• DocumentCode
    3341328
  • Title

    Security in Tele-Lab — Protecting an online virtual lab for security training

  • Author

    Willems, C. ; Dawoud, W. ; Klingbeil, T. ; Meinel, C.

  • Author_Institution
    Hasso Plattner Inst., Potsdam, Germany
  • fYear
    2009
  • fDate
    9-12 Nov. 2009
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    The rapid burst of Internet usage and the corresponding growth of security risks and online attacks for the everyday user or the enterprise employee have emerged the terms Awareness Creation and Information Security Culture. Nevertheless, security education widely has remained an academic issue. Teaching system or network security on the basis of practical experience inherits a great challenge for the teaching environment, which is traditionally solved using a computer laboratory at a university campus. The Tele-Lab project offers a system for hands-on IT security training within a remote virtual lab environment - over the Web, accessible by everyone. Such a system is inherently exposed to various security threats, since it has to provide full access to virtual machines running attack tools for potentially malicious users. The paper at hand introduces usage, management and operation of Tele-Lab as well as its architecture. Furthermore, this work focuses on possible attacks, the challenges when securing such a system, and shows how to set up an infrastructure that ensures the main security objectives identified as authentication, authorisation and availability.
  • Keywords
    authorisation; computer based training; virtual instrumentation; virtual machines; IT security training; Internet; Tele-Lab project; authentication; authorisation; awareness creation; computer laboratory; enterprise employee; information security culture; network security; online virtual lab; security education; teaching system; university campus; virtual machines; Authentication; Authorization; Computer networks; Computer science education; Computer security; Information security; Internet; Management training; Protection; Virtual machining;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Technology and Secured Transactions, 2009. ICITST 2009. International Conference for
  • Conference_Location
    London
  • Print_ISBN
    978-1-4244-5647-5
  • Type

    conf

  • DOI
    10.1109/ICITST.2009.5402506
  • Filename
    5402506