Research Article

Context-Aware Threat Hunting in Kubernetes Clusters: A Behavioral Profiling Approach using Extended Berkeley Packet Filter (eBPF) and Graph Neural Networks

17 reads
SciMatic J Cybersec Digit Forensics, 2026, 1 (1), 63-69, doi: , ISSN

Abstract

The rapid adoption of microservice architectures orchestrated via Kubernetes has introduced unprecedented operational complexity and expanded the enterprise attack surface. Traditional intrusion detection and digital forensic mechanisms often fail within cloud-native environments due to high container churn, dynamic IP allocation, and significant computational overhead. In this paper, we propose a context-aware threat hunting framework that combines low-overhead kernel telemetry via Extended Berkeley Packet Filter (eBPF) with Heterogeneous Graph Neural Networks (HGNNs) for fine-grained behavioral profiling. Our architecture intercepts low-level system call sequences and socket lifecycle events in real time, enriching them with orchestration-level metadata, including namespace, pod, and service-account contexts. We construct dynamic provenance graphs that capture the multi-layered interactions between host kernel primitives and Kubernetes abstractions. Using a relational graph convolutional network with temporal attention, our model learns structural and sequential patterns of benign cluster behavior to detect subtle anomalies indicative of advanced persistent threats, privilege escalation, and lateral movement. Evaluated on a production-grade multi-node Kubernetes testbed subjected to diverse real-world attack scenarios, our approach achieved an F1-score of 0.968, outperforming state-of-the-art signature-based and baseline anomaly detection tools while maintaining a negligible CPU overhead of under 2.4%.

Keywords Graph Neural Networks eBPF Container Forensics Kubernetes Security Threat Hunting
Authors 2

The team behind this paper

2 authors, 2 institutions.

This paper King Fahd University of Petroleum and Minerals — Saudi Arabia King Fahd University of… 1 author Tallinn University of Technology — Estonia Tallinn University of T… 1 author Prof. Tariq Al-Mansoor — corresponding author TA Prof. Tariq Al-Mansoor ✉ Dr. Elena Rostova ER Dr. Elena Rostova

Readership

17 reads over 1 month.

#8 most read in this journal this month
17
August 2026

Blockchain Confirmation

Loading...
If you want to upload this article to SciMatic Hybrid Blockchain, install MetaMask extension to your web browser, create a wallet and buy SCI coins at SciMatic using credit or contact your country coordinator.
One article costs 10 SCI coins to be in the Blockchain. Buy SCI Coins

Bibliographic Information

Prof. Tariq Al-Mansoor, Dr. Elena Rostova, (2026). Context-Aware Threat Hunting in Kubernetes Clusters: A Behavioral Profiling Approach using Extended Berkeley Packet Filter (eBPF) and Graph Neural Networks, SciMatic Journal of Cybersecurity and Digital Forensics, 1(1): 63-69
Bibtex Citation
@article{prof._tariq_al-mansoor2026sjcdf,
author = {Prof. Tariq Al-Mansoor and Dr. Elena Rostova},
title = {Context-Aware Threat Hunting in Kubernetes Clusters: A Behavioral Profiling Approach using Extended Berkeley Packet Filter (eBPF) and Graph Neural Networks},
journal = {SciMatic Journal of Cybersecurity and Digital Forensics},
year = {2026},
volume = {1},
number = {1},
pages = {63-69},
doi = {},
url = {https://scimatic.org/show_manuscript/9706}
}
APA Citation
Al-Mansoor, P.T., Rostova, D.E., (2026). Context-Aware Threat Hunting in Kubernetes Clusters: A Behavioral Profiling Approach using Extended Berkeley Packet Filter (eBPF) and Graph Neural Networks. SciMatic Journal of Cybersecurity and Digital Forensics, 1(1), 63-69. https://doi.org/

Author Information

  • To change your profile photo, login to scimatic.org, go to your profile and change the photo.
  • Provide a face photo, and not full body.
  • It is better to remove the background from your photo. Go to Remove Background and then upload to profile
  • If you are unable to login, go to Reset My Password provide your email registered with the article and get new password.
  • In case of any other problem, contact your editor directly or write to us at info @ scimatic.org