Conceptual Hardware View (Under Construction)
The Cyber Security Education & Research Center (CERC) Lab will use a combination of hardware and virtual capabilities to perform lab exercises and conduct research projects.
Conceptual Software View (Under Construction)
The Cyber Center lab will establish a baseline (golden) harware and software configuration that is ready to execute Lab exercises. Software and tools loaded will include:
- Microsoft Hyper-V, Oracle VirtualBox, or VMWare Workstation/Fusion (tbd)
- Kali Linux
- pfSense firewall
Open Source Tools:
Support for the following open source cyber security tools available in the Cyber Lab:
- Metasploit – provides information about security vulnerabilities and aids in penetration testing and IDS signature development.
- OpenSSH – provides a secure channel over an unsecured network in a client–server architecture
- OpenVAS (Open Vulnerability Assessment System) – originally known as GNessUs is a software framework of several services and tools offering vulnerability scanning and vulnerability management.
- Onion – Linux distro for IDS (Intrusion Detection) and NSM (Network Security Monitoring). It’s based on Xubuntu 10.04 and contains Snort, Suricata, Sguil, Squert, Snorby, Bro, NetworkMiner, Xplico, and many other security tools.
- OSSEC Wireshark – free and open-source packet analyzer used for network troubleshooting, analysis, software and communications protocol development, and education.
- SQLMAP – sqlmap is an open source software that is used to detect and exploit database vulnerabilities and provides options for injecting malicious codes into them. It is a penetration testing tool that automates the process of detecting and exploiting SQL injection flaws providing its user interface in the terminal.[
OWASP Top 10 -2017 – The Open Web Application Security Project (OWASP)(OWASP) Ten Most Critical Web Application Security Risks