• DocumentCode
    1906036
  • Title

    Cyber security analysis testbed: Combining real, emulation, and simulation

  • Author

    Van Leeuwen, Brian ; Urias, Vincent ; Eldridge, John ; Villamarin, Charles ; Olsberg, Ron

  • Author_Institution
    Sandia Nat. Labs., Albuquerque, NM, USA
  • fYear
    2010
  • fDate
    5-8 Oct. 2010
  • Firstpage
    121
  • Lastpage
    126
  • Abstract
    Cyber security analysis tools are necessary to evaluate the security, reliability, and resilience of networked information systems against cyber attack. It is common practice in modern cyber security analysis to separately utilize real systems of computers, routers, switches, firewalls, computer emulations (e.g., virtual machines) and simulation models to analyze the interplay between cyber threats and safeguards. In contrast, Sandia National Laboratories has developed novel methods to combine these evaluation platforms into a hybrid testbed that combines real, emulated, and simulated components. The combination of real, emulated, and simulated components enables the analysis of security features and components of a networked information system. When performing cyber security analysis on a system of interest, it is critical to realistically represent the subject security components in high fidelity. In some experiments, the security component may be the actual hardware and software with all the surrounding components represented in simulation or with surrogate devices. Sandia National Laboratories has developed a cyber testbed that combines modeling and simulation capabilities with virtual machines and real devices to represent, in varying fidelity, secure networked information system architectures and devices. Using this capability, secure networked information system architectures can be represented in our testbed on a single, unified computing platform. This provides an “experiment-in-a-box” capability. The result is rapidly-produced, large-scale, relatively low-cost, multi-fidelity representations of networked information systems. These representations enable analysts to quickly investigate cyber threats and test protection approaches and configurations.
  • Keywords
    Internet; security of data; computer emulation; cyber attack; cyber security analysis testbed; cyber security analysis tool; cyber threat; evaluation platform; firewall; hybrid testbed; networked information system reliability; networked information system resilience; secure networked information system architecture; security component; security feature analysis; virtual machines; Analytical models; Computational modeling; Data models; Hardware; Logic gates; Security; Virtual private networks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Technology (ICCST), 2010 IEEE International Carnahan Conference on
  • Conference_Location
    San Jose, CA
  • ISSN
    1071-6572
  • Print_ISBN
    978-1-4244-7403-5
  • Type

    conf

  • DOI
    10.1109/CCST.2010.5678720
  • Filename
    5678720