Skip to main navigation Skip to search Skip to main content

A Comparative Study of Security Mechanisms to Prevent Denial of Service (Dos) Attacks in Kubernetes

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Kubernetes is a powerful and widely used container orchestration platform. However, its popularity also makes it an attractive target for cybersecurity attacks such as Denial-of-Service (DoS), which can significantly disrupt the services and operations of organizations. To help to improve the security practices of Kubernetes-based clusters, we present a comparative study in which we systematically evaluated six popular security defense mechanisms (i.e., Rate Limiting, Resource Quotas, Network Policies, Role-Based Access Control, API Rate Limiting, and Service Meshes) against DoS attacks. Using a controlled test environment with Minikube, we assess each mechanism's effectiveness at blocking attacks, its performance overhead, and its operational complexity. Our results show that no single mechanism is sufficient on its own; instead, a layered combination yields the strongest defense. We conclude with actionable guidance for practitioners on selecting and integrating these mechanisms to enhance Kubernetes resilience against DoS threats.

Original languageEnglish
Title of host publicationProceedings - 2025 13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025
EditorsReyes Juarez-Ramirez, Carlos Fernandez y Fernandez, Samantha Jimenez, Alan Ramirez-Noriega, Cesar Guerra-Garcia, Guillermo Licea Sandoval, Jorge Octavio Hernandez-Ocharan, Elvia Aispuro-Felix, Abhishek Kumar, Manuel Alejandro Pastrana Pardo
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages223-232
Number of pages10
ISBN (Electronic)9798331567286
DOIs
Publication statusPublished - 2025
Event13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025 - La Paz, Mexico
Duration: 27 Oct 202531 Oct 2025

Publication series

NameProceedings - 2025 13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025

Conference

Conference13th International Conference in Software Engineering Research and Innovation, CONISOFT 2025
Country/TerritoryMexico
CityLa Paz
Period27/10/2531/10/25

Keywords

  • Cybersecurity
  • Denial-of-Service
  • Kubernetes
  • Secure Software Engineering

Fingerprint

Dive into the research topics of 'A Comparative Study of Security Mechanisms to Prevent Denial of Service (Dos) Attacks in Kubernetes'. Together they form a unique fingerprint.

Cite this