<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>EVA: A Hybrid Cyber Range</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Shabeer Ahmad</string-name>
          <email>shabeer.ahmad@gssi.it</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nicolo Maunero</string-name>
          <email>nicolo.maunero@polito.it</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Paolo Prinetto</string-name>
          <email>paolo.prinetto@polito.it</email>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>CINI - Cybersecurity National Lab</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>GSSI - Gran Sasso Science Institute</institution>
          ,
          <addr-line>L'Aquila</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Politecnico di Torino, Dipartimento di Automatica e Informatica</institution>
          ,
          <addr-line>Torino</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Over the recent years, cyber attacks have increased constantly. Attacks targeting sensors networks, or exploiting the growing number of networked devices, are becoming even more frequent. This has led to the need to nd a way to train the teams responsible for defending computer systems in order to make them able to respond to any threats quickly. The fact that it is impossible to carry out training operations directly on corporate networks or critical infrastructure has led to the birth of Cyber Ranges, virtual or hybrid systems that allow training in safe and isolated environments. In this paper we present a model for the implementation of a Hybrid Cyber-Range (HCR), based on the model of a real Water Supply System WSS). The HCR shall combine the dynamism and exibility of virtualised Cyber-Ranges (CR) and the realism of Cyber-Physical Systems (CPS).</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        a type of CR that integrates, within it, also real components used in ICS and critical
infrastructures, to increase its realism [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. Hereinafter, we will identify this type of CRs as Hybrid
Cyber Ranges (HCRs).
      </p>
      <p>In this paper we present EVA, an Hybrid Cyber Range based on the model of a Water Supply
System. The objective of EVA is to provide a realistic testbed, representing in the best way,
and as faithfully as possible, a real Water Supply System. Moreover it shall also provides the
exibility of a CR in deploying di erent scenarios and the possibility to easily test new products
and/or solutions before adopting them in a real system. The paper is structured as follows:
rst a brief overview on CRs developed by both industry and academy and the de nition of the
various teams that interact with a CR. Then the model and implementation of EVA, the
emulator of a real aqueduct, is presented, continuing with the introduction of the model adopted
for upgrading EVA from a CPS to a HCR. Some improvements and issues to be addressed in
the near future are eventually presented.
2
2.1</p>
    </sec>
    <sec id="sec-2">
      <title>Background</title>
      <sec id="sec-2-1">
        <title>Cyber Range</title>
        <p>
          A Cyber Range (CR) is a platform that can provide advanced cyber-security training exercises
for university students and professionals, changing the way to approach cybersecurity2. In as
document of 2018 [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ] NIST de nes a Cyber Range as \an interactive, simulated
representation of an organisation's local network, system, tools, and applications that are connected to a
simulated internet level environment."
The use of CRs derives from the need to have protected and secure environments where
performing cybersecurity activities, isolated from the outside world and without the need to operate
directly on the corporate networks or infrastructures under analysis.
        </p>
        <p>Three di erent types of CR can be identi ed:
Physical Cyber Ranges : the testbed faithfully recreates a network or computing
infrastructure, guaranteeing the highest level of loyalty, often using real components of the reference
infrastructure. This typology is, on the one hand, the best for gaining experience and
gathering results with the aim of improving the defences of a given infrastructure. On the
other hand, it has the disadvantages of (i) being less exible, since a modi cation may
require the reconstruction of the entire CR, and (ii) requiring a very expensive set-up
process.</p>
        <p>Virtual Cyber Ranges : in the testbed all the components of the reference infrastructure
are simulated, using virtualisation technologies, to obtain testbeds of di erent complexity.
The main advantage of this approach is that the components needed to build it (servers
for hosting virtual machines) can be easily found, at a relatively low cost, on the market.
It is also possible, in this case, to get a high degree of exibility and scalability in changing
the simulated environment. However, this approach has the disadvantage of not providing
an experience very similar to the real one.</p>
        <p>Hybrid Cyber Ranges : sometimes referred as Cyber-Physical Ranges, this typology is a
hybrid of the two previous ones. It aims to combine the positive aspects of both approaches,
having the exibility of a virtual environment with the realism resulting from the use of
real-word hardware components of the reference infrastructure.
