Chouliaras Nestoras, Kantzavelou Ioanna, Maglaras Leandros, Pantziou Grammati, Amine Ferrag Mohamed
University of West Attica, Athens, Greece.
School of Computer Science, Napier University, Edinburgh, United Kingdom.
PeerJ Comput Sci. 2023 Sep 7;9:e1574. doi: 10.7717/peerj-cs.1574. eCollection 2023.
Cyberattacks, particularly those targeting systems that store or handle sensitive data, have become more sophisticated in recent years. To face increasing threats, continuous capacity building and digital skill competence are needed. Cybersecurity hands-on training is essential to upskill cybersecurity professionals. However, the cost of developing and maintaining a cyber range platform is high. Setting up an ideal digital environment for cybersecurity exercises can be challenging and often need to invest a lot of time and system resources in this process. In this article, we present a lightweight cyber range platform that was developed under the open-source cloud platform OpenStack, based on Docker technology using IaC methodology. Combining the advantages of Docker technology, DevOps automation capabilities, and the cloud platform, the proposed cyber range platform achieves the maximization of performance and scalability while reducing costs and resources.
近年来,网络攻击,尤其是针对存储或处理敏感数据的系统的攻击,变得越来越复杂。为应对日益增加的威胁,需要持续进行能力建设和提升数字技能。网络安全实践培训对于提升网络安全专业人员的技能至关重要。然而,开发和维护网络靶场平台的成本很高。为网络安全演练搭建一个理想的数字环境可能具有挑战性,并且在此过程中通常需要投入大量时间和系统资源。在本文中,我们展示了一个轻量级的网络靶场平台,该平台是在开源云平台OpenStack下开发的,基于使用基础设施即代码(IaC)方法的Docker技术。结合Docker技术、DevOps自动化能力和云平台的优势,所提出的网络靶场平台在降低成本和资源的同时实现了性能和可扩展性的最大化。