Slashdot Mirror


Cyber Defense Competition Has A New Champion

lisah writes "Several colleges across the country went head-to-head in San Antonio, Texas last weekend at the National Collegiate Cyber Defense Competition to see which team could best protect their networks against attacks. In a modern day version of Steal the Flag, the teams duked it out using identical network setups that included a Cisco router and five servers. In the end, Baker College took the champion's title from last year's winner, Texas A & M University."

43 of 66 comments (clear)

  1. Cyber war-gaming by BWJones · · Score: 4, Interesting

    This is going to become more critical not just in terms of servers and informational or command based attacks, but also in terms of actual combat systems as we start to integrate more robots and remote networked combat platforms. For instance, my last visit to Creech AFB was very informative, but also illustrated a number of potential weaknesses in the system that controls remotely operated unmanned aerial vehicles actively engaging in combat.

    Exercises such as these are critically important to war-game any networked system, particularly when that system is using commercial off the shelf solutions and commodity hardware that is accessible and easy to explore outside the realm of cyber warfare. i.e. war-gaming your attacks before going live...

    --
    Visit Jonesblog and say hello.
    1. Re:Cyber war-gaming by Divebus · · Score: 2, Insightful

      Exercises such as these are critically important to war-game any networked system... ...like defending against RIAA network invasions of Colleges?
      --

      Most of the stuff on /. won't survive first contact with facts.
    2. Re:Cyber war-gaming by smallfries · · Score: 1

      It's good to hear that people are still actively trying to hasten Judgment Day

      --
      Slashdot: where don knuth is an idiot because he cant grasp the awesome power of php
  2. Baker college?!? by fain0v · · Score: 1

    I always thought it was one step above a community college! Either I was wrong or they have improved a lot recently.

    1. Re:Baker college?!? by BosstonesOwn · · Score: 1

      Solid proof one geek can make a difference ! :)

      --
      This package Does Not Contain a Winner
  3. On your marks, get set... by jibster · · Score: 3, Funny

    Any word on when ESPN will start broadcasting these "games" live? Throw in a few hot cheer leaders and I'd watch. Actually, anybody know where I can get tickets?

    1. Re:On your marks, get set... by Mordok-DestroyerOfWo · · Score: 4, Funny

      Coming up on ESPN 1011:

      7:00 - Co-ed full contact bash programming
      8:00 - PHP fantasy team preview
      9:00 - X-Treme PERL recital!
      10:00 - World's Strongest Stench competition
      11:00 - Geekcenter

      --
      "Never let your sense of morals prevent you from doing what is right" - Salvor Hardin
    2. Re:On your marks, get set... by g0bshiTe · · Score: 3, Funny

      My guess would have been ESPN 1337

      --
      I am Bennett Haselton! I am Bennett Haselton!
    3. Re:On your marks, get set... by beckerist · · Score: 1

      ESPN Mil Trescientos Treinta Siete!

    4. Re:On your marks, get set... by Paradise+Pete · · Score: 1
      Any word on when ESPN will start broadcasting these "games" live? Throw in a few hot cheer leaders and I'd watch.

      When I was in high school we travelled to another school for a chess match. They actually had cheerleaders. But since there were no fans, and the cheerleaders of course had to be quiet, it was rather strange.

    5. Re:On your marks, get set... by lythander · · Score: 1

      Seriously, I work with one of the major partners making this competition happen, and they're already in talks with ESPN2. They're working hard on visualization techniiques to make it TV-friendly.

  4. Not sure what this proves by menace3society · · Score: 4, Insightful

    Usually competitions like this are in "Which OS is most secure" kinds of settings, where the ostensible purpose is to find out which OS is the most secure. However, in this case, you had you had a bunch of different OSs all linked together, and you had to protect them from a bunch of security professionals. I imagine these "pros" probably weren't hard-core hackers, and given that, I'm not sure what the value of the exercise was. These pros won't have anything in their arsenal that everybody doesn't already know about it (at least, if they're studying computer security, they *ought* to know about it), and so we're basically left with (and this is something the article mentions) a bunch of people changing their conf files as fast as possible. If you ask me, they should six Eastern Europeans and North Koreans, and offer them $10,000 for every box they own. If the teams box doesn't get owned, they get the ten grand. Simpler, more interesting, and far more realistic.

    1. Re:Not sure what this proves by Dachannien · · Score: 5, Funny

      All sounded pretty good until you used the word "owned". Damn straight. Everybody knows the technical term is "pwned".

