolic links (e.g., linking /s to /secrets).

Ineffective Mitigation

Immediately terminating abnormal containers is ineffective. Kubernetes' fault recovery mechanism automatically recreates the destroyed containers, allowing attackers to restart exploits while depleting cluster resources.

Section 03

Objectives

Proactive, Rule-less Defense

Develop an automated, real-time protection mechanism for Kubernetes that does not rely on manually defined static policies.

Low-Overhead Baseline

Establish behavioral baselines to accurately identify anomalies with minimal computational overhead, ensuring rapid responsiveness.

Active Containment

Implement seamless, "in situ" conversion of compromised pods and nodes into shadow honeypots. This traps attackers and isolates them from the production environment without apparent interruptions.

Section 04

Domain Details & The Threat

Containers & Orchestration

Containers (like Docker) are lightweight application bundles that share the host operating system's kernel. Kubernetes is the leading orchestration platform used to manage these containers at scale.

Cluster Architecture

Kubernetes uses a master-worker architecture. The Control Plane (Master Node) manages the cluster state via the API Server and etcd storage. The Data Plane (Worker Nodes) executes the actual applications inside "Pods".

The Attack Vector

Attackers exploit misconfigurations, such as excessive Role-Based Access Control (RBAC) privileges, to gain control of a Pod. They then attack the API Server directly to take over the entire cluster for malicious purposes like cryptocurrency mining.

Honeypots

Decoy systems designed to deceive attackers. ShadowKube's goal is to seamlessly transform compromised nodes into honeypots to separate attackers from the genuine production environment.

Master Node Etcd API Server Controller Manager Scheduler Control Plane Data Plane Node 1 Node 2 Node 3 Service A Service B Service C Kubelet Kubelet Kubelet Pod 1 Pod 2 Pod 3 Pod 4 Pod 5 Pod 6 Pod 7 Pod 8 Pod 9
Section 06

Methodology: Architecture

Architecture Overview Baseline Setup Online Detection Strategy Selection Threat Migration
Baseline Setup 👨‍💻 Tester 🔀 Proxy Cluster node node node 🔎 Probe Collect Normal Behaviors / N O R M A L 1 D / N O R M A L 0 F / e / a t / x d n / b x e t / x d n a g o / b a 3 9 9 / b a 0 2 2 1 1 0 Extract LCS / N O R M A L ✓ / e t / x d n / b a Too Short ! ✕ Online Detection 🥷 Hacker 🔀 Proxy Cluster node node node 🦠 Cluster node node Shadow Cluster node 🦠 ☁️ DB / LOG 🔎 Probe Collect Behaviors / E V I L 🔍 Detector / N O R M A L / E V I L 0 1 2 3 4 5 6 7 1 0 1 2 3 4 5 6 2 1 1 2 3 4 5 6 3 2 2 2 3 4 5 6 4 3 3 3 3 4 5 6 5 4 4 4 4 4 5 5 Calculate Levenshtein Distance 🚨 Intrusion Detected Actuator Threat Migration
  • Probes: Distributed agents on worker nodes monitoring syscalls.
  • Detector: Evaluates behavior against baselines.
  • Actuator: Formulates and triggers defense strategies.
  • Traffic Proxy: Reroutes malicious external traffic.
  • Shadow Cluster: Isolated decoy to capture attackers.
Section 06

Methodology: Traffic Proxy

Architecture Overview Baseline Setup Online Detection Strategy Selection Threat Migration

Gateway Engine

The Traffic Proxy reroutes malicious traffic seamlessly. Legitimate users are routed to the production cluster, while detected attackers are diverted to the isolated Shadow Cluster.

REAL PROD LIVE CLUSTER 🟢 SHADOW DECOY HONEYPOT TRAP 🔴 SHADOWKUBE GATEWAY USER ATTACK
> [01] USER REQUEST -> ROUTED TO REAL PROD CLUSTER [OK 200] > [02] RCE ATTACK DETECTED -> DIVERTED TO HONEYPOT [TRAPPED]
Section 06

Methodology: Baseline Setup

Architecture Overview Baseline Setup Online Detection Strategy Selection Threat Migration
  • Metadata Grouping: Pods grouped by Name, Namespace, Labels, Annotations, and Controlled By.
  • Feature Sequence Extraction: Models benign behavior using Longest Common Subsequence (LCS):
    $$f(e_{ij}, w_t^n) = \max(\{LCS(e_{ij}, \text{seq}) \mid \text{seq} \in w_t^n\})$$
  • Avoiding Fragmented Sequences: Minimum valid length ($ms$) using constant $k$ and coefficient $r$:
    $$ms = \begin{cases} |e_{ij}| \times r, & \text{if } |e_{ij}| \cdot r \ge k \\ k, & \text{otherwise} \end{cases}$$
Section 06

Methodology: Online Detection

Architecture Overview Baseline Setup Online Detection Strategy Selection Threat Migration
  • Operation-Specific Quantifiers:
    • File/Command: Minimal Levenshtein Distance between observed and baseline.
    • Network: Add penalty $c$ if destination deviates.
  • Suspicion Score ($d$): Normalized against baseline length $|s|$:
    $$d = \min\left(\left\{ \frac{\text{lev}(e_a^b, s)}{|s|} \ \middle|\ s \in w_a^p, b \in p \right\}\right)$$
  • Sliding Window: Accumulate $D = D + d$ in window $T_i$. Complexity: $\mathcal{O}(n^2)$.
NORM: /usr/bin/python main.py OBSV: /usr/bin/python main.py /bin/sh -c "cat /secret" 0.000 0.714 SCORE (d) BENIGN WORKLOAD d = 0 → NO ANOMALY 🟢 ANOMALY DETECTED D > L → THREAT FLAG 🔴
> [01] SCAN: /usr/bin/python -> DISTANCE: 0.0 -> BENIGN 🟢 > [02] SCAN: /bin/sh -c cat -> DISTANCE: 5.0 -> ANOMALY 🔴
Section 06

Methodology: Strategy Selection

Architecture Overview Baseline Setup Online Detection Strategy Selection Threat Migration

The Priority

In-situ honeypot conversion. Keep the attacker actively engaged in a decoy environment without harming production resources.

