<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>PAIDEUSIS: A Remote Hybrid Cyber Range for Hardware, Network, and IoT Security Training</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Giulio Berra</string-name>
          <email>giulio@gmx.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gaspare Ferraro</string-name>
          <email>ferraro@gaspa.re</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Matteo Fornero</string-name>
          <email>matteo.fornero@consorzio-cini.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nicolo Maunero</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Paolo Prinetto</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gianluca Roascio</string-name>
          <email>gianluca.roasciog@polito.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Cybersecurity National Laboratory</institution>
          ,
          <addr-line>Consorzio Interuniversitario Nazionale per l'Informatica</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Dipartimento di Automatica e Informatica, Politecnico di Torino</institution>
          ,
          <addr-line>Turin</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Today, simulation environments known as cyber ranges are attracting considerable attention across the cybersecurity ecosystem, for their ability to emulate realistic situations and o er pragmatic training to security professionals and students. The extraordinary capabilities of virtualization systems provide great impetus to the development of such platforms, which can scale and be easily maintained. However, many security threats related to the hardware domain of devices are di cult to reproduce in such environments, while instead they are assuming a strategic importance, in a world permeated by electronic devices, which control the objects of our daily life and which handle a large ow of people's private data. This paper presents PAIDEUSIS, a hybrid training environment that seeks to combine the advantages of virtualization and scalability with the realism of hardware devices physically present and connected to the cyber range, including a wide range of devices such as IoT, industrial control, and network hardware devices. Issues faced during the implementation and the management of the platform are presented, as well as the features of some hosted theatres and scenarios based on embedded and IoT devices, some of which already used in relevant Capture-the-Flag (CTF) competitions.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>In recent times, cyber incidents have shown a considerable increase. An ever-growing number
of companies, in all sectors, have now transferred the management of their infrastructures and
their products to the digital domain. This signi cantly increased the attack surface, including
all the connected IT and OT devices, up to data centers. If data are everywhere, then the
attackers are everywhere too.</p>
      <p>Training is thus becoming more and more crucial, not just for cutting-edge security
professional teams, but also for students, with the aim of reducing corporate or critical infrastructures
and, on the other hand, by the availability of proper labs and well-equipped training
environments for a large number of students. In both cases the problem is the same: how to train an
increasing number of people on scenarios as real as possible?</p>
      <p>
        The answer to this question led to the spread of the \cyber ranges" [
        <xref ref-type="bibr" rid="ref34">34</xref>
        ], i.e., platforms
where it is possible to emulate realistic scenarios, replicating a plethora of cyber-attacks, to
enhance skills of operators and users in identifying cyber-breaches and in nding mitigation
strategies to arrest them [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]. The most relevant military organizations, such as NATO [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ] or
the US Department of Defense [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], have been implementing training platforms to virtualize
realistic scenarios and likely dangerous situations, and a wide variety of cyber ranges is now
available also from many digital corporates at international level, such as [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] and [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        But in the bulk of the market, perhaps something is still missing. Today the possibilities
of virtualization are almost unlimited, and the spread of SDN (Software-De ned Network) [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ]
demonstrates the possibility to abstract a large part of the hardware from the physical
domain to implement a network for corporate use. Even if attracted by these possibilities, the
community should not underestimate that not everything can be reduced to software: many
corporate networks still have routers, switches and physical rewalls in their IT and OT
infrastructures, especially when they need to interface with ICS and SCADA. Plus, IoT networks
that permeates our cities, our businesses, our houses, and our bodies are de nitely not virtual.
Virtualizing these realities for training reasons could be limiting, as it has been proven that
attackers themselves use absolutely realistic testbeds to develop complex exploits [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>This is why it is important to design cyber ranges capable of combining the virtual scenarios
with am additional set of scenarios based on real, physical devices. Hybrid cyber ranges aim to
solve the problem, combining the dynamism and exibility of fully virtual cyber ranges, with
the realism of Cyber-Physical Systems (CPS), IoT, and IIoT scenarios.</p>
      <p>
        In addition to the introduced \realism", the exploitation of physical devices in training
platforms also adds the possibility of enabling training and education on security aspects related
to the hardware components of the system, and not only to the software they run. In fact, there
is a wide range of threats related to the physicality of devices and enabled by vulnerabilities
introduced in the their design and production phases [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ], regardless of all the protections that
can be adopted in the higher software layers.
      </p>
      <p>
        In this paper, we present PAIDEUSIS, a cyber training camp implemented in Turin, that
merges virtualized components and physical devices, including a wide range of IoT devices,
industrial control devices, and network devices. The word &amp; (read /paideusis/) was used
in the Ancient Greece to indicate the education of young people to life and war, and by extension
also the place where this education was provided. The transliteration of this word,
PAIDEUSIS, was chosen to name our hybrid cyber range project. Through the combination of devices
and services, the purpose of PAIDEUSIS is to o er multiple scenarios and testbeds, ranging
from guided programming training of devices to actual training sessions in VAPT (Vulnerability
Assessment &amp; Penetration Testing), including gaming sessions in the CTF (Capture-the-Flag)
domain [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], up to Cyber-Defense Excercises (CDX) for security specialists [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
      </p>
      <p>PAIDEUSIS is a cyber range:
• fully usable from remote, with the possibility of interacting with real devices from any
position;
• with non- xed but adaptable scenarios, according to needs;
• recon gurable remotely, thanks to formal methods and languages for de ning new
scenarios.</p>
      <p>Among the others, PAIDEUSIS o ers scenarios for:
• training in the programming and exploitation of Hardware Security Modules and
Platforms, such as the SEcube™ device1;
• training in the con gurations issues and in vulnerabilities arti cially introduced in
communication devices, such as the Tiesse TGR Wi-Fi Routers2;
• training on side-channel attacks over real processors, such as the the ChipWhisperer-Nano
devices3;
• training and competitions based on vulnerable hardware devices, both synthesized on
FPGAs and emulated through customized EDA (Electronic Design Automation)
environments, such as ModelSim4;
• reproducing IoT networks and ICS's, with real sensors and SCADA devices.
