Week 8 Discussion 2 – Cyber Defense

profilemid908
red_team.docx

· Red team/blue team exercises. Using a simulated network, the red team attempts to attack the network while the blue team defends it. The red team plays the role of an attacker with no boundaries on what they are willing to do, while the blue team is usually prohibited from hacking back against the red team.

· Exercises that test the technical defenses of an organization, including their ability to detect attacks. This is usually known as penetration testing. In penetration testing there is a red team attacking the organization's network, but since it is a real, operating network, there are always strict limits on how far the red team can go, for instance, destruction is not allowed. The defenders are usually unaware or just vaguely aware that a penetration test is underway, making the test more realistic.

· Exercises that test the resilience of an organization when a security breach occurs. This type of exercise typically addresses the technical tasks to detect, contain, maintain and recover, but also public relations, interaction with law enforcement, and so on. These exercises are simulations, because you can't practice with a real attack without creating real consequences.

· Military exercises that simulate cyberwar. These don't necessarily have the artificial limitations of the other types of exercises, but just like other types of military exercises, they require the participants to make assumptions about the motivations, tactics and capabilities of the enemy.

 

There are several academic competitions that involve red team/blue team exercises, at the college and even high school levels. Probably the best known, at least in this region, is the Collegiate Cyber Defense Competition (CCDC).