VLDB 2026 Research / reviewers in the wild / expert
Jan Vykopal
dblp:28/7563
· DBLP profile ↗
35ranked-venue papers
9as first author
17since 2021 · last 2026
0000-0002-3425-0951ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 25 · 8 first-author · 13 since 2021Security and privacy · 7 · 3 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multimodal Analytics of Cybersecurity Crisis Preparation Exercises: What Predicts Success?
Conrad Borchers, Valdemar Svábenský, Sandesh K. Kafle, Kevin K. Tang, Jan Vykopal |
AIED (3) | 5 |
| 2026 | Design and exploratory evaluation of a digital tabletop exercise for maritime cybersecurity
Muhammed Erbas, Sandesh K. Kafle, Daniel Volf, Jan Vykopal, Leonidas Tsiopoulos, Risto Vaarandi, Ricardo Lugo |
Comput. Secur. | 4 |
| 2025 | Cybersecurity Study Programs: What's in a Name?abstractImproving cybersecurity education has become a priority for many countries and organizations worldwide. Computing societies and professional associations have recognized cybersecurity as a distinctive computing discipline and created specialized cybersecurity curricular guidelines. Higher education institutions are introducing new cybersecurity programs, attracting students to this expanding field. In this paper, we examined 101 study programs across 24 countries. Based on their analysis, we argue that top-ranked universities have not yet fully implemented the guidelines and offer programs that have "cyber" in their name but lack some essential elements of a cybersecurity program. In particular, most programs do not sufficiently cover non-technical components, such as law, policies, or risk management. Also, most programs teach knowledge and skills but do not expose students to experiential learning outside the traditional classroom (such as internships) to develop their competencies. As a result, graduates of these programs may not meet employer expectations and may require additional training. To help program directors and educators improve their programs and courses, this paper offers examples of effective practices from cybersecurity programs around the world and our teaching practice. Jan Vykopal, Valdemar Svábenský, Michael Tuscano Lopez II, Pavel Celeda |
SIGCSE (1) | 1 |
| 2024 | Detecting Unsuccessful Students in Cybersecurity Exercises in Two Different Learning EnvironmentsabstractThis full paper in the research track evaluates the usage of data logged from cybersecurity exercises in order to predict students who are potentially at risk of performing poorly. Hands-on exercises are essential for learning since they enable students to practice their skills. In cybersecurity, hands-on exercises are often complex and require knowledge of many topics. Therefore, students may miss solutions due to gaps in their knowledge and become frustrated, which impedes their learning. Targeted aid by the instructor helps, but since the instructor's time is limited, efficient ways to detect struggling students are needed. This paper develops automated tools to predict when a student is having difficulty. We formed a dataset with the actions of 313 students from two countries and two learning environments: KYPO CRP and EDURange. These data are used in machine learning algorithms to predict the success of students in exercises deployed in these environments. After extracting features from the data, we trained and cross-validated eight classifiers for predicting the exercise outcome and evaluated their predictive power. The contribution of this paper is comparing two approaches to feature engineering, modeling, and classification performance on data from two learning environments. Using the features from either learning environment, we were able to detect and distinguish between successful and struggling students. A decision tree classifier achieved the highest balanced accuracy and sensitivity with data from both learning environments. The results show that activity data from cybersecurity exercises are suitable for predicting student success. In a potential application, such models can aid instructors in detecting struggling students and providing targeted help. We publish data and code for building these models so that others can adopt or adapt them. Valdemar Svábenský, Kristián Tkácik, Aubrey Birdwell, Richard Weiss 0001, Ryan Baker 0001, Pavel Celeda, Jan Vykopal, Jens Mache, Ankur Chattopadhyay |
FIE | 7 |
| 2024 | From Paper to Platform: Evolution of a Novel Learning Environment for Tabletop ExercisesabstractFor undergraduate students of computing, learning to solve complex practical problems in a team is an essential skill for their future careers. This skill is needed in various fields, such as in cybersecurity and IT governance. Tabletop exercises are an innovative teaching method used in practice for training teams in incident response and evaluation of contingency plans. However, tabletop exercises are not yet widely established in university education. This paper presents data and teaching experience from a cybersecurity course that introduces tabletop exercises in classrooms using a novel technology: INJECT Exercise Platform (IXP), a web-based learning environment for delivering and evaluating the exercises. This technology substantially improves the prior practice, since tabletop exercises worldwide have usually been conducted using pen and paper. Unlike in traditional tabletop exercises, which are difficult to evaluate manually, IXP provides insights into students' behavior and learning based on automated analysis of interaction data. We demonstrate IXP's capabilities and evolution by comparing exercise sessions hosted throughout three years at different stages of the platform's readiness. The analysis of student data is supplemented by the discussion of the lessons learned from employing IXP in computing education contexts. The data analytics enabled a detailed comparison of the teams' performance and behavior. Instructors who consider innovating their classes with tabletop exercises may use IXP and benefit from the insights in this paper. Valdemar Svábenský, Jan Vykopal, Martin Horák, Martin Hofbauer, Pavel Celeda |
