EconPapers    
Economics at your fingertips  
 

KubeHound: Detecting Microservices’ Security Smells in Kubernetes Deployments

Giorgio Dell’Immagine, Jacopo Soldani () and Antonio Brogi
Additional contact information
Giorgio Dell’Immagine: Department of Computer Science, University of Pisa, Largo B. Pontecorvo 3, 56127 Pisa, Italy
Jacopo Soldani: Department of Computer Science, University of Pisa, Largo B. Pontecorvo 3, 56127 Pisa, Italy
Antonio Brogi: Department of Computer Science, University of Pisa, Largo B. Pontecorvo 3, 56127 Pisa, Italy

Future Internet, 2023, vol. 15, issue 7, 1-26

Abstract: As microservice-based architectures are increasingly adopted, microservices security has become a crucial aspect to consider for IT businesses. Starting from a set of “security smells” for microservice applications that were recently proposed in the literature, we enable the automatic detection of such smells in microservice applications deployed with Kubernetes. We first introduce possible analysis techniques to automatically detect security smells in Kubernetes-deployed microservices. We then demonstrate the practical applicability of the proposed techniques by introducing KubeHound , an extensible prototype tool for automatically detecting security smells in microservice applications, and which already features a selected subset of the discussed analyses. We finally show that KubeHound can effectively detect instances of security smells in microservice applications by means of controlled experiments and by applying it to existing, third-party applications.

Keywords: microservices; smell detection; security; Kubernetes (search for similar items in EconPapers)
JEL-codes: O3 (search for similar items in EconPapers)
Date: 2023
References: View complete reference list from CitEc
Citations:

Downloads: (external link)
https://www.mdpi.com/1999-5903/15/7/228/pdf (application/pdf)
https://www.mdpi.com/1999-5903/15/7/228/ (text/html)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:gam:jftint:v:15:y:2023:i:7:p:228-:d:1179825

Access Statistics for this article

Future Internet is currently edited by Ms. Grace You

More articles in Future Internet from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().

 
Page updated 2025-03-19
Handle: RePEc:gam:jftint:v:15:y:2023:i:7:p:228-:d:1179825