The remainder of the paper is organized as follows. Section 2 provides background information
on cyber ranges and analyzes the current state of the art; Section 3 details the PAIDEUSIS
features and architecture, providing some examples on the the most signi cant scenarios; Section
4 nally concludes the paper.
2
2.1</p>
    </sec>
    <sec id="sec-2">
      <title>Background</title>
      <sec id="sec-2-1">
        <title>Cyber Range Taxonomy</title>
        <p>
          According to NIST, \cyber ranges are interactive, simulated representations of an organization's
local network, system, tools, and applications that are connected to a simulated Internet level
environment " [
          <xref ref-type="bibr" rid="ref1">1</xref>
          ]. Yamin et al. [
          <xref ref-type="bibr" rid="ref34">34</xref>
          ] introduced and provided a comprehensive taxonomy for
cyber ranges, classifying them by purpose, by composition and construction of the testbed and
scenarios, and by used technologies, among the other metrics. Figure 1 gives a schematic view
of the proposed classi cation scheme.
        </p>
        <p>
          Among dimensions of the taxonomy, there are:
• Scenario: it de nes the storytelling and the virtual setting for the test, the
competition or the exercise that is performed, but also the steps to be performed and how the
events described are interlaced, in order to help users in identifying the simulation. It
is further charachterized by (a) a Purpose (e.g., an experimental session, a test of new
components or of a defence mechanism, a competition, a training or a teaching session),
(b) an Environment (physical, virtual or hybrid, see below), (c) a Storyline, i.e., how the
activity should be carried out, (d) a Type (static or dynamic depending on the possibility
of modifying its composition while played), (e) a Domain (e.g., industrial, IoT, etc.) and
(f) the Tools used for design and development of the given scenario.
• Teaming: it de nes the categorization of the groups of people, users or maintainers, who
interact with the cyber range. User teams are of two types: Red Teams, in charge of
nding and exploiting the vulnerabilities of a scenario, and Blue Teams, in charge instead
of correcting the vulnerabilities and stemming the problems found within the scenario.
Among maintainer teams, there are White Teams, which represents the team of experts
in charge of setting up the scenarios and inserting the vulnerabilities, and Green Teams,
responsible for the design and development of the infrastructure that hosts the scenarios.
2http://www.tiesse.com/
3https://www.newae.com/products/NAE-CW1101
4https://www.intel.it/content/www/it/it/software/programmable/quartus-prime/model-sim.html
• Monitoring: it de nes how user teams' activity is controlled by management teams, to
ensure compliance with agreed rules and to assign scoring. It is characterized by employed
Methods and Tools, as well as by the abstraction Layer at which the control is carried
out.
• Scoring: it de nes the methods for assigning the score, which can be by objectives
(e.g., the discovery of a ag [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] within the scenario), or through the analysis of the logs
produced by the activity of the participants.
• Management: it establishes the management methods of the cyber range, through the
de nition of Roles and Resources ; it also establishes the methods with which the scenarios
are o ered through portals or dashboards (Range Management ).
2.2
2.2.1
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>State of the Art</title>
        <sec id="sec-2-2-1">
          <title>Physical cyber ranges</title>
          <p>Physical cyber ranges aim to provide an exact replica of the target infrastructure in an isolated
and secure environment. All the devices composing the scenario are the real, physical one,
and no part of the reference infrastructure is emulated. This approach provides the maximum
loyalty with respect to a target infrastructure or target devices, but loses the ability to easily
scale, provides little exibility, and has a considerable impact in setup costs.</p>
          <p>
            A notable example is the National SCADA Testbed (NSTB) [
            <xref ref-type="bibr" rid="ref8">8</xref>
            ], implemented by the US
Department of Energy. The aim of the project is to study, on the one hand, how an electricity
supply system would respond to cyber attacks and on the other hand, to provide a hyper-realistic
testbed for vulnerability identi cation and mitigation techniques. The testbed is composed
of a full-scale electrical power grid and several substations, all implemented using industry
standard technologies, such as SCADA, and various network and industrial protocols (e.g., IP
and MODBUS).
          </p>
          <p>
            Another example is provided by Morris et al., who developed a critical infrastructure testbed
at the Mississippi State University [
            <xref ref-type="bibr" rid="ref22">22</xref>
            ]. 7 scenarios are proposed including, among the others,
petrochemical, steel manufacturing and electrical power grid. The range consists of a control
system that includes PLCs, sensors, actuators, interface and management software commonly
found in the industrial world, and several physical processes modelling components of the target
infrastructure, such as containers for water and oil and smart grid transmission. The system
is used not only for security assessment and research activities, but also in teaching activities
within the courses o ered by the university itself.
2.2.2
          </p>
        </sec>
        <sec id="sec-2-2-2">
          <title>Virtual cyber ranges</title>
          <p>In virtual cyber ranges, all the scenario components are emulated through the adoption of
virtualization solutions. This approach provides the maximum degree of exibility and scalability,
but sacri cing in realism. The category of virtual cyber ranges is certainly the richest in
examples, due to the much higher ability to maintain a completely virtual component infrastructure
compared to physical cyber ranges.</p>
          <p>One of the most important work in this area is the advancement and aggregation of
competence that the Horizon 2020 European project is promoting through the projects
CONCORDIA5, SPIDER6 and CYBERWISER.eu7.</p>
          <p>
            Within the CONCORDIA project, several cyber ranges are being proposed, each of the
with di erent purposes and domains. One of the most important is KYPO [
            <xref ref-type="bibr" rid="ref9">9</xref>
            ], developed by
the Mosaryk University and recently released as an open-source platform. Provided under the
Platform-as-a-Service paradigm [
            <xref ref-type="bibr" rid="ref16">16</xref>
            ], the KYPO cyber range is designed to be modular, exible
and with an high degree of scalability. It is built to be hosted on cloud infrastructure.
