sponsors
help promote
usenix conference policies
Experiences with Honey-Patching in Active Cyber Security Education
Frederico Araujo, Mohammad Shapouri, Sonakshi Pandey, and Kevin Hamlen, The University of Texas at Dallas
Modern cyber security educational programs that emphasize technical skills often omit or struggle to effectively teach the increasingly important science of cyber deception. A strategy for effectively communicating deceptive technical skills by leveraging the new paradigm of honey-patching is discussed and evaluated. Honey-patches mislead attackers into believing that failed attacks against software systems were successful. This facilitates a new form of penetration testing and capture-the-flag style exercise in which students must uncover and outwit the deception in order to successfully bypass the defense. Experiences creating and running the first educational lab to employ this new technique are discussed, and educational outcomes are examined.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Frederico Araujo and Mohammad Shapouri and Sonakshi Pandey and Kevin Hamlen},
title = {Experiences with {Honey-Patching} in Active Cyber Security Education},
booktitle = {8th Workshop on Cyber Security Experimentation and Test (CSET 15)},
year = {2015},
address = {Washington, D.C.},
url = {https://www.usenix.org/conference/cset15/workshop-program/presentation/araujo},
publisher = {USENIX Association},
month = aug
}
connect with us