Exploring Cyber Range Platforms: Innovations in Cybersecurity Education, Research, and Beyond

Rasmi-Vlad Mahmoud · 2025

In recent years, the growing interest in cybersecurity has transformed the timing and approach to education in the field.Cybersecurity education now begins progressively in schools, often through games, and evolves into lectures and hands-on training at higher levels.The field perfectly suits active learning approaches, in which learners engage with educational content through discussions, collaborative tasks, or interactive exercises.Key technologies in this approach are cyber ranges.These virtual environments can mimic real-world IT infrastructure and offer a dynamic environment to explore and train in real cyber security scenarios, whether defensive, offensive or collaborative, within a secure framework.This thesis explores the role of cyber range platforms in educational and research settings, with a specific focus on their features and applications.It introduces DefAtt, a cyber range platform, highlighting its key attributes and integrating gamification to help the educational process.The emphasis is on how these platforms can significantly improve cybersecurity education, making it more engaging and effective.Consequently, cyber ranges are versatile technologies that can facilitate multiple roles within the cybersecurity sector.Specifically, they enhance the "Detect" function by offering a restrained study, testing, and training environment.This controlled environment facilitates the simulation of actual cyber threats and the formulation of effective risk mitigation and management procedures.Detection is vital for safeguarding an organization's assets.It involves continuous monitoring of the organization's ICT infrastructure and applications to maintain visibility and promptly identify any security incidents.This thesis presents an overview of contemporary approaches and methodologies for infrastructure monitoring within cybersecurity, with particular emphasis on security information event management (SIEM) systems.The methods converge around the Elastic-Logstash-Kibana stack to collect, process, and correlate various log sources, which are crucial for threat detection.Ultimately, the thesis provides directions on how this data might be further used for cybersecurity.The second focus of this thesis moves towards anti-malware research, preiii cisely dynamic malware analysis using the same SIEM systems but building upon existing open-source platforms.Traditional sandboxes generally are nonrealistic and non-transparent, whereas cyber ranges maintain the same characteristics over iterations.Moreover, they are changing the analysis perspective by simulating interactions between multiple systems to make analysis more realistic and practical.This thesis also leverages the suggested ecosystem to gather, organize, and synthesize malware activity into the AAU_MalData dataset.This dataset is carefully formatted and timestamped, with a chronological system activity log.It captures granular information, such as event descriptions, process and file behaviour, and registry changes.It provides a rich landscape for analyzing and comprehending malware activity.This journey has been much more than writing a thesis.It has been a mix of emotions, powered by many cups of tea and, later, driven by coffee.However, none would have been possible without the support of various people in my life.This is a big THANK YOU to all of you who have contributed to this, from meetings during COVID to laughter and drinks during conferences.This PhD would not have existed without Jens, who invested a lot of time mentoring me when I moved to Denmark.Over the years, his enthusiasm has not changed; he has the same energy and has kept being visionary.One of the things I have always admired is his ability to remain calm and fair.I have challenged that over the years way too many times, but somehow Jens managed to always be understanding and ready to help in any way he could.Oh, and I almost forgot, thank you for convincing me to move to Copenhagen, it was an excellent decision.Continuing on the supervisor's thread, Egon was my co-supervisor at the beginning of my PhD when everything was new, and many questions popped into my mind.He guided me through those moments and thought that I should not sweat the small things.In addition, Marios came in and I am very grateful for this.I like his approach towards big problems, his "step-by-step" strategy and I am thankful for being there, either acting as a sparing partner to generate new ideas or asking the correct questions to bring me back on track.However, my external stay would not have been possible without Sergio, the breath of fresh air I needed to reignite my desire to research.Sergio and the whole lab welcomed me to their research group and made my stay at UCM3 wonderful.Sergio and I worked together in designing the last part of this PhD, which was later finished back home, but he continued the collaboration, being involved even after my stay had ended.I am grateful for the chance to befriend and work with him.Besides being a fine researcher, he is a very friendly person.During my PhD, I was fortunate to have two "stations".I started the PhD in Aalborg, where I was part of the WCN section, helped and guided by the people from the A3 corridor

Read the paper · More papers on PaperTik