Virtualization mechanisms allow to build complex network infrastructure with many interacting
devices and di erent entities to represent the target infrastructure. The cyber range is
completely accessible through a web interface with di erent functionalities base of the user role
within the range, from scenario preparation to active execution.
          </p>
          <p>The CODE Cyber Range is a completely virtual platform developed by the CODE research
institute of the Munich University8. So far, it implements 3 di erent scenarios with 80
individuale exercises from di erent subject area used for experimentation but also for training in the
master degree program of the university.</p>
          <p>The RISE Cyber Range, developed by the RISE Sweden's national research institute,
allows the possibility of emulating the customers' network or build complex scenarios thanks to
virtualisation and emulation9. The focus of the project is to provide a cybersecurity training
5https://www.concordia-h2020.eu
6https://spider-h2020.eu
7https://www.cyberwiser.eu
8https://www.unibw.de/code/forschung/zentrallabore/cyber-range
9https://www.ri.se/en/cyberrange
platform testbed for the public and private sector, including SME's, which often lack the
resources to carry on this type of activities. It is important to highlight the use of this cyber
range as a test and validation facility for cybersecurity certi cation in Sweden.</p>
          <p>The CYBERWISER.eu project focuses its work on the development of a platform for the
training of cybersecurity professional. All the courses and material provided are composed
on lecture material and hands-on practical experience on the remote cyber range platform.
Particular attention is being put on de ning precise guideline for scenario development, from
speci cation to requirements and deployment, in order to allow a long term maintenance of the
platform.</p>
          <p>
            The SPIDER European project is focusing its attention on emerging telecommunication
technologies and in particular on 5G networks [
            <xref ref-type="bibr" rid="ref5">5</xref>
            ]. They propose a Cyber Range as a Service
(CRaaS) platform that o ers dedicated training to professional as well as non-expert in the eld.
The platform leverage on traditional virtualisation technologies to emulate 5G functions. The
focus of the proposed cyber range is not only to provide training support but also, by including
econometric models, provide decision support for investments and metrics for understanding
the economical impact of a possible succesful attack.
          </p>
          <p>
            Another notable example is FITS, presented by Moraes et al. [
            <xref ref-type="bibr" rid="ref21">21</xref>
            ]. The testbed is thought
as an infrastructure for network experimentations, leveraging on virtualisation softwares to
recreate the network environment the users needs for testing their solutions. To support the
infrastructure, several nodes are placed around the world, not only in Brazilian institutions, but
also in European ones. In a later work, the FITS infrastructure has been enhanced with the RIO
platform [
            <xref ref-type="bibr" rid="ref4">4</xref>
            ], an orchestration infrastructure to ease the experimental scenario deployment. In
RIO, it is possible to de ne the characteristics of the experiment through a descriptive language
gathered in a con guration le. During the creation of VMs and all the virtual components of
the scenario, the con guration le is parsed to apply the described characteristics.
          </p>
          <p>
            Recently, cyber ranges have started to be adopted in cybersecurity academic teaching. The
Tele-lab platform [
            <xref ref-type="bibr" rid="ref32">32</xref>
            ], developed at the University of Potsdam, is a laboratory built around
the use of virtual machines assigned to students for their exercises. Virtual machine content
changes based on the learning objective it is dedicated for, and di erent machines are created
from a pool of starting templates. In the abovementioned work, authors posed the attention
on the dynamic deployment of exercise scenarios: it is possible to change a set of parameter
for the the virtual machines (scripts for executing programs, network connections, and so on)
to create easily new scenarios avoiding the reuse of old ones.
2.2.3
          </p>
        </sec>
        <sec id="sec-2-2-3">
          <title>Hybrid cyber ranges</title>
          <p>As the name suggests, hybrid cyber ranges to take the best of both physical and virtual
approaches: adopting virtualisation techniques to improve the scalability and exibility, while
using real hardware devices as targets of the activity carried out, to provide a good degree of
realism.</p>
          <p>
            Among the notable works, Mallouhi et al. proposed a testbed to evaluate security solutions
for SCADA systems [
            <xref ref-type="bibr" rid="ref18">18</xref>
            ]. They propose a hybrid testbed, composed of a real SCADA
controller and several virtual components to emulate a Smart Grid infrastructure. Several macro
blocks can be identi ed: (i) a control center providing control and the way to interact with
the components of the simulated model, (ii) a power distribution grid, (iii) a network of
simulated components such as PLU, RTU and various devices, and (iv) a simulation system, using
commercial applications, of the electric grid, controlled by the SCADA system.
          </p>
          <p>
            In [
            <xref ref-type="bibr" rid="ref14">14</xref>
            ], another example of a power grid hybrid testbed is proposed by Hong et al.. A real
SCADA system has been adopted, while the power system and the various electronic devices
are, instead, simulated using software solutions and virtualization.
          </p>
          <p>
            Furfaro et al. [
            <xref ref-type="bibr" rid="ref12">12</xref>
            ] propose a hybrid cyber range where real smart devices (such as surveillance
cameras and Android smartphones) and emulated ones coexist and cooperate within a virtual
environment used for studying security for IoT applications. The most interesting part of this
work is the original software used to deploy the scenarios, SmallWorld [
            <xref ref-type="bibr" rid="ref13">13</xref>
            ]. In SmallWorld, the
scenarios are not seen as monolithic blocks, but composed of several interconnected parts that
facilitate reusability and scalability. Therefore, it is possible for developers to deploy virtualized
components customised for the speci c scenario, from operating system to the devices.
