<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - cyber-ranges</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/cyber-ranges/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2018-06-27T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/cyber-ranges/atom.xml</id>
    <entry xml:lang="en">
        <title>Emerging Cyber Ranges: Competition to Compliance</title>
        <published>2018-06-27T00:00:00+00:00</published>
        <updated>2018-06-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/"/>
        <id>https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons SANS @ Night presentation Emerging Cyber Ranges: Competition
to Compliance, delivered on June 27, 2018, explores how purpose-built
environments can accelerate offensive and defensive security practice, foster
competitive e-sports, and underpin formal compliance and product validation
efforts .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cyber-range&quot;&gt;Cyber Range&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon defines a cyber range as any isolated, refreshable networkvirtual
or physicalused to detonate malware, test exploits, or simulate advanced
threats. He surveys existing platforms from SANS NetWars (both virtual
challenges and the physical CyberCity model) to JYVSECTECs SCADA-focused ranges
and the Michigan Cyber Range, and even the DARPA-led National Cyber Range. Each
example illustrates how controlled environments enable realistic training,
product proof-of-concepts, and large-scale team competitions without risking
production assets .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;principles-to-proof-of-concept&quot;&gt;Principles to Proof of Concept&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the talk shifts to design principles and hands-on constructs. Harmon
outlines key requirementscontainment, auto-scaling, encrypted peer tunnels,
explicit authorization, rapid restoration, and portabilityand presents a
Raspberry Pi-based proof-of-concept leveraging OPNsense, HardenedBSD routing,
iPXE booting, and YubiKey-backed hardware security modules. He also covers
adversary simulation using MITRE CALDERA, Uber Metta, and Netflixs Simian Army,
and shows how cyber ranges can be woven into compliance lifecyclesfrom
requirements gathering through vendor evaluation, baseline verification, and
resilience testingtransforming these playgrounds into governance-grade testbeds
.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;58296_2018-06-27_Cyber_Ranges-SANS_with_Script.pdf&quot;&gt;Cyber Ranges,
Script&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