2.2</p>
      </sec>
      <sec id="sec-2-2">
        <title>Teams De nition</title>
        <p>
          One of the most eminent and successful training activities that a Cyber-Range could o er is
the one in which it provides a battle eld where di erent teams oppose each other [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
Red Teams are normally composed of a small number of experts who have the task of
attacking or compromising the security simulated scenario, organization or infrastructure.
They must be well conscious of the so-called TTP (Tactics, Techniques and Procedures)
of the attackers [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ].
        </p>
        <p>
          Blue Teams have the task of defending the scenario and have the mentality of the defenders
and are trained to detect, respond, and mitigate the attacks done by Red Teams. Members
of the Blue Team need to stop unauthorised or illegal activities by mitigating potential
vulnerabilities. The capabilities and expertises of Blue Team's strongly e ect the whole
exercise scenario [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
        </p>
        <p>White Team responsible for the design and construction of the scenario used for the exercises.</p>
        <p>Moreover, the White Team acts as supervisor on exercises involving attack and defence
paradigm, establishing the nal score. It is essential for the White Team to make sure
that the exercise is conducted according to the scenario and according to the objective.
Admin Team the administration team is responsible for the supervision of the entire cyber
range, are in charge of monitoring the session and assigning scores to each team.
Design Team is composed of the persons in charge of the design of the reference infrastructure
on which the CR is based.
2.3
2.3.1</p>
      </sec>
      <sec id="sec-2-3">
        <title>State-of-the-Art</title>
        <sec id="sec-2-3-1">
          <title>Physical CRs</title>
          <p>As far as Physical Cyber Ranges are concerned, it is very di cult to nd examples in literature
of testbed with high level of delity with respect to the real-word target infrastructure, both
because of the di culty of implementing this type of CRs and because the construction of such
structures would often require the disclosure of business secrets and/or the precise topology of
the internal network.</p>
          <p>
            The most prominent and ambitious project of physical cyber range is Cybertropolis [
            <xref ref-type="bibr" rid="ref8">8</xref>
            ], a
project of the United State (U.S.) Department of Defence (DoD), situated at the Muscatatuck
Urban Training Complex (MUTC)3. In continuous evolution and improvement, it aims to
provide participants with the opportunity to interact with a real-word scenario. In fact, it allows the
integration of di erent dimensions, such as role-players, and interaction with a hyper-realistic
environment. It is composed of several elements such as a prison complex, a full size functioning
water treatment plant and waste water treatment plant, a state-of-the-art implementation of
internet of things systems for smart homes, and so on.
          </p>
          <p>
            Ahmed et al. proposed a SCADA system testbed [
            <xref ref-type="bibr" rid="ref1">1</xref>
            ] for research and training. Built using
real-world industrial components, it its composed of models of a waste water treatment plant,
a power transmission and distribution systems and a gas pipeline. All these systems are
smallscaled but fully functionals. The main drawback of this project is that it provide insu cient
scalability and exibility and does not give the possibility to design di erent attack scenario.
3https://www.atterburymuscatatuck.in.ng.mil/Muscatatuck/CyberTropolis/
          </p>
          <p>
            Aditya et al. proposed SWaT [
            <xref ref-type="bibr" rid="ref14">14</xref>
            ], a testbed based on a model of a Water Supply System.
Also in this case is a small-scale, fully functional model built with real-world industrial
components. The goal of the project is to have a safe testbed where to research possible vulnerabilities
and test new cyber defence strategies. As before, the main drawback of this project is that
it provide insu cient scalability and exibility as well as the impossibility to deliver di erent
attack scenario for cyber defence training.
2.3.2
          </p>
        </sec>
        <sec id="sec-2-3-2">
          <title>Virtual CRs</title>
          <p>
            Virtual Cyber Ranges are the most common and used thanks to their exibility and relatively
low building and maintenance costs. KYPO Cyber Range is a Czech project [
            <xref ref-type="bibr" rid="ref24">24</xref>
            ] funded by the
Ministry of the Interior of the Czech Republic as part of the Security Research Program of the
Czech Republic. The Objectives of the KYPO Project was to build a scenario for carrying out
research and developing methods for mitigating attacks on critical infrastructure in the Czech
Republic.