          </p>
          <p>Another important aspect of this work is represented by the emulation of active entities'
behaviour, such as malicious users or applications. The evolution of the scenario during its
execution can be di erent each time, even with the same starting conditions, increasing
considerably their reusability.</p>
          <p>
            Tsai et al. presented Testbed@TWISC [
            <xref ref-type="bibr" rid="ref30">30</xref>
            ], a network emulation testbed developed in
Taiwan for research purposes. A web-based interface is provided to users, who are able to
create scenarios using the available hardware and virtual resources, as well as a series of toolkit
for security analysis, such as exploit tools for the o ence, or rewalls and access controllers for
the defence. To build the scenario, users have a series of the hardware components at their
disposal, such as switches, IoT devices and routers. To improve scalability and exibility of the
system, it is possible to simulate other components, network infrastructures and devices using
virtualization solutions.
          </p>
          <p>Within the CONCORDIA European project, there are two cyber ranges that fall in the
hybrid cyber range category. One is the TELECOM Nancy Cyber Range, having at its core
the DIATEAM HNS (Hybrid Network Simulation) cyber range server10. The platform is used in
the TELECOM Nancy University to support teaching activities and experimentations. While
it uses standard virtualisation for running scenarios, it is possible to attach other physical
networking platform or devices for testing and experimentations.</p>
          <p>The other one is the Airbus Cyber Range, developed by Airbus11. Also in this case, the core
of the cyber range leverages on virtualisation technologies to build scenarios with the possibility
of adding and integrating physical networks and OT components.
2.3</p>
        </sec>
      </sec>
      <sec id="sec-2-3">
        <title>Cyber Range Orchestration: CRACK</title>
        <p>A non-marginal role in the success of a cyber range is played by the possibility of recon guring
its scenarios to continuously create new ones. This aspect becomes fundamental when the
cyber range must be used for training or cybersecurity competitions, where the reuse of an old
scenario would make the exercise and activity of the participating teams almost vain.</p>
        <p>
          Considering the complexity of the scenarios usually proposed within a cyber range, creating
a new scenario can take a considerable amount of time, especially if compared to the time
of use of the latter. It is therefore necessary to use orchestration solutions that facilitate the
de nition and deployment of scenarios. The most promising project in this area is CRACK [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ],
a framework for the design and deployment of scenarios developed and maintained by the
University of Genoa. At the foundation of this framework is CRACK SDL, a Scenario De nition
Language, based on TOSCA, an infrastructure speci cation language developed by OASIS [
          <xref ref-type="bibr" rid="ref23">23</xref>
          ];
TOSCA is a notable example from the Infrastructure-as-Code (IaC) paradigm [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ], that in the
last years emerged as the main infrastructure design approach.
        </p>
        <p>10https://www.diateam.net/what-is-a-cyber-range/#hybrid_cyber_ranges
11https://airbus-cyber-security.com/products-and-services/prevent/cyberrange/</p>
        <p>The fundamental element of CRACK SDL is the node, representing an element within the
scenario that can be a network device, a virtual machine or a rewall, but not only: through a
node, it is possible to represent users, software, networks, security policies, vulnerabilities and
many other items. Therefore, the approach makes possible to break down a scenario into its
fundamental elements, that can be combined with each other in a simple and intuitive way to
easily build new scenarios.</p>
        <p>
          In the work of Russo [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ], various application examples and utilities of CRACK SDL o er
are presented. In fact, it is possible to create a real pipeline starting from the de nition
of the components, the required features of the scenario and how these elements must be
interconnected; the design is then automatically deployed on the cyber range infrastructure
after passing through a veri cation phase, checking that the described features are consistent
with the objective of the scenario.
3
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Features</title>
      <p>As already introduced, the main objective of PAIDEUSIS is to be a training platform for
security aspects related to the hardware domain, which very often do not play central roles in
the current ecosystem of cyber ranges. The greatest challenge is therefore to be able to adapt
the known virtualization capabilities in order to enable scenarios to host physical devices as
their main actors. This means that, on the one hand, virtualization techniques are exploited
in order to (i) implement the interfaces with the hardware devices, (ii) properly export their
services, (iii) provide the needed connections inside the scenario. On the other hand, wired
or wireless links are used between these devices (actually present and visible in the scenario)
and other supportive devices (e.g., network infrastructure) to allow them to participate in the
scenarios.</p>
      <p>Internally, PAIDEUSIS is organized as follows. The fundamental entity is the component,
i.e., any hardware or software element, virtual or real, that makes up the cyber range. A
subnet is a set of components directly interconnected via LAN (Wi-Fi, Ethernet) or PAN
(USB, Bluetooth) interfaces (in case of real hardware devices), or via virtual interfaces when
devices are virtualized. The range (or theater) is a set of one or more subnets aimed to host
compatible and coherent scenarios. The subnet/range relation is in principle many-to-many :
a range may need more subnets to be set up, and several ranges can use a same subnet of
components (Figure 2).</p>
      <p>The scenario is here de ned as a particular setting of the range, and represents what already
presented in Section 2. Finally, a session is the single instance of an interaction, scheduled over
time, between a user team and a particular scenario, being user teams (Red or Blue) as de ned
in Section 2. Sessions are stateless over time: once the session is gone, every information about
how users interacted with the scenario is lost.</p>
      <p>The physical topology of PAIDEUSIS is depicted in Figure 3. From the outside, it is
possible to access two main services, represented by two virtual servers: one for user teams (in
yellow) and one for maintainer teams (in green). Downstream of these, there are infrastructure
servers, to which the target physical devices are connected. Among others, Wi-Fi routers,
SCADA controllers, microcontrollers, FPGAs, general-purpose IoT cards connected to sensors
or actuator devices and also customized boards for physical attacks are present.</p>
      <p>Depending on the scenarios, these servers are responsible for the virtualization of the
terminals interfacing with the devices, or for the direct exposure of their services. Alternatively,
the machines can be used to virtualize the devices themselves, to enable scenarios where only
emulated hardware is present, or emulated hardware together with physical hardware.</p>
      <p>The groupings of identical or similar devices are directly connected to a server customized for
them, e.g., sized according to the speci cities of the possible scenarios linked to these devices.
