{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T01:10:02Z","timestamp":1785892202756,"version":"3.56.0"},"reference-count":105,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,5,26]],"date-time":"2023-05-26T00:00:00Z","timestamp":1685059200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"U.S. National Science Foundation","doi-asserted-by":"crossref","award":["2247141, 2310179"],"award-info":[{"award-number":["2247141, 2310179"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100009226","name":"U.S. National Security Agency","doi-asserted-by":"crossref","award":["H98230-21-1-0175"],"award-info":[{"award-number":["H98230-21-1-0175"]}],"id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2023,10,31]]},"abstract":"<jats:p>\n            <jats:bold>Context:<\/jats:bold>\n            Kubernetes has emerged as the de-facto tool for automated container orchestration. Business and government organizations are increasingly adopting Kubernetes for automated software deployments. Kubernetes is being used to provision applications in a wide range of domains, such as time series forecasting, edge computing, and high-performance computing. Due to such a pervasive presence, Kubernetes-related security misconfigurations can cause large-scale security breaches. Thus, a systematic analysis of security misconfigurations in Kubernetes manifests, i.e., configuration files used for Kubernetes, can help practitioners secure their Kubernetes clusters.\n          <\/jats:p>\n          <jats:p>\n            <jats:bold>Objective:<\/jats:bold>\n            <jats:italic>The goal of this paper is to help practitioners secure their Kubernetes clusters by identifying security misconfigurations that occur in Kubernetes manifests<\/jats:italic>\n            .\n          <\/jats:p>\n          <jats:p>\n            <jats:bold>Methodology:<\/jats:bold>\n            We conduct an empirical study with 2,039 Kubernetes manifests mined from 92 open-source software repositories to systematically characterize security misconfigurations in Kubernetes manifests. We also construct a static analysis tool called Security Linter for Kubernetes Manifests (\n            <jats:sc>SLI-KUBE<\/jats:sc>\n            ) to quantify the frequency of the identified security misconfigurations.\n          <\/jats:p>\n          <jats:p>\n            <jats:bold>Results:<\/jats:bold>\n            In all, we identify 11 categories of security misconfigurations, such as absent resource limit, absent\n            <jats:monospace>securityContext<\/jats:monospace>\n            , and activation of\n            <jats:monospace>hostIPC<\/jats:monospace>\n            . Specifically, we identify 1,051 security misconfigurations in 2,039 manifests. We also observe the identified security misconfigurations affect entities that perform mesh-related load balancing, as well as provision pods and stateful applications. Furthermore, practitioners agreed to fix 60% of 10 misconfigurations reported by us.\n          <\/jats:p>\n          <jats:p>\n            <jats:bold>Conclusion:<\/jats:bold>\n            Our empirical study shows Kubernetes manifests to include security misconfigurations, which necessitates security-focused code reviews and application of static analysis when Kubernetes manifests are developed.