当前位置: X-MOL 学术Comput. Secur. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Serious games as a tool to model attack and defense scenarios for cyber-security exercises
Computers & Security ( IF 5.6 ) Pub Date : 2021-08-20 , DOI: 10.1016/j.cose.2021.102450
Muhammad Mudassar Yamin 1 , Basel Katt 1 , Mariusz Nowostawski 1
Affiliation  

Technology is evolving rapidly; this poses a problem for security specialists and average citizens as their technological skill sets are quickly made obsolete. This makes the knowledge and understanding of cyber-security in a technologically evolving world difficult. Global IT infrastructure and individuals’ privacy are constantly under threat. One way to tackle this problem is by providing continuous training and self-learning platforms. Cyber-security exercises can provide a necessary platform for training people’s cyber-security skills. However, conducting cyber-security exercises with new and unique scenarios requires comprehensive planning and commitment to the preparation time and resources. In this work, we propose a serious game for the development of cyber-security exercise scenarios. The game provides a platform to model simulated cyber-security exercise scenarios, transforming them into an emulated cyber-security exercise environment using domain-specific language (DSL) and infrastructure orchestration. In this game, players can play as cyber attackers or defenders in a multiplayer environment to make operational cyber-security decisions in real-time. The decisions are evaluated for the development of operational cyber-attack and defense strategies.



中文翻译:

严肃游戏作为为网络安全演习建模攻击和防御场景的工具

技术发展迅速;这给安全专家和普通公民带来了问题,因为他们的技术技能很快就会过时。这使得在技术不断发展的世界中对网络安全的知识和理解变得困难。全球 IT 基础设施和个人隐私不断受到威胁。解决此问题的一种方法是提供持续培训和自学平台。网络安全演习可以为培训人们的网络安全技能提供必要的平台。然而,在新的和独特的场景下进行网络安全演习需要全面的规划和对准备时间和资源的承诺。在这项工作中,我们为网络安全演习场景的开发提出了一个严肃的游戏。该游戏提供了一个平台来模拟模拟网络安全演习场景,使用领域特定语言 (DSL) 和基础设施编排将它们转换为模拟网络安全演习环境。在这款游戏中,玩家可以在多人游戏环境中扮演网络攻击者或防御者的角色,实时做出运营网络安全决策。这些决策被评估以制定可操作的网络攻击和防御策略。

更新日期:2021-08-29
down
wechat
bug