Exploiting and Securing Docker containers and Kubernetes pods from a MitM attack

arXiv:2609.16253 · cs.CR · Submitted 2026-09-14 · Read on arXiv

cs.CR

Submitted: 2026-09-14

Updated: 2026-09-14

Comments: This work was submitted in partial requirements for the degree of Msc Cybersecurity at Teesside University

License: http://creativecommons.org/licenses/by/4.0/

The gist: PURPOSE - Workloads in containers, such as Docker containers and Kubernetes pods, are vulnerable to many of the same attacks as workloads in non-container environments, including phishing,

Terminology

Abstract

PURPOSE - Workloads in containers, such as Docker containers and Kubernetes pods, are vulnerable to many of the same attacks as workloads in non-container environments, including phishing, application exploits and network intrusions. This systematic review and design-and-creation study explores techniques for securing containerised-based operating systems against Man-in-the-Middle (MitM) attacks. The proposed framework uses a conceptual model for representing communication and cryptographic primitives, together with the AnBxJ Java security library and container firewalls operating at layer 7 of the OSI model. The study addresses the question: How can containerised-based operating systems be effectively secured from Man-in-the-Middle attacks? It aims to support practitioners in protecting Docker and Kubernetes deployments by systematising security practices and applying a zero trust architecture. METHODOLOGY - The research uses a Systematic Review (SR) based on the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA), bringing together evidence from studies addressing the same research topic. FINDINGS - Success factors were identified, and a security mechanism was successfully implemented in a containerised-based operating system scenario. VALUE - The findings may help practitioners protect Kubernetes and Docker installations by systematising container security practices and providing a zero trust architecture for containerised-based operating systems.

Related papers