          </p>
          <p>The Michigan Cyber-Range4 is powered by Merit Network Network5, the nation's
longestrunning research and education network. Above all, Michigan Cyber Range is the largest
unclassi ed network, especially designed for cybersecurity training and It o ers courses
including Penetration Testing, Ethical Hacking, Vulnerability Assessment, Secure Coding, and Digital
and Networking Forensics.</p>
          <p>
            Emulab and DETER are two of the most renowned emulation facilities for Virtual Cyber
Ranges developed in academia for performing cyber-security training and exercises. Emulab
[
            <xref ref-type="bibr" rid="ref21">21</xref>
            ], was launched by University of Utah and was used for both university facilities and open
source emulation software for testbeds. The Emulab software is used in more than twenty other
emulation testbeds over the globe and it is mainly utilised for carrying out research in the
elds of networking and distributed systems. DETER6 (a derivative of Emulab), founded by
the Department of Homeland Security and the Department of Defence, is an emulation-based
cyber-range having more capabilities as compared to Emulab. The DETER testbed is used for
medium size national-level experimentation and training in cybersecurity.
          </p>
          <p>
            DARPA (Defence Advanced Research Project Agency) commenced the (U.S.) National
Cyber-Range (NCR) plan to design the architecture and software tools required for a secure,
self-contained cyber testing amenity [
            <xref ref-type="bibr" rid="ref18">18</xref>
            ]. DARPA (NCR) is probably the most famous and
ambitious project for cyber-defense training with the aim of simulating cyber-attacks on computer
networks, it is planned to be built on a large scale to emulate the complexity of commercial
networks and it should allow new cyber technologies to be tested and validated in a representative
environment.
          </p>
          <p>
            The Cisco Cyber Range [
            <xref ref-type="bibr" rid="ref7">7</xref>
            ] o ers a specialised technical training activity to assist sta
responsible for the security to create and improve the skills and experience needed to answer
modern cyber-threats. CISCO Cyber Range o ers a specialises scenario that enables
securitysta to play the role of both attacker and defender to discover the latest techniques of
vulnerability exploitation and utilizing advanced tools tactics and techniques to minimise and remove
threats.
4https://www.merit.edu/cyberrange/
5https://www.merit.edu
6https://deter-project.org
2.3.3
          </p>
        </sec>
        <sec id="sec-2-3-3">
          <title>Hybrid CRs</title>
          <p>
            The Hybrid Cyber Range, as mentioned above, aims to combine the versatility of virtualisation
with the realism of real components of the infrastructure that has to be recreated. There
are several projects in this eld, both academic and industrial, usually focused on critical
infrastructures such as Water Supply Systems and Power Plants [
            <xref ref-type="bibr" rid="ref6 ref9">6, 9</xref>
            ].
          </p>
          <p>
            In 2016 Ashok et al. proposed a testbed for assessing security of Smart Grid called
PowerCyber [
            <xref ref-type="bibr" rid="ref2">2</xref>
            ]. It's a project of the Iowa State University, composed of a mix of real hardware,
software emulated components and virtualization technologies for scalability. It is remotely
accessible and can be used for simulating di erent cyber attack scenarios.
          </p>
          <p>
            Tebekaemi et al. proposed an hybrid testbed [
            <xref ref-type="bibr" rid="ref22">22</xref>
            ] for assessing the security in communication
protocols in smart grid. This testbed is composed of a combination of real hardware components
and virtualized ones. This approach allows for a great scalability and modularity since new
components can be added easily and the virtualisation of some components helps in keeping the
overall cost small. However this system is built with the speci c goal of security assessing and
thus it does not implement any functionalities allowing di erent attack scenarios for training
purposes.