\n          <\/jats:p>","DOI":"10.1145\/3579639","type":"journal-article","created":{"date-parts":[[2023,1,10]],"date-time":"2023-01-10T12:26:24Z","timestamp":1673353584000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":89,"title":["Security Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study"],"prefix":"10.1145","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5056-757X","authenticated-orcid":false,"given":"Akond","family":"Rahman","sequence":"first","affiliation":[{"name":"Auburn University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8084-5123","authenticated-orcid":false,"given":"Shazibul Islam","family":"Shamim","sequence":"additional","affiliation":[{"name":"Auburn University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1603-3574","authenticated-orcid":false,"given":"Dibyendu Brinto","family":"Bose","sequence":"additional","affiliation":[{"name":"Virginia Tech, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7466-2985","authenticated-orcid":false,"given":"Rahul","family":"Pandita","sequence":"additional","affiliation":[{"name":"Github, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,5,26]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3183519.3183549"},{"issue":"8","key":"e_1_3_2_3_2","first-page":"9","article-title":"Compilers, principles, techniques","volume":"7","author":"Aho Alfred V.","year":"1986","unstructured":"Alfred V. Aho, Ravi Sethi, and Jeffrey D. Ullman. 1986. Compilers, principles, techniques. Addison Wesley 7, 8 (1986), 9.","journal-title":"Addison Wesley"},{"key":"e_1_3_2_4_2","article-title":"[CVE-2020\u201315257] Don\u2019t use \u2013net=host . Don\u2019t use spec.hostNetwork.","author":"Suda Akihiro","year":"2020","unstructured":"Akihiro Suda. 2020. [CVE-2020\u201315257] Don\u2019t use \u2013net=host . Don\u2019t use spec.hostNetwork. (January 2022). Retrieved January 9, 2022 from https:\/\/medium.com\/nttlabs\/dont-use-host-network-namespace-f548aeeef575.","journal-title":"https:\/\/medium.com\/nttlabs\/dont-use-host-network-namespace-f548aeeef575"},{"key":"e_1_3_2_5_2","unstructured":"akondrahman. 2022. akondrahman\/sli-kube. Retrieved from https:\/\/hub.docker.com\/repository\/docker\/akondrahman\/sli-kube."},{"key":"e_1_3_2_6_2","unstructured":"Ales Nosek. 2017. Accessing Kubernetes Pods from Outside of the Cluster. (January 2022). Retrieved January 18 2022 from https:\/\/alesnosek.com\/blog\/2017\/02\/14\/accessing-kubernetes-pods-from-outside-of-the-cluster\/."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9508-2"},{"key":"e_1_3_2_8_2","article-title":"Why HTTPS matters","author":"Basques Kayce","year":"2015","unstructured":"Kayce Basques. 2015. Why HTTPS matters. (January 2022). Retrieved January 12, 2022 from https:\/\/web.dev\/why-https-matters\/.","journal-title":"https:\/\/web.dev\/why-https-matters\/"},{"key":"e_1_3_2_9_2","article-title":"bitnami-labs\/sealed-secrets","author":"labs bitnami","year":"2022","unstructured":"bitnami labs. 2022. bitnami-labs\/sealed-secrets. (January 2022). Retrieved January 10, 2022 from https:\/\/github.com\/bitnami-labs\/sealed-secrets.","journal-title":"https:\/\/github.com\/bitnami-labs\/sealed-secrets"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/EnCyCriS52570.2021.00009"},{"key":"e_1_3_2_11_2","article-title":"checkov","year":"2022","unstructured":"bridgecrew. 2022. checkov. (May 2022). Retrieved May 12, 2022 from https:\/\/www.checkov.io\/4.Integrations\/Kubernetes.html.","journal-title":"https:\/\/www.checkov.io\/4.Integrations\/Kubernetes.html"},{"key":"e_1_3_2_12_2","article-title":"Ensure containers do not run with AllowPrivilegeEscalation","year":"2022","unstructured":"bridgecrew. 2022. Ensure containers do not run with AllowPrivilegeEscalation. (January 2022). Retrieved January 10, 2022 from https:\/\/docs.bridgecrew.io\/docs\/ensure-containers-do-not-run-with-allowprivilegeescalation.","journal-title":"https:\/\/docs.bridgecrew.io\/docs\/ensure-containers-do-not-run-with-allowprivilegeescalation"},{"key":"e_1_3_2_13_2","article-title":"Limit mounting Docker socket daemon in a container","year":"2022","unstructured":"bridgecrew. 2022. Limit mounting Docker socket daemon in a container. (January 2022). Retrieved January 20, 2022 from https:\/\/docs.bridgecrew.io\/docs\/bc_k8s_26.","journal-title":"https:\/\/docs.bridgecrew.io\/docs\/bc_k8s_26"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-5519-3_8"},{"key":"e_1_3_2_15_2","article-title":"A MAP for Kubernetes Supply Chain Security","author":"Bugwadia Jim","year":"2022","unstructured":"Jim Bugwadia. 