arrow
返回

CyExec*: A High-Performance Container-Based Cyber Range With Scenario Randomization

delete2021-01-01
delete13
delete
OA
AI
R
Ryotaro Nakata *
A
Akira Otsuka
DOI:10.1109/ACCESS.2021.3101245delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
With increasing threats to information security, information security education through practical exercises specifically cyber range has attracted attention. However, the use of a cyber range is not widespread because of the high initial and maintenance cost and difficulty of developing new scenarios. Because many virtual instances are executed in the cyber range, the advantage of container type virtualization, which can provide a lightweight execution environment, is expected to increase efficient hardware utilization and decrease the total cost. On the other hand, containers pose challenges in scalability and scenario development when it comes to their use in cyber ranges because their performance advantages and vulnerability reproducibility have not been reported. In this paper, we conducted an exhaustive experiment to compare the performance and reproducibility of container-type virtualization with other virtualization types. The results show that containers can provide a more efficient execution environment than the other types, with almost perfect vulnerability reproducibility of more than 99% while reducing memory consumption by half and storage consumption to 1/60. The container's high performance and reproducibility enabled us to develop CyExec*, a cyber range system with DAG-based scenario randomization technology. CyExec* can increase educational effectiveness by automatically generating multiple scenarios with the same learning objective. Compared with a random scenario generator for CTF using another virtualization type, CyExec* shows more than three times higher performance. CyExec* can solve existing cyber range issues.
Keyword:
Virtualization
Containers
Hardware
Information security
Training
Security
Reproducibility of results
Container
cyber attacks
CSIRT
cyber range
Docker
incident response
information security education
virtualization technology

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

暂无机构信息
引用论文

引用论文

Red light shines a path forward on leaf minimum conductance
err2021-10-29
err0
errOAAI
errLucas A. Cernusak; Martin G. De Kauwe
err分享
err收藏
Cyber ranges and security testbeds: Scenarios, functions, tools and architecture
err2020-01-01
err123
errOAAI
errYamin, Muhammad Mudassar; Katt, Basel; Gkioulos, Vasileios
err分享
err收藏
err分享
err收藏
err分享
err收藏
没有更多内容