Detail publikačního výsledku

Passive Monitoring of a Sandbox Environment During Hands-On Cybersecurity Training

LAZAROV, W.; MORAWIEC, D.; RYBÁR, M.; GALLUS, P.; COUFALÍKOVÁ, A.; FUJDIAK, R.; MARTINÁSEK, Z.

Originální název

Passive Monitoring of a Sandbox Environment During Hands-On Cybersecurity Training

Anglický název

Passive Monitoring of a Sandbox Environment During Hands-On Cybersecurity Training

Druh

Stať ve sborníku v databázi WoS či Scopus

Originální abstrakt

This paper presents the design and implementation of a sandbox monitoring system to record user activity, such as executed commands and visited domains. The system was deployed and tested during hands-on cybersecurity training with 56 participants. Several monitoring tools were evaluated, including Tetragon, Packetbeat, and an eBPFbased DNS Monitor. The paper discusses their advantages, disadvantages, and performance, with an analysis of the processing and relevance of the collected logs. Although the tools proved to be effective, DNS monitoring generated large volumes of irrelevant queries. While filtering reduced noise, it also discarded relevant data. To address this limitation, we developed a custom Browser Monitor extension to directly capture visited domains and metadata, independent of network protocols and DNS encryption. Performance evaluation demonstrated that both sandbox and persistent monitoring services introduced only minimal RAM and CPU overhead. Overall, sandbox monitoring proved to be a lightweight solution that enhances cyber range training by providing actionable insights into user behavior for post-analysis and feedback.

Anglický abstrakt

This paper presents the design and implementation of a sandbox monitoring system to record user activity, such as executed commands and visited domains. The system was deployed and tested during hands-on cybersecurity training with 56 participants. Several monitoring tools were evaluated, including Tetragon, Packetbeat, and an eBPFbased DNS Monitor. The paper discusses their advantages, disadvantages, and performance, with an analysis of the processing and relevance of the collected logs. Although the tools proved to be effective, DNS monitoring generated large volumes of irrelevant queries. While filtering reduced noise, it also discarded relevant data. To address this limitation, we developed a custom Browser Monitor extension to directly capture visited domains and metadata, independent of network protocols and DNS encryption. Performance evaluation demonstrated that both sandbox and persistent monitoring services introduced only minimal RAM and CPU overhead. Overall, sandbox monitoring proved to be a lightweight solution that enhances cyber range training by providing actionable insights into user behavior for post-analysis and feedback.

Klíčová slova

Cybersecurity; Cyber range; Hands-on training; Sandboxing; DevSecOps; Monitoring; DNS traffic; Shell commands

Klíčová slova v angličtině

Cybersecurity; Cyber range; Hands-on training; Sandboxing; DevSecOps; Monitoring; DNS traffic; Shell commands

Autoři

LAZAROV, W.; MORAWIEC, D.; RYBÁR, M.; GALLUS, P.; COUFALÍKOVÁ, A.; FUJDIAK, R.; MARTINÁSEK, Z.

Vydáno

01.06.2026

Nakladatel

Springer

Místo

London, United Kingdom

ISBN

978-3-032-24807-7

Kniha

Intelligent Computing

Strany od

398

Strany do

417

Strany počet

20

URL

BibTex

@inproceedings{BUT201618,
  author="{} and Willi {Lazarov} and  {} and Daniel {Morawiec} and Matěj {Rybár} and Petr {Gallus} and Aneta {Coufalíková} and Radek {Fujdiak} and Zdeněk {Martinásek}",
  title="Passive Monitoring of a Sandbox Environment During Hands-On Cybersecurity Training",
  booktitle="Intelligent Computing",
  year="2026",
  pages="398--417",
  publisher="Springer",
  address="London, United Kingdom",
  doi="10.1007/978-3-032-24807-7\{_}26",
  isbn="978-3-032-24807-7",
  url="https://doi.org/10.1007/978-3-032-24807-7_26"
}