Election Security in the Cloud: A CTF Activity to Teach Cloud and Web Security

Zachary Romano, Jennifer Windsor, Mathew VanDerPol, Joel Coffman · 2021 IEEE Frontiers in Education Conference (FIE) · 2021

In this innovative practice work in progress (WIP) paper, we present a novel capture the flag (CTF) activity to teach students about the potential pitfalls and consequences of cloud misconfiguration. While cloud computing has proved an attractive option in terms of pricing, availability, and scalability, potential cloud consumers must equally weigh the security concerns of a cloud environment. The real-world consequences of misconfigurations are self-evident; cloud consuming companies that suffer a misconfiguration-related breach lose data, time, money, and trust from their customers. However, breaches due to misconfiguration are common, and this prevalence starts with inadequate education. Existing resources in cloud computing courses do not provide sufficient urgency, depth, or engagement when covering cloud security. Consequently, we created a CTF activity that has students pose as malicious actors who seek to compromise an election application running on a cloud environment. We believe that students who complete our CTF activity will have a deeper understanding of the potential pitfalls and consequences of cloud misconfiguration and a better understanding of how to protect against such issues in their own applications, and we are currently evaluating the extent to which our CTF activity achieves these goals.

Read the paper · More papers on PaperTik