Особливості виявлення та нейтралізації APT-загроз в інфраструктурі Kubernetes
Вантажиться...
Файли
Дата
Автори
Науковий керівник
Редактор
Інші учасники
Відповідальний
ORCID
Назва журналу
Номер ISSN
Назва тому
DOI
Альтернативна назва
Анотація
У роботі досліджено еволюцію та специфіку атак класу Розвиненої тривалої загрози (APT) у середовищі оркестрації контейнерів Kubernetes. Проаналізовано ключові відмінності методів закріплення зловмисників у хмарній інфраструктурі порівняно з класичними мережами, зокрема використання контролерів (DaemonSets,
The paper explores the evolution and specificity of the Advanced Persistent Threat (APT) class in the Kubernetes orchestration container environment. It analyzes key differences in methods for attackers to establish themselves in cloud infrastructure through classical networks, including the use of controllers (DaemonSets, CronJobs) and RBAC manipulation. The problem of "forensic gap" is identified, which arises due to the ephemerality of containers and complicates incident investigation. Based on the analysis of Microsoft and MITRE ATT&CK threat matrices, a comprehensive protection strategy is proposed, based on the principles of Zero Trust, network micro-segmentation, and continuous runtime monitoring.
The paper explores the evolution and specificity of the Advanced Persistent Threat (APT) class in the Kubernetes orchestration container environment. It analyzes key differences in methods for attackers to establish themselves in cloud infrastructure through classical networks, including the use of controllers (DaemonSets, CronJobs) and RBAC manipulation. The problem of "forensic gap" is identified, which arises due to the ephemerality of containers and complicates incident investigation. Based on the analysis of Microsoft and MITRE ATT&CK threat matrices, a comprehensive protection strategy is proposed, based on the principles of Zero Trust, network micro-segmentation, and continuous runtime monitoring.
Опис
Ключові слова
Розвинена тривала загроза , APT-атака , Kubernetes , безпека контейнерів , форензичний розрив , RBAC , Zero Trust , матриця загроз , ефемерність , бічне переміщення , Advanced persistent threat , APT attack , container security , forensic breach , ZeroTrust , threat matrix , ephemerality , lateral movement
УДК
Тип документа
Мова
ISSN
Посилання на публікацію
Серія, номер
ISBN
ББК
Інші ідентифікатори
Пов’язані матеріали
Спонсорська підтримка
Правовласник
Бібліографічний опис
Пугачева К. В. Особливості виявлення та нейтралізації APT-загроз в інфраструктурі Kubernetes // Матеріали LV Всеукраїнської науково-технічної конференції підрозділів ВНТУ, Вінниця, 24-27 березня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/all-fm/all-fm-2026/paper/view/26881.
Схвалення
Рецензія
Доповнено
Цитується в
Список використаної літератури (1)
- APT Attacks: What Is an Advanced Persistent Threat? [Електронний ресурс]. – Режим https://datami.ee/ua/blog/apt-attacks-what-is-an-advanced-persistent-threat/ (дата звернення: 14.12.2025). Attack matrix for Kubernetes / Microsoft Security Blog [Електронний ресурс]. – Режим https://www.microsoft.com/en-us/security/blog/2020/04/02/attack-matrix-kubernetes/ (дата звернення: 14.12.2025). MITRE ATT&CK Technique T1078: Valid Accounts [Електронний ресурс]. – Режим https://attack.mitre.org/techniques/T1078/ (дата звернення: 14.12.2025). доступу: доступу: доступу: