<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - automation</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/automation/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2018-06-27T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/automation/atom.xml</id>
    <entry xml:lang="en">
        <title>Emerging Cyber Ranges: Competition to Compliance</title>
        <published>2018-06-27T00:00:00+00:00</published>
        <updated>2018-06-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/"/>
        <id>https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons SANS @ Night presentation Emerging Cyber Ranges: Competition
to Compliance, delivered on June 27, 2018, explores how purpose-built
environments can accelerate offensive and defensive security practice, foster
competitive e-sports, and underpin formal compliance and product validation
efforts .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cyber-range&quot;&gt;Cyber Range&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon defines a cyber range as any isolated, refreshable networkvirtual
or physicalused to detonate malware, test exploits, or simulate advanced
threats. He surveys existing platforms from SANS NetWars (both virtual
challenges and the physical CyberCity model) to JYVSECTECs SCADA-focused ranges
and the Michigan Cyber Range, and even the DARPA-led National Cyber Range. Each
example illustrates how controlled environments enable realistic training,
product proof-of-concepts, and large-scale team competitions without risking
production assets .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;principles-to-proof-of-concept&quot;&gt;Principles to Proof of Concept&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the talk shifts to design principles and hands-on constructs. Harmon
outlines key requirementscontainment, auto-scaling, encrypted peer tunnels,
explicit authorization, rapid restoration, and portabilityand presents a
Raspberry Pi-based proof-of-concept leveraging OPNsense, HardenedBSD routing,
iPXE booting, and YubiKey-backed hardware security modules. He also covers
adversary simulation using MITRE CALDERA, Uber Metta, and Netflixs Simian Army,
and shows how cyber ranges can be woven into compliance lifecyclesfrom
requirements gathering through vendor evaluation, baseline verification, and
resilience testingtransforming these playgrounds into governance-grade testbeds
.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;58296_2018-06-27_Cyber_Ranges-SANS_with_Script.pdf&quot;&gt;Cyber Ranges,
Script&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>DDoS Survival</title>
        <published>2013-10-18T00:00:00+00:00</published>
        <updated>2013-10-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmon and Phil Reno present at the (ISC)2 Twin Cities Area Chapter
on DDoS Survival, delivered on October 18, 2013, provides a comprehensive primer
on Distributed Denial of Service (DDoS) attacks and how organizations can
withstand and mitigate them. It begins by defining DDoS as resource exhaustion
aimed at disrupting servicesand tracing its roots from IRC-driven pranks to
sophisticated protest and extortion campaigns.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;threats-and-attack-techniques&quot;&gt;Threats and Attack Techniques&lt;&#x2F;h2&gt;
&lt;p&gt;The first section surveys real-world threats and attack techniques. The
presenters highlight notable incidents such as Anonymous&#x2F;AntiSec campaigns and
itsoknoproblembro browser-based botnets and reference data on rising attack
volumes from sources like Arbor Networks. They categorize attack vectors across
the OSI stack (TCP&#x2F;SSL floods, HTTP-level assaults like Slowloris and
chunked-header exploits, and ICMP&#x2F;UDP floods) and assess attacker skill levels,
from low-effort LOIC&#x2F;XOIC scripts to more advanced injection-driven browser
botnets.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense-and-resilience&quot;&gt;Defense and Resilience&lt;&#x2F;h2&gt;
&lt;p&gt;The second section focuses on defense and resilience strategies. Harmon and Reno
outline four architectural approaches: ISP-level scrubbing, Cloud SOC via
proxy&#x2F;DNS redirection, full-service cloud scrubbing with BGP rerouting, and
in-house solutions. Detailing the pros and cons of each. They emphasize risk
transference through CDNs and anti-DDoS services, null-routing tactics, and
bigger pipes, supplemented by application-level tweaks. The presentation
concludes with guidance on selecting providers (key questions on SLAs,
mitigation capabilities, and cost structures), proactive load testing, and
leveraging automation tools (Chef, Puppet, Ansible, SaltStack, Fabric) to scale
and verify infrastructure readiness under attack.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56583_2013-10-18_DDoS_Survival-ISC2TC.pdf&quot;&gt;DDoS Survival&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
