help promote
usenix conference policies
You are here
Finding the Balance Between Guidance and Independence in Cybersecurity Exercises
Richard Weiss, The Evergreen State College; Frankly Turbak, Wellesley College; Jens Mache and Erik Nilsen, Lewis and Clark College; Michael E. Locasto, SRI International
In order to accomplish cyber security tasks, one needs to know how to analyze complex data and when and how to use tools. Many hands-on exercises for cybersecurity courses have been developed to teach these skills. There is a spectrum of ways that these exercises can be taught. On one end of the spectrum are prescriptive exercises, in which students follow step-by- step instructions to run scripted exploits, perform penetration testing, do security audits, etc. On the other end of the spectrum are open-ended exercises and capture-the- flag activities, where little guidance is given on how to proceed.
This paper reports on our experience with trying to find a balance between these extremes in the context of one of the suite of cybersecurity exercises that we have developed in the EDURange framework. The particular exercise that we present teaches students about dynamic analysis of binaries using strace. We have found that students are most successful in these exercises when they are given the right amount of prerequisite knowledge and guidance as well as some opportunity to find creative solutions. Our scenarios are specifically designed to develop analysis skills and the security mindset in students and to complement the theoretical aspects of the discipline and develop practical skills.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Richard Weiss and Frankly Turbak and Jens Mache and Erik Nilsen and Michael E. Locasto},
title = {Finding the Balance Between Guidance and Independence in Cybersecurity Exercises},
booktitle = {2016 USENIX Workshop on Advances in Security Education (ASE 16)},
year = {2016},
address = {Austin, TX},
url = {https://www.usenix.org/conference/ase16/workshop-program/presentation/weiss},
publisher = {USENIX Association},
month = aug
}
connect with us