Organizing large scale hacking competitions

  • Authors:
  • Nicholas Childers;Bryce Boe;Lorenzo Cavallaro;Ludovico Cavedon;Marco Cova;Manuel Egele;Giovanni Vigna

  • Affiliations:
  • Security Group, Department of Computer Science, University of California, Santa Barbara;Security Group, Department of Computer Science, University of California, Santa Barbara;Security Group, Department of Computer Science, University of California, Santa Barbara;Security Group, Department of Computer Science, University of California, Santa Barbara;Security Group, Department of Computer Science, University of California, Santa Barbara;Security Group, Department of Computer Science, University of California, Santa Barbara;Security Group, Department of Computer Science, University of California, Santa Barbara

  • Venue:
  • DIMVA'10 Proceedings of the 7th international conference on Detection of intrusions and malware, and vulnerability assessment
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Computer security competitions and challenges are a way to foster innovation and educate students in a highly-motivating setting. In recent years, a number of different security competitions and challenges were carried out, each with different characteristics, configurations, and goals. From 2003 to 2007, we carried out a number of live security exercises involving dozens of universities from around the world. These exercises were designed as "traditional" Capture The Flag competitions, where teams both attacked and defended a virtualized host, which provided several vulnerable services. In 2008 and 2009, we introduced two completely new types of competition: a security "treasure hunt" and a botnet-inspired competition. These two competitions, to date, represent the largest live security exercises ever attempted and involved hundreds of students across the globe. In this paper, we describe these two new competition designs, the challenges overcome, and the lessons learned, with the goal of providing useful guidelines to other educators who want to pursue the organization of similar events