ITiCSE (1) | 2 |
| 2024 | Research and Practice of Delivering Tabletop ExercisesabstractTabletop exercises are used to train personnel in the efficient mitigation and resolution of incidents. They are applied in practice to support the preparedness of organizations and to highlight inefficient processes. Since tabletop exercises train competencies required in the workplace, they have been introduced into computing courses at universities as an innovation, especially within cybersecurity curricula. To help computing educators adopt this innovative method, we survey academic publications that deal with tabletop exercises. From 140 papers we identified and examined, we selected 14 papers for a detailed review. The results show that the existing research deals predominantly with exercises that follow a linear format and exercises that do not systematically collect data about trainees' learning. Computing education researchers can investigate novel approaches to instruction and assessment in the context of tabletop exercises to maximize the impact of this teaching method. Due to the relatively low number of published papers, the potential for future research is immense. Our review provides researchers, tool developers, and educators with an orientation in the area, a synthesis of trends, and implications for further work. Jan Vykopal, Pavel Celeda, Valdemar Svábenský, Martin Hofbauer, Martin Horák |
ITiCSE (1) | 1 |
| 2023 | Want to Raise Cybersecurity Awareness? Start with Future IT ProfessionalsabstractAs cyber threats endanger everyone, from regular users to computing professionals, spreading cybersecurity awareness becomes increasingly critical. Therefore, our university designed an innovative cybersecurity awareness course that is freely available online for students, employees, and the general public. The course offers simple, actionable steps that anyone can use to implement defensive countermeasures. Compared to other resources, the course not only suggests learners what to do, but explains why and how to do it. To measure the course impact, we administered it to 138 computer science undergraduates within a compulsory information security and cryptography course. They completed the course as a part of their homework and filled out a questionnaire after each lesson. Analysis of the questionnaire responses revealed that the students valued the course highly. They reported new learning, perspective changes, and transfer to practice. Moreover, they suggested suitable improvements to the course. Based on the results, we have distilled specific insights to help security educators design similar courses. Lessons learned from this study are relevant for cybersecurity instructors, course designers, and educational managers. Lydia Kraus, Valdemar Svábenský, Martin Horák, Vashek Matyas, Jan Vykopal, Pavel Celeda |
ITiCSE (1) | 5 |
| 2023 | Capability Assessment Methodology and Comparative Analysis of Cybersecurity Training PlatformsabstractCybersecurity training is a key endeavour for ensuring that the IT workforce possess the knowledge and practical skills required to counter the ever-increasing cybersecurity threats that our society is faced with. While some related systems, such as Capture The Flag platforms, have been available for almost one decade, platforms that support full-fledged cybersecurity training exercises have only been released as open source in recent years. Given the complexity of such cybersecurity training platforms, the question that arises is how to meaningfully evaluate and compare their capabilities in order to identify the most suitable solution for a given type of organization and/or training activity. In this paper, we introduce a capability assessment methodology for cybersecurity training platforms that focuses on the three key aspects of training: content representation, environment management, and training facilitation. The assessment tool that we developed is used to evaluate two open-source cybersecurity training platforms, CyTrONE and KYPO. We then conduct a comparative analysis of these two platforms based on our first-hand developer experience with them, and discuss the lessons learned from implementing, deploying and using these platforms. The assessment tool and the detailed technical comparative analysis that we conducted are intended as instruments and references for anyone who plans to deploy or develop cybersecurity training platforms. Razvan Beuran, Jan Vykopal, Daniela Belajová, Pavel Celeda, Yasuo Tan, Yoichi Shinoda |
Comput. Secur. | 2 |
