<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Analysis of cyber exercises approaches</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute of special communication and information protection National technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Pukhov institute for modeling in energy engineering of National academy of sciences of Ukraine</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>0000</fpage>
      <lpage>0001</lpage>
      <abstract>
        <p>Raising awareness of the organization's employees comes down to cyber exercise. They can target both an individual employee and specialists in general. This is implemented mainly in four stages of organization of the cyber exercises. In the first stage, the purpose, scenarios, evaluating system of results for their execution are defined, and scenario-modeling environment is established. It is tested for compliance with the purpose of cyber exercises within the second stage. In the third stage, cybersecurity scenarios are being developed. The results of the execution are evaluated in the fourth stage. This is due to the relevance of the analysis of approaches to the organization of cyber exercises. In solving this problem, it was established that there was no uniform interpretation of this concept. First, such ambiguity of interpretations is associated with the direction of cyber exercises. Therefore, approaches to their organization are focused on obtaining theoretical knowledge, practical skills, and cybersecurity skills. Primarily, an incident detection and prevention approach is common. Another common approach is assessment of cybersecurity through penetration testing. The application of these approaches can be generalized and organized as a game.</p>
      </abstract>
      <kwd-group>
        <kwd>cybersecurity</kwd>
        <kwd>scenario</kwd>
        <kwd>incident</kwd>
        <kwd>cyber exercises</kwd>
        <kwd>cyber exercises approaches</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        An important element of promoting and maintaining cybersecurity in an organization
is knowledge and awareness of existing threats types and real attacks on critical
infrastructure. [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Cyber exercises are organized through awareness-raising programs for
cybersecurity organizations. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. It mainly comes down to training in an interactive
form and is characterized by orientation both for the individual employee and for
specialists as a whole.
      </p>
      <p>
        There are four stages in the organization of cyber exercises [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1-3</xref>
        ]. In the first stage,
goals, scenarios, evaluating system of results for their execution, and the
scenario-modeling environment are established. The environment is being tested for compliance with
the goals of cyber exercises in the second stage. In the third stage, established
cybersecurity scenarios are being worked out, while the results of their execution are evaluated
at the fourth stage [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Depending on the purpose of cyber exercises and the training
level of organization employees, it can be organized using different approaches.
2
      </p>
    </sec>
    <sec id="sec-2">
      <title>Cyber exercises approaches</title>
      <p>
        Now there is no unified interpretation of the “cyber exercises”, concept for example:
“cyber training”, “cyber range”. Sometimes “cyberlearning” term is used, particularly,
when organizing remote cyber exercises. It is focused primarily on obtaining theoretical
knowledge. Unlike “cyberlearning”, a characteristic feature of “cyber training” and
“cyber range” is the focus on obtaining of practical cybersecurity skills [
        <xref ref-type="bibr" rid="ref1 ref2 ref3 ref4">1-4</xref>
        ].
      </p>
      <p>
        Such terms as “cybersecurity exercises”, “cyber defense exercises” are often used
as interchangeable, and describe cyber exercises as processes for preparing, evaluating,
practicing, and improving the effectiveness of the organization to ensure cybersecurity
[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. They cover large-scale computer modeling activities, as well as tabletop exercises,
for example, prepared possible scenarios card.
      </p>
      <p>
        In military terms “drills” and “exercises” sometimes refer to similar activities,
especially when it comes to training sessions [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The term “drills” is used to describe
systematic training in the use of techniques or tools by performing exercises repeatedly.
The repetitive, systematic nature of tasks as "drills" distinguishes them from other types
of exercises.
      </p>
      <p>
        A typical approach to organizing cyber exercises is characterized by the acquisition
of skills and abilities to respond to cybersecurity incidents. First, they focus on both
their detection and prevention of manifestation in future activities [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. In addition, it is
possible to focus on assessing cybersecurity through penetration testing. This is the
basis of an approach to identifying information vulnerabilities in cyberspace [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ],
including the use of social engineering [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. At the same time, the use of a game approach
to organizing cyber exercises is common. Within its framework, two teams are
distinguished – attackers and “victims” [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
2.1
      </p>
      <sec id="sec-2-1">
        <title>Defense Oriented Approach</title>
        <p>
          The specificity of each of the known approaches to organizing cyber exercises is
determined by their purpose and focus, and depends on the training level (qualifications) of
the organization’s specialists. Among them, an approach that focuses on responding to
cyber incidents and reducing the consequences of their manifestations stands out.
