Christopher Stricklan

dblp:295/3602 · also Chris Stricklan · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0002-0750-5963ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2024 PWN Lessons Made Easy with Docker: Toward an Undergraduate Vulnerability Research Cybersecurity Class
abstract
Developing expertise in vulnerability research is critical to closing the cybersecurity workforce shortage. However, very few institutions have adopted vulnerability research into their cybersecurity curriculum, and fewer have examined how to teach this skill to students. The recent emergence of lightweight, container-based virtualization presents a unique opportunity to address this challenge by offering reproducible environments that ease course facilitation. This paper presents an undergraduate vulnerability course design. Our approach leverages a hands-on methodology that challenges students to develop complex binary exploits over our lectures, labs, and exams. We share our detailed design, labs, experiences, lessons learned, and a lightweight virtual environment for this course for others to build on our initial success.
T. J. OConnor, Alex Schmith, Christopher Stricklan, Marco M. Carvalho, Sneha Sudhakaran
SIGCSE (1)3
2022 Toward an Automatic Exploit Generation Competition for an Undergraduate Binary Reverse Engineering Course
abstract
Analyzing binary programs without source code is critical for cybersecurity professionals. This paper presents an undergraduate binary reverse engineering course design that culminates with a comprehensive binary exploitation competition. Our approach challenges students to develop tools that automatically detect and exploit program vulnerabilities. We hypothesize that this competition presents a unique opportunity to exercise the core competencies of binary reverse engineering. We share our detailed design, labs, experiences, and lessons learned from this course for others to build on our initial success.
T. J. OConnor, Carl Mann, Tiffanie Petersen, Isaiah Thomas, Christopher Stricklan
ITiCSE (1)5
2021 Teaching a Hands-On Mobile and Wireless Cybersecurity Course
abstract
The combination of theory-based and practical hands-on learning represents a powerful approach for cybersecurity education. Placing the student in the adversarial mindset strengthens this approach and is commonly exercised in network penetration testing, reverse engineering, and binary exploitation coursework. In this paper, we present an undergraduate mobile and wireless security course design that balances theoretical learning with a hands-on and adversarial thinking approach. Our course consists of inter-woven lectures and lab sessions. Labs consist of contemporary attacks against radio-frequency (RF) enabled hardware, Internet of Things (IoT) firmware, and wireless protocols. In the culmination exercise, the students attack a flawed RF protocol implemented on GnuRadio to allow students to demonstrate their knowledge synthesis. We believe that sharing this experience will prove valuable for instructors who wish to introduce adversarial thinking into mobile and wireless security courses while overcoming the challenge of remote students.
T. J. OConnor, Christopher Stricklan
ITiCSE (1)2
2021 Towards Binary Diversified Challenges For A Hands-On Reverse Engineering Course
abstract
The balance of a practical hands-on and theoretical approach for reverse engineering coursework offers a strong approach for cybersecurity education. This balance is key to helping students build the skills necessary to contribute to the industry upon graduation. However, the remote learning demands of the current pandemic present a challenge to this approach. Inappropriate collaboration between students poses a threat to the educational benefits of practice-based learning. Specifically, inappropriate collaboration can threaten the development of critical problem skills gained during individual work. Further, relying on instructors to create unique challenges for each student fails to scale. To overcome these challenges, we have implemented a binary diversification system that produces unique reverse engineering challenges per student. In this paper, we present the technical details and lessons learned implementing this approach. We believe that sharing our approach will benefit cybersecurity education instructors looking to overcome the challenges of remote-learning cybersecurity coursework.
Christopher Stricklan, T. J. OConnor
ITiCSE (1)1