English

Cyber-Deception and Attribution in Capture-the-Flag Exercises

Cryptography and Security 2015-07-08 v1

Abstract

Attributing the culprit of a cyber-attack is widely considered one of the major technical and policy challenges of cyber-security. The lack of ground truth for an individual responsible for a given attack has limited previous studies. Here, we overcome this limitation by leveraging DEFCON capture-the-flag (CTF) exercise data where the actual ground-truth is known. In this work, we use various classification techniques to identify the culprit in a cyberattack and find that deceptive activities account for the majority of misclassified samples. We also explore several heuristics to alleviate some of the misclassification caused by deception.

Keywords

Cite

@article{arxiv.1507.01922,
  title  = {Cyber-Deception and Attribution in Capture-the-Flag Exercises},
  author = {Eric Nunes and Nimish Kulkarni and Paulo Shakarian and Andrew Ruef and Jay Little},
  journal= {arXiv preprint arXiv:1507.01922},
  year   = {2015}
}

Comments

4 pages Short name accepted to FOSINT-SI 2015

R2 v1 2026-06-22T10:07:31.757Z