Maryam Rostamipoor

dblp:354/7992 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2025 KubeKeeper: Protecting Kubernetes Secrets Against Excessive Permissions
abstract
Kubernetes has become the dominant platform for managing containerized applications, but its native Secrets management mechanisms introduce security vulnerabilities, especially in environments where third-party applications may have excessive permissions. In this paper, we present KubeKeeper, a comprehensive solution for protecting Kubernetes Secrets against leakage due to excessive permissions. KubeKeeper automatically encrypts Secrets and ensures that only explicitly authorized Pods can access their decrypted form. This is achieved by integrating with Kubernetes’ admission control framework to transparently enforce access policies, without requiring changes to application code and with minimal integration effort into existing cluster infrastructure. We evaluated KubeKeeper on a diverse set of 498 Kubernetes applications and demonstrate that it successfully protects Secrets against all identified excessive permissions, without introducing performance degradation during execution or any significant overhead during Pod creation and deployment.
Maryam Rostamipoor, Aliakbar Sadeghi, Michalis Polychronakis
EuroS&P1
2025 LeakLess: Selective Data Protection against Memory Leakage Attacks for Serverless Platforms
Maryam Rostamipoor, Seyedhamed Ghavamnia, Michalis Polychronakis
NDSS1
2023 Confine: Fine-grained system call filtering for container attack surface reduction
Maryam Rostamipoor, Seyedhamed Ghavamnia, Michalis Polychronakis
Comput. Secur.1