论文标题

Dockerized Android:一个基于容器的平台,用于构建网络范围的移动Android场景

Dockerized Android: a container-based platform to build mobile Android scenarios for Cyber Ranges

论文作者

Capone, Daniele, Caturano, Francesco, Delicato, Angelo, Perrone, Gaetano, Romano, Simon Pietro

论文摘要

培训人们有关安全性的最佳方法是通过网络范围,即网络安全专家使用的虚拟平台来学习新技能和攻击向量。为了实现这种虚拟方案,通常采用基于容器的虚拟化,因为它在性能,资源使用和便携性方面提供了一些好处。不幸的是,当前一代的网络范围不考虑移动设备,如今,这些设备在我们的日常生活中无处不在。这样的设备通常代表黑客进入目标网络的第一个入口点。因此,重要的是要制造可用的工具,允许在安全环境中模仿移动设备,而不会产生在现实世界中造成任何损害的风险。这项工作旨在提出Dockerized Android,即一个框架,该框架解决了下一代网络范围内为移动设备实现脆弱环境的问题。我们展示了平台的设计和实现,并展示了如何使用实现的功能实现复杂的虚拟移动杀戮链方案。

The best way to train people about security is through Cyber Ranges, i.e., the virtual platform used by cyber-security experts to learn new skills and attack vectors. In order to realize such virtual scenarios, container-based virtualization is commonly adopted, as it provides several benefits in terms of performance, resource usage, and portability. Unfortunately, the current generation of Cyber Ranges does not consider mobile devices, which nowadays are ubiquitous in our daily lives. Such devices do often represent the very first entry point for hackers into target networks. It is thus important to make available tools allowing to emulate mobile devices in a safe environment without incurring the risk of causing any damage in the real world. This work aims to propose Dockerized Android, i.e., a framework that addresses the problem of realizing vulnerable environments for mobile devices in the next generation of Cyber Ranges. We show the platform's design and implementation and show how it is possible to use the implemented features to realize complex virtual mobile kill-chains scenarios.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源