Cyber ranges are virtual training ranges that have emerged as indispensable environments for conducting secure exercises and simulating real or hypothetical scenarios. These complex computational infrastructures enable the simulation of attacks, facilitating the evaluation of defense tools and methodologies and developing novel countermeasures against threats. One of the main challenges of cyber range scalability is the exercise evaluation that often requires the manual intervention of human operators, the White team. This paper proposes a novel approach that uses Blue and Red team reports and well-known databases to automate the evaluation and assessment of the exercise outcomes, overcoming the limitations of existing assessment models. Our proposal encompasses evaluating various aspects and metrics, explicitly emphasizing Blue Teams' actions and strategies and allowing the automated generation of their cyber posture.
翻译:网络靶场是虚拟训练环境,已成为开展安全演练、模拟真实或假设场景不可或缺的平台。这些复杂的计算基础设施能够模拟攻击,促进防御工具与方法的评估,并开发针对威胁的新型对抗措施。网络靶场可扩展性的主要挑战之一在于演练评估往往需要人工操作者(白队)的手动干预。本文提出了一种创新方法,利用蓝队与红队的报告及权威数据库,实现演练结果的自动化评估与鉴定,从而突破现有评估模型的局限性。我们的方案涵盖多维度指标评估,重点突出蓝队的行动与策略,并支持其网络态势的自动生成。