3
          </p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Our Goal</title>
      <p>Our goal is to implement a Hybrid Cyber Range (HCR) through which we can, on the one
hand, assess the security of a CPS and, on the other hand, make serious gaming events and/or
training teams while combining the exibility of a CR and the realism of a CPS.</p>
      <p>As a rst step, EVA, an emulator of a real Water Supply System, was built. It is a fully
functional small scale model of a WSS composed of industrial components and devices to achieve
the maximum realism (see Section 4). Then was necessary to equip EVA with additional feature
to make it able to serve also as a Cyber Range (CR). The HCR based on EVA must have some
speci c features and need to be used in di erent context:</p>
      <p>Training the Blue Teams: Blue Teams need isolated and secure environments where
they can be trained. It is often unfeasible to use the real network or infrastructure for
training activities. But the team responsible for defending the corporate infrastructure or
network must be able to respond to real threats quickly. For this reason our HCR must
have the necessary exibility to support the development of di erent attack scenarios
while maintaining a good realism to have an experience of use and interaction as close as
possible to the real one.</p>
      <p>Training the Design Team: the Design Team can take advantage of the use of an HCR
as this would give them the exibility to test new solutions before using them in the eld,
having an isolated environment, but at the same time realistic and very similar to the
real one.</p>
      <p>Mock up: for our purposes it is necessary that the HCR is responsible for an easy and
fast replacement and/or addition of new components and devices. This is because many
companies, especially those operating in the eld of critical infrastructure, need a system
with which to test new components before using them in the eld.</p>
      <p>See Section 5 for more detail about EVA as a HCR.
4</p>
      <p>EVA as a CPS</p>
      <p>EVA (Emulatore di Vero Acquedotto - Emulator of a Real Aqueduct) is a CPS representing
a functioning model of a real Water Supply System (WSS). Apart from the basic components
such as tanks, pipes, pumps etc., EVA comprises sensors, actuators, communication protocol,
and SCADA/ICS as a controller. The IT and OT part of EVA are composed of industrial
components used in the real WSS, including the SCADA, but other component, such as pump
and sensors, are low-quality equipment just used in this rst phase of building the model. The
physical system was designed according to the architecture of a real WSS shown in Figure
17. As a general overview, the model works in the following way. The water is gathered from
a source, that can represent a lake or aquifer. The water is then puri ed and collected in a
dedicated storage system before being distributed to the customers (people houses, hospital or
other infrastructures).
4.1</p>
      <sec id="sec-3-1">
        <title>EVA Implementation</title>
        <p>protocol has been chosen because is one of the most used in industrial facilities. The slaves
Raspberry Pis are directly connected to sensors and actuators. In a rst phase data are collected
and sent to the controller, in charge of analysing informations and decide whether or not to
activate actuators and, thus, sending the appropriate commands to the slaves. Since sensor and
actuators are low quality components the purpose of the Raspberry Pi slaves is to implement
the communication protocol, Modbus, for communicating with the master controller. Finally,
also the external environment, namely ecosystem, was implemented in order to give a more
realistic view of the system.
5</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>EVA as a Cyber Range</title>
      <p>In order to convert EVA into a Cyber Range, we must rst provide a way to quickly and easily
change the behaviour of the system for representing di erent scenarios. In addition we should
avoid changing a large part of the composition of the system to represent di erent scenarios,
since this would require high maintenance costs.
5.1</p>
      <sec id="sec-4-1">
        <title>Model</title>
        <p>EVA, as any other CPS, can be modelled splitting its architecture in term of several components,
being them hardware or software; a possible model is shown in Figure 2, where components are
exchanging information items (data, states, and controls) via proper physical communication
infrastructures, wired or wireless, indi erently. In order to upgrade EVA to serve as a Cyber
Range, a plenty of \ exibility" has to be introduced in its structure, to allow all the involved
CR teams, 2, to properly work at their best. From both a conceptual and a practical point
of view, the structure of Figure 2 has to be modi ed, inserting an additional Wrapper on top
of each components, aimed at providing the possibility of dynamically changing the behaviour
of the underlying component without physically modifying it. More details in the next section
5.2. In few words, through the use of the Wrapper it is possible to change the input and output
of the given component, changing the source of these signal accordingly to the requirements of
the scenario.
