- Research Article
3
- 10.1016/j.jisa.2024.103847
LSPR23: A novel IDS dataset from the largest live-fire cybersecurity exercise
- Aug 06, 2024
- Journal of Information Security and Applications
- Allard Dijk + 5 more +5
Publications from 2021 to 2026
Showing 10 of 15 papers
LSPR23: A novel IDS dataset from the largest live-fire cybersecurity exercise
Comparison of agility in 13–16-year-old volleyball and football players and non-athletes
The aim of the study was to find and compare the agility abilities and anthropometric characteristics of 13–16-year-old volleyball and football players and adolescents not engaged in sports. The following research questions were posed: to find the agility results and anthropometric characteristics of volleyball and football players and non-athletes and to compare the agility results and anthropometric characteristics between athletes and not non-athletes and between different sports in both boys and girls. In total, 63 subjects participated in the study – 45 of them practised sports and 18 did not. Among those who practised sports, there were 19 volleyball and 26 football players. The following agility tests were applied in the study: T-test, four corners test, 5-0-5 run test and Illinois test. For data analysis, the Microsoft Excel program was used. The subjects’ height, weight, fat percentage and fat amount were measured. The means, minimum and maximum values, standard deviations, and body mass indices were calculated. To find correlations within the groups, correlation analysis was used. To establish statistical significance between the groups, Student’s t-test was used. The results revealed that, among both boys and girls, athletes were statistically significantly faster than non-athletes; only in Illinois test, there was no statistically significant difference. In girls, there were statistically significant differences between athletes and non-athletes in weight, fat percentage, fat amount and body mass index. In boys, however, there were no statistically significant differences in the body build characteristics between athletes and non-athletes. Football players were better in agility tests compared to volleyball players. Football boys were statistically significantly taller and older, and, in most tests, they were also statistically significantly faster than volleyball boys. Volleyball girls were statistically significantly taller and weighed more, but, in all tests, football girls were statistically significantly faster than volleyball girls. In all groups, the fat-related indicators, like fat percentage, fat amount and body mass index, were in mutual correlation. According to the body mass index scale, 45 subjects were of normal weight, 6 were overweight, 1 was obese and 11 were underweight. The authors of the paper hold the view that, namely in this age group, the athletes of sports games should practice agility and be tested in it, as, according to literature, the development of agility slows down at the age of 16–17 years, and therefore, can be one of the obstacles for reaching the top in adult athletes.
Read moreEU Common Position on International Law and Cyberspace
The discussion on international law applicable to cyber operations has shifted from asking whether international law applies to cyberspace to how it applies. Recently the European Union declared in its renewed cybersecurity strategy the ambition to develop common EU position on the application of international law in cyberspace. As part of a broader vision in striving for leadership on standards, norms and regulatory frameworks in cyberspace, the joint communication underlined the need for taking a more proactive stance in the discussions at the United Nations and other relevant international fora. However, less than half of the European Union Member States have issued a public statementon the interpretation of international law in cyberspace and hence, reaching a consensus on the interpretation of relevant concepts of international law appears a challenge. This article provides an overview of the current status of EuropeanUnion Member States’ public statements on international law applicable to cyber operations, identifies the domains of international law where convergence of views can be observed and highlights the areas with notable differences.
Read moreData Quality Problem in AI-Based Network Intrusion Detection Systems Studies and a Solution Proposal
Network Intrusion Detection Systems (IDSs) have been used to increase the level of network security for many years. The main purpose of such systems is to detect and block malicious activity in the network traffic. Researchers have been improving the performance of IDS technology for decades by applying various machine-learning techniques. From the perspective of academia, obtaining a quality dataset (i.e. a sufficient amount of captured network packets that contain both malicious and normal traffic) to support machine learning approaches has always been a challenge. There are many datasets publicly available for research purposes, including NSL-KDD, KDDCUP 99, CICIDS 2017 and UNSWNB15. However, these datasets are becoming obsolete over time and may no longer be adequate or valid to model and validate IDSs against state-of-the-art attack techniques. As attack techniques are continuously evolving, datasets used to develop and test IDSs also need to be kept up to date. Proven performance of an IDS tested on old attack patterns does not necessarily mean it will perform well against new patterns. Moreover, existing datasets may lack certain data fields or attributes necessary to analyse some of the new attack techniques. In this paper, we argue that academia needs up-to-date high-quality datasets. We compare publicly available datasets and suggest a way to provide up-to-date high-quality datasets for researchers and the security industry. The proposed solution is to utilize the network traffic captured from the Locked Shields exercise, one of the world’s largest live-fire international cyber defence exercises held annually by the NATO CCDCOE. During this three-day exercise, red team members consisting of dozens of white hackers selected by the governments of over 20 participating countries attempt to infiltrate the networks of over 20 blue teams, who are tasked to defend a fictional country called Berylia. After the exercise, network packets captured from each blue team’s network are handed over to each team. However, the countries are not willing to disclose the packet capture (PCAP) files to the public since these files contain specific information that could reveal how a particular nation might react to certain types of cyberattacks. To overcome this problem, we propose to create a dedicated virtual team, capture all the traffic from this team’s network, and disclose it to the public so that academia can use it for unclassified research and studies. In this way, the organizers of Locked Shields can effectively contribute to the advancement of future artificial intelligence (AI) enabled security solutions by providing annual datasets of up-to-date attack patterns.
Read moreEstonian women’s national volleyball team’s success in 2019 European Championship final tournament
The aim of the article was to analyse the game success and tactics of the Estonian team in subgroup C of the 2019 European Championship final tournament in sets won and lost.
