The best way to train people about security is through Cyber Ranges, i.e., the virtual platform used by cyber-security experts to learn new skills and attack vectors. In order to realize such virtual scenarios, container-based virtualization is commonly adopted, as it provides several benefits in terms of performance, resource usage, and portability. Unfortunately, the current generation of Cyber Ranges does not consider mobile devices, which nowadays are ubiquitous in our daily lives. Such devices do often represent the very first entry point for hackers into target networks. It is thus important to make available tools allowing to emulate mobile devices in a safe environment without incurring the risk of causing any damage in the real world. This work aims to propose Dockerized Android, i.e., a framework that addresses the problem of realizing vulnerable environments for mobile devices in the next generation of Cyber Ranges. We show the platform's design and implementation and show how it is possible to use the implemented features to realize complex virtual mobile kill-chains scenarios.
翻译:对人们进行安全培训的最佳方式是通过网络区域,即网络安全专家用来学习新技能和攻击矢量的虚拟平台。为了实现这种虚拟情景,通常采用集装箱虚拟化,因为它在性能、资源使用和可移动性方面提供了若干好处。不幸的是,目前一代网络区域不考虑移动设备,而现在移动设备在我们日常生活中是无处不在的。这种设备常常代表黑客进入目标网络的第一切入点。因此,重要的是提供工具,允许在安全环境中模仿移动设备,而不会在现实世界中造成任何损害。这项工作的目的是提出多克化和机器人,即一个框架,解决在下一代网络区域实现移动设备脆弱环境的问题。我们展示了平台的设计和实施,并展示如何利用已安装的功能实现复杂的虚拟移动杀人链情景。