Teaching Penetration Testing

We are devising lessons and tools for using in a class of information security students. Students are presented with realistic exercises (e.g., realistic scenarios and objectives) and they are evaluated by their performance. We have created a simulation tool, Core Insight, which has been integrated to a penetration testing learning kit in order to perform these exercises without requiring the underlying hardware and settings. We are designing scenarios of ascending difficulty which test the students' ability in different aspects (e.g., information gathering, attacking different topologies, evading tight firewalling).

The material will follow shortly. Check our talk at Troopers '08 for starters.

Publications