Examining Penetration Tester Behavior in the Collegiate Penetration Testing Competition

Examining Penetration Tester Behavior in the Collegiate Penetration Testing Competition
复制标题

DOI:
10.1145/3514040
复制
发表时间:
2022-04
期刊:
ACM Transactions on Software Engineering and Methodology (TOSEM)
影响因子:
--
通讯作者:
Benjamin S. Meyers;Sultan Fahad Almassari;Brandon N. Keller;Andrew Meneely
Benjamin S. Meyers;Sultan Fahad Almassari;Brandon N. Keller;Andrew Meneely
中科院分区:
其他
文献类型:
--
作者:
Benjamin S. Meyers;Sultan Fahad Almassari;Brandon N. Keller;Andrew Meneely

文献摘要

被引文献

相似文献

渗透测试是对安全软件进行工程设计的关键实践。恶意攻击者有许多策略可供他们使用,软件工程师需要知道攻击者在攻击的前几个小时将优先使用哪些策略。像MITRE ATT和CK™这样的项目提供了知识,但人们如何在实际情况中实际使用这些知识?渗透测试比赛提供了一个现实的、受控的环境,用来衡量和比较攻击者的效率。在这项工作中,我们检查漏洞发现和攻击者行为的细节,目标是使用2019年大学生渗透测试竞赛(CPTC)的数据来改进现有的漏洞评估流程。我们为10个渗透测试员团队发现的37个独特漏洞构建了98个漏洞发现和利用的时间表。我们通过映射到通用弱点枚举和MITRE ATT&CK™将相关漏洞分组在一起。我们发现:(1)与资源控制不当(例如,会话固定)相关的漏洞比与访问控制不当(例如,弱密码要求)相关的漏洞更快、更频繁地被发现和更快地利用,(2)渗透测试者遵循从发现/收集到横向移动/攻击前的明确过程。我们的方法有助于更快地分析未来CPTC活动中的漏洞。
Penetration testing is a key practice toward engineering secure software. Malicious actors have many tactics at their disposal, and software engineers need to know what tactics attackers will prioritize in the first few hours of an attack. Projects like MITRE ATT&CK™ provide knowledge, but how do people actually deploy this knowledge in real situations? A penetration testing competition provides a realistic, controlled environment with which to measure and compare the efficacy of attackers. In this work, we examine the details of vulnerability discovery and attacker behavior with the goal of improving existing vulnerability assessment processes using data from the 2019 Collegiate Penetration Testing Competition (CPTC). We constructed 98 timelines of vulnerability discovery and exploits for 37 unique vulnerabilities discovered by 10 teams of penetration testers. We grouped related vulnerabilities together by mapping to Common Weakness Enumerations and MITRE ATT&CK™. We found that (1) vulnerabilities related to improper resource control (e.g., session fixation) are discovered faster and more often, as well as exploited faster, than vulnerabilities related to improper access control (e.g., weak password requirements), (2) there is a clear process followed by penetration testers of discovery/collection to lateral movement/pre-attack. Our methodology facilitates quicker analysis of vulnerabilities in future CPTC events.