Most cyber ranges used today to train security professionals and students are pure software-based simulation environments. However, many security threats related to the hardware domain of devices are difficult to reproduce in these software environments.
Therefore, we have developed a unique capability here at ASU that combines both software and hardware aspects of system vulnerability assessment and penetration testing at different scales.
In addition to supporting the conventional software-based computer systems simulation, the Arizona Cyber Range (AzCR) provides scalability with the realism of hardware devices physically present in an emulated environment.
With AzCR, we can perform high-fidelity, hardware-in-the-loop security vulnerability assessment and penetration testing in systems at different scales – e.g., electrical power grid systems, industrial plants with different sensors, actuators, interfaces and physical processes models, and automotive Controller Area Network (CAN) bus.
With AzCR, we can provide a testbed for security validation and safety proof of concepts in cyber-physical systems (CPS).
Active System Hardening: the AzCR platform has its own, very intuitive, graphical user interface that allows:
- management of cyber agents, both virtual and physical;
- monitoring and analysis of the events and the evolution of participant agents;
- scoring to assess the sophistication of attacks and robustness of defense mechanisms;
- use of machine learning algorithms and game theory to augment the scenario entropy of cyber mission exercises.