CERT Training Platform over the Event-Recordable Container


연구 분야: Safety



학회: ACM ICEA '20: Proceedings of the 2020 ACM International Conference on Intelligent Computing and its Emerging Applications


초록

The current COVID-19 pandemic has resulted in many changes in the IT systems and services of institutions, which also heightened the concerns regarding the potential increase in intrusion incidents, especially when most works in institutions are performed at home. The need for pre-training against intrusion incidents has then become extremely necessary. Unfortunately, current learning methods in existing studies are insufficient for application in the present demand because these methods were originally designed for environments that are tailored-fit for learners and not in actual environments. This paper proposes a training system, namely, computer emergency response team (CERT), that can be specifically designed for learners in an institution to provide intrusion-incident cases using a Web-based training system. CERT can easily replicate the service or system in an institution to a honeypot environment to automatically collect and classify intrusion incidents using diverse evaluation criteria so that learning can be achieved from different perspectives. Hence, the institution operating service and system can easily be replicated. Artifacts of intrusion incidents are collected using the Docker container technology and event-recordable container, which are analyzed using a Web browser without installing a separate program. Thus, optimal learning results from the analysis of actual attacks are expected.


Author Profile
Namjun Kim

Sejong University Seoul Republic of Korea

Korea
Author Profile
Chanmo Yang

Sejong University Seoul Republic of Korea

Korea
Author Profile
Daebeom Cho

Sejong University Seoul Republic of Korea

Korea

📄 논문 정보

발행 연도 2021년
인용수 0
출판 국가 Korea
사이트 ACM
좋아요 수 0

연관 논문 목록 (55건)