Simulating Cyber-Attacks for Fun and Profit
Ariel Futoransky (1), Fernando Miranda (1), Jose Orlicki (1, 2),, Carlos Sarraute (1, 2) ((1) Core Security Technologies, (2) Instituto, Tecnologico Buenos Aires)

TL;DR
Insight is a low-resource, realistic cyber-attack simulation platform that models complex scenarios with vulnerabilities, aiding security research, training, and risk assessment.
Contribution
This paper introduces Insight, a novel simulation platform capable of realistic cyber-attack modeling with low hardware requirements and detailed vulnerability and exploit simulation.
Findings
Enables realistic attack scenario simulation with interconnected networks.
Supports testing of zero-day vulnerabilities and exploits.
Useful for pentesting training and security evaluation.
Abstract
We introduce a new simulation platform called Insight, created to design and simulate cyber-attacks against large arbitrary target scenarios. Insight has surprisingly low hardware and configuration requirements, while making the simulation a realistic experience from the attacker's standpoint. The scenarios include a crowd of simulated actors: network devices, hardware devices, software applications, protocols, users, etc. A novel characteristic of this tool is to simulate vulnerabilities (including 0-days) and exploits, allowing an attacker to compromise machines and use them as pivoting stones to continue the attack. A user can test and modify complex scenarios, with several interconnected networks, where the attacker has no initial connectivity with the objective of the attack. We give a concise description of this new technology, and its possible uses in the security research field,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Advanced Malware Detection Techniques
