In cybersecurity, a vulnerability is a weakness of hardware or software that attackers can exploit. Therefore, eliminating or mitigating vulnerabilities is a critical security control for effective defense. However, deliberately creating a vulnerable environment can be helpful. For software developers, it is a security test of software; for system administrators, it is an experiment in cyberattacks; and for educators and trainers, it is a learning resource for cybersecurity. People can learn about vulnerabilities by testing and experimenting to confirm and observe vulnerable environments. This paper discusses use cases and presents a model of vulnerable environments and our original system. It enables the efficient and automatic reproduction of vulnerable environments and the replicable execution of attacks in virtual space. For this purpose, we utilize the Infrastructure as Code (IaC) principle. A vulnerable environment is represented as code, and the system automates provisioning it and executing an attack through a machine-readable definition rather than manual configuration and execution. The primary values of the work are reproducibility, consistency, repeatability, disposability, transparency, and accessibility of vulnerable environments. It helps users effortlessly and repeatedly reproduce vulnerabilities and attacks safely.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Intentional Reproduction of Vulnerable Environments

  • Seiya Kamata,
  • Akihito Nakamura

摘要

In cybersecurity, a vulnerability is a weakness of hardware or software that attackers can exploit. Therefore, eliminating or mitigating vulnerabilities is a critical security control for effective defense. However, deliberately creating a vulnerable environment can be helpful. For software developers, it is a security test of software; for system administrators, it is an experiment in cyberattacks; and for educators and trainers, it is a learning resource for cybersecurity. People can learn about vulnerabilities by testing and experimenting to confirm and observe vulnerable environments. This paper discusses use cases and presents a model of vulnerable environments and our original system. It enables the efficient and automatic reproduction of vulnerable environments and the replicable execution of attacks in virtual space. For this purpose, we utilize the Infrastructure as Code (IaC) principle. A vulnerable environment is represented as code, and the system automates provisioning it and executing an attack through a machine-readable definition rather than manual configuration and execution. The primary values of the work are reproducibility, consistency, repeatability, disposability, transparency, and accessibility of vulnerable environments. It helps users effortlessly and repeatedly reproduce vulnerabilities and attacks safely.