| 2022 | Designing Adaptive Cybersecurity Hands-on TrainingabstractThis Research To Practice Full Paper presents an instructor guide and a tool to improve the creation of cybersecurity hands-on training with adaptive learning support. Adaptive learning uses students' performance and skills to assign suitable tasks to improve their learning experience. While it is well-established in many domains, it is rarely used in operating systems, networking, and cybersecurity. In this paper, we improve and present how to ease the creation and optimization process of adaptive hands-on training by instructors. To the best of our knowledge, this paper is one of the first works investigating the process of creating cybersecurity training with adaptive learning. The training uses metrics such as pre-training assessment and performance during the previous tasks in training to assign suitable tasks for each student. With the help of the developed tool, we demonstrate how metrics settings influence the students' transitions between training tasks. The instructors can easily visualize students' transitions throughout the training. This approach helps the instructors adapt the metrics to predict students' transitions between tasks for each training session. The results from performed simulations show that our tool might increase the efficiency of the adaptive training and students' experience even more. Using the experience from the simulations and past training sessions, we propose the design process for the whole creation of adaptive training. This design process is general enough to be adopted by other domains such as operating systems and networking that may use adaptive learning techniques for their hands-on assignments. We have released the tool and all the software components under an open-source license, so other instructors can freely use and adopt them. Pavel Seda, Jan Vykopal, Pavel Celeda, Igor Ignác |
FIE | 2 |
| 2022 | Evaluating Two Approaches to Assessing Student Progress in Cybersecurity ExercisesabstractCybersecurity students need to develop practical skills such as using command-line tools. Hands-on exercises are the most direct way to assess these skills, but assessing students' mastery is a challenging task for instructors. We aim to alleviate this issue by modeling and visualizing student progress automatically throughout the exercise. The progress is summarized by graph models based on the shell commands students typed to achieve discrete tasks within the exercise. We implemented two types of models and compared them using data from 46 students at two universities. To evaluate our models, we surveyed 22 experienced computing instructors and qualitatively analyzed their responses. The majority of instructors interpreted the graph models effectively and identified strengths, weaknesses, and assessment use cases for each model. Based on the evaluation, we provide recommendations to instructors and explain how our graph models innovate teaching and promote further research. The impact of this paper is threefold. First, it demonstrates how multiple institutions can collaborate to share approaches to modeling student progress in hands-on exercises. Second, our modeling techniques generalize to data from different environments to support student assessment, even outside the cybersecurity domain. Third, we share the acquired data and open-source software so that others can use the models in their classes or research. Valdemar Svábenský, Richard Weiss 0001, Jack Cook, Jan Vykopal, Pavel Celeda, Jens Mache, Radoslav Chudovský, Ankur Chattopadhyay |
SIGCSE (1) | 4 |
| 2022 | Preventing Cheating in Hands-on Lab AssignmentsabstractNetworking, operating systems, and cybersecurity skills are exercised best in an authentic environment. Students work with real systems and tools in a lab environment and complete assigned tasks. Since all students typically receive the same assignment, they can consult their approach and progress with an instructor, a tutoring system, or their peers. They may also search for information on the Internet. Having the same assignment for all students in class is standard practice efficient for learning and developing skills. However, it is prone to cheating when used in a summative assessment such as graded homework, a mid-term test, or a final exam. Students can easily share and submit correct answers without completing the assignment. In this paper, we discuss methods for automatic problem generation for hands-on tasks completed in a computer lab environment. Using this approach, each student receives personalized tasks. We developed software for generating and submitting these personalized tasks and conducted a case study. The software was used for creating and grading a homework assignment in an introductory security course enrolled by 207 students. The software revealed seven cases of suspicious submissions, which may constitute cheating. In addition, students and instructors welcomed the personalized assignments. Instructors commented that this approach scales well for large classes. Students rarely encountered issues while running their personalized lab environment. Finally, we have released the open-source software to enable other educators to use it in their courses and learning environments. Jan Vykopal, Valdemar Svábenský, Pavel Seda, Pavel Celeda |
SIGCSE (1) | 1 |
| 2021 | Reinforcing Cybersecurity Hands-on Training With Adaptive LearningabstractThis Research To Practice Full Paper presents how learning experience influences students' capability to learn and their motivation for further learning. Although each student is different, standard instruction methods do not adapt to individual students. Adaptive learning reverses this practice and attempts to improve the student experience. While adaptive learning is well-established in programming, it is rarely used in cybersecurity education. This paper is one of the first works investigating adaptive learning in cybersecurity training. First, we analyze the performance of 95 students in 12 training sessions to understand the limitations of the current training practice. Less than half of the students (45 out of 95) completed the training without displaying any solution, and only in two sessions, all students completed all phases. Then, we simulate how students would proceed in one of the past training sessions if it would offer more paths of various difficulty. Based on this simulation, we propose a novel tutor model for adaptive training, which considers students' proficiency before and during an ongoing training session. The proficiency is assessed using a pre-training