【24h】

A Digital Twin-Based Cyber Range for SOC Analysts

机译:面向SOC分析师的数字孪生网络范围

获取原文

摘要

Security Operations Centers (SOCs) provide a holistic view of a company's security operations. While aiming to harness this potential, companies are lacking sufficiently skilled cybersecurity analysts. One approach to meet this demand is to create a cyber range to equip potential analysts with the skills required. The digital twin paradigm offers great benefit by providing a realistic virtual environment to create a cyber range. However, to the best of our knowledge, tapping this potential to train SOC analysts has not been attempted yet. To address this research gap, a concept of a digital twin-based cyber range for SOC analysts is proposed and implemented. As part of the virtual training environment, several attacks against an industrial system are simulated. Being provided with a SIEM system that displays the real-time log data, the trainees solve increasingly complex tasks in which they have to detect the attacks performed against the system. Thereby, they learn how to interact with a SIEM system and create rules that correlate events aiming to detect security incidents. To evaluate the implemented cyber range, a comprehensive user study demonstrates a significant increase of knowledge within SIEM-related topics among the participants. Additionally, it indicates that the cyber range was subjectively perceived as a positive learning experience by the participants.
机译:安全运营中心(SOC)提供公司安全运营的整体视图。虽然旨在利用这一潜力,但公司缺乏足够熟练的网络安全分析师。满足这一需求的一种方法是创建一个网络范围,让潜在分析师具备所需的技能。数字孪生模式通过提供一个真实的虚拟环境来创建一个网络范围,提供了巨大的好处。然而,据我们所知,尚未尝试利用这种潜力来培训SOC分析师。为了填补这一研究空白,提出并实现了一个面向SOC分析师的数字孪生网络范围的概念。作为虚拟训练环境的一部分,模拟了针对工业系统的几种攻击。由于配备了一个显示实时日志数据的SIEM系统,学员们可以解决越来越复杂的任务,在这些任务中,他们必须检测对系统执行的攻击。因此,他们学习如何与SIEM系统交互,并创建关联事件的规则,以检测安全事件。为了评估实施的网络范围,一项全面的用户研究表明,参与者对SIEM相关主题的了解显著增加。此外,它还表明,参与者主观上认为网络范围是一种积极的学习体验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号