2022. A MAP for Kubernetes Supply Chain Security. (November 2022). Retrieved November 02, 2022 from https:\/\/nirmata.com\/2022\/03\/15\/a-map-for-kubernetes-supply-chain-security\/.","journal-title":"https:\/\/nirmata.com\/2022\/03\/15\/a-map-for-kubernetes-supply-chain-security\/"},{"key":"e_1_3_2_16_2","unstructured":"Canonical. 2021. Kubernetes and cloud native operations report 2021. Retrieved from https:\/\/juju.is\/cloud-native-kubernetes-usage-report-2021."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.5668"},{"key":"e_1_3_2_18_2","author":"Choudhary Swati","year":"2021","unstructured":"Swati Choudhary. 2021. Kubernetes-based Architecture For An On-premises Machine Learning Platform. Master\u2019s thesis, Aalto University.","journal-title":"Kubernetes-based Architecture For An On-premises Machine Learning Platform"},{"key":"e_1_3_2_19_2","article-title":"Limiting Pod Privileges: hostPID","author":"Pisano Chris","year":"2019","unstructured":"Chris Pisano. 2019. Limiting Pod Privileges: hostPID. (January 2022). Retrieved January 21, 2022 from https:\/\/medium.com\/@chrispisano\/limiting-pod-privileges-hostpid-57ce07b05896.","journal-title":"https:\/\/medium.com\/@chrispisano\/limiting-pod-privileges-hostpid-57ce07b05896"},{"key":"e_1_3_2_20_2","unstructured":"CNCF. 2020. With Kubernetes the U.S. Department of Defense Is Enabling DevSecOps on F-16s and Battleships. Retrieved from https:\/\/www.cncf.io\/case-study\/dod\/."},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.4324\/9781410606266"},{"key":"e_1_3_2_22_2","volume-title":"Doing Qualitative Research","author":"Crabtree Benjamin F.","year":"1999","unstructured":"Benjamin F. Crabtree and William L. Miller. 1999. Doing Qualitative Research. Sage publications."},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.4135\/9780857020123"},{"key":"e_1_3_2_24_2","article-title":"Host\u2019s IPC namespace is not shared","year":"2022","unstructured":"DataDogHQ. 2022. Host\u2019s IPC namespace is not shared. (January 2022). Retrieved January 19, 2022 from https:\/\/docs.datadoghq.com\/security_platform\/default_rules\/cis-docker-1.2.0-5.16\/.","journal-title":"https:\/\/docs.datadoghq.com\/security_platform\/default_rules\/cis-docker-1.2.0-5.16\/"},{"key":"e_1_3_2_25_2","article-title":"datree","year":"2022","unstructured":"datree. 2022. datree. (May 2022). Retrieved May 14, 2022 from https:\/\/hub.datree.io\/built-in-rules#containers.","journal-title":"https:\/\/hub.datree.io\/built-in-rules#containers"},{"key":"e_1_3_2_26_2","article-title":"dghubble\/go-twitter","year":"2022","unstructured":"dghubble. 2022. dghubble\/go-twitter. (January 2022). Retrieved January 12, 2022 from https:\/\/github.com\/dghubble\/go-twitter.","journal-title":"https:\/\/github.com\/dghubble\/go-twitter"},{"key":"e_1_3_2_27_2","article-title":"Daemon socket option","year":"2022","unstructured":"Docker. 2022. Daemon socket option. (January 2022). Retrieved January 19, 2022 from https:\/\/docs.docker.com\/engine\/reference\/commandline\/dockerd\/.","journal-title":"https:\/\/docs.docker.com\/engine\/reference\/commandline\/dockerd\/"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/WETSEB.2019.00008"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.5555\/2700539"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPC.2019.2911461"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-018-9673-y"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511790942"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM.2017.24"},{"key":"e_1_3_2_34_2","article-title":"API Documentation","year":"2022","unstructured":"GitLab. 