questionnaire and various in-training metrics. Finally, we conduct a case study with 24 students and new training using the proposed tutor model and adaptive training format. The results show that the adaptive training does not overwhelm students as the original static training format. In particular, adaptive training enables students to enter several alternative training phases with lower difficulty than the phases in the original training. The proposed adaptive format is not restricted to particular training used in our case study. Therefore, it can be applied to practicing any cybersecurity topic or even in other related computing fields, such as networking or operating systems. Our study indicates that adaptive learning is a promising approach for improving the student experience in cybersecurity education. We also highlight diverse implications for educational practice that improve students' experience. Pavel Seda, Jan Vykopal, Valdemar Svábenský, Pavel Celeda |
FIE | 2 |
| 2021 | Toolset for Collecting Shell Commands and Its Application in Hands-on Cybersecurity TrainingabstractThis Full Paper in the Innovative Practice category presents and evaluates a technical innovation for hands-on classes. When learning cybersecurity, operating systems, or networking, students perform practical tasks using a broad range of command-line tools. Collecting and analyzing data about the command usage can reveal valuable insights into how students progress and where they make mistakes. However, few learning environments support recording and inspecting command-line inputs, and setting up an efficient infrastructure for this purpose is challenging. To aid engineering and computing educators, we share the design and implementation of an open-source toolset for logging commands that students execute on Linux machines. Compared to basic solutions, such as shell history files, the toolset's novelty and added value are threefold. First, its configuration is automated so that it can be easily used in classes on different topics. Second, it collects metadata about the command execution, such as a timestamp, hostname, and IP address. Third, all data are instantly forwarded to central storage in a unified, semi-structured format. This enables automated processing of the data, both in real-time and post hoc, to enhance the instructors' understanding of student actions. The toolset works independently of the teaching content, the training network's topology, or the number of students working in parallel. We demonstrated the toolset's value in two learning environments at four training sessions. Over two semesters, 50 students played educational cybersecurity games using a Linux command-line interface. Each training session lasted approximately two hours, during which we recorded 4439 shell commands. The semiautomated data analysis revealed different solution patterns, used tools, and misconceptions of students. Our insights from creating the toolset and applying it in teaching practice are relevant for instructors, researchers, and developers of learning environments. We provide the software and data resulting from this work so that others can use them in their hands-on classes. Valdemar Svábenský, Jan Vykopal, Daniel Tovarnák, Pavel Celeda |
FIE | 2 |
| 2021 | Scalable Learning Environments for Teaching Cybersecurity Hands-onabstractThis Innovative Practice full paper describes a technical innovation for scalable teaching of cybersecurity hands-on classes using interactive learning environments. Hands-on experience significantly improves the practical skills of learners. However, the preparation and delivery of hands-on classes usually do not scale. Teaching even small groups of students requires a substantial effort to prepare the class environment and practical assignments. Further issues are associated with teaching large classes, providing feedback, and analyzing learning gains. We present our research effort and practical experience in designing and using learning environments that scale up hands-on cybersecurity classes. The environments support virtual networks with full-fledged operating systems and devices that emulate realworld systems. The classes are organized as simultaneous training sessions with cybersecurity assignments and learners' assessment. For big classes, with the goal of developing learners' skills and providing formative assessment, we run the environment locally, either in a computer lab or at learners' own desktops or laptops. For classes that exercise the developed skills and feature summative assessment, we use an on-premises cloud environment. Our approach is unique in supporting both types of deployment. The environment is described as code using open and standard formats, defining individual hosts and their networking, configuration of the hosts, and tasks that the students have to solve. The environment can be repeatedly created for different classes on a massive scale or for each student on-demand. Moreover, the approach enables learning analytics and educational data mining of learners' interactions with the environment. These analyses inform the instructor about the student's progress during the class and enable the learner to reflect on a finished training. Thanks to this, we can improve the student class experience and motivation for further learning. Using the presented environments KYPO Cyber Range Platform and Cyber Sandbox Creator, we delivered the classes on-site or remotely for various target groups of learners (K-12, university students, and professional learners). The learners value the realistic nature of the environments that enable exercising theoretical concepts and tools. The instructors value time-efficiency when preparing and deploying the hands-on activities. Engineering and computing educators can freely use our software, which we have released under an open-source license. We also provide detailed documentation and exemplary hands-on training to help other educators adopt our teaching innovations and enable sharing of reusable components within the community. Jan Vykopal, Pavel Celeda, Pavel Seda, Valdemar Svábenský, Daniel Tovarnák |
