Scalable and automated Evaluation of Blue Team cyber posture in Cyber Ranges

Autor: Bianchi, Federica, Bassetti, Enrico, Spognardi, Angelo
Rok vydání: 2023
Předmět:
Druh dokumentu: Working Paper
DOI: 10.1145/3605098.3636154
Popis: Cyber ranges are virtual training ranges that have emerged as indispensable environments for conducting secure exercises and simulating real or hypothetical scenarios. These complex computational infrastructures enable the simulation of attacks, facilitating the evaluation of defense tools and methodologies and developing novel countermeasures against threats. One of the main challenges of cyber range scalability is the exercise evaluation that often requires the manual intervention of human operators, the White team. This paper proposes a novel approach that uses Blue and Red team reports and well-known databases to automate the evaluation and assessment of the exercise outcomes, overcoming the limitations of existing assessment models. Our proposal encompasses evaluating various aspects and metrics, explicitly emphasizing Blue Teams' actions and strategies and allowing the automated generation of their cyber posture.
Databáze: arXiv