A Hands-on Approach for Teaching Denial of Service Attacks: A Case Study

A Hands-on Approach for Teaching Denial of Service Attacks: A Case Study
复制标题

拒绝服务攻击教学的实践方法:案例研究

DOI:
10.28945/1920
复制
发表时间:
2013
期刊:
J. Inf. Technol. Educ. Innov. Pract.
影响因子:
--
通讯作者:
Walid Ibrahim
Walid Ibrahim
中科院分区:
--
文献类型:
--
作者:
Z. Trabelsi;Walid Ibrahim

文献摘要

被引文献

相似文献

本文介绍了实施综合道德黑客实践实验室练习的案例研究,这是安全教育的基础。练习涉及三种常见的拒绝服务 (DoS) 攻击,即 Land、TCP(传输控制协议)SYN(同步)洪水和 Teardrop 攻击。 DoS 攻击是教授道德黑客和入侵检测技术的安全课程的重要主题。本文还讨论了检测 DoS 攻击的常见防御技术,包括入侵检测系统 (IDS) 和软件工具。在实验室实践练习中,Snort 工具被用作 IDS 防御解决方案。动手实验练习的学习目标是让学生学习如何在隔离的网络实验室环境中实施和检测 DoS 攻击。将道德黑客行为添加到信息安全课程中会引发各种道德和法律问题。一些学生会以不适当甚至有时非法的方式使用所获得的进攻性实践技能。因此,学生可能会威胁到他们的职业生涯,伤害他人,并使所在机构的整个信息安全计划面临风险。此外,学校和教育工作者可能对其学生的行为承担责任。为了提高成功且无问题的教授道德黑客技术的信息安全计划的机会,本文列出了学校和教育工作者应采取的一系列步骤,以确保学生对自己的行为负责,并教育学生了解任何不当行为的后果。还讨论了提供练习对学生在实现课程成果方面的表现的影响。课程评估结果表明,所提供的动手实验练习使学生能够更好地剖析攻击并吸收从讲座中学到的概念。通过练习,学生们学得更好,这对他们的表现产生了积极的影响。
This paper presents a case study of the implementation of comprehensive ethical hacking handson lab exercises, which are fundamental to security education. The exercises are about three common Denial of Service (DoS) attacks, namely, the Land, the TCP (transmission control protocol) SYN (synchronization) flood, and the Teardrop attacks. DoS attacks are important topics for security courses teaching ethical hacking and intrusion detection techniques. The paper discusses also common defense techniques for detecting DoS attacks, including Intrusion Detection Systems (IDS) and Software tools. Snort tool is used as the IDS defense solution during the hands-on lab exercises. The learning objective of the hands-on lab exercises is for students to learn how to implement and detect the DoS attacks in an isolated network laboratory environment. Adding ethical hacking to an information security curriculum raises a variety of ethical and legal issues. Some students will use the acquired offensive hands-on skills in inappropriate and sometimes illegal ways. Hence, students may threaten their careers, hurt others, and put their institution’s entire information security program at risk. Also, schools and educators may be held liable for the actions of their students. To contribute to improving the chances of having a successful and problem free information security programs that teach ethical hacking techniques, the paper lists a number of steps that should be taken by schools and educators to ensure that students are responsible for their actions and educate students on the consequences of any misconduct. The impact of offering the exercises on the students’ performance in terms of achieving the course outcomes is also discussed. The course assessment results show that the offered hands-on lab exercises allowed students to better anatomize the attacks and assimilate the concepts learned from the lecture. The students have learned better with the exercises which had a positive effect on their performance.