SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKubernetes security is a complex subject that relies on well-designed Role-Based Access Control (RBAC). Kubernetes service account tokens contain the permissions an application utilizes to authenticate and perform actions in a Kubernetes environment. Research highlights how these tokens can be used individually within containers. However, more research is needed on how these tokens can be used en-masse from a compromised host to escalate privileges and gain control of a Kubernetes cluster. This paper explores the privileges requested by many popular applications today and showcases how their service accounts are utilized to compromise a Kubernetes environment further.