    2. Re:Not sure what this proves by Anonymous Coward · · Score: 4, Interesting

      A friend of mine, who knew the pros -- at least for the regionals that I *almost* got to compete in (not bitter, nope, not me) -- said they were Serious Business. The point is to go into a new system, figure out what's broken (because the systems the blue teams were provided were broken, sploitwise), and fix it. Changing your conf files as fast as possible means you have to know which files to change in which ways. I don't think the game is entirely realistic either, but it is important to know the methods. Between the in-depth study of a competitor's assigned system and the actual experience of an attack, you get a pretty good grasp of what it's like.

    3. Re:Not sure what this proves by ja1217 · · Score: 4, Interesting

      I also participated in the competition, but due to issues with our Firewall (the stupid scanner the provided with us didn't work and we ended up taking our network down several times for unecessary reasons) we didn't pass the qualifying rounds. However, I went along to one of the later rounds and was allowed to sit in with the hackers. But as Anonymous said, the goal is mainly to fix a machine that already has holes as fast as possible. In my competition, we had two linux boxes (Red Hat 7 for DNS and Fedora 8 for web), a FreeBSD box for sendmail, a Win2k back up DNS, 2003 server for LDAP, and two Windows XP desktops. While the hackers weren't allowed to use 0 day vulnerabilities, they did have tools like CORE Impact at their disposal and within the first 5 minutes of the competition had owned every windows box. The only time I remember a *nix box getting owned was my groups. We were two busy fixing the LDAP server and forgot to change the default password of the BSD box from "password" because they were on the same machine (we had a virtual machine set up for our competition. This had its annoyances, but we could quickly recover from hacks by doind a revert to snapshot with VM ware. They probably disabled the revert feature in later competitions as in a real business environment, which they were trying to simulate, reverting could cause massive data loss.) Towards the end when things were winding down, one team had gotten owned really hard and wasn't about to recover, so they started doing trick programs on them. At one point, they had a screen cast of one of the competitors computers running on their own so they could see exactly what that school was doing. So they ran a trick program that made it look like it was running the Vista install process. We quick ran over and saw them frantically trying to cancel it with no effect. And then they ran a delete all on that computer. Even though my team lost, we had lots of fun and I was able to learn a lot. We'll be back next year (Millersville University) and hope to regain our position of at least 2nd place at Nationals, which we had for the 2 previous years.

    4. Re:Not sure what this proves by yabastaaa · · Score: 1

      Usually competitions like this are in "Which OS is most secure" kinds of settings, where the ostensible purpose is to find out which OS is the most insecure. fixed that for ya
    5. Re:Not sure what this proves by thelordzero · · Score: 3, Informative

      Usually competitions like this are in "Which OS is most secure" kinds of settings, where the ostensible purpose is to find out which OS is the most secure. However, in this case, you had you had a bunch of different OSs all linked together, and you had to protect them from a bunch of security professionals. I imagine these "pros" probably weren't hard-core hackers, and given that, I'm not sure what the value of the exercise was. These "pros" as you said are actually professional flown in from around the country who either are partners in consulting companies or just a level below that. Everyone on the red team does it for a living at the national level and certainly is not a bunch of non hardcore hackers who said o lets have fun. But then again what do i know, I was on the red team.
    6. Re:Not sure what this proves by luaplevap · · Score: 1

      Usually competitions like this are in "Which OS is most secure" kinds of settings, where the ostensible purpose is to find out which OS is the most secure. However, in this case, you had you had a bunch of different OSs all linked together, and you had to protect them from a bunch of security professionals. I imagine these "pros" probably weren't hard-core hackers, and given that, I'm not sure what the value of the exercise was. These pros won't have anything in their arsenal that everybody doesn't already know about it (at least, if they're studying computer security, they *ought* to know about it), and so we're basically left with (and this is something the article mentions) a bunch of people changing their conf files as fast as possible. If you ask me, they should six Eastern Europeans and North Koreans, and offer them $10,000 for every box they own. If the teams box doesn't get owned, they get the ten grand. Simpler, more interesting, and far more realistic. being both from eastern europe and also a decent hacker, I like that idea
    7. Re:Not sure what this proves by menace3society · · Score: 1

      Oh, so you make your living breaking into systems and either selling the information you find, or exploiting it directly to get rich?

