A platform for evaluator-centric cybersecurity training and data acquisition

Jaime C. Acosta, Joshua McKee, Alexander Fielder, S. Salamah
{"title":"A platform for evaluator-centric cybersecurity training and data acquisition","authors":"Jaime C. Acosta, Joshua McKee, Alexander Fielder, S. Salamah","doi":"10.1109/MILCOM.2017.8170768","DOIUrl":null,"url":null,"abstract":"Empirical-based models for security technologies in the commercial and military domain, including those that focus on protection, detection, and broader risk analysis, leverage data captured from sensors on network-connected devices including gateways, routers, and host nodes. Lacking, however, are datasets that contain specific state observations and actions from the evaluator (red/blue teammer) workstation; we call this the inside-view. This is largely due to issues associated with data ownership, data classification, and the lack of integrated evaluator-centric data-collection mechanisms. To enable and promote creation of open datasets that capture the inside-view, we introduce a scalable platform that consists of two main elements. First, the emulation sandbox, or EmuBox, is an open-source and portable (i.e., it can execute on a laptop) solution for creating small-to medium-sized heterogeneous scenarios for evaluators to set up practice environments and competitions and to hone their skills. Second, the evaluatorcentric and extensible logger, ECEL, is a centralized management system that uses plugins for capturing and formatting evaluator data. We conclude the paper by providing a case study to demonstrate the setup and configuration of the platform along with a performance analysis.","PeriodicalId":113767,"journal":{"name":"MILCOM 2017 - 2017 IEEE Military Communications Conference (MILCOM)","volume":"10 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"MILCOM 2017 - 2017 IEEE Military Communications Conference (MILCOM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MILCOM.2017.8170768","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

Empirical-based models for security technologies in the commercial and military domain, including those that focus on protection, detection, and broader risk analysis, leverage data captured from sensors on network-connected devices including gateways, routers, and host nodes. Lacking, however, are datasets that contain specific state observations and actions from the evaluator (red/blue teammer) workstation; we call this the inside-view. This is largely due to issues associated with data ownership, data classification, and the lack of integrated evaluator-centric data-collection mechanisms. To enable and promote creation of open datasets that capture the inside-view, we introduce a scalable platform that consists of two main elements. First, the emulation sandbox, or EmuBox, is an open-source and portable (i.e., it can execute on a laptop) solution for creating small-to medium-sized heterogeneous scenarios for evaluators to set up practice environments and competitions and to hone their skills. Second, the evaluatorcentric and extensible logger, ECEL, is a centralized management system that uses plugins for capturing and formatting evaluator data. We conclude the paper by providing a case study to demonstrate the setup and configuration of the platform along with a performance analysis.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
一个以评估人员为中心的网络安全培训和数据采集平台
商业和军事领域安全技术的基于经验的模型,包括那些专注于保护、检测和更广泛的风险分析的模型,利用从网络连接设备(包括网关、路由器和主机节点)上的传感器捕获的数据。然而,缺少包含评估者(红/蓝队员)工作站的特定状态观察和动作的数据集;我们称之为内景。这主要是由于与数据所有权、数据分类以及缺乏以评估者为中心的集成数据收集机制相关的问题。为了支持和促进捕获内部视图的开放数据集的创建,我们引入了一个可扩展的平台,该平台由两个主要元素组成。首先,仿真沙箱,或EmuBox,是一个开源和便携的(即,它可以在笔记本电脑上执行)解决方案,用于创建小型到中型的异构场景,供评估人员设置实践环境和比赛,并磨练他们的技能。其次,以评估器为中心的可扩展日志记录器ECEL是一个集中式管理系统,它使用插件来捕获和格式化评估器数据。我们通过提供一个案例研究来演示平台的设置和配置以及性能分析来结束本文。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Improved target-tracking process in PCL Evasion and causative attacks with adversarial deep learning Performance of selection DF scheme for a relay system with non-identical Rician fading Single-channel blind separation of co-frequency PSK signals with unknown carrier frequency offsets Design of a software defined radio-based tactical DSA network
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1