The union of one of these "thematic" servers with its cluster of devices may constitute a range
by itself, but may also not. A range can be set up by grouping any set of components within
the cyber range, in any place, thanks to network virtualization techniques.</p>
      <p>In such a promiscuity between virtual and real devices, the setting up of new theaters may
require the Green Team to operate directly on the physical infrastructure. On the contrary,
as for the setting up of the scenarios and the operations of the White Team, PAIDEUSIS is
overcoming this limitation thanks to the use of TOSCA and CRACK SDL (see 2.3)</p>
      <p>The tool used for creating virtual machines within the infrastructure is PROXMOX VE12,
which o ers an intuitive graphical interface for management. For setting up the virtual
networks, WireGuard13, an open-source tool, is used. WireGuard uses strong cryptography and
has better performance than other similar tools such as OpenVPN. Thanks to WireGuard,
users connect to the scenario transparently with respect to the infrastructure, passing through
the user services without even seeing them. In other words, WireGuard con guration les are
distributed to users, that are projected into the scenario once applied the con guration in their
terminals. Once connected, users start the session through authentication or other mechanisms
provided by the scenario speci cations. In addition to the convenience for the users, WireGuard
has the advantage of abstracting the service from the infrastructure, also allowing an
isolationby-design that acts as a security tool for the platform itself: devices not to be included in the
scenario are not included in the VPN con guration, and they are in no way reachable.</p>
      <p>As for monitoring and scoring, PAIDEUSIS does not establish any a-priori criterion, and
delegates the implementation of the methods for user activity monitoring and score assignment
to the White Team in charge of setting up the scenario. These features can be conveyed
through the maintainer services, which remain active during the sessions, and are obviously
12https://www.proxmox.com/en/
13https://www.wireguard.com/
connected to the infrastructure in which the scenario is being played. PAIDEUSIS has been
used in conjunction with external CTF competition platforms, such as CyberChallenge.IT 14,
which separately o ered its ag submission service, with these hidden in the scenarios hosted
by the cyber range.
3.1</p>
      <sec id="sec-3-1">
        <title>Ranges</title>
        <p>
          Some of the ranges currently hosted within PAIDEUSIS are presented below.
• SEcube™ Range: this range is mainly suitable for hosting training scenarios for
programming the SEcube™ device15, a System-in-Package (SiP) developed by Blu5 Group16
and designed for high security applications. SEcube™ embeds in one chip 3 components:
(i) a STM32F4 microcontroller by STMicroelectronics, (ii) a MachX02 FPGA by Lattice
Semiconductor and (iii) an EAL5+ certi ed Smart Card by In neon. Users are o ered
interaction with a Xubuntu17 virtual desktop, to which the development board is connected.
14https://cyberchallenge.it/
15https://www.secube.eu/
16https://www.blu5group.com/
17https://xubuntu.org/
The VM is provided with the necessary tools for programming the 3 components of the
SiP. A Cisco UCS C240 M4 High-Density Rack Server, with 2 Intel Xeon processors and
128 GB of RAM, runs concurrently 40 virtual machines. The server has been expanded
with PCI-Express additional cards to support all the necessary USB connections. Each
USB port has a separate controller, in order to isolate the IOMMU groups. The range can
also be used for scenarios other than programming scenarios, such as CTFs based on the
exploit of vulnerabilities present in the rmware of the microcontroller or in the design
synthesized on the FPGA. At the moment, the range is actively used for the practice part
of the course \Cybersecurity for Embedded Systems", held as Master Degree course in
Politecnico di Torino.
• ChipWhisperer Range: this is the theater dedicated to the ChipWhisperer-Nano
devices18, a board of NewAE Technology Inc. that allows to experiment physical attacks
against a victim chip on the board, such as power side-channel analysis [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ] or fault
attacks [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ]. The dedicated server has a setting similar to that for the SEcube™ Range, even
if the interaction machines need much less resources, having no graphical interface and
not requiring the use of speci c tools for programming or synthesis: interaction with the
device is done via Python scripts. Also in this case, in addition to training scenarios for
starters, there is the possibility to host more advanced gaming scenarios, thus enabling a
category of challenges barely present in the international CTF panorama [
          <xref ref-type="bibr" rid="ref25">25</xref>
          ].
• Digital Hardware Emulation Range: this range is used to host challenges on security
problems stem from digital hardware designs [
          <xref ref-type="bibr" rid="ref25">25</xref>
          ]. The adopted EDA Environment is
currently centered around ModelSim19, through which it is possible to simulate any digital
circuit descriptions in both Verilog and VHDL (e.g., from small size such as simple OTP
authenticators or random number generators, up to real microprocessors, microcontrollers
or DSPs). In several scenarios, hardware trojans [
          <xref ref-type="bibr" rid="ref33">33</xref>
          ] or other logical vulnerabilities are
arti cially inserted into the circuits. Participants have o ine access to the hardware
description, and can interact with the simulated devices via a customized command line
interface. This acts as a lter to and from the ModelSim instance that runs on an interface
virtual machine and simulates the device. The output of the simulation is strictly limited
according to the requirements of the speci c scenario. Red Teams typically use an encoded
sequence of inputs (ranging from simple ModelSim commands to set and view signals, up
to complex Assembly programs) to exploit the introduced vulnerabilities and capture
the hidden ags. Blue Teams are instead supposed to submit e ective patches to the
vulnerabilities.