Therefore, cyber exercises are carried out to practice protection methods that can be
used in responding to cybersecurity incidents. Defense Oriented Approach for cyber
exercises is one of the most promising approaches to cybersecurity [
          <xref ref-type="bibr" rid="ref1 ref7">1, 7</xref>
          ].
        </p>
        <p>
          Raising the awareness of the organization’s employees is achieved through various
forms of cyber exercise, in particular, progressive, specialized and individual. This
allows participants to test their knowledge, ability, and cybersecurity skills. Among the
common forms of cyber-training, the following ones stand out [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]:
1. Tabletop exercises – this is a scenario-based discussion that validates proactive
countermeasures against simulated cyber incidents. For example: Elevation of Privilege
(EoP), EoP card game helps to study possible threats to software and computer systems,
Cyber Atlantic exercises conducted by ENISA, Cyber 9/12 Challenge tabletop activity
to developing national security policy recommendations for cyber incident scenario.
These exercises validate cybersecurity plans to identify vulnerabilities and determine
how to handle them.
        </p>
        <p>2. Simulation exercises – these are practical training sessions in which cyber
incidents are simulated. For example: Cyber Coalition, Cyber Europe exercises conducted
by ENISA. Practical activities allow participants to see the effects of cyberattacks in a
controlled environment.</p>
        <p>
          3. Full scale Exercises – these are challenging exercises that are designed to
provide practical skills in real time. For example: Locked Shields and Baltic Shields
exercises. This type of simulation is realistic, it allows you to check cybersecurity plans,
security policies [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]. Their main purpose is to analyze and test methods of countering
cyberattacks.
        </p>
        <p>
          The Defense Oriented Approach is more about system administration and digital
forensics. Participants of cyber exercise who seek to defend themselves against cyber
incidents and their consequences should be aware that defense activities are a
continuous process that can be represented by a sequence of such actions [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]:
1. Creation of a security policy – Involves the use of various tools to eliminate
vulnerabilities. Encryption methods can be used to hide the transmitted data through
channels exposed to dangerous influences. Systems with known security vulnerabilities
should be kept up to date by the remediation of them. Ensuring physical security
provides for reliable storage of equipment.
        </p>
        <p>2. Security status monitoring – Plays a critical role in determining how effectively
security policy requirements are met. This is achieved by using, for example, intrusion
detection and prevention systems. They can be considered as an effective solution for
monitoring unwanted traffic.</p>
        <p>3. Testing of security measures is seen as the only way to convince the
implemented means to maintain the security policy. The purpose of security measures testing
is to identify all possible loopholes and weaknesses of the software system, which might
result in a loss of important information.</p>
        <p>4. Improving security assurance – achieved by considering vulnerability reports
and security advisories that help keep abreast of new potential attacks. Monitoring,
testing, and identifying vulnerabilities is critical to refining and tuning security policies.</p>
        <p>
          Such actions are considered as the basis for the presentation “Security Wheel” (see,
for example [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ], Fig. 1). They should be used to ensure the security of information
assets, to track them by stages of the life cycle. Due to this, it is possible to timely detect
attacks and, most importantly, reduce their occurrence and, as a result, improve security
configuration.
        </p>
        <p>
          In the Defense Oriented Approach, there are at least three ways to organize exercises
for cyber exercises participants [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ]:
        </p>
        <p>1. Obtaining requirements and services that must be provided and / or developing
their own measures, means to meet them.</p>
        <p>2. Obtaining the default settings for certain systems, programs, or services that
must be provided and configured to meet security requirements.</p>
        <p>3. Access to the installed and configured systems, programs, services whose
security must be ensured. In this approach, the attacker can be seen as an instructor or an
external party.</p>
        <p>An example of using Defense Oriented Approach is Blue Teaming exercise. It is
designed to train the team, which must ensure the security of pre-configured and secure
infrastructure. Red Team real or automated (in the form of scenarios), prepares a
training scenario in accordance with the set goal.</p>
        <p>Obtaining theoretical knowledge and skills of cyber defense (cyber defence
exercises, CDX) are among examples of cyber exercises. The main focus is on cybersecurity
defense tasks. In particular, conducting forensic investigations and practicing security
configuration skills, such as networking.</p>
        <p>The Cyber Europe exercises focus on simulating manifestations of large-scale
security incidents that could lead to a cyber crisis. The training offers opportunities for
digital forensic analysis (e.g. of incidents or malware), as well as solving complex business
continuity situations and overcoming cybercrises.
