A model of risk-aware scheduling in container orchestrators considering the attacker’s horizontal movement
Common container orchestrator schedulers focus on resource metrics and distribution policies, ignoring the security risks associated with lateral movement between containers and cluster nodes. This paper presents a risk-based pod placement model that accounts for three channels of lateral movement: shared system calls on a node (risk of container escape), role-based access control mismatches, and network interactions between pods. Probabilistic estimates of container compromise are introduced as a function of node security. A greedy algorithm for sequential container assignment suitable for use in real-world schedulers is proposed. A comparative analysis with leading approaches to securing container environments is provided. The results of this study can be applied for the development of Kubernetes scheduler extensions that integrate placement-level security.


