Dynamic Application Security Testing for Kubernetes Deployment: An Experience Report from Industry


연구 분야: Analysis



학회: FSE Companion '25: Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering


초록

While Kubernetes enables practitioners to rapidly deploy their software and perform container orchestration efficiently, security of the Kubernetes-based deployment infrastructure is a concern for industry practitioners. A systematic understanding of how dynamic analysis can be used for securing Kubernetes deployments can aid practitioners in securing their Kubernetes deployments. We present an experience report, where we describe empirical findings from three dynamic application security testing (DAST) tools on a Kubernetes deployment used by 'Company-Z'. From our empirical study, we find (i) 3,442 recommended security configurations are violated in 'Company-Z's' Kubernetes deployment; and (ii) of the three studied DAST tools, Kubescape and Kubebench provide the highest support with respect to detecting 14 types of recommended security configurations. Based on our findings, we recommend practitioners to apply DAST tools for their Kubernetes deployments, and security researchers to investigate how to detect configuration violations dynamically in the Kubernetes deployment.


Author Profile
Shazibul Islam Shamim

Kennesaw State University Marietta USA

United States
Author Profile
Hanyang Hu

Company-Z San Francisco California USA

United States
Author Profile
Akond Ashfaque Ur Rahman

Auburn University Auburn Alabama USA

United States

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 United States
사이트 ACM
좋아요 수 0

연관 논문 목록 (420건)