Rebecca Acheampong, T. Balan, D. Popovici, Alexandre Rekeraho
{"title":"使用Ansible实现虚拟环境中的安全场景自动化和部署","authors":"Rebecca Acheampong, T. Balan, D. Popovici, Alexandre Rekeraho","doi":"10.1109/comm54429.2022.9817150","DOIUrl":null,"url":null,"abstract":"Cyber security is a 21st-century challenge doubled by the risk introduced by the lack of cyber security workforce. To bridge this workforce gap, cyber security learning environment are necessary. The Cyber range is cyber virtual environment for security training for cyber security professionals. This study presents the next-generation tools for developing Cyber ranges in the cloud and integrates automation with Ansible hence, orchestrating the virtual environment for the efficacy of security testsbeds, equipping the user with cyber security readiness to defend against real-life cyber-attacks. The proposed automation methodology can be also incorporated in continuous integration queues, defining the Infrastructure as Code (IaC) DevSecOps strategy. The developed scalable and reusable platform allows malicious cyber activities to be simulated through automation. The exercises and the tools employed gives security professionals a good understanding of adversary's operations. while the vulnerabilities are mapped to MITRE ATT &CK knowledge base. Our results show that, the developed Cyber range platform is suitable and effective for cyber security training. Notwithstanding, we propose future studies be carried out to look into cyber security problematic in virtual reality (VR) platforms.","PeriodicalId":118077,"journal":{"name":"2022 14th International Conference on Communications (COMM)","volume":"77 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-06-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Security Scenarios Automation and Deployment in Virtual Environment using Ansible\",\"authors\":\"Rebecca Acheampong, T. Balan, D. Popovici, Alexandre Rekeraho\",\"doi\":\"10.1109/comm54429.2022.9817150\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Cyber security is a 21st-century challenge doubled by the risk introduced by the lack of cyber security workforce. To bridge this workforce gap, cyber security learning environment are necessary. The Cyber range is cyber virtual environment for security training for cyber security professionals. This study presents the next-generation tools for developing Cyber ranges in the cloud and integrates automation with Ansible hence, orchestrating the virtual environment for the efficacy of security testsbeds, equipping the user with cyber security readiness to defend against real-life cyber-attacks. The proposed automation methodology can be also incorporated in continuous integration queues, defining the Infrastructure as Code (IaC) DevSecOps strategy. The developed scalable and reusable platform allows malicious cyber activities to be simulated through automation. The exercises and the tools employed gives security professionals a good understanding of adversary's operations. while the vulnerabilities are mapped to MITRE ATT &CK knowledge base. Our results show that, the developed Cyber range platform is suitable and effective for cyber security training. Notwithstanding, we propose future studies be carried out to look into cyber security problematic in virtual reality (VR) platforms.\",\"PeriodicalId\":118077,\"journal\":{\"name\":\"2022 14th International Conference on Communications (COMM)\",\"volume\":\"77 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-06-16\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 14th International Conference on Communications (COMM)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/comm54429.2022.9817150\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 14th International Conference on Communications (COMM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/comm54429.2022.9817150","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
摘要
网络安全是一项21世纪的挑战,缺乏网络安全人员带来的风险使其成倍增加。为了弥补这一劳动力缺口,网络安全学习环境是必要的。Cyber靶场是为网络安全专业人员提供安全培训的网络虚拟环境。本研究提出了用于在云中开发网络范围的下一代工具,并将自动化与Ansible集成,从而为安全测试平台的有效性编排虚拟环境,为用户提供网络安全准备,以抵御现实生活中的网络攻击。建议的自动化方法也可以合并到持续集成队列中,定义基础设施即代码(IaC) DevSecOps策略。开发的可扩展和可重用平台允许通过自动化模拟恶意网络活动。演习和使用的工具使安全专业人员对对手的行动有了很好的了解。同时将漏洞映射到MITRE ATT &CK知识库。结果表明,所开发的网络靶场平台适用于网络安全培训,效果良好。尽管如此,我们建议未来进行研究,以调查虚拟现实(VR)平台中的网络安全问题。
Security Scenarios Automation and Deployment in Virtual Environment using Ansible
Cyber security is a 21st-century challenge doubled by the risk introduced by the lack of cyber security workforce. To bridge this workforce gap, cyber security learning environment are necessary. The Cyber range is cyber virtual environment for security training for cyber security professionals. This study presents the next-generation tools for developing Cyber ranges in the cloud and integrates automation with Ansible hence, orchestrating the virtual environment for the efficacy of security testsbeds, equipping the user with cyber security readiness to defend against real-life cyber-attacks. The proposed automation methodology can be also incorporated in continuous integration queues, defining the Infrastructure as Code (IaC) DevSecOps strategy. The developed scalable and reusable platform allows malicious cyber activities to be simulated through automation. The exercises and the tools employed gives security professionals a good understanding of adversary's operations. while the vulnerabilities are mapped to MITRE ATT &CK knowledge base. Our results show that, the developed Cyber range platform is suitable and effective for cyber security training. Notwithstanding, we propose future studies be carried out to look into cyber security problematic in virtual reality (VR) platforms.