A Method for Teaching Open Source Intelligence (OSINT) Using Personalised Cloud-based Exercises

被引:0
|
作者
Yari, Saber [1 ]
Mases, Sten [1 ]
Maennel, Olaf [1 ]
机构
[1] Tallinn Univ Technol TalTech, Tallinn, Estonia
关键词
cybersecurity education; gamification; cybersecurity exercises; OSINT;
D O I
10.34190/ICCWS.20.091
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The ability to analyse publicly available information is highly valued in the cybersecurity community and is often crucial in areas such as incident investigation and penetration testing. However, it has been challenging to provide practical hands-on exercises to train the techniques relevant to open source intelligence (OSINT). This is particularly so as gathering sensitive data about a real person or organisation in a classroom exercise is likely to bring out a multitude of ethical and legal issues. To conduct classroom-based OSINT exercises it is possible to create a sandbox environment with simulated services or to create some publicly available services that can be analysed by the students. However, both approaches having their shortcomings. In a sandbox environment, it is very difficult to simulate relevant real-world systems such as Facebook, Google, or Shodan. Setting up public services to be available to everyone is also problematic as it is usually not possible to provide an individual student experience. Therefore, once one participant has found the answer, it is very easy to cheat and share the solution with others. This paper presents a novel way for constructing a learning environment focusing on OSINT exercises where capture the flag (CTF) style tasks are conducted in cloud based virtual labs. The students use real applications throughout the exercise environment with the network traffic in the virtual lab routed through a specialised proxy. Here the contents of the web sites are modified to contain flags that are individual for each participant. Assessment approaches and scenario development are discussed together with key learning points from conducting this case study. This experimental setup is already being used in a university undergraduate level introductory course in cybersecurity at the Tallinn University of Technology.
引用
收藏
页码:480 / 489
页数:10
相关论文
共 50 条
  • [1] Open Source Intelligence (OSINT): An Oxymoron?
    Miller, Bowman H.
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENCE AND COUNTERINTELLIGENCE, 2018, 31 (04) : 702 - 719
  • [2] Modelling the effect of deception on investigations using open source intelligence (OSINT)
    Watters, Paul A.
    [J]. JOURNAL OF MONEY LAUNDERING CONTROL, 2013, 16 (03): : 238 - +
  • [3] Intelligence in the internet age: The emergence and evolution of Open Source Intelligence (OSINT)
    Glassman, Michael
    Kang, Min Ju
    [J]. COMPUTERS IN HUMAN BEHAVIOR, 2012, 28 (02) : 673 - 682
  • [4] The role of linked open data (LOD): A perspective based on open-source intelligence (OSINT)
    Varon-Capera, Alvaro
    Gaona-Garcia, Paulo Alonso
    Montenegro-Marin, Carlos Enrique
    [J]. LOGOS CIENCIA & TECNOLOGIA, 2024, 16 (02): : 171 - 185
  • [5] A systematic review on research utilising artificial intelligence for open source intelligence (OSINT) applications
    Browne, Thomas Oakley
    Abedin, Mohammad
    Chowdhury, Mohammad Jabed Morshed
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (04) : 2911 - 2938
  • [6] Systematic Literature Review to Investigate the Application of Open Source Intelligence (OSINT) with Artificial Intelligence
    Goncalves Evangelista, Joao Rafael
    Sassi, Renato Jose
    Romero, Marcio
    Napolitano, Domingos
    [J]. JOURNAL OF APPLIED SECURITY RESEARCH, 2021, 16 (03) : 345 - 369
  • [7] Evaluation of Cloud-based Open Educational Resources for Teaching Microelectronics
    Bonyar, Attila
    Martinek, Peter
    Krammer, Oliver
    Geczy, Attila
    Illyefalvi-Vitez, Zsolt
    Tzanova, Slavka
    [J]. 2018 41ST INTERNATIONAL SPRING SEMINAR ON ELECTRONICS TECHNOLOGY (ISSE), 2018,
  • [8] Open-source cloud-based energy calculator/simulator
    Evans, R.
    [J]. 2013 ISES SOLAR WORLD CONGRESS, 2014, 57 : 2838 - 2847
  • [9] Next generation data fusion Open Source Intelligence (OSINT) system based on MPEG7
    Pfeiffer, Mark
    Avila, Marco
    Backfried, Gerhard
    Pfannerer, Norbert
    Riedler, Juergen
    [J]. 2008 IEEE CONFERENCE ON TECHNOLOGIES FOR HOMELAND SECURITY, VOLS 1 AND 2, 2008, : 41 - 46
  • [10] COMPOSE: An Open Source Cloud-Based Scalable IoT Services Platform
    Raggett, Dave
    [J]. ERCIM NEWS, 2015, (101): : 30 - 31