2.2</p>
      </sec>
      <sec id="sec-2-2">
        <title>Offense Oriented Approach</title>
        <p>
          Computer systems can be compromised in various ways, and countering complex and
persistent attacks consists of understanding the sequence of possible malicious actions
and thinking of the attacker. Exercises within the Offense Oriented Approach, namely
Red Teaming, support the development of security measures and tools given the
complexity of attacks. That is why this approach to organizing cyber exercises is focused
on practicing proactive cyber security mechanisms. Such exercises usually simulate the
protection of critical infrastructure from cyber security incidents [
          <xref ref-type="bibr" rid="ref7 ref9">7, 9</xref>
          ].
        </p>
        <p>
          Most of the exercises in this approach to organizing cyber exercises involve
operating servers and performing penetration tests on target systems. Starting with target
system recognition, vulnerability detection and assessment, cyber security participants
check security violations, try to use them to achieve the goal of conducting a scenario
to access the target system [
          <xref ref-type="bibr" rid="ref6 ref9">6, 9</xref>
          ]. Maintaining access to the system and introducing
hidden command and control systems ensures the effectiveness of cyber exercises.
Testing security plan, measures, and procedures implemented by simulating attacker
behavior can improve security.
        </p>
        <p>
          Participants in cyber exercises should master the offensive model of behavior to
ensure cybersecurity. It helps to better understand how to defend against cybersecurity
incidents. At the same time, there is a need for a deep understanding of how to conduct
attacks in order to know how to mitigate them and minimize possible losses. Therefore,
the Offense Oriented Approach encourages participants to view the exercises as
attackers (intruders). They will have to conduct attacks to accomplish various tasks.
Simulating real attacks is reduced to performing a sequence of steps, namely (see, e.g. [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ], Fig.
2):
1. Reconnaissance.
        </p>
        <p>2. Weaponization (takes into account the received information during
reconnaissance, creation of malicious software).</p>
        <p>3. Delivery (detection of vulnerabilities for the threats implementation).
4. Exploitation (realization of threats due to identified vulnerabilities).
5. Privilege escalation (exploiting a bug, to gain elevated access to resources).
6. Lateral movement (when an attacker moves from a compromised device to
others on this network).</p>
        <p>7. Command and control.
8. Exfiltrate and complete (data extraction, placement backdoors).</p>
        <p>In Offense Oriented Approach, a system that is preconfigured for known
vulnerabilities can be affected. At the same time, most of them do not necessarily have to be
guided by someone during the attack.</p>
        <p>Using Red Teaming as a cybersecurity training exercise can be an effective way to
gain the decision-making skills and abilities needed to detect and counter cybersecurity
incidents. Red Teaming exercises may involve the use of a set of available methods and
tools, or may develop a response to unforeseen situations. Offense Oriented Approach
to organize cyber exercise is extremely useful for testing infrastructure and systems,
identifying security vulnerabilities, and configuration errors when learning to counter
cyberattacks. During cyber exercises, it is important to understand the possible
consequences. The closest thing to cyberattack training is the format of so-called “ethical
hacking”, which may also be called pentesting and Red Teaming.</p>
        <p>Examples of the “offensive” type international cyber exercises are Locked Shields,
Cyber Coalition, Baltic Cyber Shield. These cyber trainings are focused on improving
technical skills for response, cyber investigations, proactive response to cyber incidents
in order to protect critical infrastructure.
2.3</p>
      </sec>
      <sec id="sec-2-3">
        <title>War Game Approach</title>
        <p>The approach chosen for cyber exercises should depend on their intended purpose. As
a rule, they are designed to provide theoretical knowledge and practical skills to security
administrators. This is realized through the use of the Defense Oriented Approach.
Whereas penetration testing exercises are based on Offense Oriented Approach.
