Cloud-native environments rely heavily on Kubernetes. Misconfigurations & vulnerabilities frequently expose clusters to severe attacks (privilege escalation, container escapes).
Existing defenses use easily bypassed static rules or high-overhead machine learning (false-positives during traffic bursts) and lack automated mitigation.
ShadowKube: Achieves 97.7% TPR with 0% FPR across 43 CVEs, converting compromised nodes into honeypots in seconds.
Integrating LLMs to dynamically handle anomalies and using communication simulation to emulate massive clusters with minimal hardware.
Machine learning models analyzing system calls suffer from high false positives. During legitimate traffic bursts—common in Kubernetes—false positive rates spike from 4.9% to 27.1%.
Rule-based tools (like Falco) rely on static file paths and require extensive rule maintenance. Attackers easily bypass these rules using techniques like symbolic links (e.g., linking /s to /secrets).
Immediately terminating abnormal containers is ineffective. Kubernetes' fault recovery mechanism automatically recreates the destroyed containers, allowing attackers to restart exploits while depleting cluster resources.
Develop an automated, real-time protection mechanism for Kubernetes that does not rely on manually defined static policies.
Establish behavioral baselines to accurately identify anomalies with minimal computational overhead, ensuring rapid responsiveness.
Implement seamless, "in situ" conversion of compromised pods and nodes into shadow honeypots. This traps attackers and isolates them from the production environment without apparent interruptions.
Containers (like Docker) are lightweight application bundles that share the host operating system's kernel. Kubernetes is the leading orchestration platform used to manage these containers at scale.
Kubernetes uses a master-worker architecture. The Control Plane (Master Node) manages the cluster state via the API Server and etcd storage. The Data Plane (Worker Nodes) executes the actual applications inside "Pods".
Attackers exploit misconfigurations, such as excessive Role-Based Access Control (RBAC) privileges, to gain control of a Pod. They then attack the API Server directly to take over the entire cluster for malicious purposes like cryptocurrency mining.
Decoy systems designed to deceive attackers. ShadowKube's goal is to seamlessly transform compromised nodes into honeypots to separate attackers from the genuine production environment.
The Traffic Proxy reroutes malicious traffic seamlessly. Legitimate users are routed to the production cluster, while detected attackers are diverted to the isolated Shadow Cluster.
In-situ honeypot conversion. Keep the attacker actively engaged in a decoy environment without harming production resources.
If migrating the node would critically impact the production cluster's availability, ShadowKube falls back to immediate pod deletion.
Prioritizes converting the hijacked node in-place, preserving attacker connections silently.
Dynamically rewrites iptables rules. Silent-routes attacker traffic to
Shadow Cluster.
Terminates benign workloads on target node. Master recreates them on healthy nodes instantly.
Swaps production credentials with decoy shadow cluster credentials. Integrates active logging.
6 VMs (4 Prod, 2 Shadow)
K8s 1.19.16, Docker 24.0.5
Simulating complex traffic flows
A deliberately vulnerable weather query microservice deployed to simulate real-world service architectures and expose typical attack surfaces.
With 0% False Positives (vs Falco's 11.6% TPR)
Full silent conversion via async optimization.
Questions & Discussion