• Network Security Range: this range hosts network hardware devices, such as routers,
switches or rewalls, on which one can exercise his/her skills relating security-oriented
con guration and programming, but on which it is also possible to develop competition
scenarios. The range has in fact hosted a scenario among those included in the 2020
national nal event of the CyberChallenge.IT CTF competition, which was attended by
28 teams of ethical hackers from Italian academies. The challenge name was home r00ter
and it consisted of 28 Wi-Fi routers by Tiesse20, arranged in a same room and programmed
with a custom developed rmware, connected to the same switch but isolated from a
networking standpoint due to the use of a separate VLAN for each device. Each
teamassigned router was only reachable through a dedicated VPN. First, participants had to
18https://www.newae.com/products/NAE-CW1101
19https://www.intel.it/content/www/it/it/software/programmable/quartus-prime/model-sim.html
20http://www.tiesse.com/
nd an entry point and break into their assigned router. Secondly, once inside their device,
the goal was to exploit the other teams' routers, but using the physical Wi-Fi connection.
• Industrial Control System Range: this theater represents the cyber range adaptation
of a real aqueduct emulator, EVA [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ], which includes industrial control devices such as
SCADA controllers. These communicate, using protocols like MODBUS over Wi-Fi, with
IoT devices connected to sensors and actuators, opening valves or indicating tank levels.
It is an important critical infrastructure of reference for hosting, e.g., training scenarios
for Blue Teams such as Incident Response Teams from the industrial world.
4
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Conclusions</title>
      <p>The preset paper outlined PAIDEUSIS, a hybrid cyber range speci cally developed as a training
platform for security issues related to real hardware devices. These are physically included
in the infrastructure, and made available to the users via a proper combinations of several
di erent virtualization services. Available devices currently include microcontrollers, FPGAs,
open security platforms, ICS's and SCADAs, IoT and IIoT devices, communication devices,
and speci c boards for side-channel analysis exploitation.</p>
      <p>The paper also presented some implementation details and some of the exploited
management tools, including PROXMOX, WireGuard and CRACK. Signi cant examples of theaters
and scenarios set up within the infrastructure were provided, as well.</p>
      <p>A complex environment such as PAIDEUSIS requires continuous maintenance,
improvements, and upgrades. In particular, we are currently focusing on the following aspects: (i) a
greater adaptability of CRACK in order to manage a scalable number of physical devices within
theaters and (ii) new ranges that faithfully reproduce smart buildings and smart cities scenarios,
including, among the others, general-purpose IoT devices connected to physical access control
devices, air quality monitoring stations, and video surveillance cameras.
5</p>
    </sec>
    <sec id="sec-5">
      <title>Acknowledgments</title>
      <p>The activities presented in this paper are partially supported by: (i) the Italian CINI
Cybersecurity National Laboratory via the program CyberChallenge.IT, and (ii) Blu5 Labs. Thanks
also go to the technical partners of PAIDEUSIS, including Blu5 Labs21, Cisco22 and Tiesse23,
as well as to LINKS Foundation24 in Turin for the physical hosting of the infrastructure.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Cyber</given-names>
            <surname>Ranges - NIST</surname>
          </string-name>
          . https://www.nist.gov/system/files/documents/2018/02/13/cyber_ ranges.pdf. [Online; accessed 10-March-2021].
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>IBM X-Force Command</surname>
          </string-name>
          Brochure. https://www.ibm.com/downloads/cas/GO7BG1XV. [Online; accessed 06-March-2021].
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>S.</given-names>
            <surname>Ahmad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Maunero</surname>
          </string-name>
          , and
          <string-name>
            <given-names>P.</given-names>
            <surname>Prinetto</surname>
          </string-name>
          .
          <article-title>Eva: A hybrid cyber range</article-title>
          .
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>I. D.</given-names>
            <surname>Alvarenga</surname>
          </string-name>
          and
          <string-name>
            <given-names>O. C.</given-names>
            <surname>Duarte</surname>
          </string-name>
          .
          <article-title>Rio: A denial of service experimentation platform in a future internet testbed</article-title>
          .
          <source>In 2016 7th International Conference on the Network of the Future (NOF)</source>
          , pages
          <fpage>1</fpage>
          <article-title>{5</article-title>
          . IEEE,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>A.</given-names>
            <surname>Angelogianni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Brignone</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Gerosavva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Ghering</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kavallieros</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Karapistoli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Machamint</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Polvanesi</surname>
          </string-name>
          , E. Veroni, and
          <string-name>
            <given-names>C.</given-names>
            <surname>Xenakis</surname>
          </string-name>
          .
          <article-title>The spider concept: A cyber range as a service platform</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>M.</given-names>
            <surname>Artac</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Borovssak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E. Di</given-names>
            <surname>Nitto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Guerriero</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D. A.</given-names>
            <surname>Tamburri</surname>
          </string-name>
          .
          <article-title>Devops: introducing infrastructure-as-code</article-title>
          .
          <source>In 2017 IEEE/ACM 39th International Conference on Software Engineering Companion (ICSE-C)</source>
          , pages
          <fpage>497</fpage>
          {
          <fpage>498</fpage>
          . IEEE,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A.</given-names>
            <surname>Barenghi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Breveglieri</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Koren</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Naccache</surname>
          </string-name>
          .
          <article-title>Fault injection attacks on cryptographic devices: Theory, practice, and countermeasures</article-title>
          .
