<link rel="stylesheet" href="styles.f3b1fba60ec7970c.css">

Удосконалення моделі проактивного реагування на інциденти в Kubernetes-кластерах шляхом кореляції подій та автоматизованої ізоляції

Вантажиться...
Ескіз

Дата

Автори

Назва журналу

Номер ISSN

Назва тому

DOI

Анотація

This paper addresses the problem of delayed incident response in highly dynamic Kubernetes container orchestration environments. It is established that traditional monitoring systems (SIEM, IDS) are often unable to provide timely threat localization due to the high volume of events and their rapid development. An improved proactive response model is proposed, based on the correlation of heterogeneous events (Kubernetes Audit Logs, system logs, network flows) to calculate an integral risk score for each container. Based on this score, the model activates an automated isolation algorithm that instantly restricts network access (via NetworkPolicy) and resources of the compromised element, preventing the lateral spread of the attack.

Опис

Тип документа

Мова

ISSN

Бібліографічний опис

Марчук В. О., Салієва О. В. Удосконалення моделі проактивного реагування на інциденти в Kubernetes-кластерах шляхом кореляції подій та автоматизованої ізоляції // Матеріали Міжнародної науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2026)», м. Вінниця, 22-26 червня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/mn/mn2026/paper/view/26390.

Схвалення

Рецензія

Доповнено

Цитується в

Список використаної літератури (5)

  1. The 2023 Kubernetes Security Report [Електронний ресурс] / Wiz Research // wiz.io - 2023 - Режим доступу до ресypcy: https://www.wiz.io/blog/key-takeaways-from-the-wiz-2023-kubernetes-security-report.
  2. Gartner. Market Guide for Cloud-Native Application Protection Platforms [Електронний ресурс] / Gartner - 2024 - Режим доступу до ресypcy: https://www.crowdstrike.com/en-us/resources/reports/2024-gartner-marketguide-for-cloud-native-application-protection-platforms/
  3. Automated Incident Response in Kubernetes [Електронний ресурс] / A. Sharma, R. Gill // International Journal of Network Security & Its Applications (IJNSA) - 2022 - Vol. 14, No. 3 - Режим доступу до ресypcy: https://aircconline.com/ijnsa/V14N3/14322ijnsa01.pdf
  4. Q. Li. A security event description of intelligent applications in edge-cloud environment. Journal of Cloud Computing. / Q. Li // journalofcloudcomputing.springeropen.com - 2020 - Режим доступу до ресурсу: https://journalofcloudcomputing.springeropen.com/articles/10.1186/s13677-020-00171-0
  5. H. Pitkar. Cloud Security Automation Through Symmetry: Threat Intelligence, Event Correlation and Automation. In: Symmetry 17(6), / H. Pitkar // mdpi.com - 2025 - Режим доступу до ресурсу: https://www.mdpi.com/2073-8994/17/6/859