| Veröffentlichte Version Download ( PDF | 430kB) | Lizenz: Creative Commons Namensnennung-NichtKommerziell-KeineBearbeitung 4.0 International |
Data Collection in Cyber Exercises Through Monitoring Points: Observing, Steering, and Scoring
Pfaller, Tobias, Skopik, Florian, Reuter, Lenhard und Leitner, Maria
(2025)
Data Collection in Cyber Exercises Through Monitoring Points: Observing, Steering, and Scoring.
In: 11th International Conference on Information Systems Security and Privacy, February 20-22, 2025, Porto, Portugal.
Veröffentlichungsdatum dieses Volltextes: 20 Mrz 2025 13:08
Konferenz- oder Workshop-Beitrag
DOI zum Zitieren dieses Dokuments: 10.5283/epub.76397
Zusammenfassung
Cyber security exercises are an essential means to train people and increase their skill levels in IT operations, cyber incident response, and forensic investigations. Unfortunately, carrying out high-quality exercises requires tremendous human effort in planning, deploying, executing and evaluating well-planned cyber exercise scenarios. While planning a scenario is often only a one time effort, ...
Cyber security exercises are an essential means to train people and increase their skill levels in IT operations, cyber incident response, and forensic investigations. Unfortunately, carrying out high-quality exercises requires tremendous human effort in planning, deploying, executing and evaluating well-planned cyber exercise scenarios. While planning a scenario is often only a one time effort, and deployment can be highly automatized today, their repeated execution and evaluation is a resource-intensive task. Usually human experts manually observe the participants to recognize any difficulties in carrying out the exercise and to keep track of the participants’ progress. This is an essential prerequisite to not only support participants during the exercise, but also to drive the scenario further through timely injects, and provide feedback after the exercise. All this manual effort makes exercises a costly activity, reduces scalability and hinders their wide adoption. We argue that with automating observations, recognizing participant progress with only little to no human effort, and even steering the delivery of customized injects, cyber exercises could be carried out much more cost-effective. In this paper, we therefore introduce the concept of monitoring points which enable the scenario-dependent collection of technical data and the calculation of behavior and progress metrics to rate participants in exercises. This is the foundational basis for steering an exercise on the one side, and evaluation on the other side. We showcase our concept and implementation in course of a demonstrator consisting of a cyber exercise comprising 14 participants and discuss its applicability.
Alternative Links zum Volltext
Beteiligte Einrichtungen
Details
| Dokumentenart | Konferenz- oder Workshop-Beitrag (Paper) | ||||
| Verlag: | SciTePress | ||||
|---|---|---|---|---|---|
| Seitenbereich: | S. 355-366 | ||||
| Datum | 2025 | ||||
| Institutionen | Informatik und Data Science Informatik und Data Science > Fachbereich Wirtschaftsinformatik > Lehrstuhl für KI in der IT-Sicherheit (Prof. Dr. Maria Leitner) | ||||
| Identifikationsnummer |
| ||||
| Stichwörter / Keywords | Cyber Exercise, Cyber Exercise Scenario, Participant Observation, Activity Monitoring, Cyber Exercise Evaluation, Cyber Scenario Steering Innovative Security Awareness and Education; Security and Privacy Metrics; Threat Awareness; Vulnerability Analysis and Countermeasures | ||||
| Dewey-Dezimal-Klassifikation | 000 Informatik, Informationswissenschaft, allgemeine Werke > 004 Informatik | ||||
| Status | Veröffentlicht | ||||
| Begutachtet | Ja, diese Version wurde begutachtet | ||||
| An der Universität Regensburg entstanden | Zum Teil | ||||
| URN der UB Regensburg | urn:nbn:de:bvb:355-epub-763973 | ||||
| Dokumenten-ID | 76397 |
Downloadstatistik
Downloadstatistik