Visible to the public CyRIS: A Cyber Range Instantiation System for Facilitating Security Training

TitleCyRIS: A Cyber Range Instantiation System for Facilitating Security Training
Publication TypeConference Paper
Year of Publication2016
AuthorsPham, Cuong, Tang, Dat, Chinen, Ken-ichi, Beuran, Razvan
Conference NameProceedings of the Seventh Symposium on Information and Communication Technology
Date PublishedDecember 2016
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4815-7
Keywordscyber range, cyber-security practice, cybersecurity, cybersecurity education, Human Behavior, pubcrawl
Abstract

Cyber ranges are well-defined controlled virtual environments used in cybersecurity training as an efficient way for trainees to gain practical knowledge through hands-on activities. However, creating an environment that contains all the necessary features and settings, such as virtual machines, network topology and security-related content, is not an easy task, especially for a large number of participants. Therefore, we propose CyRIS (Cyber Range Instantiation System) as a solution towards this problem. CyRIS provides a mechanism to automatically prepare and manage cyber ranges for cybersecurity education and training based on specifications defined by the instructors. In this paper, we first describe the design and implementation of CyRIS, as well as its utilization. We then present an evaluation of CyRIS in terms of feature coverage compared to the Technical Guide to Information Security Testing and Assessment of the U.S National Institute of Standards and Technology, and in terms of functionality compared to other similar tools. We also discuss the execution performance of CyRIS for several representative scenarios.

URLhttps://dl.acm.org/doi/10.1145/3011077.3011087
DOI10.1145/3011077.3011087
Citation Keypham_cyris:_2016