FIE | 1 |
| 2021 | Toward Guidelines for Designing Cybersecurity Serious GamesabstractCybersecurity serious games provide hands-on training of cybersecurity skills and enhance security awareness. Besides the learning content, they use gamification elements to engage and motivate the players. We propose guidelines for creating technical cybersecurity games in a higher education context, based on a~literature review and experience of cybersecurity instructors. We also introduce topics for further research in this area. Miriam Gáliková, Valdemar Svábenský, Jan Vykopal |
SIGCSE | 3 |
| 2021 | Cybersecurity knowledge and skills taught in capture the flag challenges
Valdemar Svábenský, Pavel Celeda, Jan Vykopal, Silvia Brisáková |
Comput. Secur. | 3 |
| 2021 | Conceptual Model of Visual Analytics for Hands-on Cybersecurity TrainingabstractHands-on training is an effective way to practice theoretical cybersecurity concepts and increase participants' skills. In this article, we discuss the application of visual analytics principles to the design, execution, and evaluation of training sessions. We propose a conceptual model employing visual analytics that supports the sensemaking activities of users involved in various phases of the training life cycle. The model emerged from our long-term experience in designing and organizing diverse hands-on cybersecurity training sessions. It provides a classification of visualizations and can be used as a framework for developing novel visualization tools supporting phases of the training life-cycle. We demonstrate the model application on examples covering two types of cybersecurity training programs. Radek Oslejsek, Vít Rusnák, Karolína Dockalová Burská, Valdemar Svábenský, Jan Vykopal, Jakub Cegan |
IEEE Trans. Vis. Comput. Graph. | 5 |
| 2020 | KYPO4INDUSTRY: A Testbed for Teaching Cybersecurity of Industrial Control SystemsabstractThere are different requirements on cybersecurity of industrial control systems and information technology systems. This fact exacerbates the global issue of hiring cybersecurity employees with relevant skills. In this paper, we present KYPO4INDUSTRY training facility and a course syllabus for beginner and intermediate computer science students to learn cybersecurity in a simulated industrial environment. The training facility is built using open-source hardware and software and provides reconfigurable modules of industrial control systems. The course uses a flipped classroom format with hands-on projects: the students create educational games that replicate real cyber attacks. Throughout the semester, they learn to understand the risks and gain capabilities to respond to cyber attacks that target industrial control systems. Our described experience from the design of the testbed and its usage can help any educator interested in teaching cybersecurity of cyber-physical systems. Pavel Celeda, Jan Vykopal, Valdemar Svábenský, Karel Slávicek |
SIGCSE | 2 |
| 2020 | What Are Cybersecurity Education Papers About?: A Systematic Literature Review of SIGCSE and ITiCSE ConferencesabstractCybersecurity is now more important than ever, and so is education in this field. However, the cybersecurity domain encompasses an extensive set of concepts, which can be taught in different ways and contexts. To understand the state of the art of cybersecurity education and related research, we examine papers from the ACM SIGCSE and ACM ITiCSE conferences. From 2010 to 2019, a total of 1,748 papers were published at these conferences, and 71 of them focus on cybersecurity education. The papers discuss courses, tools, exercises, and teaching approaches. For each paper, we map the covered topics, teaching context, evaluation methods, impact, and the community of authors. We discovered that the technical topic areas are evenly covered (the most prominent being secure programming, network security, and offensive security), and human aspects, such as privacy and social engineering, are present as well. The interventions described in SIGCSE and ITiCSE papers predominantly focus on tertiary education in the USA. The subsequent evaluation mostly consists of collecting students' subjective perceptions via questionnaires. However, less than a third of the papers provide supplementary materials for other educators, and none of the authors published their dataset. Our results provide orientation in the area, a synthesis of trends, and implications for further research. Therefore, they are relevant for instructors, researchers, and anyone new in the field of cybersecurity education. The information we collected and synthesized from individual papers are organized in a publicly available dataset. Valdemar Svábenský, Jan Vykopal, Pavel Celeda |
SIGCSE | 2 |
| 2020 | Benefits and Pitfalls of Using Capture the Flag Games in University CoursesabstractThe concept of Capture the Flag (CTF) games for practicing cybersecurity skills is widespread in informal educational settings and leisure-time competitions. However, it is not much used in university courses. This paper summarizes our experience from using jeopardy CTF games as homework assignments in an introductory undergraduate course. Our analysis of data describing students' in-game actions and course performance revealed four aspects that should be addressed in the design of CTF tasks: scoring, scaffolding, plagiarism, and learning analytics capabilities of the used CTF platform. The paper addresses these aspects by sharing our recommendations. We believe that these recommendations are useful for cybersecurity instructors who consider using CTF games for assessment in university courses and developers of CTF game frameworks. Jan Vykopal, Valdemar Svábenský, Ee-Chien Chang |
