Virtual Air Gap for Secure Cyber Range Console Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in controlling access to cyber range virtual environments while maintaining internal network security, as individuals with access to these environments may pose a threat to network security, making it difficult to balance sufficient access with utmost security measures.
Innovation Solution
A system comprising a user device, a secure console host platform, and a virtual air gap, where user authentication occurs in the virtual air gap, physically separate from the user device and cyber-range host platform, with a broker authenticating and authorizing connections between the secure console host platform and the cyber-range host platform, ensuring secure access through multiple firewalls and a virtual kill switch to prevent unauthorized access and malware spread.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If individuals are granted access to the cyber range virtual environment, then sufficient cyber range access is enabled for simulating cyber-attacks and testing recovery techniques, but internal network security is compromised as these individuals may pose a threat to network security
Solution Approach 1:
The system divides the network into distinct segments: the internal network, the cyber range network, and a buffer zone. By segmenting the network infrastructure, users can access the cyber range while being physically isolated from the internal network, thus enabling cyber range operations without compromising internal network security
Solution Approach 2:
A buffer zone is introduced as an intermediary between the internal network and the cyber range network. This buffer zone contains authentication services and acts as a mediator that allows secure access to the cyber range while preventing direct access to the internal network, thereby resolving the security conflict
2Reliability
If a physical air gap is implemented to isolate the cyber range from the internal network, then network security is enhanced, but access control and authentication become more complex
Solution Approach 1:
Authentication services are placed within the buffer zone, which acts as an intermediary that bridges the physical air gap. This allows authentication to occur without requiring physical network connectivity between the internal network and cyber range, maintaining security while simplifying access control
Solution Approach 2:
The system transitions from requiring physical network connectivity for authentication to using wireless authentication mechanisms. By changing the dimension of communication (from wired to wireless), the system maintains the physical air gap while enabling seamless authentication processes
3Object-affected harmful factors
If the cyber range host platform is physically separated from the internal network, then malware spread is prevented, but console access control becomes more difficult
Solution Approach 1:
The buffer zone serves as an intermediary that enables console access control without requiring direct physical connectivity. Authentication and authorization services in the buffer zone manage console access while the physical separation prevents malware spread, resolving the contradiction between security and operational ease
Data Source
AI summary
Aspects of the disclosure relate to processing systems that generate a virtual air gap to facilitate improved techniques for establishing console access to a cyber range virtual environment. The computing platform may receive a request to generate a virtual air gap to facilitate brokering of a connection between a secure console host platform and a cyber range host platform. The computing platform may generate the virtual air gap, which may include a built-in kill switch. The computing platform may implement the virtual air gap, which may be configured to receive requests to establish a connection between the secure console host platform and the cyber range host platform and to grant the secure console host platform access to a broker. The broker may establish the connection, and the computing platform may terminate the connection in response to activation of the built-in kill switch.


