{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,8]],"date-time":"2026-04-08T18:40:19Z","timestamp":1775673619309,"version":"3.50.1"},"reference-count":61,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,8,25]],"date-time":"2025-08-25T00:00:00Z","timestamp":1756080000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,8,25]],"date-time":"2025-08-25T00:00:00Z","timestamp":1756080000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100013096","name":"Science and Technology Project of State Grid","doi-asserted-by":"publisher","award":["No. 5700-202352606A-3-2-ZN"],"award-info":[{"award-number":["No. 5700-202352606A-3-2-ZN"]}],"id":[{"id":"10.13039\/501100013096","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association of the Chinese Academy of Sciences","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>As cloud-native technologies continue to evolve, containerization and orchestration have become fundamental for deploying microservices. However, this advancement introduces significant security vulnerabilities, particularly due to vulnerabilities and misconfigurations that grant attackers excessive control over clusters. Existing works, including model-based learning and static rule-based approaches, suffer from limitations such as false positives and maintenance overhead, which pose significant challenges to cloud-native security.<\/jats:p>\n          <jats:p>To mitigate intrusion targeting container orchestration, we present <jats:italic>ShadowKube<\/jats:italic>, an innovative active defense framework tailored for Kubernetes. <jats:italic>ShadowKube<\/jats:italic> integrates behavioral monitoring with shadow honeypots to effectively detect and neutralize anomalous behavior. By establishing behavioral baselines to identify deviations and converting compromised nodes into honeypots, <jats:italic>ShadowKube<\/jats:italic> isolates and traps attackers, thereby mitigating the threats they pose. Comprehensive evaluations demonstrate <jats:italic>ShadowKube<\/jats:italic>\u2019s ability to detect and migrate exploitations across 43 severe CVEs and 7 common misconfiguration types. Deployment in a live environment further validates its effectiveness, with <jats:italic>ShadowKube<\/jats:italic> identifying 635 attack attempts, successfully decoying 23 active attacks. Additionally, <jats:italic>ShadowKube<\/jats:italic> could isolate attackers and convert affected nodes into honeypots within seconds. These results highlight <jats:italic>ShadowKube<\/jats:italic>\u2019s efficacy as a robust solution for enhancing security in Kubernetes clusters, offering a proactive defense mechanism against both current and emerging threats.<\/jats:p>","DOI":"10.1186\/s42400-025-00372-7","type":"journal-article","created":{"date-parts":[[2025,8,25]],"date-time":"2025-08-25T02:03:33Z","timestamp":1756087413000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Shadowkube: enhancing Kubernetes security with behavioral monitoring and honeypot integration"],"prefix":"10.1186","volume":"8","author":[{"given":"Qingwang","family":"Chen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuling","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ru","family":"Tan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3379-5113","authenticated-orcid":false,"given":"Ze","family":"Jin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juxin","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiao","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fangjiao","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qixu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,25]]},"reference":[{"key":"372_CR1","unstructured":"Amazon (2024) Amazon web service. https:\/\/aws.amazon.com\/"},{"key":"372_CR2","unstructured":"Anagnostakis KG, Sidiroglou S, Akritidis P, Xinidis K, Markatos