 The subjects were the players of the Estonian volleyball team in the final tournament of the European Championship in 2019. The paper analyses Estonia’s performance in five games of the European Championship: Hungary – Estonia, Croatia – Estonia, Romania – Estonia, the Netherlands – Estonia and Azerbaijan – Estonia. A total of 19 sets were analysed, four of which the Estonian national team won.
 As a result, it was concluded that the Estonian volleyball team had higher efficiency indicators in all the four technical elements in the sets they won than in the sets they lost. Ball reception and serve efficiency differed less in the sets won and lost than attacking and blocking efficiency. Thus, it can be concluded that sets were lost mainly because of attack and block, not serve and reception.
 The most efficient receiver (50%) in the Estonian women’s team was K. Nõlvak. The most efficient server (80%) was opposite spiker K. Moor. In attack, the most efficient player was outside hitter A. Ennok (28%). Estonia’s setter J. Mõnnakmäe was the most efficient in blocking (24%). L. Kullerkann also performed at a very good level among middle blockers and collected the greatest number of blocks in the tournament (57). K. Laak scored the greatest number of points in the championship (36 points).
Read moreFrankenstack: Real-time Cyberattack Detection and Feedback System for Technical Cyber Exercises
This paper describes a situation awareness framework, Frankenstack, that is the result of a multi-faceted endeavor to enhance the expertise of cybersecurity specialists by providing them with real-time feedback during cybersecurity exercises and verifying the performance and applicability of monitoring tools during those exercises. Frankenstack has been recently redeveloped to improve data collection and processing functions as well as cyberattack detection capability. This extensive R&D effort has combined various system and network security monitoring tools into a single cyberattack detection and exercise feedback framework.Although Frankenstack was specifically developed for the NATO CCD COE’s Crossed Swords exercise, the architecture provides a clear point of reference for others who are building such monitoring frameworks. Thus, the paper contains many technical descriptions to reduce the gap between theoretical research and practitioners seeking advice on how to implement such complex systems.
Read moreTRENDY URČOVÁNÍ ÚROVNĚ INFORMATICKÉHO MYŠLENÍ U ŽÁKŮ
SouÄasnĂ˝ celosvÄtovĂ˝ trend implementace rozvoje informatickĂŠho myĹĄlenĂ do kurikula pĹinĂĄĹĄĂ mimo jinĂŠ i diskusi urÄovĂĄnĂ rozvoje ĂşrovnÄ informatickĂŠho myĹĄlenĂ u ŞåkĹŻ. S ohledem na v tuzemsku vrcholĂcĂ revizi RVP v oblasti Informatiky a ICT podle Strategie vzdÄlĂĄvacĂ politiky ÄeskĂŠ republiky do roku 2020, je vĂ˝voj standardizovanĂ˝ch prostĹedkĹŻ a metod pro rozvoj a testovĂĄnĂ informatickĂŠho myĹĄlenĂ u ŞåkĹŻ zĂĄkladnĂch a stĹednĂch ĹĄkol jednĂm z nejaktuĂĄlnÄjĹĄĂch pedagogickĂ˝ch tĂŠmat. PĹĂspÄvek pĹedstavuje zĂĄkladnĂ moĹžnosti testovĂĄnĂ informatickĂŠho myĹĄlenĂ a diskutuje jejich pouĹžitĂ na ĹĄkolĂĄch v ÄeskĂŠ republice.
Read moreTowards Measuring Global DDoS Attack Capacity
In today's Internet, distributed denial-of-service (DDoS) attacks play an ever-increasing role and constitute a risk to any commercial, military or governmental entity that has a presence on the Internet or simply has an Internet connection. To address this threat on all levels, decision-makers have to rely on trustworthy information regarding attack capacity, sources, and the largest contributors. The lack of this information limits the ability of technicians, policymakers, and other relevant decision-makers to remediate the issue as efficiently as possible. This research introduces a methodology for measuring the properties of individual devices participating in such attacks. These properties include rate limiting, amplification factor, and speed, which allows the calculation of each device's actual contribution to the attack capacity. This methodology was implemented as a proof of concept for the NTP protocol and the results indicate that it has promising potential. Individual measurements aggregated together provide insights into particular abused protocols: all the protocols together could provide the global DDoS attack capacity.
Read moreEstonia And UNIFIL: The Benefits to a Small State of UN Peacekeeping
Abstract This article considers Estonia’s contribution, since May 2015, of an infantry company to the Finnish contingent of the Finnish/Irish battalion of the United Nations Interim Force in Lebanon. It is intended to provide a case study of a small European state’s involvement in UN peacekeeping in the ‘post- Afghanistan’ security environment. Drawing on interviews with Estonian officials and peacekeepers, it sets out the rationale for Estonia’s contribution and explores the degree to which participation has met the expectations of the Estonian defence leadership. It concludes that participation in UNIFIL has largely been a valuable policy, both politically and for the defence forces.
Read moreMutual Legal Assistance & Other Mechanisms for Accessing Extraterritorially Located Data
This article discusses the role of Mutual Legal Assistance (MLA) and other established mechanisms of international cooperation in the fight against cyber crime. The analysis is limited to mechanisms facilitating access to extraterritorially located data. After a brief account on the legal prerequisites of successful fight against cyber crime, the article proceeds to exploring both traditional as well as alternative cooperation mechanisms for transborder data access. Given the realistic assessment that the amount of digital evidence to be accessed extraterritorially will only increase with time, the article focuses on the difficulties in accessing data under the current MLA procedures. The article reiterates that States are in need for more time-effective measures for transborder data access. Unless the identified inefficiencies pertaining to MLA are addressed, the traditional focus on territoriality, and assuming the other State being the primary counterpart for carrying out investigative measures requiring transborder access to evidence, will continue to gradually shift to more operational mechanisms that do not necessarily require the prior authorisation of the State where the data is located.
Read more