KubeCap: A Framework for Capability Minimization in Kubernetes via Static Analysis and LLM-Assisted Rule Inference
cs.CR, cs.SE
Submitted: 2026-08-27
Updated: 2026-08-27
Comments: 12 pages, 5 figures, accepted to the 37th IEEE International Symposium on Software Reliability Engineering (ISSRE 2026)
Code: https://github.com/anabioticsoul/KubeCap
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- GenKubeSec: LLM-Based Kubernetes Misconfiguration Detection, Localization, Reasoning, and Remediation
- KubeGuard: LLM-Assisted Kubernetes Hardening via Configuration Files and Runtime Logs Analysis
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs