• DocumentCode
    3308502
  • Title

    Developing and delivering hands-on information assurance exercises: experiences with the cyber defense lab at UMBC

  • Author

    Sherman, Alan T. ; Roberts, Brian O. ; Byrd, William E. ; Baker, Matthew R. ; Simmons, John

  • Author_Institution
    Dept. of Comput. Sci. & Electr. Eng., Maryland Univ., Baltimore, MD, USA
  • fYear
    2004
  • fDate
    10-11 June 2004
  • Firstpage
    242
  • Lastpage
    249
  • Abstract
    In summer 2003, we developed four new hands-on information assurance educational exercises for use in the UMBC undergraduate and graduate curricula. Exercise topics comprise buffer overflow attacks, vulnerability scanning, password security and policy, and flaws in the wired equivalent privacy (WEP) protocol. During each exercise, each student carries out structured activities using a laptop from a mobile cart that can be rolled into any classroom. These dedicated, isolated machines permit a student to make mistakes safely, even while acting as the system administrator, without adversely affecting any other user. Each exercise is organized in a modular fashion to facilitate varied use for different courses, levels, and available time. Our experiences delivering these exercises show that practical hands-on activities motivate students and enhance learning. In this paper we describe our exercises and share lessons learned, including the importance of careful planning, ethical considerations, the rapid obsolescence of tools, and the difficulty of including exercises in already busy courses.
  • Keywords
    buffer storage; computer science education; data privacy; educational courses; ethical aspects; human factors; protocols; security of data; UMBC undergraduate curricula; buffer overflow attacks; computer security education; cyber defense lab; hands-on information assurance educational exercises; password security; vulnerability scanning; wired equivalent privacy protocol; Buffer overflow; Buildings; Computer science; Computer science education; Computer security; Information security; Portable computers; Privacy; Problem-solving; Protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance Workshop, 2004. Proceedings from the Fifth Annual IEEE SMC
  • Print_ISBN
    0-7803-8572-1
  • Type

    conf

  • DOI
    10.1109/IAW.2004.1437823
  • Filename
    1437823