2022. API Documentation. (June 2022). Retrieved June 01, 2022 from https:\/\/docs.gitlab.com\/ee\/api\/.","journal-title":"https:\/\/docs.gitlab.com\/ee\/api\/"},{"key":"e_1_3_2_35_2","article-title":"Manage Secrets & Protect Sensitive Data","year":"2022","unstructured":"Hashicorp. 2022. Manage Secrets & Protect Sensitive Data. (January 2022). Retrieved January 19, 2022 from https:\/\/www.vaultproject.io\/.","journal-title":"https:\/\/www.vaultproject.io\/"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1088\/1757-899x\/1043\/3\/032008"},{"key":"e_1_3_2_37_2","article-title":"The package manager for Kubernetes","year":"2021","unstructured":"Helm. 2021. The package manager for Kubernetes. (November 2021). Retrieved November 03, 2021 from https:\/\/helm.sh\/.","journal-title":"https:\/\/helm.sh\/"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380395"},{"key":"e_1_3_2_39_2","volume-title":"Kubernetes Patterns: Reusable Elements for Designing Cloud-Native Applications","author":"Ibryam Bilgin","year":"2019","unstructured":"Bilgin Ibryam and Roland Hu\u00df. 2019. Kubernetes Patterns: Reusable Elements for Designing Cloud-Native Applications. O\u2019Reilly Media."},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev45635.2020.00024"},{"key":"e_1_3_2_41_2","article-title":"Istio\/Gateway","year":"2022","unstructured":"Istio. 2022. Istio\/Gateway. (January 2022). Retrieved January 10, 2022 from https:\/\/istio.io\/latest\/docs\/reference\/config\/.","journal-title":"https:\/\/istio.io\/latest\/docs\/reference\/config\/"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2015.12"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.5555\/2486788.2486877"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3440749.3442594"},{"key":"e_1_3_2_45_2","unstructured":"Derek Kortepeter. 2019. U.S. lawmakers eye AWS role in Capital One data breach. Retrieved fromhttps:\/\/techgenix.com\/aws-capital-one-data-breach\/."},{"key":"e_1_3_2_46_2","volume-title":"Content Analysis: An Introduction to Its Methodology","author":"Krippendorff Klaus","year":"2018","unstructured":"Klaus Krippendorff. 2018. Content Analysis: An Introduction to Its Methodology. Sage publications."},{"key":"e_1_3_2_47_2","unstructured":"Klaus Krippendorff and Joseph L. Fleiss. 1978. Reliability of binary attribute data. Biometrics 34 1 (1978) 142\u2013144."},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3183519.3183548"},{"key":"e_1_3_2_49_2","article-title":"kubelinter","year":"2022","unstructured":"kubelinter. 2022. kubelinter. (May 2022). Retrieved May 13, 2022 from https:\/\/docs.kubelinter.io\/#\/generated\/checks.","journal-title":"https:\/\/docs.kubelinter.io\/#\/generated\/checks"},{"key":"e_1_3_2_50_2","unstructured":"Kubernetes 2020. Kubernetes User Case Studies. Retrieved from https:\/\/kubernetes.io\/case-studies\/."},{"key":"e_1_3_2_51_2","unstructured":"Kubernetes. 2021. Production-Grade Container Orchestration. Retrieved fromhttps:\/\/kubernetes.io\/."},{"key":"e_1_3_2_52_2","article-title":"kind","author":"sigs kubernetes","year":"2022","unstructured":"kubernetes sigs. 2022. (June 2022). Retrieved June 02, 2022 from kind. https:\/\/kind.sigs.k8s.io\/.","journal-title":"https:\/\/kind.sigs.k8s.io\/"},{"key":"e_1_3_2_53_2","unstructured":"Matthew Lombard Jennifer Snyder-Duch and Cheryl Campanella Bracken. 2010. Practical resources for assessing and reporting intercoder reliability in content analysis research projects. https:\/\/www.researchgate.net\/profile\/Cheryl-Bracken\/publication\/242785900_Practical_Resources_for_Assessing_and_Reporting_Intercoder_Reliability_in_Content_Analysis_Research_Projects\/. [Online; accessed 14-Jan-2023]."