However, a mixed approach, namely the War Game Approach, is advisable for a
comprehensive cyber exercise.</p>
        <p>The Mixed Approach combines the Defense Oriented Approach with the Offense
Oriented Approach. Thus, its complexity is achieved when performing exercises with
cyber defense. In this case, the participants of the cyber exercise are divided into two
teams. The first plays the role of a defender (“victim”). The second reflects the role of
attackers (intruders).</p>
        <p>
          An example of cyber exercise that combines offensive and defensive approaches is
the CTF competition (Capture the flag) [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. These training exercises give participants
the opportunity to feel the role of an attacker or a defender. They can test their abilities
in solving cybersecurity problems. They provide for the detection of vulnerabilities,
exploit implementation, data protection, forensics. Fulfillment of tasks is evaluated by
the gain in the form of “flags”. In particular, a file with a unique string of special
characters [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]. Checking the “flags” in the system allows setting grades depending on the
complexity of the tasks.
        </p>
        <p>
          There are two main formats of CTF [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]:
1. Task-based (Jeopardy) – training is reduced to solving as many problems as
possible in different areas (digital forensics, web application, cryptography, mobile
Security)
        </p>
        <p>2. Attack-defense – training is reduced to the protection of, for example, the
network, server, confidential information and maintaining the functionality of intended
services at the same time as the implementation of attacks aimed at violating services
is carried out by the enemy team.</p>
        <p>Participants in cyber exercises are involved in scenarios, and the team of attackers
uses real tools of operation and penetration to attack the virtual network. The defense
team monitors the state of the network and network equipment and protects the
network, they can also practice counterattacks against the red team. A group of people,
known as the white team, create the training environment and control the cyber training.
They establish a set of rules for interaction between the red and blue teams and
sometimes act as instructors to give tips to exercise participants in cyber training.</p>
      </sec>
      <sec id="sec-2-4">
        <title>Cyber exercise tools</title>
        <p>
          The use of tools in organizing cyber exercise is mostly reduced to such options:
1. Simulation tools – tools that allow you to conduct practical training sessions, for
example [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]: online platform, cyber training range. They simulate cyber incidents, the
response to which is expected in real time.
        </p>
        <p>
          2. Tabletop tools – toolboxes that are allowed to conduct cyber exercise based on
discussion, for example [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ]: cards with the exercise scenario, quiz. Participants gather
and discuss their role in an emergency (cybersecurity incident) and possible response
options.
        </p>
        <p>Both types of cyber exercise tools have their advantages and disadvantages.
Fullscale modeling may involve the use of virtual network environments that allow exercise
participants to monitor the manifestations of cybersecurity incidents. However, this
requires a lot of resources and detailed planning. At the same time, tabletop tools should
use a small period of time, taking into account the need for concentration. Because they
are focused on discussions and therefore the sense of urgency and realism in modeling
is lost.</p>
        <p>
          If special skills are not required to prepare for the use of tabletop tools, then the use
of simulation tools is due to the presence of theoretical knowledge and skills in setting
them up. However, despite this, it is now common to simulate real-world situations
using appropriate hardware and software. Developing realistic and scalable scenarios
becomes important for effective cyber exercises. An example of such cyber exercise
tools is [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]:
        </p>
        <p>1. Hardware cyber range, although realistic, but large-scale, expensive and
timeconsuming to set up. Due to its cost, the number of exercise participants who can be
trained in any of the scenarios of cyber threats is limited. In addition, it limits the total
number of cyber exercise participants over a set period of time. We should also mention
the wired cyber range, which is characterized by the complexity of modeling wireless
tactical networks with their inherent vulnerabilities.</p>
        <p>
          2. Virtual cyber range is considered as a simulation environment that provides
realtime hardware and software for the implementation of cyber threats to the network
infrastructure [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ]. It is closely integrated with physical equipment, programs, network
monitoring tools, intrusion detection and prevention systems and structural modeling
“battlefield”. This provides cybersecurity skills and countermeasures against
cyberattacks (see, e.g. [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], Fig. 3). Simulation is about presenting a real system with an analog
that is easier to manage, providing the same functionality, without reference to a
specific location and equipment.