E, Keromytis AD (2005) Detecting targeted attacks using shadow honeypots. In: 14th USENIX Security Symposium (USENIX Security 05), USENIX Association, Baltimore, MD, https:\/\/www.usenix.org\/conference\/14th-usenix-security-symposium\/detecting-targeted-attacks-using-shadow-honeypots"},{"key":"372_CR3","unstructured":"Aquasec (2024) Container escape. https:\/\/www.aquasec.com\/cloud-native-academy\/container-security\/container-escape\/"},{"key":"372_CR4","unstructured":"Aquasecurity (2024) Tracee. https:\/\/github.com\/aquasecurity\/tracee"},{"key":"372_CR5","doi-asserted-by":"publisher","unstructured":"Bergroth L, Hakonen H, Raita T (2000) A survey of longest common subsequence algorithms. In: Proceedings Seventh International Symposium on String Processing and Information Retrieval. SPIRE 2000, 39\u201348, https:\/\/doi.org\/10.1109\/SPIRE.2000.878178","DOI":"10.1109\/SPIRE.2000.878178"},{"key":"372_CR6","unstructured":"Blackberry (2024) Falco bypasses. https:\/\/github.com\/blackberry\/Falco-bypasses"},{"key":"372_CR7","unstructured":"Box HT (2024) Penetration testing reports. https:\/\/www.hackthebox.com\/blog\/penetration-testing-reports-template-and-guide"},{"issue":"10","key":"372_CR8","first-page":"63","volume":"4","author":"ML Bringer","year":"2012","unstructured":"Bringer ML, Chelmecki CA, Fujinoki H (2012) A survey: recent advances and future trends in honeypot research. Int J Comput Netw Inf Secur 4(10):63","journal-title":"Int J Comput Netw Inf Secur"},{"key":"372_CR9","unstructured":"Canonical (2024) Canonical kubernetes usage report 2023. https:\/\/juju.is\/cloud-native-kubernetes-usage-report-2022"},{"key":"372_CR10","unstructured":"CDK (2024) Cdk. https:\/\/github.com\/cdk-team\/CDK"},{"key":"372_CR11","unstructured":"Chen (2024) Shadowkube supporting materials. https:\/\/sites.google.com\/view\/shadowkube"},{"key":"372_CR12","unstructured":"CrowdStrike (2024) Crowdstrike 2024 global threat report. https:\/\/www.crowdstrike.com\/global-threat-report\/"},{"key":"372_CR13","unstructured":"Docker (2024a) Docker. https:\/\/www.docker.com\/"},{"key":"372_CR14","unstructured":"Docker (2024b) Docker swarm. https:\/\/docs.docker.com\/engine\/swarm\/"},{"key":"372_CR15","unstructured":"Elkeid (2024) Elkeid. https:\/\/elkeid.bytedance.com\/docs\/"},{"key":"372_CR16","unstructured":"Falco (2024) Falco. https:\/\/github.com\/falcosecurity\/falco"},{"key":"372_CR17","unstructured":"Google (2024) Google cloud. https:\/\/cloud.google.com\/"},{"key":"372_CR18","doi-asserted-by":"crossref","unstructured":"Guan C, Liu H, Cao G, Zhu S, Porta TFL (2023) Honeyiot: adaptive high-interaction honeypot for iot devices through reinforcement learning. Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks https:\/\/api.semanticscholar.org\/CorpusID:258182800","DOI":"10.1145\/3558482.3590195"},{"key":"372_CR19","doi-asserted-by":"crossref","unstructured":"Gupta C, van Ede T, Continella A (2023) Honeykube: designing and deploying a microservices-based web honeypot. In: SecWeb 2023","DOI":"10.1109\/SPW59333.2023.00005"},{"key":"372_CR20","unstructured":"Honeyd (2024) Honeyd. https:\/\/www.honeyd.org\/"},{"issue":"3","key":"372_CR21","doi-asserted-by":"publisher","first-page":"674","DOI":"10.1109\/TPDS.2020.3029088","volume":"32","author":"RR Karn","year":"2020","unstructured":"Karn RR, Kudva P, Huang H, Suneja S, Elfadel IM (2020) Cryptomining detection in container clouds using system calls and explainable machine learning. IEEE Trans Parallel Distrib Syst 32(3):674\u2013691","journal-title":"IEEE Trans Parallel Distrib Syst"},{"key":"372_CR22","unstructured":"Katchinskiy M, Morag A (2023) leveraging kubernetes rbac to backdoor clusters. https:\/\/www.aquasec.com\/blog\/leveraging-kubernetes-rbac-to-backdoor-clusters\/"},{"key":"372_CR23","doi-asserted-by":"crossref","unstructured":"Kokolakis