PenQuest: a gamified attacker/defender meta model for cyber security assessment and education

PenQuest: a gamified attacker/defender meta model for cyber security assessment and education
复制标题

PenQuest:用于网络安全评估和教育的游戏化攻击者/防御者元模型

DOI:
10.1007/s11416-019-00342-x
复制
发表时间:
2019
影响因子:
1.5
通讯作者:
H. Janicke
H. Janicke
中科院分区:
--
文献类型:
--
作者:
R. Luh;Marlies Temper;S. Tjoa;S. Schrittwieser;H. Janicke

文献摘要

被引文献

相似文献

对IT系统的攻击对关键信息和基础设施的保密性、完整性和可用性构成越来越大的威胁。同时,攻击技术和可能的对策的复杂相互作用,使得适当地规划、实施和评估组织的防御变得困难。通常情况下,技术威胁和组织控制的世界仍然是脱节的。在本文中,我们介绍了PenQuest,这是一个元模型,旨在呈现信息系统攻击及其缓解的完整视图,同时为语义数据丰富和安全教育提供工具。PenQuest模拟启用时间的攻击者/防御者行为,作为动态、不完全信息多人游戏的一部分,该游戏的规则集的重要部分来自已建立的信息安全来源,如STIX、CAPEC、CVE/CWE和NIST SP 800-53。攻击模式、漏洞和缓解控制通过实用的、以数据为中心的机制映射到对应的策略和具体操作。游戏化模型考虑并定义了广泛的参与者、资产和操作,从而支持评估网络风险,同时让技术专家有机会在抽象的IT基础设施的背景下探索特定的攻击场景。我们实现了PenQuest作为一个物理严肃游戏原型,并在高等教育环境中成功地进行了测试。更多的专家访谈帮助评估了该模型对信息安全场景的适用性。
Attacks on IT systems are a rising threat against the confidentiality, integrity, and availability of critical information and infrastructures. At the same time, the complex interplay of attack techniques and possible countermeasures makes it difficult to appropriately plan, implement, and evaluate an organization’s defense. More often than not, the worlds of technical threats and organizational controls remain disjunct. In this article, we introduce PenQuest, a meta model designed to present a complete view on information system attacks and their mitigation while providing a tool for both semantic data enrichment and security education. PenQuest simulates time-enabled attacker/defender behavior as part of a dynamic, imperfect information multi-player game that derives significant parts of its ruleset from established information security sources such as STIX, CAPEC, CVE/CWE and NIST SP 800-53. Attack patterns, vulnerabilities, and mitigating controls are mapped to counterpart strategies and concrete actions through practical, data-centric mechanisms. The gamified model considers and defines a wide range of actors, assets, and actions, thereby enabling the assessment of cyber risks while giving technical experts the opportunity to explore specific attack scenarios in the context of an abstracted IT infrastructure. We implemented PenQuest as a physical serious game prototype and successfully tested it in a higher education environment. Additional expert interviews helped evaluate the model’s applicability to information security scenarios.