5.2</p>
      </sec>
      <sec id="sec-4-2">
        <title>Wrapper</title>
        <p>In the previous section the concept of Wrapper has been introduced. Within the CR model
this new component will give the possibility to get the exibility required to serve di erent
purposes, being them training, gaming or mock-up. As you can see in Figure 3, the Wrapper
connects directly to all the inputs and outputs of each component of the CPS. It will therefore
be possible to arbitrarily control the inputs and outputs of the component by choosing the
appropriate source based on the scenario. In terms of model, the Wrapper is composed by:
Wrapper Controlloer : this allows to control the behaviour of the Wrapper modifying the
interconnection and data exchange inside it;
Wrapper Data &amp; Interconnection: managed by the Wrapper Controlle de nes how inputs
and outputs of the component are routed.</p>
        <p>Moreover Wrappers can communicate directly between each other by means of a dedicated
interconnection, bypassing components or physical interconnections, this for allowing a greater
exibility in the scenario de nition and implementation. In general the Wrapper can work in
the following ways:</p>
        <p>Normal Mode: the Wrapper does not interact with the component, not changing the
component inputs and outputs in any way. This mode of operation can be used when it
is necessary to study the properties of the CPS in general or the speci c component in
particular to discover potential vulnerabilities.</p>
        <p>Vulnerability Injection: the Wrapper takes control of the inputs and outputs of the
component for inserting a vulnerability not previously present. This mode of operation
is used by the White Team during the design and deployment of the scenario, this could
mean, in practice, for example changing the software running on a speci c component.
Vulnerability Remediation: the Wrapper take control only of the component inputs.
In this mode of operation those who interact with the Wrapper, the Blu Team, should not
notice its presence. The Blu Team will interact with the component, as it would do in a
normal way, to be able to apply patches to vulnerabilities (perhaps introduced previously
by the White Team).</p>
        <p>Attack Injection: the Wrapper takes control of the component's inputs and outputs.
The Red Team can use this mode to carry out a campaign of attacks. It is particularly
useful in the training phase of the Blu Team as it allows the Red Team to simulate an
attack even in the absence of a speci c vulnerability (think of the case of a
sensor/actuator, the insertion of a vulnerability would require replacement of it). By modifying
the component inputs, the Red Team will be able to simulate a direct attack on that
component, while, by modifying the outputs appropriately, it will be able to simulate an
attack starting from that component.</p>
        <p>Behaviour Modi cation: the Wrapper takes control over the inputs and outputs of
the connected component. The Design Team can take advantage of this mode to emulate
new components or interconnections and protocols, bypassing the existing ones, thanks
also to the direct interconnection between two Wrapper. It is therefore possible to test
new solutions, both hardware and software, without the need to modify or rebuild the
cyber physical model.</p>
        <p>Mock Up: the exibility introduced by the use of Wrappers around each component can
become useful also for mock-up operations. New components, being them hardware or
software, can be easily added to the CPS without the need of rebuilding the entire system
from scratch, while maintaining a good enough realism to gather information about the
performance of the new components before adopting them in the real system.
6</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Attacks Modelization</title>
      <p>Given the model proposed in the section 6.1 and the cyber physical model on which the proposed
CR is based, we can now see some examples of attacks on similar systems and how these can
be easily modelled with the proposed CR.
6.1</p>
      <sec id="sec-5-1">
        <title>False Data Injection Attacks</title>
        <p>
          As reported in [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ] these attacks can be divided into Response Injection Attacks and Command
Injection Attacks, both possible because network of ICS often do not use authentication for
packets. As far as response injection attacks are concerned, the objective is to intercept, modify
and forward the packets containing the measurements coming from the sensors. Allowing, for
example, to switch o pumps of an aqueduct by making the central control system believe that
critical limits have been reached. Command injection attacks instead, works in a similar way
but, an attacker intercepts the commands sent by the central control system to the actuators.
He then proceeds to modify them appropriately and then forwards the desired commands. In
the speci c case of EVA it is possible to easily model and simulate this attack thanks to the
use of the Wrapper. In a training scenario, the Red Team responsible for the attack campaign,
in one case, will take control over the outputs of the sensor (Figure 4), sending arbitrary data
to the central control unity, bypassing the actual sensor outputs.
