Teaching DNS Spoofing Attack Using a Hands-on Cybersecurity Approach Based on Virtual Kali Linux Platform

Zouheir Trabelsi, Medha Mohan Ambali Parambil, Tariq Qayyum, Ban Alomar · 2024

The realm of academic security education is primarily focused on defensive strategies. However, there's a growing acceptance of offensive techniques, initially crafted by hackers. Several educators in the field of information security believe that incorporating offensive strategies into the curriculum creates more adept security professionals than focusing solely on defensive methods. Students in information security courses must engage in offensive and defensive tactics to effectively handle malicious activities and devise suitable security measures. This paper presents a case study on executing an in-depth, practical cybersecurity laboratory exercise centered on a prevalent network attack, the DNS spoofing attack, which is vital for network security training. The primary educational goal of this hands-on lab exercise is to equip students with the skills to conduct a DNS spoofing attack within a controlled, virtual network environment using Kali Linux. The introduction of this offensive cybersecurity lab exercise resulted in enhanced student performance; however, it also raised significant ethical issues. Consequently, the paper outlines several measures that academic institutions should consider to mitigate the risks associated with teaching offensive strategies in information security education programs.

Read the paper · More papers on PaperTik