National Cyber Range Overview
Title | National Cyber Range Overview |
Publication Type | Conference Paper |
Year of Publication | 2014 |
Authors | Ferguson, B., Tall, A., Olsen, D. |
Conference Name | Military Communications Conference (MILCOM), 2014 IEEE |
Date Published | Oct |
ISBN Number | 978-1-4799-6770-4 |
Keywords | computer network security, Cyberspace, cyberspace resiliency testing, cyberspace security threats, Department of Defense, DoD communication networks, Malware, National Cyber Range, NCR, range, Resource management, security, test, Testing, traffic emulation, US Department of Defense, virtual machines |
Abstract | The National Cyber Range (NCR) is an innovative Department of Defense (DoD) resource originally established by the Defense Advanced Research Projects Agency (DARPA) and now under the purview of the Test Resource Management Center (TRMC). It provides a unique environment for cyber security testing throughout the program development life cycle using unique methods to assess resiliency to advanced cyberspace security threats. This paper describes what a cyber security range is, how it might be employed, and the advantages a program manager (PM) can gain in applying the results of range events. Creating realism in a test environment isolated from the operational environment is a special challenge in cyberspace. Representing the scale and diversity of the complex DoD communications networks at a fidelity detailed enough to realistically portray current and anticipated attack strategies (e.g., Malware, distributed denial of service attacks, cross-site scripting) is complex. The NCR addresses this challenge by representing an Internet-like environment by employing a multitude of virtual machines and physical hardware augmented with traffic emulation, port/protocol/service vulnerability scanning, and data capture tools. Coupled with a structured test methodology, the PM can efficiently and effectively engage with the Range to gain cyberspace resiliency insights. The NCR capability, when applied, allows the DoD to incorporate cyber security early to avoid high cost integration at the end of the development life cycle. This paper provides an overview of the resources of the NCR which may be especially helpful for DoD PMs to find the best approach for testing the cyberspace resiliency of their systems under development. |
URL | https://ieeexplore.ieee.org/document/6956748 |
DOI | 10.1109/MILCOM.2014.27 |
Citation Key | 6956748 |