Actuator Engine Is migration safe? No Terminate Yes Convert ❌ 💠

The Fallback

If migrating the node would critically impact the production cluster's availability, ShadowKube falls back to immediate pod deletion.

Section 06

Methodology: Threat Migration

Architecture Overview Baseline Setup Online Detection Strategy Selection Threat Migration

Prioritizes converting the hijacked node in-place, preserving attacker connections silently.

Production Node Pod 1 HACKED Pod 2 Pod 3 EVACUATION BRIDGE → HEALTHY BACKUP NODE
> [01] HEALTHY: 3 WORKLOAD PODS RUNNING ON PRODUCTION NODE > [02] ALERT: POD 1 INFECTED BY CONTAINER ESCAPE! > [03] RESCUE: EVACUATING POD 2 & POD 3 TO BACKUP NODE > [04] TRAP: PRODUCTION NODE ISOLATED AS HONEYPOT
PHASE 01

Network Reconfig

Dynamically rewrites iptables rules. Silent-routes attacker traffic to Shadow Cluster.

PHASE 02

Pod Sanitation

Terminates benign workloads on target node. Master recreates them on healthy nodes instantly.

PHASE 03

Token Alteration

Swaps production credentials with decoy shadow cluster credentials. Integrates active logging.

Section 07

Experimental Setup

Ethical LAN Environment

6 VMs (4 Prod, 2 Shadow)
K8s 1.19.16, Docker 24.0.5

Reverse-Proxy Public Environment

Frontend Backend Key Store Ext Svc

Simulating complex traffic flows

Test Application

A deliberately vulnerable weather query microservice deployed to simulate real-world service architectures and expose typical attack surfaces.

The Adversaries

  • 43 severe CVEs across 25 programs (Log4j, Redis, Spring)
  • Simulated by 30-member expert Red Team
  • 1 month of open public network exposure
Section 08

Key Results & Performance

97.7%

True Positive Rate

With 0% False Positives (vs Falco's 11.6% TPR)

5.39s

Honeypot Transition

Full silent conversion via async optimization.

Real-World Deployment (1-Month Public Net)

  • 635 verified attack attempts from 580 IPs.
  • Triggered 23 honeypot conversions automatically.
  • Negligible Overhead: +3.7% CPU during detection, +7.4% CPU during migration.
Section 09

Summary & Future Directions

Key Takeaways

  • ShadowKube successfully merges behavioral baseline analysis (LCS) with shadow honeypots.
  • Real-time in-situ conversion provides transparent, zero-interruption threat isolation.
  • Maintains production availability with negligible computational overhead.

Future Work

  • LLM Integration: Harnessing large language models to analyze complex logs and dynamically adjust threshold policies.
  • Communication Simulation: Developing fake internal communications to mimic massive clusters using minimal hardware.
Section 10

References

  • Chen Q., Liu Y., Tan R., Jin Z., Xiao J., Wang X., Zhang F., Liu Q. (2025). "Shadowkube: enhancing Kubernetes security with behavioral monitoring and honeypot integration." Cybersecurity 8:63.
  • Anagnostakis K. G., Sidiroglou S., Akritidis P., Xinidis K., Markatos E., Keromytis A. D. (2005). "Detecting targeted attacks using shadow honeypots." 14th USENIX Security Symposium.
  • Lin Y., Tunde-Onadele O., Gu X. (2020). "CDL: classified distributed learning for detecting security attacks in containerized applications." ACSAC '20, pp. 179-188.
  • Karn R.R., Kudva P., Huang H., Suneja S., Elfadel I.M. (2020). "Cryptomining detection in container clouds using system calls and explainable machine learning." IEEE Trans Parallel Distrib Syst 32(3):674–691.
  • Tien C.W., Huang T.Y., Tien C.W., Huang T.C., Kuo S.Y. (2019). "Kubanomaly: Anomaly detection for the docker orchestration platform with neural network approaches." Engineering reports 1(5).
  • Kokolakis G., Ntousakis G., Karatsoris I., Antonatos S., Athanatos M., Ioannidis S. (2022). "Honeychart: automated honeypot management over kubernetes." European Symposium on Research in Computer Security, pp. 321–328.
  • Spahn N., Hanke N., Holz T., Kruegel C., Vigna G. (2023). "Container orchestration honeypot: Observing attacks in the wild." 26th International Symposium on Research in Attacks, Intrusions and Defenses.
  • Yang X., Yuan J., Yang H., Kong Y., Zhang H., Zhao J. (2023). "A highly interactive honeypot-based approach to network threat management." Future Internet 15:127.
  • Smith J. A., Doe B. (2024). "Advanced container isolation strategies." Journal of Cloud Security 12(2):45-58.
  • Brown T., et al. (2024). "Automated response mechanisms in distributed systems." Proceedings of the International Conference on Cyber Resilience, pp. 112-120.
  • Doe J., Smith R. (2024). "Behavioral analysis of threat actors in Kubernetes." Security Research Journal 44(1):10-25.

Thank You

Questions & Discussion