Web CARTT: The Web-Based Cyber Automated Red Team Tool

被引:0
|
作者
Berrios, Joseph [1 ]
Shaffer, Alan [1 ]
Singh, Gurminder [1 ]
机构
[1] Naval Postgrad Sch, Monterey, CA 93943 USA
关键词
red team; defensive cyber operations; automated vulnerability analysis; web-based assessment;
D O I
10.34190/IWS.21.017
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Red teaming is a well-established methodology for ensuring and augmenting cyber system security; however, the training, expertise, and knowledge of appropriate tools and techniques required to perform effective red teaming come with a significant cost in time and resources. To address these issues, we have previously developed a "red team in a box" (RTIB) capability, called CARTT (Cyber Automated Red Team Tool), to perform automated red team actions on the internal enterprise network without the need for its users to be experts in this field. This current research has extended CARTT by developing a client/server model system that allows operators to perform red team testing on target networks from a simple remote web interface. Using a command-and-control architecture, the extended CARTT provides the ability for cyber operators and network administrators to identify hosts on a target network, conduct vulnerability analysis on those hosts and the target network, attempt to exploit discovered vulnerabilities based on user selected options, and generate the results of these red teaming actions. Additionally, CARTT now provides a tiered role system, so that higher level "commander" users can direct and monitor the actions and results of subordinate "operator" users; as well, the system provides an "administrator" management role. By providing a simple user interface that automates interaction with the underlying tools, operators are able to utilize CARTT without extensive training or experience in red team operations. The ease of use and reliance on open source software greatly reduces the requirements for organizations to use this tool for red teaming their networks.
引用
收藏
页码:11 / 19
页数:9
相关论文
共 50 条
  • [21] A web-based requirements analysis tool
    Anton, AI
    Liang, E
    Rodenstein, RA
    PROCEEDINGS OF THE 5TH WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES (WET ICE '96), 1996, : 238 - 243
  • [22] Web-based actuator selection tool
    Madden, JD
    Filipozzi, L
    Smart Structures and Materials 2005: Electroactive Polymer Actuators and Devices( EAPAD), 2005, 5759 : 9 - 15
  • [23] Dynamic Web-based tutorial tool
    Rodanski, Benedykt S.
    2006 7TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY BASED HIGHER EDUCATION AND TRAINING, VOLS 1 AND 2, 2006, : 67 - 70
  • [24] Create designs with Web-based tool
    Moretti, G
    EDN, 2001, 46 (13) : 20 - 20
  • [25] Web-based tools for team-based development
    Barlow, J
    ASSOCIATION FOR INFORMATION SYSTEMS PROCEEDING OF THE AMERICAS CONFERENCE ON INFORMATION SYSTEMS, 1997, : 966 - 968
  • [26] RNAit:: an automated web-based tool for the selection of RNAi targets in Trypanosoma brucei
    Redmond, S
    Vadivelu, J
    Field, MC
    MOLECULAR AND BIOCHEMICAL PARASITOLOGY, 2003, 128 (01) : 115 - 118
  • [27] Web-Based Tool for the Automated 3-D Reactive Molding Simulations
    Rajca, Robert
    Matysiak, Lukasz
    Banas, Michal
    Sekula, Robert
    ADVANCED MANUFACTURING ENGINEERING, QUALITY AND PRODUCTION SYSTEMS, 2010, : 194 - 199
  • [28] Web-Based Power Flow Analysis Tool for Automated Distribution Network Control
    Ortjohann, E.
    Wirasanti, P.
    Leksawat, S.
    Schmelter, A.
    Holtschulte, D.
    Kortenbruck, J.
    2016 INTERNATIONAL SYMPOSIUM ON POWER ELECTRONICS, ELECTRICAL DRIVES, AUTOMATION AND MOTION (SPEEDAM), 2016, : 1298 - 1303
  • [29] Automated teleoperation of web-based devices using semantic web services
    Ha, YG
    Kim, J
    Jang, M
    Sohn, JC
    Yoon, H
    INNOVATIONS IN APPLIED ARTIFICIAL INTELLIGENCE, 2005, 3533 : 185 - 188
  • [30] The design of solar web, a web tool for searching in heterogeneous web-based solar databases
    Scholl, I
    ASTRONOMICAL DATA ANALYSIS SOFTWARE AND SYSTEMS X, 2001, 238 : 86 - 89