Web CARTT: The Web-Based Cyber Automated Red Team Tool

被引:0
|
作者
Berrios, Joseph [1 ]
Shaffer, Alan [1 ]
Singh, Gurminder [1 ]
机构
[1] Naval Postgrad Sch, Monterey, CA 93943 USA
关键词
red team; defensive cyber operations; automated vulnerability analysis; web-based assessment;
D O I
10.34190/IWS.21.017
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Red teaming is a well-established methodology for ensuring and augmenting cyber system security; however, the training, expertise, and knowledge of appropriate tools and techniques required to perform effective red teaming come with a significant cost in time and resources. To address these issues, we have previously developed a "red team in a box" (RTIB) capability, called CARTT (Cyber Automated Red Team Tool), to perform automated red team actions on the internal enterprise network without the need for its users to be experts in this field. This current research has extended CARTT by developing a client/server model system that allows operators to perform red team testing on target networks from a simple remote web interface. Using a command-and-control architecture, the extended CARTT provides the ability for cyber operators and network administrators to identify hosts on a target network, conduct vulnerability analysis on those hosts and the target network, attempt to exploit discovered vulnerabilities based on user selected options, and generate the results of these red teaming actions. Additionally, CARTT now provides a tiered role system, so that higher level "commander" users can direct and monitor the actions and results of subordinate "operator" users; as well, the system provides an "administrator" management role. By providing a simple user interface that automates interaction with the underlying tools, operators are able to utilize CARTT without extensive training or experience in red team operations. The ease of use and reliance on open source software greatly reduces the requirements for organizations to use this tool for red teaming their networks.
引用
收藏
页码:11 / 19
页数:9
相关论文
共 50 条
  • [31] A Methodology for the Development of Web-based Information Systems: Web Development Team Perspective
    Abdul-Aziz, Azlianor
    Koronios, Andy
    Gao, Jing
    Sulong, Muhammad Suhaizan
    AMCIS 2012 PROCEEDINGS, 2012,
  • [32] Automated and Manual Grading of Web-Based Assignments
    Peveler, Matthew
    Maicus, Evan
    Cutler, Barbara
    SIGCSE 2020: PROCEEDINGS OF THE 51ST ACM TECHNICAL SYMPOSIUM ON COMPUTER SCIENCE EDUCATION, 2020, : 1373 - 1373
  • [33] Automated Web-Based Geoprocessing of Rental Prices
    Schernthanner, Harald
    Steppan, Sebastian
    Kuntzsch, Christian
    Borg, Erik
    Asche, Hartmut
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2017, PT IV, 2017, 10407 : 512 - 524
  • [34] Automated specification and verification of Web-based applications
    ter Beek, Maurice H.
    Lafuente, Alberto Lluch
    JOURNAL OF LOGICAL AND ALGEBRAIC METHODS IN PROGRAMMING, 2017, 87 : 51 - 51
  • [35] Color red in web-based knowledge testing
    Gnambs, Timo
    Appel, Markus
    Batinic, Bernad
    COMPUTERS IN HUMAN BEHAVIOR, 2010, 26 (06) : 1625 - 1631
  • [36] Bed management team with Kanban web-based application
    Lima Rocha, Hermano Alexandre
    Lima da Cruz Santos, Ana Kelly
    de Castro Alcantara, Antonia Celia
    Suliano da Costa Lima, Carmen Sulinete
    Maia Oliveira Rocha, Sabrina Gabriele
    Cardoso, Roberto Melo
    Cremonin, Jair Rodrigues, Jr.
    INTERNATIONAL JOURNAL FOR QUALITY IN HEALTH CARE, 2018, 30 (09) : 708 - 714
  • [37] A web-based multidisciplinary team meeting visualisation system
    Jung, Hoijoon
    Jung, Younhyun
    Feng, David Dagan
    Fulham, Michael
    Kim, Jinman
    INTERNATIONAL JOURNAL OF COMPUTER ASSISTED RADIOLOGY AND SURGERY, 2019, 14 (12) : 2221 - 2231
  • [38] WikiDev 2.0: Web-based Software Team Collaboration
    Fokaefs, Marios
    Bauer, Ken
    Stroulia, Eleni
    2009 ICSE WORKSHOP ON WIKIS FOR SOFTWARE ENGINEERING, 2009, : 67 - 77
  • [39] Design of a Web-based care team scheduler for PalmCIS
    Stetson, PD
    McKnight, LK
    Chen, E
    Cimino, JJ
    AMIA 2002 SYMPOSIUM, PROCEEDINGS: BIOMEDICAL INFORMATICS: ONE DISCIPLINE, 2002, : 1172 - 1172
  • [40] A Web-Based Tool for Biomedical Signal Management
    Cano-Ortiz, S. D.
    Langmann, R.
    Martinez-Canete, Y.
    Lombardia-Legra, L.
    Herrero-Betancourt, F.
    Jacques, H.
    ONLINE ENGINEERING & INTERNET OF THINGS, 2018, 22 : 758 - 763