Web CARTT: The Web-Based Cyber Automated Red Team Tool

被引:0
|
作者
Berrios, Joseph [1 ]
Shaffer, Alan [1 ]
Singh, Gurminder [1 ]
机构
[1] Naval Postgrad Sch, Monterey, CA 93943 USA
关键词
red team; defensive cyber operations; automated vulnerability analysis; web-based assessment;
D O I
10.34190/IWS.21.017
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Red teaming is a well-established methodology for ensuring and augmenting cyber system security; however, the training, expertise, and knowledge of appropriate tools and techniques required to perform effective red teaming come with a significant cost in time and resources. To address these issues, we have previously developed a "red team in a box" (RTIB) capability, called CARTT (Cyber Automated Red Team Tool), to perform automated red team actions on the internal enterprise network without the need for its users to be experts in this field. This current research has extended CARTT by developing a client/server model system that allows operators to perform red team testing on target networks from a simple remote web interface. Using a command-and-control architecture, the extended CARTT provides the ability for cyber operators and network administrators to identify hosts on a target network, conduct vulnerability analysis on those hosts and the target network, attempt to exploit discovered vulnerabilities based on user selected options, and generate the results of these red teaming actions. Additionally, CARTT now provides a tiered role system, so that higher level "commander" users can direct and monitor the actions and results of subordinate "operator" users; as well, the system provides an "administrator" management role. By providing a simple user interface that automates interaction with the underlying tools, operators are able to utilize CARTT without extensive training or experience in red team operations. The ease of use and reliance on open source software greatly reduces the requirements for organizations to use this tool for red teaming their networks.
引用
收藏
页码:11 / 19
页数:9
相关论文
共 50 条
  • [1] Development of Web-based Automated System for Cyber Analytic Applications
    Pillai, Athira
    Schnebly, James
    Sengupta, Shamik
    2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2018, : 866 - 871
  • [2] Web-based project collaboration tool promates team communication
    Binns, J
    CIVIL ENGINEERING, 2004, 74 (08): : 30 - 31
  • [3] Fully automated web-based tool for identifying regulatory hotspots
    Choi, Ju Hun
    Kim, Taegun
    Jung, Junghyun
    Joo, Jong Wha J.
    BMC GENOMICS, 2020, 21 (Suppl 10)
  • [4] Web-Based CASE Tool for Automated Rendering of UML Models
    Palaniappan, Sellappan
    Ling, Louis
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2008, 8 (08): : 146 - 152
  • [5] BenchStab: a tool for automated querying of web-based stability predictors
    Velecky, Jan
    Berezny, Matej
    Musil, Milos
    Damborsky, Jiri
    Bednar, David
    Mazurenko, Stanislav
    BIOINFORMATICS, 2024, 40 (09)
  • [6] Fully automated web-based tool for identifying regulatory hotspots
    Ju Hun Choi
    Taegun Kim
    Junghyun Jung
    Jong Wha J. Joo
    BMC Genomics, 21
  • [7] DEVELOPMENT AND IMPLEMENTATION OF A WEB-BASED PEER EVALUATION TOOL FOR TEAM PROJECTS
    Balascio, Carmine C.
    Kinney, Beth Kano
    2012 ASEE ANNUAL CONFERENCE, 2012,
  • [8] Solar Web: A web tool for searching in web-based solar databases
    Scholl, I
    VIRTUAL OBSERVATORIES OF THE FUTURE, PROCEEDINGS, 2001, 225 : 225 - 229
  • [9] DockTope: a Web-based tool for automated pMHC-I modelling
    Maurício Menegatti Rigo
    Dinler Amaral Antunes
    Martiela Vaz de Freitas
    Marcus Fabiano de Almeida Mendes
    Lindolfo Meira
    Marialva Sinigaglia
    Gustavo Fioravanti Vieira
    Scientific Reports, 5
  • [10] SAUCE: A Web-Based Automated Assessment Tool for Teaching Parallel Programming
    Schlarb, Moritz
    Hundt, Christian
    Schmidt, Bertil
    EURO-PAR 2015: PARALLEL PROCESSING WORKSHOPS, 2015, 9523 : 54 - 65