SIGCSE | 1 |
| 2019 | Towards Learning Analytics in Cybersecurity Capture the Flag GamesabstractCapture the Flag games are software applications designed to exercise cybersecurity concepts, practice using security tools, and understand cyber attacks and defense. We develop and employ these games at our university for training purposes, unlike in the traditional competitive setting. During the gameplay, it is possible to collect data about players' in-game actions, such as typed commands or solution attempts, including the timing of these actions. Although such data was previously employed in computer security research, to the best of our knowledge, there were few attempts to use this data primarily to improve education. In particular, we see an open and challenging research problem in creating an artificial intelligence assistant that would facilitate the learning of each player. Our goal is to propose, apply, and experimentally evaluate data analysis and machine learning techniques to derive information about the players' interactions from the in-game data. We want to use this information to automatically provide each player with a personalized formative assessment. Such assessment will help the players identify their mastered concepts and areas for improvement, along with suggestions and actionable steps to take. Furthermore, we want to identify high- or low-performing players during the game, and subsequently, offer them game tasks more suitable to their skill level. These interventions would supplement or even replace feedback from instructors, which would significantly increase the learning impact of the games, enable more students to learn cybersecurity skills at an individual pace, and lower the costs. Valdemar Svábenský, Jan Vykopal, Pavel Celeda |
SIGCSE | 2 |
| 2019 | Visual Feedback for Players of Multi-Level Capture the Flag Games: Field Usability StudyabstractCapture the Flag games represent a popular method of cybersecurity training. Providing meaningful insight into the training progress is essential for increasing learning impact and supporting participants' motivation, especially in advanced hands-on courses. In this paper, we investigate how to provide valuable post-game feedback to players of serious cybersecurity games through interactive visualizations. In collaboration with domain experts, we formulated user requirements that cover three cognitive perspectives: gameplay overview, person-centric view, and comparative feedback. Based on these requirements, we designed two interactive visualizations that provide complementary views on game results. They combine a known clustering and time-based visual approaches to show game results in a way that is easy to decode for players. The purposefulness of our visual feedback was evaluated in a usability field study with attendees of the Summer School in Cyber Security. The evaluation confirmed the adequacy of the two visualizations for instant post-game feedback. Despite our initial expectations, there was no strong preference for neither of the visualizations in solving different tasks. Radek Oslejsek, Vít Rusnák, Karolína Dockalová Burská, Valdemar Svábenský, Jan Vykopal |
VizSEC | 5 |
| 2018 | Evaluation of Cyber Defense Exercises Using Visual Analytics ProcessabstractThis Innovative Practice Full Paper addresses modern cyber ranges which represent unified platforms that offer efficient organization of complex hands-on exercises where participants can train their cybersecurity skills. However, the functionality targets mostly learners who are the primary users. Support of organizers performing analytic and evaluation tasks is weak and ad-hoc. It makes harder to improve the quality of an exercise, particularly its impact on learners. In this paper, we present an application of a well-structured visual analytics process to the organization of cyber exercises. We illustrate that the classification derived from the adoption of the visual analytics process helps to clarify and formalize analytical tasks of educators and enables their systematic support in cyber ranges. We demonstrate an application of our approach on a particular series of eight exercises we have organized in last three years. We believe the presented approach is beneficial for anyone involved in preparation and execution of any complex exercise. Radek Oslejsek, Jan Vykopal, Karolína Dockalová Burská, Vít Rusnák |
FIE | 2 |
| 2018 | Gathering Insights from Teenagers' Hacking Experience with Authentic Cybersecurity ToolsabstractThis Work-In-Progress Paper for the Innovative Practice Category presents a novel experiment in active learning of cybersecurity. We introduced a new workshop on hacking for an existing science-popularizing program at our university. The workshop participants, 28 teenagers, played a cybersecurity game designed for training undergraduates and professionals in penetration testing. Unlike in learning environments that are simplified for young learners, the game features a realistic virtual network infrastructure. This allows exploring security tools in an authentic scenario, which is complemented by a background story. Our research aim is to examine how young players approach using cybersecurity tools by interacting with the professional game. A preliminary analysis of the game session showed several challenges that the workshop participants faced. Nevertheless, they reported learning about security tools and exploits, and 61% of them reported wanting to learn more about cybersecurity after the workshop. Our results support the notion that young learners should be allowed more hands-on experience with security topics, both in formal education and informal extracurricular events. Valdemar Svábenský, Jan Vykopal |
