Cyberspace exercises: defending against malicious cyber actors
Kelly W. Bennett, James Robertson · 2023
Malicious cyber actors are well-prepared and trained to negatively impact organizations, assets, or individuals. Training exercises help to mitigate these adverse effects by enabling cyber defense analysts to demonstrate their abilities to respond to cyber incidents in real-time. When a security incident occurs, the response team must quickly contain the situation, diagnose the problem, and return to a previous good state so the system down time is minimized, and the issue does not spread to other systems. Training exercises allow both red (attack) and blue (defense) teams to practice in a secure, isolated environment ensuring all team members have the necessary experience if and when incidents occur. This paper describes simulated cybersecurity research scenarios based on open-source data repositories of adversary tactics and techniques including published frameworks by MITRE and NIST. Artificial Intelligence/Machine Learning (AI/ML) techniques and methods supporting cybersecurity research will also be discussed with an emphasis towards cloud environment frameworks. Results from using AL/ML techniques, cloud-based tools and methods, cyber tabletop exercises for cybersecurity research scenarios and use cases will be included.