Published June 2, 2025 | Version v1

Koney: Cyber Deception Policies for Kubernetes

  • 1. Dynatrace Research

Contributors

  • 1. ROR icon University of Trento

Description

Manually injecting a fleet of decoys into applications and detecting access attempts to them isn’t straightforward. Kubernetes, the dominant platform for modern software development, offers a great foundation into which we can easily integrate traps to detect hackers.

This talk will introduce Koney, a first-of-its-kind operator - that is, a "plugin for Kubernetes" - that allows you to define so-called deception policies for clusters. Koney automates the setup, rotation, and teardown of honeytokens and fake API endpoints, and uses eBPF to detect, log, and forward alerts when traps have been accessed.

This talk will present how application layer cyber deception techniques can be formalized "as code" and what technical methods can be used to inject traps at runtime, all without requiring access to source code. We will continue with a live demonstration of how Koney can place honeytokens in application containers in seconds.

Participants can leave with a better understanding on how cyber deception can be formalized in policy documents and be equipped with a functional open-source tool, Koney, that lets them experiment with cyber deception in their own environments.

Files

2025-06-02 HNP 2025 - Koney - Cyber Deception Policies for Kubernetes.pdf

Additional details

Related works

Describes
Preprint: arXiv:2504.02431 (arXiv)
Conference paper: 10.1109/EuroSPW67616.2025.00084 (DOI)