A platform for evaluator-centric cybersecurity training and data acquisition
Jaime C. Acosta, Joshua McKee, Alexander Fielder, Salamah Salamah · 2017
Empirical-based models for security technologies in the commercial and military domain, including those that focus on protection, detection, and broader risk analysis, leverage data captured from sensors on network-connected devices including gateways, routers, and host nodes. Lacking, however, are datasets that contain specific state observations and actions from the evaluator (red/blue teammer) workstation; we call this the inside-view. This is largely due to issues associated with data ownership, data classification, and the lack of integrated evaluator-centric data-collection mechanisms. To enable and promote creation of open datasets that capture the inside-view, we introduce a scalable platform that consists of two main elements. First, the emulation sandbox, or EmuBox, is an open-source and portable (i.e., it can execute on a laptop) solution for creating small-to medium-sized heterogeneous scenarios for evaluators to set up practice environments and competitions and to hone their skills. Second, the evaluatorcentric and extensible logger, ECEL, is a centralized management system that uses plugins for capturing and formatting evaluator data. We conclude the paper by providing a case study to demonstrate the setup and configuration of the platform along with a performance analysis.