An Empirical Study and Benchmark of Kubernetes Misconfiguration Scanners
Haeun Eom, Bohyun Suk, Sungjae Hwang
Abstract
Kubernetes is a widely adopted container orchestration framework, yet misconfigurations remain a leading cause of cloud security incidents and a major challenge for practitioners. Automated security scanners are commonly used to detect such misconfigurations, but their effectiveness has not been systematically evaluated. As a result, it remains unclear which tools can be trusted, what misconfigurations they reliably detect, and to what extent they improve Kubernetes security. This paper presents the first systematic investigation of ten prominent Kubernetes security scanners that are actively used in practice. We begin by examining the misconfigurations that each scanner claims to detect. Although scanners provide documentation of their coverage, these descriptions are written in natural language and are often ambiguous, making it unclear what is actually detected. To address this issue, we manually analyze scanner implementations to identify their precise detection targets and validate them through dynamic testing. Our analysis reveals that scanners frequently adopt different criteria for the same documented misconfiguration, exposing significant inconsistencies caused by ambiguous specifications. Building on these results, we introduce the first comprehensive benchmark for Kubernetes misconfigurations, covering all misconfigurations targeted by the ten scanners. The benchmark includes 4,109 misconfiguration files for static and dynamic analysis and 144 shell scripts for dynamic analysis, encompassing 281 unique misconfigurations. Using this benchmark, we conducted an empirical evaluation of ten scanners. Our results show that, in static scanning, Kubescape achieves the highest recall (43.8%), and it also performs best in dynamic analysis with an recall of 62.3%. We further analyze the strengths and limitations of each scanner, identifying coverage gaps that significantly affect detection effectiveness. Our findings provide practical guidance for practitioners selecting Kubernetes security scanners and highlight key challenges that should be addressed by the software engineering community. Moreover, the proposed benchmark establishes a foundation for future research on Kubernetes security.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bb710109-9cfb-4585-92e2-06590525f3b7Related papers
- On Prescription or Off Prescription? An Empirical Study of Community-Prescribed Security Configurations for KubernetesShazibul Islam Shamim, Hanyang Hu, Akond RahmanICSE 2025 · 4 citations
- Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in KubernetesNanzi Yang, Xingyu Liu, Wenbo Shen, Jinku Li et al.CCS 2025
- Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes OperatorsAndong Chen, Ziyi Guo, Zhaoxuan Jin, Zhenyuan Li et al.NDSS 2026 · 2 citations
- Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration ChallengesSumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz et al.NDSS 2026 · 3 citations
- Quantifying Frontier LLM Capabilities for Container Sandbox EscapeRahul Marchand, Art Cathain, Jerome Wynne, Philippos Giavridis et al.ICML 2026 · 9 citations
