【24h】

Design Considerations for Cyber Security Testbeds: A Case Study on a Cyber Security Testbed for Education

机译:网络安全测试平台的设计注意事项:以教育网络安全测试平台为例

获取原文
获取原文并翻译 | 示例

摘要

Educational testbeds have been developed for many years. Within the past ten years, the development of cloud-based storage architectures as well as the facilitation of memory and storage technology allowed for the building of small to medium-sized testbeds at low or medium cost. These developments provide the foundation for the development of educational testbeds that can be used for cyber security training and exercise of various target groups (e.g., students, IT professionals, engineers) in many domains (e.g., cyber security, IoT, Industry 4.0). Testbeds have been well established within the information security community (e.g., malware analysis, cyber security experimentation, etc.). However, these testbeds often require a certain level of maintenance or resources and were therefore not often used in non-expert communities. However, it is essential that testbeds gain a wider audience in order to enable many different groups cyber security skills and competencies. In this paper, we analyze how an educational testbed could be designed by (1) examining established testbeds in research and education and (2) analyzing how typical testbeds are designed. Based on this, we propose a design life cycle, i.e. a methodology to facilitate the development of cyber security testbeds. We demonstrate our findings in a case study. In the study, we designed and implemented a cyber security testbed for educational purposes using open source technology. The results and reviewed literature validate the design life cycle and show dependencies between the underlying technology of the testbed and the designed challenges. These findings contribute to the overall development of testbeds and can be used as basis for future work. We plan to further extend this testbed in order to develop an automated and flexible cyber security testbed.
机译:教育测试平台已经开发了很多年。在过去的十年中,基于云的存储体系结构的发展以及对内存和存储技术的促进,使得能够以中低成本构建中小型测试平台。这些发展为教育测试平台的开发奠定了基础,这些测试平台可用于网络安全培训以及在许多领域(例如网络安全,物联网,工业4.0)的各个目标群体(例如学生,IT专业人员,工程师)的锻炼。在信息安全社区内已经建立了良好的测试平台(例如,恶意软件分析,网络安全实验等)。但是,这些测试平台通常需要一定程度的维护或资源,因此在非专家社区中并不经常使用。但是,至关重要的是,测试平台必须具有更广泛的受众,才能使许多不同的群体拥有网络安全技能和能力。在本文中,我们通过(1)在研究和教育中检查已建立的测试平台,以及(2)分析如何设计典型测试平台来分析如何设计教育测试平台。基于此,我们提出了一个设计生命周期,即一种促进网络安全测试平台开发的方法。我们通过案例研究证明我们的发现。在这项研究中,我们使用开放源代码技术设计并实现了用于教育目的的网络安全测试平台。结果和经过审查的文献验证了设计生命周期,并显示了测试床的基础技术与设计挑战之间的依赖性。这些发现有助于测试平台的整体发展,并可作为未来工作的基础。我们计划进一步扩展该测试平台,以开发一个自动化且灵活的网络安全测试平台。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号