Direkt zum Inhalt

Pfaller, Tobias ; Skopik, Florian ; Smith, Paul ; Leitner, Maria

Towards Customized Cyber Exercises using a Process-based Lifecycle Model

Pfaller, Tobias, Skopik, Florian, Smith, Paul and Leitner, Maria (2024) Towards Customized Cyber Exercises using a Process-based Lifecycle Model. In: European Interdisciplinary Cybersecurity Conference, EICC 2024, June 5-6, 2024, Xanthi, Greece.

Date of publication of this fulltext: 14 Oct 2024 09:39
Conference or workshop item
DOI to cite this document: 10.5283/epub.59246


Abstract

Cyber exercises enable the effective training of cyber security skills in a simulated, yet realistic, environment for a wide variety of professional roles. However, planning, conducting, and evaluating customized (i.e., non-standard) cyber exercise scenarios involves numerous time- and resource-intensive activities, which are still mostly carried out manually today. Unfortunately, the high costs ...

Cyber exercises enable the effective training of cyber security skills in a simulated, yet realistic, environment for a wide variety of professional roles. However, planning, conducting, and evaluating customized (i.e., non-standard) cyber exercise scenarios involves numerous time- and resource-intensive activities, which are still mostly carried out manually today. Unfortunately, the high costs related to these activities limit the practical applicability of cyber exercises to serve widely as a regular tool for skill development. Today, the flow of cyber exercise scenarios usually consists of predefined and meticulously planned injects (e.g. events) that are sequentially rolled out and thus drive the exercise. The composition of such injects resembles a linear process in its simplest form. Therefore, we argue that the utilization of existing, standardized, and well-researched methods from the business process domain provides opportunities to improve the quality of cyber exercises and at the same time reduce the workload necessary for planning and conducting them. This paper reviews the challenges related to conducting customized cyber exercises and introduces a process-based cyber exercise lifecycle model that leverages the power of process modeling languages, process engines, and process mining tools to transform cyber exercises into transparent, dynamic, and highly automated endeavors. We further describe the application of this lifecycle model in course of a proof-of-concept implementation and discuss lessons learned from its utilization at a large-scale national cyber exercise together with CERTs and authorities. While the state of the art mostly focuses on optimizing individual tasks or phases within the cyber exercise lifecycle, our contribution aims to offer a comprehensive integrated framework that spans across the phases, providing interfaces between them, and enhancing the overall effectiveness and maintainability of cyber exercises.



Involved Institutions


Details

Item typeConference or workshop item (Paper)
Publisher:ACM
Page Range:pp. 37-45
Date5 June 2024
InstitutionsInformatics and Data Science > Department Information Systems > Chair of Artificial Inteligence in IT Security (Prof. Dr. Maria Leitner)
Identification Number
ValueType
10.1145/3655693.3655713DOI
Classification
NotationType
Security and privacy → Human and societal aspects of security and privacyCCS
Applied computing → Interactive learning environmentsCCS
KeywordsCyber Exercise, Cyber Exercise Scenario, Cyber Exercise Lifecycle, Cyber Range, Process Engine
Dewey Decimal Classification000 Computer science, information & general works > 004 Computer science
StatusPublished
RefereedYes, this version has been refereed
Created at the University of RegensburgPartially
URN of the UB Regensburgurn:nbn:de:bvb:355-epub-592461
Item ID59246

Export bibliographical data

Owner only: item control page

nach oben