        </p>
        <p>In the second case, instead, the Red Team will take control over the actuator inputs (Figure 4)
sending, then, arbitrary command bypassing the ones coming from the central control unit.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>Open Issues &amp; Future Works</title>
      <p>In Section 5 the model for the Hybrid Cyber Range EVA has been presented. The work is still
in development but it is possibile to identify which are the key issues to address during the
project development.</p>
      <p>The CINI Cybersecurity National Laboratory11 has started CyberRange.IT: a national project
for creating a platform for the development of the future Italian cybersecurity community. This
platform is a network of nodes distributed throughout the national territory and each
specialized on di erent vertical domains. Each node must o er its users the facilities for learning,
carrying out research, and practical training with cyber threats and challenges originated from
the real world. EVA, within this project, must provide a testbed representing a Water Supply
Systems.</p>
      <p>
        Is therefore crucial that the HCR can be remotely accessible and can provide all the
functionalities to be interconnected with other CR to create a network of distributed testbed. Another
important aspect to be considered is the integration of an orchestrator, to manage the Wrapper
functionalities, for scenario deployment. In this case, as shown in [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ], can be used TOSCA 12
a orchestrator language released under Oasis Open Standard.
8
      </p>
    </sec>
    <sec id="sec-7">
      <title>Conclusions</title>
      <p>In this paper we have presented a model of Hybrid Cyber Range with the aim of obtaining a
system that is exible in its use but realistic. The model presented is valid for any CPS that
wants to be transformed into HCR. In this speci c case, the modeling was based on EVA, a
model of WSS.</p>
      <p>Thanks to the introduction of a Wrapper for each component it has been possible to expand
the functionality of EVA, while avoiding re-building the system, making it possible to deploy
di erent scenarios for competitions or training.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Irfan</given-names>
            <surname>Ahmed</surname>
          </string-name>
          , Vassil Roussev, William Johnson, Saranyan Senthivel, and
          <string-name>
            <given-names>Sneha</given-names>
            <surname>Sudhakaran</surname>
          </string-name>
          .
          <article-title>A scada system testbed for cybersecurity and forensic research and pedagogy</article-title>
          .
          <source>In Proceedings of the 2nd Annual Industrial Control System Security Workshop</source>
          , pages
          <fpage>1</fpage>
          <article-title>{9</article-title>
          . ACM,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Ashok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Krishnaswamy</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Govindarasu</surname>
          </string-name>
          .
          <article-title>Powercyber: A remotely accessible testbed for cyber physical security of the smart grid</article-title>
          .
          <source>In 2016 IEEE Power Energy Society Innovative Smart Grid Technologies Conference (ISGT)</source>
          , pages
          <fpage>1</fpage>
          <lpage>{</lpage>
          5,
          <string-name>
            <surname>Sep</surname>
          </string-name>
          .
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>R.</given-names>
            <surname>Baldoni</surname>
          </string-name>
          and R. De Nicola.
          <article-title>The future of cybersecurity in italy</article-title>
          .
          <source>CINI-Consorzio Interuniversitario Nazionale Informatica</source>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Mart</surname>
            <given-names>n Barrere</given-names>
          </string-name>
          , Chris Hankin, Angelo Barboni, Giulio Zizzo, Francesca Boem, Sergio Ma eis, and Thomas Parisini.
          <article-title>Cps-mt: A real-time cyber-physical system monitoring tool for security research</article-title>
          .
          <source>In 2018 IEEE 24th International Conference on Embedded and Real-Time Computing Systems and Applications (RTCSA)</source>
          , pages
          <fpage>240</fpage>
          {
          <fpage>241</fpage>
          . IEEE,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Alvaro</surname>
            <given-names>A Cardenas</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Saurabh</given-names>
            <surname>Amin</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Shankar</given-names>
            <surname>Sastry</surname>
          </string-name>
          .
          <article-title>Secure control: Towards survivable cyberphysical systems</article-title>
          .
          <source>In 2008 The 28th International Conference on Distributed Computing Systems Workshops</source>
          , pages
          <volume>495</volume>
          {
          <fpage>500</fpage>
          . IEEE,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Mehmet</given-names>
            <surname>Hazar</surname>
          </string-name>
          <string-name>
            <surname>Cintuglu</surname>
          </string-name>
          , Osama A Mohammed,
          <string-name>
            <given-names>Kemal</given-names>
            <surname>Akkaya</surname>
          </string-name>
          , and
          <string-name>
            <given-names>A Selcuk</given-names>
            <surname>Uluagac</surname>
          </string-name>
          .