},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177730491"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-1342-5_62"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-6494-2"},{"key":"e_1_3_2_57_2","article-title":"host ports and hostnetwork: The NATty gritty","year":"2020","unstructured":"max. 2020. host ports and hostnetwork: The NATty gritty. (January 2022). Retrieved January 17, 2022 from https:\/\/lambda.mu\/hostports_and_hostnetwork\/.","journal-title":"https:\/\/lambda.mu\/hostports_and_hostnetwork\/"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180201"},{"key":"e_1_3_2_59_2","article-title":"ptrace(2) Linux manual page","author":"Kerrisk Michael","year":"2021","unstructured":"Michael Kerrisk. 2021. ptrace(2) Linux manual page. (January 2022). Retrieved January 21, 2022 from https:\/\/man7.org\/linux\/man-pages\/man2\/ptrace.2.html.","journal-title":"https:\/\/man7.org\/linux\/man-pages\/man2\/ptrace.2.html"},{"key":"e_1_3_2_60_2","volume-title":"Kubernetes: A Step-By-Step Guide For Beginners To Build, Manage, Develop, and Intelligently Deploy Applications By Using Kubernetes (2020 Edition)","author":"Miles S.","year":"2020","unstructured":"S. Miles. 2020. Kubernetes: A Step-By-Step Guide For Beginners To Build, Manage, Develop, and Intelligently Deploy Applications By Using Kubernetes (2020 Edition). Independently Published. Retrieved fromhttps:\/\/books.google.com\/books?id=M4VmzQEACAAJ."},{"key":"e_1_3_2_61_2","unstructured":"Mirantis. 2021. What are the primary reasons your organization is using Kubernetes?Retrieved from https:\/\/www.mirantis.com\/cloud-case-studies\/paypal\/."},{"key":"e_1_3_2_62_2","article-title":"2021 CWE Top 25 Most Dangerous Software Weaknesses","year":"2021","unstructured":"MITRE. 2021. 2021 CWE Top 25 Most Dangerous Software Weaknesses. (January 2022). Retrieved January 21, 2022 from https:\/\/cwe.mitre.org\/top25\/archive\/2021\/2021_cwe_top25.html.","journal-title":"https:\/\/cwe.mitre.org\/top25\/archive\/2021\/2021_cwe_top25.html"},{"key":"e_1_3_2_63_2","article-title":"Kubernetes in IT administration and serverless computing: An empirical study and research challenges","author":"Mondal Subrota Kumar","year":"2021","unstructured":"Subrota Kumar Mondal, Rui Pan, H. M. Kabir, Tan Tian, and Hong-Ning Dai. 2021. Kubernetes in IT administration and serverless computing: An empirical study and research challenges. The Journal of Supercomputing 78, 1 (2021), 2937\u20132987.","journal-title":"The Journal of Supercomputing"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9512-6"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2005.1553571"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/EEEIC\/ICPSEurope51590.2021.9584756"},{"key":"e_1_3_2_67_2","unstructured":"Jarmo Nevala. 2018. Cybersecurity Situation Analysis-Survey in Central Finland Master\u2019s thesis School of Technology Communication and Transport."},{"key":"e_1_3_2_68_2","article-title":"Docker Container Breakout: Abusing SYS_MODULE capability!","author":"Sharma Nishant","year":"2020","unstructured":"Nishant Sharma. 2020. Docker Container Breakout: Abusing SYS_MODULE capability! (January 2022). Retrieved January 14, 2022 from https:\/\/blog.pentesteracademy.com\/abusing-sys-module-capability-to-perform-docker-container-breakout-cf5c29956edd.","journal-title":"(January 2022). Retrieved January 14, 2022 from https:\/\/blog.pentesteracademy.com\/abusing-sys-module-capability-to-perform-docker-container-breakout-cf5c29956edd"},{"key":"e_1_3_2_69_2","unstructured":"NIST. 2021. misconfiguration. Retrieved fromhttps:\/\/csrc.nist.gov\/glossary\/term\/misconfiguration."},{"key":"e_1_3_2_70_2","article-title":"D-Link Issues Patch for Hard-Coded Password Router Vulnerabilities","author":"Advisory NJCCIC","year":"2021","unstructured":"NJCCIC Advisory. 