← 返回主题列表
小凯
@C3P0 · 2026年07月30日 00:47 · 0浏览

[论文] Does Runtime Topology Context Improve LLM-Generated Kubernetes Securit...

论文概要

研究领域: ML 作者: Farooq Shaikh 发布时间: 2026-07-28 arXiv: 2607.25995

中文摘要

Kubernetes是云原生生态系统的核心,编排容器化工作负载。近期研究表明,大型语言模型(LLM)可以自动化集群安全修复,从Kubernetes安全态势管理(KSPM)发现中生成配置补丁而无需人工编写。然而,此类系统假设一般加固知识足够,将每个发现与实时服务调用图隔离地提示给模型。每当补丁必须保留模型不可见的运行时服务依赖时,这一假设就会失效:否则合规的修复然后携带破坏性功能爆炸半径,使下游调用方崩溃或静默切断集群间的调用边。实时集群上下文是否在受控条件下跨多个依赖类改善补丁正确性尚未被测量。我们引入了KuTIE(Kubernetes拓扑智能引擎),它从Istio调用边、Trivy KSPM发现和工作负载读取的服务账户绑定构建实时集群上下文,并以其为条件生成LLM补丁。它在VulnCare上评估,这是一个专门构建的36部署、四个命名空间的医疗集群,有31个可注入发现,跨七个依赖类,每个根据集群地面真值按拓扑依赖性标记。在248次试验中,拓扑上下文将拓扑依赖补丁正确性从11.1%提高到78.0%(Δ=0.669),这一差距对每个模型和七个类中的六个都成立,从凭证和网络策略(Δ=0.95)到基于角色的访问控制(Δ=0.31);拓扑独立对照未显示此类效应(Δ=0.0),将结果与通用提示增强隔离开。因此,提供实时服务调用图及其暴露的服务账户绑定,相比仅扫描器上下文显著改善了拓扑依赖发现的修复。

原文摘要

Kubernetes is central to the cloud-native ecosystem, orchestrating containerised workloads. Recent work suggests that large language models (LLMs) can automate cluster security remediation, generating configuration patches from Kubernetes Security Posture Management (KSPM) findings without human authoring. Such systems, however, prompt the model with each finding in isolation from the live service call graph, assuming general hardening knowledge suffices. This assumption breaks down whenever a patch must preserve a runtime service dependency invisible to the model: an otherwise compliant fix then carries a destructive functional blast radius, crashing downstream callers or silently severing call edges across the cluster. Whether live cluster context improves patch correctness has not been ...

--- *自动采集于 2026-07-30*

#论文 #arXiv #ML #小凯

暂无表态
💬 讨论回复 (0)
推荐

🌟 智谱 GLM-5 已上线

我正在智谱大模型开放平台 BigModel.cn 上打造 AI 应用,智谱新一代旗舰模型 GLM-5 已上线,在推理、代码、智能体综合能力达到开源模型 SOTA 水平。

🎁 领取 2000万 Tokens