          <source>Proceedings of the IEEE</source>
          ,
          <volume>100</volume>
          (
          <issue>11</issue>
          ):
          <volume>3056</volume>
          {
          <fpage>3076</fpage>
          ,
          <string-name>
            <surname>Nov</surname>
          </string-name>
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>K.</given-names>
            <surname>Barnes</surname>
          </string-name>
          and
          <string-name>
            <given-names>B.</given-names>
            <surname>Johnson</surname>
          </string-name>
          .
          <article-title>National scada test bed substation automation evaluation report</article-title>
          .
          <source>Technical report, Idaho National Laboratory (INL)</source>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>P.</given-names>
            <surname>Celeda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Cegan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Vykopal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Tovarnak</surname>
          </string-name>
          , et al.
          <article-title>Kypo{a platform for cyber defence exercises. M&amp;S Support to Operational Tasks Including War Gaming, Logistics, Cyber Defence</article-title>
          .
          <source>NATO Science and Technology Organization</source>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>C.</given-names>
            <surname>Eagle</surname>
          </string-name>
          .
          <article-title>Computer security competitions: Expanding educational outcomes</article-title>
          .
          <source>IEEE Security Privacy</source>
          ,
          <volume>11</volume>
          (
          <issue>4</issue>
          ):
          <volume>69</volume>
          {
          <fpage>71</fpage>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>B.</given-names>
            <surname>Ferguson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Tall</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Olsen</surname>
          </string-name>
          .
          <article-title>National cyber range overview</article-title>
          .
          <source>In 2014 IEEE Military Communications Conference</source>
          , pages
          <volume>123</volume>
          {
          <fpage>128</fpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>A.</given-names>
            <surname>Furfaro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Argento</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Parise</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Piccolo</surname>
          </string-name>
          .
          <article-title>Using virtual environments for the assessment of cybersecurity issues in iot scenarios</article-title>
          .
          <source>Simulation Modelling Practice and Theory</source>
          ,
          <volume>73</volume>
          :
          <fpage>43</fpage>
          {
          <fpage>54</fpage>
          ,
          <year>2017</year>
          . Smart Cities and Internet of Things.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>A.</given-names>
            <surname>Furfaro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Piccolo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Sacca</surname>
          </string-name>
          , and
          <string-name>
            <surname>Andrea</surname>
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Parise</surname>
          </string-name>
          .
          <article-title>A virtual environment for the enactment of realistic cyber security scenarios</article-title>
          .
          <source>In 2016 2nd International Conference on Cloud Computing Technologies and Applications (CloudTech)</source>
          , pages
          <fpage>351</fpage>
          {
          <fpage>358</fpage>
          . IEEE,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>J.</given-names>
            <surname>Hong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Stefanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fshosha</surname>
          </string-name>
          , C. Liu,
          <string-name>
            <given-names>P.</given-names>
            <surname>Gladyshev</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Govindarasu</surname>
          </string-name>
          .
          <article-title>An intrusion and defense testbed in a cyber-power system environment</article-title>
          .
          <source>In 2011 IEEE Power and Energy Society General Meeting</source>
          , pages
          <fpage>1</fpage>
          <issue>{5</issue>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>KasperskyLab</surname>
          </string-name>
          .
          <article-title>Threat landscape for industrial automation systems</article-title>
          . https://ics-cert.kaspersky.com/reports/2019/03/27/ threat-landscape
          <article-title>-for-industrial-automation-</article-title>
          <string-name>
            <surname>systems-</surname>
          </string-name>
          h2-
          <year>2018</year>
          /. [Online; accessed 06- March-2021].
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16] E. Keller and
          <string-name>
            <surname>J. Rexford.</surname>
          </string-name>
          <article-title>The" platform as a service" model for networking</article-title>
          .
          <source>INM/WREN</source>
          ,
          <volume>10</volume>
          :
          <fpage>95</fpage>
          {
          <fpage>108</fpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>P.</given-names>
            <surname>Kocher</surname>
          </string-name>
          , J. Ja e, and
          <string-name>
            <given-names>B.</given-names>
            <surname>Jun</surname>
          </string-name>
          .
          <article-title>Di erential power analysis</article-title>
          .
          <source>In Annual International Cryptology Conference</source>
          , pages
          <volume>388</volume>
          {
          <fpage>397</fpage>
          . Springer,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>M.</given-names>
            <surname>Mallouhi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Al-Nashif</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Cox</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Chadaga</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Hariri</surname>
          </string-name>
          .
          <article-title>A testbed for analyzing security of scada control systems (tasscs)</article-title>
          .
          <source>In ISGT 2011</source>
          , pages
          <issue>1{7</issue>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>J. A.</given-names>
            <surname>Mattson</surname>
          </string-name>
          .
          <article-title>Cyber defense exercise: A service provider model</article-title>
          .
          <source>In IFIP World Conference on Information Security Education</source>
          , pages
          <volume>81</volume>
          {
          <fpage>86</fpage>
          . Springer,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>F. J. R.</given-names>
            <surname>Melon</surname>
          </string-name>
          , T. U. Vaisanen, and
          <string-name>
            <given-names>M.</given-names>
            <surname>Pihelgas</surname>
          </string-name>
          .
          <article-title>Eve and adam: Situation awareness tools for nato ccdcoe cyber exercises</article-title>
          .