2021. D-Link Issues Patch for Hard-Coded Password Router Vulnerabilities. (January 2022). Retrieved January 12, 2022 from https:\/\/www.cyber.nj.gov\/alerts-advisories\/d-link-issues-patch-for-hard-coded-password-router-vulnerabilities.","journal-title":"https:\/\/www.cyber.nj.gov\/alerts-advisories\/d-link-issues-patch-for-hard-coded-password-router-vulnerabilities"},{"key":"e_1_3_2_71_2","article-title":"Kubernetes Hardening Guidance","year":"2021","unstructured":"NSA. 2021. Kubernetes Hardening Guidance. (January 2022). Retrieved January 10, 2022 from https:\/\/media.defense.gov\/2021\/Aug\/03\/2002820425\/-1\/-1\/1\/CTR_KUBERNETESHARDENINGGUIDANCE.PDF.","journal-title":"https:\/\/media.defense.gov\/2021\/Aug\/03\/2002820425\/-1\/-1\/1\/CTR_KUBERNETESHARDENINGGUIDANCE.PDF"},{"key":"e_1_3_2_72_2","article-title":"Docker Security Cheat Sheet","year":"2022","unstructured":"OWASP. 2022. Docker Security Cheat Sheet. (January 2022). Retrieved January 11, 2022 from https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/.","journal-title":"(January 2022). Retrieved January 11, 2022 from https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2013.02.009"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/3387905.3388597"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3278142.3278149"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev51306.2021.00024"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380409"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09841-8"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00033"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/3408897"},{"key":"e_1_3_2_81_2","article-title":"Verifiability Package for Paper","author":"Rahman Akond","year":"2022","unstructured":"Akond Rahman, Shazibul Islam Shamim, Dibyendu Brinto Bose, and Rahul Pandita. 2022. Verifiability Package for Paper. (August 2022). Retrieved August 20, 2022 from https:\/\/figshare.com\/s\/bced7c8353853a983cd7.","journal-title":"https:\/\/figshare.com\/s\/bced7c8353853a983cd7"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2019.04.013"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/Agile.2015.12"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606589"},{"key":"e_1_3_2_85_2","article-title":"Sealed Secrets with Kubernetes","author":"Rajapakse Kasun","year":"2021","unstructured":"Kasun Rajapakse. 2021. Sealed Secrets with Kubernetes. (January 2022). Retrieved January 10, 2022 from https:\/\/enlear.academy\/sealed-secrets-with-kubernetes-a3f4d13dbc17.","journal-title":"https:\/\/enlear.academy\/sealed-secrets-with-kubernetes-a3f4d13dbc17"},{"key":"e_1_3_2_86_2","article-title":"Medical Data Leaks Linked to Hardcoded Credentials in Code","author":"Rashid Fahmida","year":"2020","unstructured":"Fahmida Rashid. 2020. Medical Data Leaks Linked to Hardcoded Credentials in Code. (January 2022). Retrieved January 02, 2022 from https:\/\/www.beyondtrust.com\/blog\/entry\/hardcoded-and-embedded-credentials-are-an-it-security-hazard-heres-what-you-need-to-know.","journal-title":"https:\/\/www.beyondtrust.com\/blog\/entry\/hardcoded-and-embedded-credentials-are-an-it-security-hazard-heres-what-you-need-to-know"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319008.3319018"},{"key":"e_1_3_2_88_2","unstructured":"RedHat. 2021. State of Kubernetes Security Report. Retrieved fromhttps:\/\/www.redhat.com\/en\/resources\/state-kubernetes-security-report."},{"key":"e_1_3_2_89_2","article-title":"Kubernetes Service Mesh: A Comparison of Istio, Linkerd, and Consul","author":"Manpathak Sachin","year":"2019","unstructured":"Sachin Manpathak. 2019. Kubernetes Service Mesh: A Comparison of Istio, Linkerd, and Consul. (January 2022). Retrieved January 20, 2022 from https:\/\/platform9.com\/blog\/kubernetes-service-mesh-a-comparison-of-istio-linkerd-and-consul\/.","journal-title":"https:\/\/platform9.com\/blog\/kubernetes-service-mesh-a-comparison-of-istio-linkerd-and-consul\/"},{"key":"e_1_3_2_90_2","volume-title":"The Coding Manual for Qualitative Researchers","author":"Saldana Johnny","year":"2015","unstructured":"Johnny Saldana. 