CTF: Cops and Robbers

Bachelor seminar · HPI

About the course

Bachelor project seminar (4 SWS, 6 ECTS, taught in English). The information below is from the most recent run in summer semester 2022.

This experimental project seminar is about learning and training with the advanced techniques of practical system and network security. Two teams (each with about 5–6 members) challenge each other and the tutoring team within three challenges, with changing roles either as attackers or defenders of a target IT system. For each challenge, the teams have to prepare their arms: setting up a secure system (under given constraints) for the defenders, choosing and testing recon and penetration tools for the attackers. After preparation, the teams hold a supervised Capture-the-Flag live challenge.

During the whole seminar there is a meta-challenge, as each team has to provide the tutors with a wiki that contains all information about the team’s progress. Besides the challenges, each participant selects a security-relevant topic, does research on it (reading and testing), and gives a short presentation (15–20 minutes) during the seminar.

Topics for the challenges:

  1. System and network security
  2. Web and service/application security
  3. Managing large environments (a combination of the first two topics in a larger environment)

Important notice

We are not guiding you for hacking, and participation in this seminar is not an excuse for any kind of malicious action towards unauthorized resources over the Internet. You are not allowed to attack any resources other than the ones (servers, VMs, …) you receive from the tutors during the seminar, and you are required to check with the tutors before any action.

Format

Students are divided into two groups. For the first two challenges, each group is either the red (attackers) or the blue (defenders) team. The blue team prepares a network scenario for the red team. After scenario preparation, the red team is allowed to attack the scenario for several hours in a live hacking session, during which the blue team’s task is to surveil the red team. Both teams present their findings a few days later.

After the first two challenges, a third challenge with an even more advanced scenario covers additional topics. For documentation purposes, each team writes a report about this challenge.

During the semester, each student prepares one short individual introduction about attacking and defending techniques that might be used in the scenarios later on. These presentations are held before the challenge preparations start. Possible topics:

  • Password security and new authentication methods
  • Security of mobile operating systems and apps
  • Security of the social web
  • Web security: SSL/TLS, web application firewalls (WAF), …
  • Email security: signature, encryption, spamming, phishing, …
  • IoT security: home automation, vehicles, …
  • Virtualization and cloud security
  • Switches, routers, gateways and firewalls
  • Intrusion detection (IDS/IPS)
  • SSH tunneling and virtual private networks (VPN)
  • IPsec, IPv6 and the relevant security issues
  • Network scanning and monitoring
  • Complex attacks and APTs
  • SIEM and security analytics
  • Attack categories and vulnerability modeling

Requirements

Participants are expected to have successfully finished the lectures/seminars:

  • Internet- und WWW-Technologien
  • Internet Security – Weaknesses and Targets

Additional fields of knowledge that might help (but are not required):

  • Networking technologies (TCP/IP, switches, VLANs, …)
  • Server administration (Linux, SSH, hardware management, …)
  • Operating systems (management, internals, …)
  • Monitoring and logging techniques
  • Experience with virtual machine monitors

Please keep in mind that this seminar is highly dependent on team effort.

Literature

Grading

Overview of all grade-relevant parts (subject to change):

  • Wiki (log of your activities): 15%
    • Accuracy of your activity log
    • Uptime
  • Challenge one: 20%
    • Achievements (red team)
    • Presentation
    • Preparation (blue team)
  • Challenge two: 20%
    • Achievements (red team)
    • Presentation
    • Preparation (blue team)
  • Individual introduction/presentation: 15%
  • Challenge three: 30%
    • Achievements
    • Report (documentation in your wiki in PDF format)

Bonus points are awarded for additional activities leading to information disclosure of the other team. To pass the course, you have to attend all presentation sessions as well as all challenge sessions.

Schedule

The seminar starts with an introductory session at the beginning of the semester. During the semester, participants prepare and give their individual presentations. After the lecture period, the three challenges are held as a block seminar; expect to work full time during the challenge preparation phases.

Format

  • Bachelor seminar

Institution

  • HPI

Semesters

All courses