Organizations have rapidly shifted infrastructure and applications over to public cloud computing services such as AWS (Amazon Web Services), Google Cloud Platform, and Azure. Unfortunately, such services have security models that are substantially different and more complex than traditional enterprise security models. As a result, misconfiguration errors in cloud deployments have led to dozens of well-publicized breaches. This paper describes Thunder CTF, a scaffolded, scenario-based CTF (Capture-the-Flag) for helping students learn about and practice cloud security skills. Thunder CTF is easily deployed at minimal cost and is highly extensible to allow for crowd-sourced development of new levels as security issues evolve in the cloud.
翻译:不幸的是,这类服务具有与传统企业安全模式大相径庭且更为复杂的安全模式。 结果,云部署中的错误配置导致数十起广为人知的违规事件。 本文描述了雷雷CTF, 一种以情景为基础的假想CTF(Capture-Flag ), 帮助学生学习和练习云安全技能。 雷雷CTF很容易以最低的成本部署,并且极有可能随着云层安全问题的演变而出现新的水平。