论文标题

网络范围和测试床的评论:当前和未来趋势

A Review of Cyber-Ranges and Test-Beds: Current and Future Trends

论文作者

Ukwandu, Elochukwu, Farah, Mohamed Amine Ben, Hindy, Hanan, Brosset, David, Kavallieros, Dimitris, Atkinson, Robert, Tachtatzis, Christos, Bures, Miroslav, Andonovic, Ivan, Bellekens, Xavier

论文摘要

事实证明,网络情境意识在对组织内部的威胁和脆弱性中的全面理解中具有价值,因为曝光程度受网络杂种和既定流程的普遍水平的控制。对安全规定的更准确评估将为需要更加勤奋管理的最脆弱环境提供信息。网络攻击自动化的快速扩散正在减少信息和操作技术之间的差距,并需要审查针对新的复杂网络攻击,趋势,技术和缓解反应的当前鲁棒性水平。更深入的表征也是预测未来漏洞的基础,反过来指导最合适的部署技术。因此,令人耳目一新的实践和培训范围以支持用户和运营商的决策。培训条款的基础是使用网络范围(CRS)和测试床(TBS),平台/工具,这些平台/工具有助于深入了解攻击的演变以及将最有影响力的对策部署以逮捕违规行为的方法。在本文中,评估了记录的CR和TB平台的评估。 CRS和TBS按类型,技术,威胁场景,应用程序和可达到的培训范围进行细分。为了丰富对CR和结核病研究的分析,并加以研究,开发了分类法,以更广泛地理解CRS和TBS的未来。分类法对CRS/TBS的不同维度进行了详细说明,并强调了应用区域之间的分化减少。

Cyber situational awareness has been proven to be of value in forming a comprehensive understanding of threats and vulnerabilities within organisations, as the degree of exposure is governed by the prevailing levels of cyber-hygiene and established processes. A more accurate assessment of the security provision informs on the most vulnerable environments that necessitate more diligent management. The rapid proliferation in the automation of cyber-attacks is reducing the gap between information and operational technologies and the need to review the current levels of robustness against new sophisticated cyber-attacks, trends, technologies and mitigation countermeasures has become pressing. A deeper characterisation is also the basis with which to predict future vulnerabilities in turn guiding the most appropriate deployment technologies. Thus, refreshing established practices and the scope of the training to support the decision making of users and operators. The foundation of the training provision is the use of Cyber-Ranges (CRs) and Test-Beds (TBs), platforms/tools that help inculcate a deeper understanding of the evolution of an attack and the methodology to deploy the most impactful countermeasures to arrest breaches. In this paper, an evaluation of documented CR and TB platforms is evaluated. CRs and TBs are segmented by type, technology, threat scenarios, applications and the scope of attainable training. To enrich the analysis of documented CR and TB research and cap the study, a taxonomy is developed to provide a broader comprehension of the future of CRs and TBs. The taxonomy elaborates on the CRs/TBs different dimensions, as well as, highlighting a diminishing differentiation between application areas.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源