2015. The Coding Manual for Qualitative Researchers. SAGE."},{"key":"e_1_3_2_91_2","article-title":"Hardcoded and Embedded Credentials are an IT Security Hazard Here\u2019s What You Need to Know","author":"Schwarz Julian","year":"2019","unstructured":"Julian Schwarz. 2019. Hardcoded and Embedded Credentials are an IT Security Hazard Here\u2019s What You Need to Know. (July 2021). Retrieved July 02, 2021 from https:\/\/www.beyondtrust.com\/blog\/entry\/hardcoded-and-embedded-credentials-are-an-it-security-hazard-heres-what-you-need-to-know.","journal-title":"https:\/\/www.beyondtrust.com\/blog\/entry\/hardcoded-and-embedded-credentials-are-an-it-security-hazard-heres-what-you-need-to-know"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev45635.2020.00025"},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E52221.2021.00037"},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1613\/jair.1.12631"},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1109\/CHASE.2013.6614738"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2786812"},{"key":"e_1_3_2_97_2","article-title":"snyk","year":"2022","unstructured":"Snyk. 2022. snyk. (May 2022). Retrieved May 15, 2022 from https:\/\/snyk.io\/security-rules\/kubernetes\/.","journal-title":"https:\/\/snyk.io\/security-rules\/kubernetes\/"},{"key":"e_1_3_2_98_2","unstructured":"Stackrox. 2021. Kubernetes and Container Security and Adoption Trends. Retrieved fromhttps:\/\/www.stackrox.com\/kubernetes-adoption-security-and-market-share-for-containers\/."},{"key":"e_1_3_2_99_2","article-title":"stefanprodan\/podinfo","year":"2022","unstructured":"stefanprodan. 2022. stefanprodan\/podinfo. (January 2022). Retrieved January 12, 2022 from https:\/\/github.com\/stefanprodan\/podinfo.","journal-title":"https:\/\/github.com\/stefanprodan\/podinfo"},{"key":"e_1_3_2_100_2","unstructured":"T4. 2020. Container Platform Market Share Market Size and Industry Growth Drivers 2018\u20132023. Retrieved fromhttps:\/\/www.t4.ai\/industries\/container-platform-market-share."},{"key":"e_1_3_2_101_2","unstructured":"Twain Taylor. 2020. 5 Kubernetes security incidents and what we can learn from them. Retrieved fromhttps:\/\/techgenix.com\/5-kubernetes-security-incidents\/."},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1109\/SOSE52839.2021.00019"},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-6419.1996.tb00013.x"},{"key":"e_1_3_2_104_2","article-title":"Kubernetes clusters should not grant CAPSYSADMIN security capabilities","year":"2021","unstructured":"Vowneee. 2021. Kubernetes clusters should not grant CAPSYSADMIN security capabilities. (January 2022). Retrieved January 15, 2022 from https:\/\/serverfault.com\/questions\/1068292\/kubernetes-clusters-should-not-grant-capsysadmin-security-capabilities.","journal-title":"https:\/\/serverfault.com\/questions\/1068292\/kubernetes-clusters-should-not-grant-capsysadmin-security-capabilities"},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSM.2009.5306304"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2018.8328743"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3579639","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3579639","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:48:44Z","timestamp":1750182524000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3579639"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,26]]},"references-count":105,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,10,31]]}},"alternative-id":["10.1145\/3579639"],"URL":"https:\/\/doi.org\/10.1145\/3579639","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,26]]},"assertion":[{"value":"2022-02-22","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-11-26","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-05-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}