        </p>
        <p>
          The general cyber range model of a cyber exercise site is defined by the following
components [
          <xref ref-type="bibr" rid="ref13 ref2">2, 13</xref>
          ]:
        </p>
        <p>1. Orchestration Layer – layer that uses input data from RLMS. It is designed to
orchestrate cybersecurity tools. At the same time, it integrates the technology and
service components of the cyber range.</p>
        <p>2. Underlying Infrastructure – level of infrastructure, which determines the realism
and accuracy of the cyber range. In addition, ways of generating traffic and modeling
attacks are used.</p>
        <p>3. Virtualization Layer – layer, which is defined as a firewall between the target
and underlying infrastructures. Whereas the target infrastructure is considered relative
to the feasibility of attacks.</p>
        <p>4. Target Infrastructure – a simulated environment in which cyber exercise
participants training. Based on the purpose of their organization, scenarios will be generated
to create the target infrastructure at the orchestration level. A scenario may contain
configuration-specific information, including IP address ranges, routing information,
server stacks, and software.</p>
        <p>The approaches to organizing cyber exercises are analyzed in Table 1, taking into
account the peculiarities of their use and the relevant tools (see Table 1).</p>
        <p>Formulation of
the approach
Defense Oriented</p>
        <p>Approach
Offense Oriented</p>
        <p>Approach
War Game
Approach</p>
        <p>Tools
cards with the
exercise scenario,
quiz, virtual cyber</p>
        <p>range
virtual cyber
range, online
plat</p>
        <p>form
virtual cyber
range, online
platform</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Conclusion</title>
      <p>Thus, the organization of cyber exercises is accompanied by the use of various
concepts. Each of them determines their specificity, taking into account the orientation of
both the individual employee and the specialists as a whole. Such features determine
the choice of approaches to the organization of cyber exercises. In particular, they can
focus on individual cybersecurity tasks, for example, on incident response (“Cyber
defense”), cybersecurity assessment (“Compensation Testing”), or reduction of the
number of solutions to the game (“War game”).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Seker</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ozbenli</surname>
          </string-name>
          , H.:
          <article-title>The Concept of Cyber Defence Exercises (CDX): Planning, Execution, Evaluation</article-title>
          . In: 2018
          <source>International Conference on Cyber Security and Protection of Digital Services (Cyber Security)</source>
          . pp.
          <fpage>1</fpage>
          -
          <lpage>9</lpage>
          , IEEE, Glasgow, Scotland,
          <string-name>
            <surname>UK</surname>
          </string-name>
          , (
          <year>2018</year>
          ) https://doi.org/10.1109/CyberSecPODS.
          <year>2018</year>
          .
          <volume>8560673</volume>
          , last accessed
          <year>2020</year>
          /18/11.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Yamin</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Katt</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gkioulos</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          :
          <article-title>Cyber Ranges and Security Testbeds: Scenarios, Functions, Tools and Architecture</article-title>
          .
          <source>Computers &amp; Security</source>
          , vol.
          <volume>88</volume>
          (
          <year>2020</year>
          ), https://doi.org/ 10.1016/j.cose.
          <year>2019</year>
          .
          <volume>101636</volume>
          , last accessed
          <year>2020</year>
          /11/10.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Kick</surname>
          </string-name>
          , J.:
          <article-title>Cyber exercise playbook</article-title>
          .
          <source>The MITRE Corporation</source>
          , Wiesbaden, Germany (
          <year>2014</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Vykopal</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vizvary</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Oslejsek</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Celeda</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tovarnak</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Lessons learned from complex hands-on defence exercises in a cyber range</article-title>
          ,
          <source>In: IEEE Frontiers in Education Conference (FIE)</source>
          . pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          . IEEE, Indianapolis, IN, USA, https://doi.org/10.1109/FIE.
          <year>2017</year>
          .
          <volume>8190713</volume>
          , last accessed
          <year>2020</year>
          /11/10.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Matania</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yoffe</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goldstein</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Structuring the national cyber defence: in evolution towards a Central Cyber Authority</article-title>
          .
          <source>Journal of Cyber Policy</source>
          , vol.
          <volume>2</volume>
          , no.
          <issue>1</issue>
          ,
          <fpage>16</fpage>
          -
          <lpage>25</lpage>
          (
          <year>2017</year>
          ), https://doi.org/10.1080/23738871.
          <year>2017</year>
          .