G, Ntousakis G, Karatsoris I, Antonatos S, Athanatos M, Ioannidis S (2022) Honeychart: automated honeypot management over kubernetes. In: European Symposium on Research in Computer Security, Springer, pp 321\u2013328","DOI":"10.1007\/978-3-031-25460-4_18"},{"key":"372_CR24","unstructured":"KubeArmor (2024) Kubearmor. https:\/\/github.com\/kubearmor\/KubeArmor"},{"key":"372_CR25","unstructured":"Kubernetes (2024a) kube-apiserver. https:\/\/kubernetes.io\/docs\/reference\/command-line-tools-reference\/kube-apiserver\/"},{"key":"372_CR26","unstructured":"Kubernetes (2024b) Kubernetes. https:\/\/kubernetes.io\/"},{"key":"372_CR27","unstructured":"Kubernetes (2024c) Kubernetes pod. https:\/\/kubernetes.io\/docs\/concepts\/workloads\/pods\/"},{"key":"372_CR28","unstructured":"Kubernetes (2024d) Network policy. https:\/\/kubernetes.io\/docs\/concepts\/services-networking\/network-policies\/"},{"key":"372_CR29","unstructured":"Kubernetes (2024e) Persistent volumes. https:\/\/kubernetes.io\/docs\/concepts\/storage\/persistent-volumes\/"},{"key":"372_CR30","unstructured":"Kubernetes (2024f) Rbac authorization. https:\/\/kubernetes.io\/docs\/reference\/access-authn-authz\/rbac\/"},{"key":"372_CR31","unstructured":"Kubescape (2024) Kubescape. https:\/\/kubescape.io\/"},{"key":"372_CR32","doi-asserted-by":"publisher","unstructured":"Lin Y, Tunde-Onadele O, Gu X (2020) Cdl: classified distributed learning for detecting security attacks in containerized applications. In: Proceedings of the 36th Annual Computer Security Applications Conference, Association for Computing Machinery, New York, NY, USA, ACSAC \u201920, p 179-188, https:\/\/doi.org\/10.1145\/3427228.3427236, https:\/\/doi.org\/10.1145\/3427228.3427236","DOI":"10.1145\/3427228.3427236"},{"key":"372_CR33","doi-asserted-by":"crossref","unstructured":"L\u00f3pez-Morales E, Rubio-Medrano C, Doup\u00e9 A, Shoshitaishvili Y, Wang R, Bao T, Ahn GJ (2020) Honeyplc: a next-generation honeypot for industrial control systems. In: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pp 279\u2013291","DOI":"10.1145\/3372297.3423356"},{"key":"372_CR34","unstructured":"Microsoft (2021) Threat matrix for kubernetes. https:\/\/microsoft.github.io\/Threat-Matrix-for-Kubernetes\/"},{"key":"372_CR35","unstructured":"Microsoft (2024a) Detecting cryptomining attacks in the wild. https:\/\/sysdig.com\/blog\/detecting-cryptomining-attacks-in-the-wild\/"},{"key":"372_CR36","unstructured":"Microsoft (2024b) Microsoft defender for kubernetes. https:\/\/learn.microsoft.com\/en-us\/azure\/defender-for-cloud\/defender-for-kubernetes-introduction"},{"key":"372_CR37","unstructured":"MITRE (2024) Kinsing. https:\/\/attack.mitre.org\/software\/S0599\/"},{"key":"372_CR38","unstructured":"Nepenthes (2024) nepenthes. https:\/\/github.com\/jrwren\/nepenthes"},{"key":"372_CR39","unstructured":"NIST (2020) Cve-2020-15257. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-15257"},{"key":"372_CR40","unstructured":"OWASP (2024) Owasp top ten. https:\/\/owasp.org\/www-project-top-ten\/"},{"key":"372_CR41","unstructured":"Podman (2024) Podman. https:\/\/podman.io\/"},{"issue":"4","key":"372_CR42","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3579639","volume":"32","author":"A Rahman","year":"2023","unstructured":"Rahman A, Shamim SI, Bose DB, Pandita R (2023) Security misconfigurations in open source kubernetes manifests: An empirical study. ACM Transactions on Software Engineering and Methodology 32(4):1\u201336","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"372_CR43","unstructured":"Redhat (2023a) 2023 kubernetes security report. https:\/\/www.redhat.com\/en\/resources\/state-kubernetes-security-report-2023"},{"key":"372_CR44","unstructured":"Redhat (2023b) Kubernetes trends report 