FIE | 2 |
| 2018 | Enhancing cybersecurity skills by creating serious gamesabstractAdversary thinking is an essential skill for cybersecurity experts, enabling them to understand cyber attacks and set up effective defenses. While this skill is commonly exercised by Capture the Flag games and hands-on activities, we complement these approaches with a key innovation: undergraduate students learn methods of network attack and defense by creating educational games in a cyber range. In this paper, we present the design of two courses, instruction and assessment techniques, as well as our observations over the last three semesters. The students report they had a unique opportunity to deeply understand the topic and practice their soft skills, as they presented their results at a faculty open day event. Their peers, who played the created games, rated the quality and educational value of the games overwhelmingly positively. Moreover, the open day raised awareness about cybersecurity and research and development in this field at our faculty. We believe that sharing our teaching experience will be valuable for instructors planning to introduce active learning of cybersecurity and adversary thinking. Valdemar Svábenský, Jan Vykopal, Milan Cermák, Martin Lastovicka |
ITiCSE | 2 |
| 2018 | Challenges Arising from Prerequisite Testing in Cybersecurity GamesabstractCybersecurity games are an attractive and popular method of active learning. However, the majority of current games are created for advanced players, which often leads to frustration in less experienced learners. Therefore, we decided to focus on a diagnostic assessment of participants entering the games. We assume that information about the players' knowledge, skills, and experience enables tutors or learning environments to suitably assist participants with game challenges and maximize learning in their virtual adventure. In this paper, we present a pioneering experiment examining the predictive value of a short quiz and self-assessment for identifying learners' readiness before playing a cybersecurity game. We hypothesized that these predictors would model players' performance. A linear regression analysis showed that the game performance can be accurately predicted by well-designed prerequisite testing, but not by self-assessment. At the same time, we identified major challenges related to the design of pretests for cybersecurity games: calibrating test questions with respect to the skills relevant for the game, minimizing the quiz's length while maximizing its informative value, and embedding the pretest in the game. Our results are relevant for educational researchers and cybersecurity instructors of students at all learning levels. Valdemar Svábenský, Jan Vykopal |
SIGCSE | 2 |
| 2018 | Timely Feedback in Unstructured Cybersecurity ExercisesabstractCyber defence exercises are intensive, hands-on learning events for teams of professionals who gain or develop their skills to successfully prevent and respond to cyber attacks. The exercises mimic the real-life, routine operation of an organization which is being attacked by an unknown offender. Teams of learners receive very limited immediate feedback from the instructors during the exercise; they can usually see only a scoreboard showing the aggregated gain or loss of points for particular tasks. An in-depth analysis of learners' actions requires considerable human effort, which results in days or weeks of delay. The intensive experience is thus not followed by proper feedback facilitating actual learning, and this diminishes the effect of the exercise. Jan Vykopal, Radek Oslejsek, Karolína Dockalová Burská, Kristína Zákopcanová |
SIGCSE | 1 |
| 2017 | Lessons learned from complex hands-on defence exercises in a cyber rangeabstractWe need more skilled cybersecurity professionals because the number of cyber threats and ingenuity of attackers is ever growing. Knowledge and skills required for cyber defence can be developed and exercised by lectures and lab sessions, or by active learning, which is seen as a promising and attractive alternative. In this paper, we present experience gained from the preparation and execution of cyber defence exercises involving various participants in a cyber range. The exercises follow a Red vs. Blue team format, in which the Red team conducts malicious activities against emulated networks and systems that have to be defended by Blue teams of learners. Although this exercise format is popular and used worldwide by numerous organizers in practice, it has been sparsely researched. We contribute to the topic by describing the general exercise life cycle, covering the exercise's development, dry run, execution, evaluation, and repetition. Each phase brings several challenges that exercise organizers have to deal with. We present lessons learned that can help organizers to prepare, run and repeat successful events systematically, with lower effort and costs, and avoid a trial-and-error approach that is often used. Jan Vykopal, Martin Vizváry, Radek Oslejsek, Pavel Celeda, Daniel Tovarnák |
FIE | 1 |