          <volume>1299193</volume>
          , last accessed
          <year>2020</year>
          /11/10.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Mokhor</surname>
            ,
            <given-names>V. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsurkan</surname>
            ,
            <given-names>O. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsurkan</surname>
            ,
            <given-names>V. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Herasymov</surname>
            ,
            <given-names>R. P.</given-names>
          </string-name>
          :
          <article-title>Information Security Assessment of Computer Systems by Socio-engineering Approach</article-title>
          .
          <source>In: Proc. XVII International Scientific and Practical Conference Information Technologies and Security: selected papers</source>
          . Vol.
          <year>2067</year>
          . Aachen, Germany: CEUR WS,
          <year>2017</year>
          . pp.
          <fpage>92</fpage>
          -
          <lpage>98</lpage>
          , http://ceur-ws.org/Vol2067/paper13.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Patriciu</surname>
            ,
            <given-names>V. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Furtuna</surname>
            ,
            <given-names>A. C.</given-names>
          </string-name>
          :
          <article-title>Guide for designing cyber security exercises</article-title>
          .
          <source>In: Proceedings of the 8th WSEAS International Conference on E-Activities and Information Security and Privacy</source>
          , pp.
          <fpage>172</fpage>
          -
          <lpage>177</lpage>
          . World Scientific and Engineering Academy and Society, WSEAS (
          <year>2009</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Knüpfer</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bierwirth</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stiemert</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schopp</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Seeber</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pöhn</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hillmann</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Cyber Taxi: A Taxonomy of Interactive Cyber Training and Education Systems</article-title>
          .
          <source>Modeldriven Simulation and Training Environments for Cybersecurity</source>
          , vol.
          <volume>12512</volume>
          ,
          <fpage>3</fpage>
          -
          <lpage>21</lpage>
          (
          <year>2020</year>
          ), https://doi.org/10.1007/978-3-
          <fpage>030</fpage>
          -62433-
          <issue>0</issue>
          _1, last accessed
          <year>2021</year>
          /16/01.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>López de Jiménez R.:</surname>
          </string-name>
          <article-title>Pentesting on web applications using ethical - hacking</article-title>
          .
          <source>In: IEEE 36th Central American and Panama Convention (CONCAPAN XXXVI)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . IEEE, San Jose, Costa Rica, https://doi.org/10.1109/CONCAPAN.
          <year>2016</year>
          .
          <volume>7942364</volume>
          , last accessed
          <year>2020</year>
          /11/10.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Dewar</surname>
            , Robert,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Cybersecurity and Cyberdefense Exercises, CSS Cyber Defense Reports, Center for Security Studies (CSS)</article-title>
          ,
          <source>ETH Zurich</source>
          , (
          <year>2018</year>
          ), https://doi.org/10.3929/ethz-b000314593,
          <source>last accessed</source>
          <year>2020</year>
          /18/11.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Cowan</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Arnold</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Beattie</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wright</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Viega</surname>
          </string-name>
          , J.:
          <article-title>Defcon Capture the Flag: Defending Vulnerable Code from Intense Attack</article-title>
          .
          <source>In: Proceedings DARPA Information Survivability Conference and Exposition</source>
          . vol.
          <volume>1</volume>
          , pp.
          <fpage>120</fpage>
          -
          <lpage>129</lpage>
          , Washington, DC, USA, https://doi.org/ 10.1109/DISCEX.
          <year>2003</year>
          .
          <volume>1194878</volume>
          , last accessed
          <year>2020</year>
          /12/18.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Angafor</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yevseyeva</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>He</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Game‐based learning: A review of tabletop exercises for cybersecurity incident response training</article-title>
          .
          <source>Security and Privacy</source>
          <volume>3</volume>
          (
          <issue>6</issue>
          ),
          <fpage>117</fpage>
          -
          <lpage>131</lpage>
          (
          <year>2020</year>
          ), https://doi.org/10.1002/spy2.126, last accessed
          <year>2020</year>
          /23/12.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <article-title>National Initiative for Cybersecurity Education (NICE). The Cyber Range: A Guide. Guidance Document for the Use Cases, Features, and Types of Cyber Ranges in Cybersecurity Education, Certification</article-title>
          and Training, https://cutt.ly/8kipFaN, last accessed
          <year>2020</year>
          /23/12.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>