          <article-title>A survey on smart grid cyber-physical system testbeds</article-title>
          .
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          ,
          <volume>19</volume>
          (
          <issue>1</issue>
          ):
          <volume>446</volume>
          {
          <fpage>464</fpage>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>CISCO.</surname>
          </string-name>
          <article-title>Cisco cyber range</article-title>
          . https://www.cisco.com/c/dam/en_us/about/doing_business/ legal/service_descriptions/docs/asf-cyber
          <article-title>-range-large</article-title>
          .pdf,
          <year>2016</year>
          . [Online; accessed 28- November-2019].
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Gary</surname>
            <given-names>M</given-names>
          </string-name>
          <string-name>
            <surname>Deckard.</surname>
          </string-name>
          <article-title>Cybertropolis: breaking the paradigm of cyber-ranges and testbeds</article-title>
          .
          <source>In 2018 IEEE International Symposium on Technologies for Homeland Security (HST)</source>
          , pages
          <fpage>1</fpage>
          <article-title>{4</article-title>
          . IEEE,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Hannes</given-names>
            <surname>Holm</surname>
          </string-name>
          , Martin Karresand, Arne Vidstrom, and
          <string-name>
            <given-names>Erik</given-names>
            <surname>Westring</surname>
          </string-name>
          .
          <article-title>A survey of industrial control system testbeds</article-title>
          .
          <source>In Nordic Conference on Secure IT Systems</source>
          , pages
          <fpage>11</fpage>
          {
          <fpage>26</fpage>
          . Springer,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Abdulmalik</surname>
            <given-names>Humayed</given-names>
          </string-name>
          , Jingqiang Lin,
          <string-name>
            <given-names>Fengjun</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>and Bo</given-names>
            <surname>Luo</surname>
          </string-name>
          .
          <article-title>Cyber-physical systems securitya survey</article-title>
          .
          <source>IEEE Internet of Things Journal</source>
          ,
          <volume>4</volume>
          (
          <issue>6</issue>
          ):
          <year>1802</year>
          {
          <year>1831</year>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>Frank</given-names>
            <surname>Jiang and Michael R Frater.</surname>
          </string-name>
          <article-title>Towards a reliable aquatic-based cyber physical system: A new contextsituation aware low overhead routing scheme</article-title>
          .
          <source>In 2013 IEEE International Conference on Cyber Technology in Automation, Control and Intelligent Systems</source>
          , pages
          <fpage>30</fpage>
          {
          <fpage>35</fpage>
          . IEEE,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>KasperskyLab</surname>
          </string-name>
          .
          <article-title>Threat landscape for industrial automation systems</article-title>
          . https://icscert.kaspersky.com/reports/2019/03/27/threat-landscape
          <article-title>-for-industrial-</article-title>
          <string-name>
            <surname>automationsystems-</surname>
          </string-name>
          h2-
          <year>2018</year>
          /,
          <year>2019</year>
          . [Online; accessed 28-November-2019].
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>Hannes</given-names>
            <surname>Krause</surname>
          </string-name>
          .
          <article-title>Nato on its way towards a comfort zone in cyber defence</article-title>
          .
          <source>The Tallinn Papers</source>
          ,
          <volume>1</volume>
          (
          <issue>3</issue>
          ):1{
          <issue>6</issue>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Aditya</surname>
            <given-names>P</given-names>
          </string-name>
          <string-name>
            <surname>Mathur and Nils Ole Tippenhauer</surname>
          </string-name>
          .
          <article-title>Swat: a water treatment testbed for research and training on ics security</article-title>
          .
          <source>In 2016 International Workshop on Cyber-physical Systems for Smart Water Networks (CySWater)</source>
          , pages
          <fpage>31</fpage>
          {
          <fpage>36</fpage>
          . IEEE,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Thomas</surname>
            <given-names>H</given-names>
          </string-name>
          <string-name>
            <surname>Morris and Wei Gao</surname>
          </string-name>
          .
          <article-title>Industrial control system cyber attacks</article-title>
          .
          <source>In Proceedings of the 1st International Symposium on ICS &amp; SCADA Cyber Security Research</source>
          , pages
          <volume>22</volume>
          {
          <fpage>29</fpage>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>NIST</surname>
          </string-name>
          .
