Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range

Detalhes bibliográficos
Autor(a) principal: Cruz, Tiago
Data de Publicação: 2021
Outros Autores: Simões, Paulo
Tipo de documento: Artigo
Idioma: eng
Título da fonte: Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
Texto Completo: http://hdl.handle.net/10316/100940
https://doi.org/10.3390/app11209509
Resumo: Prior experience from the authors has shown that a heavily theoretical approach for cybersecurity training has multiple shortcomings, mostly due to the demanding and diversified nature of the prerequisites, often involving concepts about operating system design, networking and computer architecture, among others. In such circumstances, the quest for trainee engagement often turns into a delicate balancing act between managing their expectations and providing an adequate progression path. In this perspective, hands-on exercises and contact with high-fidelity environments play a vital part in fostering interest and promoting a rewarding learning experience. Making this possible requires having the ability to design and deploy different use case training scenarios in a flexible way, tailored to the specific needs of classroom-based, blended or e-learning teaching models. This paper presents a flexible framework for the creation of laboratory and cyber range environments for training purposes, detailing the development, implementation and exploration of a cyber range scenario, within the scope of a course on cyber-physical systems security. Moreover, the course structure, curricular aspects and teaching methods are also detailed, as well as the feedback obtained from the students.
id RCAP_93eedbc1e324a29a429a8a01d0144cbb
oai_identifier_str oai:estudogeral.uc.pt:10316/100940
network_acronym_str RCAP
network_name_str Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
repository_id_str 7160
spelling Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Rangecyber rangescybersecurity trainingSCADAcyber-physical systemsPrior experience from the authors has shown that a heavily theoretical approach for cybersecurity training has multiple shortcomings, mostly due to the demanding and diversified nature of the prerequisites, often involving concepts about operating system design, networking and computer architecture, among others. In such circumstances, the quest for trainee engagement often turns into a delicate balancing act between managing their expectations and providing an adequate progression path. In this perspective, hands-on exercises and contact with high-fidelity environments play a vital part in fostering interest and promoting a rewarding learning experience. Making this possible requires having the ability to design and deploy different use case training scenarios in a flexible way, tailored to the specific needs of classroom-based, blended or e-learning teaching models. This paper presents a flexible framework for the creation of laboratory and cyber range environments for training purposes, detailing the development, implementation and exploration of a cyber range scenario, within the scope of a course on cyber-physical systems security. Moreover, the course structure, curricular aspects and teaching methods are also detailed, as well as the feedback obtained from the students.2021info:eu-repo/semantics/publishedVersioninfo:eu-repo/semantics/articlehttp://hdl.handle.net/10316/100940http://hdl.handle.net/10316/100940https://doi.org/10.3390/app11209509eng2076-3417Cruz, TiagoSimões, Pauloinfo:eu-repo/semantics/openAccessreponame:Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)instname:Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informaçãoinstacron:RCAAP2022-07-21T20:40:42Zoai:estudogeral.uc.pt:10316/100940Portal AgregadorONGhttps://www.rcaap.pt/oai/openaireopendoar:71602024-03-19T21:18:13.340361Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos) - Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informaçãofalse
dc.title.none.fl_str_mv Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
title Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
spellingShingle Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
Cruz, Tiago
cyber ranges
cybersecurity training
SCADA
cyber-physical systems
title_short Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
title_full Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
title_fullStr Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
title_full_unstemmed Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
title_sort Down the Rabbit Hole: Fostering Active Learning through Guided Exploration of a SCADA Cyber Range
author Cruz, Tiago
author_facet Cruz, Tiago
Simões, Paulo
author_role author
author2 Simões, Paulo
author2_role author
dc.contributor.author.fl_str_mv Cruz, Tiago
Simões, Paulo
dc.subject.por.fl_str_mv cyber ranges
cybersecurity training
SCADA
cyber-physical systems
topic cyber ranges
cybersecurity training
SCADA
cyber-physical systems
description Prior experience from the authors has shown that a heavily theoretical approach for cybersecurity training has multiple shortcomings, mostly due to the demanding and diversified nature of the prerequisites, often involving concepts about operating system design, networking and computer architecture, among others. In such circumstances, the quest for trainee engagement often turns into a delicate balancing act between managing their expectations and providing an adequate progression path. In this perspective, hands-on exercises and contact with high-fidelity environments play a vital part in fostering interest and promoting a rewarding learning experience. Making this possible requires having the ability to design and deploy different use case training scenarios in a flexible way, tailored to the specific needs of classroom-based, blended or e-learning teaching models. This paper presents a flexible framework for the creation of laboratory and cyber range environments for training purposes, detailing the development, implementation and exploration of a cyber range scenario, within the scope of a course on cyber-physical systems security. Moreover, the course structure, curricular aspects and teaching methods are also detailed, as well as the feedback obtained from the students.
publishDate 2021
dc.date.none.fl_str_mv 2021
dc.type.status.fl_str_mv info:eu-repo/semantics/publishedVersion
dc.type.driver.fl_str_mv info:eu-repo/semantics/article
format article
status_str publishedVersion
dc.identifier.uri.fl_str_mv http://hdl.handle.net/10316/100940
http://hdl.handle.net/10316/100940
https://doi.org/10.3390/app11209509
url http://hdl.handle.net/10316/100940
https://doi.org/10.3390/app11209509
dc.language.iso.fl_str_mv eng
language eng
dc.relation.none.fl_str_mv 2076-3417
dc.rights.driver.fl_str_mv info:eu-repo/semantics/openAccess
eu_rights_str_mv openAccess
dc.source.none.fl_str_mv reponame:Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
instname:Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informação
instacron:RCAAP
instname_str Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informação
instacron_str RCAAP
institution RCAAP
reponame_str Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
collection Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos)
repository.name.fl_str_mv Repositório Científico de Acesso Aberto de Portugal (Repositórios Cientìficos) - Agência para a Sociedade do Conhecimento (UMIC) - FCT - Sociedade da Informação
repository.mail.fl_str_mv
_version_ 1799134077620584448