| 2017 | KYPO Cyber Range: Design and Use CasesabstractThe physical and cyber worlds are increasingly intertwined and exposed to cyber attacks. The KYPO cyber range provides complex cyber systems and networks in a virtualized, fully controlled and monitored environment. Time-efficient and cost-effective deployment is feasible using cloud resources instead of a dedicated hardware infrastructure. This paper describes the design decisions made during it’s development. We prepared a set of use cases to evaluate the proposed design decisions and to demonstrate the key features of the KYPO cyber range. It was especially cyber training sessions and exercises with hundreds of participants which provided invaluable feedback for KYPO platform development. Jan Vykopal, Radek Oslejsek, Pavel Celeda, Martin Vizváry, Daniel Tovarnák |
ICSOFT | 1 |
| 2017 | Exchanging security events: Which and how many alerts can we aggregate?abstractThe exchange of security alerts is a current trend in network security and incident response. Alerts from network intrusion detection systems are shared among organizations so that it is possible to see the “big picture” of current security situation. However, the quality and redundancy of the input data seem to be underrated. We present four use cases of aggregation of the alerts from network intrusion detection systems. Alerts from a sharing platform deployed in the Czech national research and education network were examined in a case study. Volumes of raw and aggregated data are presented and a rule of thumb is proposed: up to 85% of alerts can be aggregated. Finally, we discuss the practical implications of alert aggregation for the network intrusion detection system, such as (in)completeness of the alerts and optimal time windows for aggregation. Martin Husák, Milan Cermák, Martin Lastovicka, Jan Vykopal |
IM | 4 |
| 2017 | Finding Exercise Equilibrium: How to Support the Game Balance at the Very Beginning? (Abstract Only)abstractCyber defence exercises (CDX) represent a popular form of hands-on security training. Learners are usually divided into several teams that have to defend or attack virtual IT infrastructure (red vs. blue teams). CDXs are prepared for learners whose level of skills, knowledge, and background may be unknown or very diverse. This is evident in the case of high-profile international CDXs with hundreds of participants coming from government agencies, military, academia, and the private sector. In this poster, we present techniques for distributing learners into teams with respect to their level of proficiency and the prerequisite skills required by the exercise. Our aim is to reach a balance between proficiency and the exercise to make the exercise beneficial for the learners and an effective investment for sponsors. The poster describes three methods and compares their advantages and disadvantages. First, we present self-assessment questionnaires, which we have already used in four runs of a national CDX for 80 participants. We outline our findings from an analysis of the learners' self-assessment before and after the exercise, and the score they achieved during the exercise. Second, we introduce a promising method for testing the prerequisites of the exercise. This is still a work in progress but we believe that this method enables the better assessment of learners' skills with respect to the exercise content, and supports the game balance better. Finally, we compare both methods to a naïve one that shuffles participants into teams randomly. Jan Vykopal, Jakub Cegan |
SIGCSE | 1 |
| 2015 | Security Monitoring of HTTP Traffic Using Extended FlowsabstractIn this paper, we present an analysis of HTTP traffic in a large-scale environment which uses network flow monitoring extended by parsing HTTP requests. In contrast to previously published analyses, we were the first to classify patterns of HTTP traffic which are relevant to network security. We described three classes of HTTP traffic which contain brute-force password attacks, connections to proxies, HTTP scanners, and web crawlers. Using the classification, we were able to detect up to 16 previously undetectable brute-force password attacks and 19 HTTP scans per day in our campus network. The activity of proxy servers and web crawlers was also observed. Symptoms of these attacks may be detected by other methods based on traditional flow monitoring, but detection using the analysis of HTTP requests is more straightforward. We, thus, confirm the added value of extended flow monitoring in comparison to the traditional method. Martin Husák, Petr Velan, Jan Vykopal |
ARES | 3 |
| 2014 | Cloud-based testbed for simulation of cyber attacksabstractCyber attacks have become ubiquitous and in order to face current threats it is important to understand them. Studying attacks in a real environment however, is not viable and therefore it is necessary to find other methods how to examine the nature of attacks. Gaining detailed knowledge about them facilitates designing of new detection methods as well as understanding their impact. In this paper we present a testbed framework to simulate attacks that enables to study a wide range of security scenarios. The framework provides a notion of real-world arrangements, yet it retains full control over all the activities performed within the simulated infrastructures. Utilizing the sandbox environment, it is possible to simulate various security attacks and evaluate their impacts on real infrastructures. The design of the framework benefits from IaaS clouds. Therefore its deployment does not require dedicated facilities and the testbed can be deployed over miscellaneous contemporary clouds. The viability of the testbed has been verified by a simulation of particular DDoS attack. Daniel Kouril, Tomás Rebok, Tomás Jirsík, Jakub Cegan, Martin Drasar, Martin Vizváry, Jan Vykopal |
NOMS | 7 |
| 2011 | NetFlow Based Network Protection
Vojtech Krmicek, Jan Vykopal |
SecureComm | 2 |
| 2010 | Aspect-Based Attack Detection in Large-Scale Networks
Martin Drasar, Jan Vykopal, Radek Krejcí, Pavel Celeda |
RAID | 2 |