          <article-title>Cyber ranges</article-title>
          . https://www.nist.gov/system/files/documents/2018/02/13/cyber_ ranges.pdf,
          <year>2018</year>
          . [Online; accessed 28-November-2019].
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Victor-Valeriu Patriciu</surname>
          </string-name>
          and
          <article-title>Adrian Constantin Furtuna</article-title>
          .
          <article-title>Guide for designing cyber security exercises</article-title>
          .
          <source>In Proceedings of the 8th WSEAS International Conference on E-Activities and information security and privacy</source>
          , pages
          <volume>172</volume>
          {
          <fpage>177</fpage>
          . World Scienti c and Engineering Academy and Society (WSEAS),
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>Michael</given-names>
            <surname>Rosenstein</surname>
          </string-name>
          and
          <string-name>
            <given-names>Frank</given-names>
            <surname>Corvese</surname>
          </string-name>
          .
          <article-title>A secure architecture for the range-level command and control system of a national cyber range testbed</article-title>
          .
          <source>In CSET</source>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Robin</surname>
            <given-names>Rue e</given-names>
          </string-name>
          , Audrey Dorofee, David Mundie,
          <string-name>
            <given-names>Allen D</given-names>
            <surname>Householder</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Michael</given-names>
            <surname>Murray</surname>
          </string-name>
          , and
          <string-name>
            <surname>Samuel</surname>
          </string-name>
          J Perl.
          <article-title>Computer security incident response team development and evolution</article-title>
          .
          <source>IEEE Security &amp; Privacy</source>
          ,
          <volume>12</volume>
          (
          <issue>5</issue>
          ):
          <volume>16</volume>
          {
          <fpage>26</fpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Enrico</surname>
            <given-names>Russo</given-names>
          </string-name>
          , Gabriele Costa, and
          <string-name>
            <given-names>Alessandro</given-names>
            <surname>Armando</surname>
          </string-name>
          .
          <article-title>Scenario design and validation for next generation cyber ranges</article-title>
          .
          <source>In 2018 IEEE 17th International Symposium on Network Computing and Applications (NCA)</source>
          , pages
          <fpage>1</fpage>
          <article-title>{4</article-title>
          . IEEE,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Christos</surname>
            <given-names>Siaterlis</given-names>
          </string-name>
          , Andres Perez Garcia, and
          <string-name>
            <given-names>Bela</given-names>
            <surname>Genge</surname>
          </string-name>
          .
          <article-title>On the use of emulab testbeds for scienti cally rigorous experiments</article-title>
          .
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          ,
          <volume>15</volume>
          (
          <issue>2</issue>
          ):
          <volume>929</volume>
          {
          <fpage>942</fpage>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>Eniye</given-names>
            <surname>Tebekaemi</surname>
          </string-name>
          and
          <string-name>
            <given-names>Duminda</given-names>
            <surname>Wijesekera</surname>
          </string-name>
          .
          <article-title>Designing an iec 61850 based power distribution substation simulation/emulation testbed for cyber-physical security studies</article-title>
          .
          <source>In Proceedings of the First International Conference on Cyber-Technologies and Cyber-Systems</source>
          , pages
          <fpage>41</fpage>
          {
          <fpage>49</fpage>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Vincent</surname>
            <given-names>E</given-names>
          </string-name>
          <string-name>
            <surname>Urias</surname>
            , William MS Stout, Brian Van Leeuwen, and
            <given-names>Han</given-names>
          </string-name>
          <string-name>
            <surname>Lin</surname>
          </string-name>
          .
          <article-title>Cyber range infrastructure limitations and needs of tomorrow: A position paper</article-title>
          .
          <source>In 2018 International Carnahan Conference on Security Technology (ICCST)</source>
          , pages
          <fpage>1</fpage>
          <article-title>{5</article-title>
          . IEEE,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Jan</surname>
            <given-names>Vykopal</given-names>
          </string-name>
          , Radek Oslejsek, Pavel Celeda,
          <string-name>
            <given-names>Martin</given-names>
            <surname>Vizvary</surname>
          </string-name>
          , and Daniel Tovarnak.
          <article-title>Kypo cyber range: Design and use cases</article-title>
          .
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>