2023. https:\/\/www.redhat.com\/en\/resources\/kubernetes-adoption-security-market-trends-overview"},{"key":"372_CR45","unstructured":"Redhat (2024) Openshift. https:\/\/www.openshift.com\/"},{"key":"372_CR46","unstructured":"Redlock (2024) Tesla kubernetes hacked for cryptojacking. https:\/\/www.bbc.com\/news\/technology-43140005"},{"key":"372_CR47","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1007\/s10032-002-0082-8","volume":"5","author":"KU Schulz","year":"2002","unstructured":"Schulz KU, Mihov S (2002) Fast string correction with levenshtein automata. Int J Doc Anal Recogn 5:67\u201385","journal-title":"Int J Doc Anal Recogn"},{"key":"372_CR48","unstructured":"Shopify (2024) kubeaudit. https:\/\/github.com\/Shopify\/kubeaudit"},{"key":"372_CR49","doi-asserted-by":"crossref","unstructured":"Spahn N, Hanke N, Holz T, Kruegel C, Vigna G (2023) Container orchestration honeypot: Observing attacks in the wild. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, pp 381\u2013396","DOI":"10.1145\/3607199.3607205"},{"key":"372_CR50","unstructured":"spectrocloud (2023) 2023 state of production kubernetes. https:\/\/info.spectrocloud.com\/report-kubernetes-2023"},{"key":"372_CR51","unstructured":"Tetragon (2024) Tetragon. https:\/\/tetragon.io\/"},{"key":"372_CR52","unstructured":"thenewstack (2023) State of kubernetes in production. https:\/\/thenewstack.io\/the-2023-state-of-kubernetes-in-production\/"},{"key":"372_CR53","doi-asserted-by":"crossref","unstructured":"Tien CW, Huang TY, Tien CW, Huang TC, Kuo SY (2019) Kubanomaly: Anomaly detection for the docker orchestration platform with neural network approaches. Engineering reports 1(5):e12,080","DOI":"10.1002\/eng2.12080"},{"key":"372_CR54","unstructured":"VMware (2023) State of kubernetes. https:\/\/go-vmware.broadcom.com\/reg-the-state-of-kubernetes"},{"key":"372_CR55","unstructured":"Vulhub (2024) Vulhub. https:\/\/github.com\/vulhub\/vulhub"},{"key":"372_CR56","unstructured":"wikipedia (2024a) Lateral movement. https:\/\/www.cloudflare.com\/learning\/security\/glossary\/what-is-lateral-movement\/"},{"key":"372_CR57","unstructured":"wikipedia (2024b) Privilege escalation. https:\/\/bishopfox.com\/blog\/kubernetes-pod-privilege-escalation"},{"key":"372_CR58","unstructured":"Wiz (2024) Kubernetes security report 2023. https:\/\/www.wiz.io\/lp\/the-2023-kubernetes-security-report"},{"key":"372_CR59","unstructured":"Xmrig (2024) xmrig. https:\/\/github.com\/xmrig\/xmrig"},{"key":"372_CR60","doi-asserted-by":"crossref","unstructured":"Yang X, Yuan J, Yang H, Kong Y, Zhang H, Zhao J (2023) A highly interactive honeypot-based approach to network threat management. Future Internet 15:127, https:\/\/api.semanticscholar.org\/CorpusID:257827901","DOI":"10.3390\/fi15040127"},{"issue":"103","key":"372_CR61","first-page":"173","volume":"129","author":"Q Zeng","year":"2023","unstructured":"Zeng Q, Kavousi M, Luo Y, Jin L, Chen Y (2023) Full-stack vulnerability analysis of the cloud-native platform. Comput & Secur 129(103):173","journal-title":"Comput & Secur"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00372-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00372-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00372-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,25]],"date-time":"2025-08-25T02:03:45Z","timestamp":1756087425000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-025-00372-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,25]]},"references-count":61,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["372"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00372-7","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,8,25]]},"assertion":[{"value":"15 November 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 January 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 August 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"63"}}