Towards Encapsulated Cyber Security Labs: A Container Based Approach

Towards Encapsulated Cyber Security Labs: A Container Based Approach
复制标题

走向封装的网络安全实验室:基于容器的方法

DOI:
--
复制
发表时间:
2019
期刊:
Technical Symposium on Computer Science Education
影响因子:
--
通讯作者:
S. Suthaharan
S. Suthaharan
中科院分区:
--
文献类型:
--
作者:
Selvarajah Mohanarajah;Gregorry Ross;S. Suthaharan

文献摘要

被引文献

相似文献

独立于平台的封装和独立实验室可以增强资源有限的学术机构网络安全教学模块的交付。网络安全教学模块通常包含使用NETLAB+、NS-3、SEED、GENI等工具的动手实验室。使用此类实验室存在两个主要问题:学生在进行实验之前需要学习底层工具,并且建立实验室可能需要大量的 IT 支持和资源。此外,安全实验室的开发和交付还受到另外两个技术现实的阻碍:计算机系统和网络中的内置安全控制(例如 NX 位、ASL 随机化、金丝雀、防火墙等)以及学生拥有的操作环境中的异构性。在我们提出的工作中,我们研究了基于容器的教育解决方案的概念,利用 Docker 容器的独特功能(即代码的轻量级打包及其所有系统依赖项)来构建独立于平台的封装网络安全实验室。我们的方法的优点包括经济高效的教学环境、异构操作平台的可扩展性、独立于硬件、软件和网络控制,以及为学生提供无忧的学习体验。作为概念验证,我们开发了一个可互操作的封装实验室,为学生提供网络安全、缓冲区溢出等方面的实践经验。该实验室是使用 Docker 创建的并上传到中央存储库。学生可以从任何地方拉取这个实验,并可以在任何运行 Docker 守护进程的平台上执行它。我们将利用本研究中获得的知识和经验来构建我们在构建网络安全教育学习对象领域的未来研究。
Platform-independent encapsulated and self-contained labs can enhance the delivery of cybersecurity teaching modules in resource-limited academic institutions. Cybersecurity teaching modules usually incorporate hands-on labs using tools such as NETLAB+, NS-3, SEED, GENI, etc. There are two major problems in using such labs; students need to learn the underlying tool before doing labs, and setting-up a lab may require significant IT support and resources. In addition, development and delivery of security labs is barricaded by two other technical realities: built-in security controls in computer systems and networks (e.g. NX-bits, ASL-Randomization, Canaries, Firewalls, etc.), and heterogeneity in students-owned operating environments. In our proposed work, we have studied the concept of container-based educational solutions by leveraging the unique features of Docker containers (i.e., light-weight packaging of code and all of its system dependencies) to build platform-independent encapsulated cybersecurity labs. The benefits of our approach includes, cost-effective teaching environment, scalability over heterogeneous operating platforms, independence from hardware, software, and network controls, and hassle-free learning experience for students. As a proof of concept, we have developed an interoperable encapsulated lab for giving hands-on experience to students in one aspect of cybersecurity, buffer overflow. The lab was created using Docker and uploaded to a central repository. Students can pull this lab from anywhere, and can execute it on any platform that runs Docker daemon. We will use the knowledge and experience gained in this study to build our future research in the areas of building Learning Objects for cybersecurity education.