      My point wasn't that they didn't hire security professionals, or that they didn't hire people who knew how to break into systems. They hired people who don't break into systems professionally, and that's what you'll be up against in the real world. It's like putting Home Guardsmen on the front line.

    8. Re:Not sure what this proves by thelordzero · · Score: 1

      actually pretty much everyone makes a living off of the profession. That being said I was completly humbled by the team that was assembled and learned alot being there with them. Team Hilarious was great.

    9. Re:Not sure what this proves by not_hylas(+) · · Score: 1

      Didn't We Trash This Last Year?
      Elite Network Counter Strike Force pwn Teens:

      http://it.slashdot.org/comments.pl?sid=227039&cid=18391373 ... fun aside, it does sound as if they've/you all attempted to adjust the rules somewhat.

      --
      ~hylas
    10. Re:Not sure what this proves by menace3society · · Score: 1

      I'm sure they do, and I'm sure they're very talented. But, my point is, they don't make their money through technical exploits. They do audits and maybe even some white-hack attempts at penetration, but they aren't real cyber-criminals like in the Real World (tm).

      If I'm mistaken, please correct me. Also, see what kind of havoc you can cause next year by flooding the pipes with useless data. If the box is too busy serving bogus requests and it drops some legit ones, that counts as service outage, right?

    11. Re:Not sure what this proves by thelordzero · · Score: 1

      not my place to comment on white hat or not and i certainly wouldnt name anyone on the team. not my place at all. the guys on the team are the ones who can write the sploits on the fly when needed. The team lead is a guy who knows his stuff in and out as does the rest of the guys who flew in. Also flooding a connection is forbidden for the most part. I know since I had a perfect sploit lined up for one of the servers that would of DOS'ed it easily but the red teams hands were tied on that point. But yes if the server couldnt respond its a service outage. Some teams did that enough just by themselves (dam those ASA cables ehh? ;) )

    12. Re:Not sure what this proves by TXISDude · · Score: 1

      I have been to these events, and have experience in "the real world". And what does this event prove? It is an exercise designed to test student groups ability to work together as an IT department from a security perspective, and operational perspective in a simulated real world business environment. I agree theoretically that when you take over a network that has deficiencies that it would be "nice" to be able to disconnect, fix it and then reconnect to the internet - but in the real world, try telling your boss that email will be down, that e-commerce will be down, etc. . . you will quickly learn that the real world doesn't share the techie view of taking things off-line to fix them. So, you have to fix them on the fly. This is one of the most realistic aspects of this challenge - find and fix the security issues, while still keeping the systems up and running and answering management demands (the sysadmin part). Sounds simple until you try - the added dimension of finding and repairing problems while maintaining up-time makes this much harder than they typical CTF game. As for the Red Team chops, can't vouch for any of the regionals, but the finals uses a team that would impress the Defcon crowd, the bosses from China or Korea, and any realistic measure of professional hacker. Why do this: to train students to become better IT professionals when they graduate. And to work as a team - which is necessary in today's business environment. Kudos to all who tried, for in the end, they all are winners.

      --
      Hope is the worst of evils, for it prolongs the torment of man. -- Friedrich Nietzsche
  5. RIT by Digi-John · · Score: 1

    I'm just happy to see that my school (RIT) made it to the finals. Didn't even know we had a team.

    --
    Klingon programs don't timeshare, they battle for supremacy.
  6. In a previous life .. by clint999 · · Score: 1

    In a previous life this is something I did with government networks on a daily basis .. as I'm sure most slashdotter's have done.

    1. Re:In a previous life .. by clint999 · · Score: 1

      nothing to see here, move along

  7. from a Red Team member perspective.... by thelordzero · · Score: 5, Informative

    Well this competition was actually a great one. I was one of the red team members for the nationals (and also the only person to have gone from a regional team captain to the national red team). The competition was very close to the very end with only a few subtle mistakes being made as of the second day. The run down is usually like this for the red team: Day 1: Boxes are extremly vulnerable and red team had a hayday with easily found exploits. We set some backdoors and have some fun with the servers. Looking for customer data that is stored on them. Day 2: Teams have patched most boxes and taken care of most of the vulns out there. Red team goes after websites finding exploits for the most part since boxes are locked down other than holes we inserted ourselves. Default passwords on ecommerce sites are usually one of the last things to change. Day 3: Boxes and teams are finally pretty locked down. Some last holes are left over from the red team. Nessus and Core Impact and other tools are worthless at this point at the latest (if not midday saturday). This day red team is pretty much just having fun, especially the team lead, Dave with his laughing that echos down the halls making the other teams nervous. In all every team did a great job. Everyone learned alot (heck I learned alot red teaming with some of these guys). Stupid mistakes were made by every team and we (the red team) loved the teams for it. Can't wait to come back next year and seeing what the teams will do then.

