Bypassing and Securing Kubernetes Ingress Network Policies

Apr 25, 2023

Authors
Kavyashree Ramesh, Tousif Khazi, Tejas Jaiswal

About Us
IBM PTC is a proficient internal Security Test Team responsible for vulnerability assessment & ethical hacking of web, mobile applications & infrastructure.

Abstract

Ingress network policies are an important tool for securing a Kubernetes cluster, but it is possible for an attacker to bypass a network ingress policy if they are able to find a weakness or vulnerability in the policy's implementation or if they are able to exploit a weakness in the network infrastructure itself.  In order to prevent this type of bypass, it is important to regularly review and update the network ingress policy, as well as to keep the network infrastructure itself secure through the use of firewalls, intrusion detection and prevention systems, and other security measures.

Here in this article, we will discuss a few scenarios on how to bypass Network Ingress Policies with privileged service accounts and its mitigations.

Introduction to Kubernetes

Kubernetes is a powerful tool for managing cloud workloads. With Kubernetes, we have a modern container orchestration and management engine. It allows us to create and run distributed and scalable applications. Kubernetes is resilient and highly available.

Kubernetes Architecture

Read the rest of this story with a free account.

Already have an account? Sign in

Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

1 Comment
Newest
Oldest Most Voted
© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023