Cyber Range Infrastructure Limitations and Needs of Tomorrow: A Position Paper

Vincent E. Urias, William M. S. Stout, Brian P. Van Leeuwen, Han Lin · 2018

Cyber networks are extremely non-deterministic, complex systems. To address this, we must develop foundational research protocols to enable reproducible cyber experiments that can systematically uncover deep understanding of a cyber system's security posture. One core tenant of this approach is to have a test environment to enable a space to create and test hypotheses about systems and reason about results. To date, this has generally been done through cyber testbeds or cyber ranges. National infrastructure supported by various government agencies have all created multi-million dollar ranges, and support other national infrastructure such as the National Cyber Range (NCR) and the Regional Service Delivery Points (RSDP). The thrust of this paper was based on multi-year studies, the culmination of which uncovered gaps and challenges associated with using various national infrastructures to represent a multitude of complex heterogeneous systems. Ranges, such as the NCR, have experiment life-cycle processes to take a cyber experiment from inception to analysis. However, our position is that processes used are not sufficient to address gaps and challenges. In this position paper, we review current range experiment methodologies and our observations of other considerations that should require inclusion.

Read the paper · More papers on PaperTik