Battle Ground: Data Collection and Labeling of CTF Games to Understand Human Cyber Operators

07/20/2023
by   Georgel Savin, et al.
0

Industry standard frameworks are now widespread for labeling the high-level stages and granular actions of attacker and defender behavior in cyberspace. While these labels are used for atomic actions, and to some extent for sequences of actions, there remains a need for labeled data from realistic full-scale attacks. This data is valuable for better understanding human actors' decisions, behaviors, and individual attributes. The analysis could lead to more effective attribution and disruption of attackers. We present a methodological approach and exploratory case study for systematically analyzing human behavior during a cyber offense/defense capture-the-flag (CTF) game. We describe the data collection and analysis to derive a metric called keystroke accuracy. After collecting players' commands, we label them using the MITRE ATT CK framework using a new tool called Pathfinder. We present results from preliminary analysis of participants' keystroke accuracy and its relation to score outcome in CTF games. We describe frequency of action classification within the MITRE ATT CK framework and discuss some of the mathematical trends suggested by our observations. We conclude with a discussion of extensions for the methodology, including performance evaluation during games and the potential use of this methodology for training artificial intelligence.

READ FULL TEXT
research
08/31/2021

Informing Autonomous Deception Systems with Cyber Expert Performance Data

The performance of artificial intelligence (AI) algorithms in practice d...
research
06/19/2020

Modeling Individual and Team Behavior through Spatio-temporal Analysis

Modeling players' behaviors in games has gained increased momentum in th...
research
06/18/2020

"And then they died": Using Action Sequences for Data Driven,Context Aware Gameplay Analysis

Many successful games rely heavily on data analytics to understand playe...
research
08/18/2019

Towards Understanding of eSports Athletes' Potentialities: The Sensing System for Data Collection and Analysis

eSports is a developing multidisciplinary research area. At present, the...
research
09/28/2018

Game-Theoretic Model and Experimental Investigation of Cyber Wargaming

We demonstrate that game-theoretic calculations serve as a useful tool f...
research
06/03/2023

Learning to Defend by Attacking (and Vice-Versa): Transfer of Learning in Cybersecurity Games

Designing cyber defense systems to account for cognitive biases in human...
research
09/15/2023

Virtual Harassment, Real Understanding: Using a Serious Game and Bayesian Networks to Study Cyberbullying

Cyberbullying among minors is a pressing concern in our digital society,...

Please sign up or login with your details

Forgot password? Click here to reset