Experiences in Cyber Security Education: The MIT Lincoln Laboratory Capture-the-Flag Exercise

Experiences in Cyber Security Education: The MIT Lincoln Laboratory Capture-the-Flag Exercise
复制标题

网络安全教育经验:麻省理工学院林肯实验室夺旗演习

DOI:
--
复制
发表时间:
2011
期刊:
CSET
影响因子:
--
通讯作者:
Nickolai Zeldovich
Nickolai Zeldovich
中科院分区:
--
文献类型:
--
作者:
Joseph Werther;M. Zhivich;T. Leek;Nickolai Zeldovich

文献摘要

被引文献

相似文献

许多流行和成熟的网络安全捕获国旗(CTF)演习每年在各种环境中举行,包括大学和半专业安全会议。CTF的形式也有很大的不同,从线性拼图般的挑战,以团队为基础的进攻和防守自由的黑客比赛。虽然这些活动是令人兴奋和重要的技能竞赛,他们提供有限的教育机会。特别是,由于参与需要大量的先验领域知识和实用的计算机安全专业知识,大多数典型的计算机科学学生被排除在这些活动的一部分。我们设计和运行MIT/LL CTF的目标是通过提供一个不仅测试和挑战参与者的计算机安全技能,而且还教育和准备那些没有广泛的专业知识的环境,使更广泛的社区获得经验。本文介绍了我们的经验,设计,组织和运行的教育为重点的CTF,并讨论了我们的教学方法,游戏设计,评分措施,记录的数据,和经验教训。
Many popular and well-established cyber security Capture the Flag (CTF) exercises are held each year in a variety of settings, including universities and semiprofessional security conferences. CTF formats also vary greatly, ranging from linear puzzle-like challenges to team-based offensive and defensive free-for-all hacking competitions. While these events are exciting and important as contests of skill, they offer limited educational opportunities. In particular, since participation requires considerable a priori domain knowledge and practical computer security expertise, the majority of typical computer science students are excluded from taking part in these events. Our goal in designing and running the MIT/LL CTF was to make the experience accessible to a wider community by providing an environment that would not only test and challenge the computer security skills of the participants, but also educate and prepare those without an extensive prior expertise. This paper describes our experience in designing, organizing, and running an education-focused CTF, and discusses our teaching methods, game design, scoring measures, logged data, and lessons learned.