  8. Someone hasn't played UT... by bigstrat2003 · · Score: 1

    Clearly, the submitter is an FPS noob who doesn't know that it's "capture", not "steal", the flag! ;)

    --
    "16MB (fuck off, MiB fascists)" - The Mighty Buzzard
  9. steal the flag? wth by Tpl2000 · · Score: 1

    urgh....It's called CAPTURE THE FLAG!! oh come on....

    --
    Epic. Just epic.
    1. Re:steal the flag? wth by lisah · · Score: 1

      Heh....you're right! Hey, it's been a while since I played. :-)

  10. Re:CTF LOL! by Ethanol-fueled · · Score: 1

    Or insert "flags" into suspect customers...

  11. More of a System Administration Challenge (SAC!) by infiniteedge · · Score: 1

    I led a team that competed in one of the qualifiers and found the competition extremely wanting. It's more of an arcane system administration challenge rather than anything about security. Some responses to the competition are collected at my lab's blog here: http://isisblogs.poly.edu/2008/02/29/pre-neccdc/ (see the comments)

  12. Re:More of a System Administration Challenge (SAC! by thelordzero · · Score: 1

    This competition is about best defending a network in as short a time as possible. Each region creates its own scenario independent from the national level and it creates different levels of fun and realism for the teams. In essence this competition is realistic from a sys admin point of view and thats mainly the people who will be admining these system. Once again I say this as a red team point of view and that of someone who was team captain of the UTSA team this year (the hosts of the national competition every year).

  13. Re:I can beat all of them to secure my network... by Cedric+Tsui · · Score: 1

    You can also build a plane that will never crash by filling the gastanks with cement so it will never fly. But, you have to ask if it's still a plane.

  14. Re:God damn, revert this comments system already by Sancho · · Score: 1

    I like the new comments. Among other things, it means that my subscriber page views go a lot farther.

  15. Re:CTF LOL! by Ihmhi · · Score: 1

    Oh, it certainly feels like Comcast is inserting something into customers...

  16. Re:More of a System Administration Challenge (SAC! by fatigue909 · · Score: 1

    I led a team that competed in one of the qualifiers and found the competition extremely wanting. It's more of an arcane system administration challenge rather than anything about security. Some responses to the competition are collected at my lab's blog here: http://isisblogs.poly.edu/2008/02/29/pre-neccdc/ (see the comments) I agree with you completely. I was a captain for a team that made it to the finals the first year they held nationals. The majority of business injects are related to system administration. Most of the strategies to win involve patching quickly and changing stupid defaults (among other things). However, I don't complain too much because it is a fun experience. Also, I haven't come up with better "rules" for the game. One of the biggest challenges was to devise a security competition that didn't promote hacking. That makes bad press and also makes it very difficult to obtain corporate sponsorship.
  17. Re:More of a System Administration Challenge (SAC! by infiniteedge · · Score: 1

    Of course you had fun! You were on the Red team and you got to abuse groups of college students for a weekend! At least for the region we were in, the competition is NOT about how to best defend a network in as short a time as possible. It was about blindly following arbitrary rules and being a system administrator.

  18. Re:More of a System Administration Challenge (SAC! by thelordzero · · Score: 1

    To be fair, I was red team at nationals (albeit I was humlbed greatly by the rest of the red team), I was the team captain for UTSA at regionals this year. I've seen it from the blue team, white team and red team viewpoint. Blue is the most frustrating I do say but in the end I've always walked away having learned something.

  19. That should be the immediate first step by peccary · · Score: 1

    No systems should be networked until they are properly configured. If somebody hands you a crap infrastructure full of holes, the first thing to do is shut down as much internetworking as you possibly can get away with.

    1. Re:That should be the immediate first step by TheLink · · Score: 1

      Which is why these competitions have about as much relation to "security for real world systems" as F1 racing has to real life goods delivery.

      --
  20. Red Vs Blue ? by UberHoser · · Score: 1

    Ok I call shotgun !

    Who was caboose ?

    --
    Guns are for wimps... Use a crossbow.. this way you can pin them to their chair when you go postal.