          <source>In Systems Concepts</source>
          and
          <string-name>
            <surname>Integration (SCI) Panel</surname>
            <given-names>SCI</given-names>
          </string-name>
          -300
          <source>Specialists' Meeting on `Cyber Physical Security of Defense Systems'</source>
          , pages
          <string-name>
            <surname>STO</surname>
          </string-name>
          {MP,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>I. M.</given-names>
            <surname>Moraes</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Mattos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. H.</given-names>
            <surname>Ferraz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. E.</given-names>
            <surname>Campista</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Rubinstein</surname>
          </string-name>
          , L .Costa,
          <string-name>
            <surname>de M. Amorim</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Vellosoand O. C. Duarte</surname>
            , and
            <given-names>G.</given-names>
          </string-name>
          <string-name>
            <surname>Pujolle. Fits</surname>
          </string-name>
          :
          <article-title>A exible virtual network testbed architecture</article-title>
          .
          <source>Computer Networks</source>
          ,
          <volume>63</volume>
          :
          <fpage>221</fpage>
          {
          <fpage>237</fpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>T.</given-names>
            <surname>Morris</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Srivastava</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Reaves</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Gao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Pavurapu</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Reddi</surname>
          </string-name>
          .
          <article-title>A control system testbed to validate critical infrastructure protection concepts</article-title>
          .
          <source>International Journal of Critical Infrastructure Protection</source>
          ,
          <volume>4</volume>
          (
          <issue>2</issue>
          ):
          <volume>88</volume>
          {
          <fpage>103</fpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>OASIS. OASIS</surname>
          </string-name>
          <article-title>Topology and Orchestration Speci cation for Cloud Applications (TOSCA) TC</article-title>
          . https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=tosca. [Online; accessed 10-March-2021].
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>P.</given-names>
            <surname>Prinetto</surname>
          </string-name>
          and
          <string-name>
            <given-names>G.</given-names>
            <surname>Roascio</surname>
          </string-name>
          .
          <article-title>Hardware security, vulnerabilities, and attacks: A comprehensive taxonomy</article-title>
          .
          <source>In ITASEC</source>
          , pages
          <volume>177</volume>
          {
          <fpage>189</fpage>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>P.</given-names>
            <surname>Prinetto</surname>
          </string-name>
          ,
          <string-name>
            <surname>G.</surname>
          </string-name>
          <article-title>Roascio, and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Varriale</surname>
          </string-name>
          .
          <article-title>Hardware-based capture-the- ag challenges</article-title>
          .
          <source>In 2020 IEEE East-West Design Test Symposium (EWDTS)</source>
          , pages
          <fpage>1</fpage>
          <issue>{8</issue>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>P.</given-names>
            <surname>Qiu. Cyber Range - Cisco Live</surname>
          </string-name>
          . https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/ 2016/pdf/BRKSEC-2653.pdf. [Online; accessed 06-March-2021].
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>E.</given-names>
            <surname>Russo</surname>
          </string-name>
          .
          <article-title>On the Design and Implementation of Next Generation Cyber Ranges</article-title>
          .
          <source>PhD thesis</source>
          , University of Genoa,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>E.</given-names>
            <surname>Russo</surname>
          </string-name>
          ,
          <string-name>
            <surname>G.</surname>
          </string-name>
          <article-title>Costa, and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Armando</surname>
          </string-name>
          .
          <article-title>Building next generation cyber ranges with crack</article-title>
          .
          <source>Computers &amp; Security</source>
          ,
          <volume>95</volume>
          :
          <fpage>101837</fpage>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>G. P.</given-names>
            <surname>Tank</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dixit</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Vellanki</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Annapurna</surname>
          </string-name>
          .
          <article-title>Software-de ned networking-the new norm for networks</article-title>
          .
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>P.</given-names>
            <surname>Tsai</surname>
          </string-name>
          and
          <string-name>
            <given-names>C.</given-names>
            <surname>Yang</surname>
          </string-name>
          .
          <article-title>Testbed twisc: A network security experiment platform</article-title>
          .
          <source>International Journal of Communication Systems</source>
          ,
          <volume>31</volume>
          (
          <issue>2</issue>
          ):e3446,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>E.</given-names>
            <surname>Ukwandu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Farah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Hindy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Brosset</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kavallieros</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Atkinson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Tachtatzis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bures</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Andonovic</surname>
          </string-name>
          , and
          <string-name>
            <given-names>X.</given-names>
            <surname>Bellekens</surname>
          </string-name>
          .
          <article-title>A review of cyber-ranges and test-beds: current and future trends</article-title>
          .
          <source>Sensors</source>
          ,
          <volume>20</volume>
          (
          <issue>24</issue>
          ):
          <fpage>7148</fpage>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>C.</given-names>
            <surname>Willems</surname>
          </string-name>
          and
          <string-name>
            <given-names>C.</given-names>
            <surname>Meinel</surname>
          </string-name>
          .
          <article-title>Online assessment for hands-on cyber security training in a virtual lab</article-title>
          .
          <source>In Proceedings of the 2012 IEEE Global Engineering Education Conference (EDUCON)</source>
          , pages
          <fpage>1</fpage>
          <lpage>{</lpage>
          10. IEEE,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>K.</given-names>
            <surname>Xiao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Forte</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Jin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Karri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Bhunia</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Tehranipoor</surname>
          </string-name>
          .
          <article-title>Hardware trojans: Lessons learned after one decade of research</article-title>
          .
          <source>ACM Transactions on Design Automation of Electronic Systems (TODAES)</source>
          ,
          <volume>22</volume>
          (
          <issue>1</issue>
          ):
          <fpage>6</fpage>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <surname>M. M. Yamin</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          <string-name>
            <surname>Katt</surname>
            , and
            <given-names>V.</given-names>
          </string-name>
          <string-name>
            <surname>Gkioulos</surname>
          </string-name>
          .
          <article-title>Cyber ranges and security testbeds: Scenarios, functions, tools and architecture</article-title>
          .
          <source>Computers &amp; Security</source>
          ,
          <volume>88</volume>
          :
          <fpage>101636</fpage>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>