pith. sign in

arxiv: 1507.01922 · v1 · pith:YWBITPZVnew · submitted 2015-07-07 · 💻 cs.CR

Cyber-Deception and Attribution in Capture-the-Flag Exercises

classification 💻 cs.CR
keywords capture-the-flagculpritaccountactivitiesactualalleviateattackattributing
0
0 comments X
read the original abstract

Attributing the culprit of a cyber-attack is widely considered one of the major technical and policy challenges of cyber-security. The lack of ground truth for an individual responsible for a given attack has limited previous studies. Here, we overcome this limitation by leveraging DEFCON capture-the-flag (CTF) exercise data where the actual ground-truth is known. In this work, we use various classification techniques to identify the culprit in a cyberattack and find that deceptive activities account for the majority of misclassified samples. We also explore several heuristics to alleviate some of the misclassification caused by deception.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.