Web CARTT: The Web-Based Cyber Automated Red Team Tool

被引:0
|
作者
Berrios, Joseph [1 ]
Shaffer, Alan [1 ]
Singh, Gurminder [1 ]
机构
[1] Naval Postgrad Sch, Monterey, CA 93943 USA
关键词
red team; defensive cyber operations; automated vulnerability analysis; web-based assessment;
D O I
10.34190/IWS.21.017
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Red teaming is a well-established methodology for ensuring and augmenting cyber system security; however, the training, expertise, and knowledge of appropriate tools and techniques required to perform effective red teaming come with a significant cost in time and resources. To address these issues, we have previously developed a "red team in a box" (RTIB) capability, called CARTT (Cyber Automated Red Team Tool), to perform automated red team actions on the internal enterprise network without the need for its users to be experts in this field. This current research has extended CARTT by developing a client/server model system that allows operators to perform red team testing on target networks from a simple remote web interface. Using a command-and-control architecture, the extended CARTT provides the ability for cyber operators and network administrators to identify hosts on a target network, conduct vulnerability analysis on those hosts and the target network, attempt to exploit discovered vulnerabilities based on user selected options, and generate the results of these red teaming actions. Additionally, CARTT now provides a tiered role system, so that higher level "commander" users can direct and monitor the actions and results of subordinate "operator" users; as well, the system provides an "administrator" management role. By providing a simple user interface that automates interaction with the underlying tools, operators are able to utilize CARTT without extensive training or experience in red team operations. The ease of use and reliance on open source software greatly reduces the requirements for organizations to use this tool for red teaming their networks.
引用
收藏
页码:11 / 19
页数:9
相关论文
共 50 条
  • [41] A web-based information tool for application engineering
    Schmidt, J
    Feldmann, DG
    DESIGN MANAGEMENT - PROCESS AND INFORMATION ISSUES, 2001, : 59 - 66
  • [42] SKATE: A Web-Based Seismogram Digitization Tool
    Bartlett, Andrew H.
    Lichtner, Benjamin A.
    Nita, Marius
    Yashar, Benamy
    Bartlett, Lowell E.
    SEISMOLOGICAL RESEARCH LETTERS, 2018, 89 (05) : 1886 - 1893
  • [43] DAREonline: A Web-Based Domain Engineering Tool
    Dos Santos, Raimundo F.
    Frakes, William B.
    FORMAL FOUNDATIONS OF REUSE AND DOMAIN ENGINEERING, PROCEEDINGS, 2009, 5791 : 246 - 257
  • [44] A web-based multidisciplinary team meeting visualisation system
    Hoijoon Jung
    Younhyun Jung
    David Dagan Feng
    Michael Fulham
    Jinman Kim
    International Journal of Computer Assisted Radiology and Surgery, 2019, 14 : 2221 - 2231
  • [45] A web-based tool for Arabic sentiment analysis
    El-Masri, Mazen
    Altrabsheh, Nabeela
    Mansour, Hanady
    Ramsay, Allan
    ARABIC COMPUTATIONAL LINGUISTICS (ACLING 2017), 2017, 117 : 38 - 45
  • [46] ACT: A web-based adaptive communication tool
    Gogoulou, Agoritsa
    Gouli, Evangelia
    Grigoriadou, Maria
    Samarakou, Maria
    CSCL 2005: COMPUTER SUPPORTED COLLABORATIVE LEARNING 2005: THE NEXT 10 YEARS, PROCEEDINGS, 2005, : 180 - 189
  • [47] Dinosys: An annotation tool for web-based learning
    Desmontils, E
    Jacquin, C
    Simon, L
    ADVANCES IN WEB-BASED LEARNING - ICWL 2004, 2004, 3143 : 59 - 66
  • [48] CoAT: A Web-based, Collaborative Annotation Tool
    Satybaldiev, Aziret
    Hevesi, Peter
    Hirsch, Marco
    Rey, Vitor Fortes
    Lukowicz, Paul
    UBICOMP/ISWC'19 ADJUNCT: PROCEEDINGS OF THE 2019 ACM INTERNATIONAL JOINT CONFERENCE ON PERVASIVE AND UBIQUITOUS COMPUTING AND PROCEEDINGS OF THE 2019 ACM INTERNATIONAL SYMPOSIUM ON WEARABLE COMPUTERS, 2019, : 814 - 818
  • [49] Distributed Web-based image processing tool
    de Boer, M
    Hesser, J
    Männer, R
    METMBS'00: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON MATHEMATICS AND ENGINEERING TECHNIQUES IN MEDICINE AND BIOLOGICAL SCIENCES, VOLS I AND II, 2000, : 657 - 663
  • [50] A web-based tool for data analysis and presentation
    Tesoriero, R
    Zelkowitz, M
    IEEE INTERNET COMPUTING, 1998, 2 (05) : 63 - 69