Удосконалення моделі проактивного реагування на інциденти в Kubernetes-кластерах шляхом кореляції подій та автоматизованої ізоляції
Вантажиться...
Файли
Дата
Автори
Назва журналу
Номер ISSN
Назва тому
DOI
Анотація
This paper addresses the problem of delayed incident response in highly dynamic Kubernetes container orchestration
environments. It is established that traditional monitoring systems (SIEM, IDS) are often unable to provide timely threat
localization due to the high volume of events and their rapid development. An improved proactive response model is proposed,
based on the correlation of heterogeneous events (Kubernetes Audit Logs, system logs, network flows) to calculate an integral
risk score for each container. Based on this score, the model activates an automated isolation algorithm that instantly restricts
network access (via NetworkPolicy) and resources of the compromised element, preventing the lateral spread of the attack.
Опис
Ключові слова
Тип документа
Мова
ISSN
Бібліографічний опис
Марчук В. О., Салієва О. В. Удосконалення моделі проактивного реагування на інциденти в Kubernetes-кластерах шляхом кореляції подій та автоматизованої ізоляції // Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/26390.
Схвалення
Рецензія
Доповнено
Цитується в
Список використаної літератури (5)
- The 2023 Kubernetes Security Report [Електронний ресурс] / Wiz Research // wiz.io - 2023 - Режим доступу до ресypcy: https://www.wiz.io/blog/key-takeaways-from-the-wiz-2023-kubernetes-security-report.
- Gartner. Market Guide for Cloud-Native Application Protection Platforms [Електронний ресурс] / Gartner - 2024 - Режим доступу до ресypcy: https://www.crowdstrike.com/en-us/resources/reports/2024-gartner-marketguide-for-cloud-native-application-protection-platforms/
- Automated Incident Response in Kubernetes [Електронний ресурс] / A. Sharma, R. Gill // International Journal of Network Security & Its Applications (IJNSA) - 2022 - Vol. 14, No. 3 - Режим доступу до ресypcy: https://aircconline.com/ijnsa/V14N3/14322ijnsa01.pdf
- Q. Li. A security event description of intelligent applications in edge-cloud environment. Journal of Cloud Computing. / Q. Li // journalofcloudcomputing.springeropen.com - 2020 - Режим доступу до ресурсу: https://journalofcloudcomputing.springeropen.com/articles/10.1186/s13677-020-00171-0
- H. Pitkar. Cloud Security Automation Through Symmetry: Threat Intelligence, Event Correlation and Automation. In: Symmetry 17(6), / H. Pitkar // mdpi.com - 2025 - Режим доступу до ресурсу: https://www.mdpi.com/2073-8994/17/6/859