| dc.contributor.advisor | Kotzanikolaou, Panagiotis | |
| dc.contributor.advisor | Κοτζανικολάου, Παναγιώτης | |
| dc.contributor.author | Tassis, Panagiotis | |
| dc.contributor.author | Tάσσης, Παναγιώτης | |
| dc.date.accessioned | 2026-09-04T06:22:58Z | |
| dc.date.available | 2026-09-04T06:22:58Z | |
| dc.date.issued | 2026-07 | |
| dc.identifier.uri | https://dione.lib.unipi.gr/xmlui/handle/unipi/19714 | |
| dc.description.abstract | Καθώς η ψηφιοποίηση επεκτείνεται σε κάθε κλάδο, η συχνότητα και ο όγκος των κυβερνοεπιθέσεων αυξάνονται με ρυθμούς που δεν έχουν παρατηρηθεί ποτέ στο παρελθόν. Η συνεχιζόμενη έλλειψη εξειδικευμένων επαγγελματιών στον τομέα της κυβερνοασφάλειας, σε συνδυασμό με τη διαρκή εξέλιξη των μεθόδων επίθεσης, καταδεικνύουν επιτακτική την ανάγκη για εκπαιδευτικές υποδομές που να προσομοιώνουν ρεαλιστικά κυβερνοπεριβάλλοντα. Παραδοσιακές τεχνικές, όπως η πρακτική εξάσκηση σε εργαστηριακό περιβάλλον, οι διαγωνισμοί Capture the Flag (CTF) και η εκπαίδευση μέσω εικονικών μηχανών, συμβάλλουν σημαντικά στην απόκτηση δεξιοτήτων. Ωστόσο, αυτοί οι πόροι καθίστανται γρήγορα ξεπερασμένοι, καθώς νέες απειλές εμφανίζονται καθημερινά.
Τα Cyber Ranges προσφέρουν μια ολοκληρωμένη λύση, προσομοιώνοντας δίκτυα, συστήματα και εφαρμογές σε ρεαλιστικά αλλά ελεγχόμενα περιβάλλοντα. Παρέχουν δυνατότητες κατάρτισης και δοκιμών στον τομέα της κυβερνοασφάλειας, επιτρέποντας την αξιολόγηση νέων απειλών σε λειτουργικά περιβάλλοντα, χωρίς τον κίνδυνο διακοπής λειτουργίας ή διαρροής ευαίσθητων δεδομένων.
Η παρούσα διπλωματική εργασία προτείνει τόσο μια μεθοδολογία όσο και μια υλοποίηση για την κατασκευή ενός Cyber Range μέσω μιας εικονικής υποδομής. Η προτεινόμενη προσέγγιση περιλαμβάνει:
1. Τον σχεδιασμό και τη μεθοδολογία για την κατασκευή ενός επεκτάσιμου, αυτοματοποιημένου περιβάλλοντος Cyber Range, με ανάλυση της υποδομής, των τεχνολογιών και των διαδικασιών που χρησιμοποιούνται για τη μοντελοποίηση ρεαλιστικών σεναρίων επιθέσεων και κρίσιμων υπηρεσιών.
2. Την πρακτική υλοποίηση του περιβάλλοντος, με έμφαση στην ανάπτυξη του Ludus Cyber Range, την αρχιτεκτονική του συστήματος, τα εργαλεία αυτοματοποίησης και τη διαμόρφωση της τοπολογίας που προσομοιώνει ένα επιχειρησιακό δίκτυο.
3. Την εκτέλεση και αξιολόγηση ενός Full-Chain Attack Lifecycle μέσω εξομοίωσης αντιπάλου (adversary emulation) και επαλήθευσης ανίχνευσης (detection validation), με στόχο την αποτίμηση της λειτουργικότητας, της αξιοπιστίας και της επεκτασιμότητας του Cyber Range στην προσομοίωση ρεαλιστικών κυβερνοεπιθέσεων.
Με την επίδειξη αυτών των διαδικασιών, η εργασία προτείνει μια δομημένη μεθοδολογία που απλοποιεί την ανάπτυξη ρεαλιστικών Cyber Ranges. Η προσέγγιση αυτή μπορεί να υιοθετηθεί από οργανισμούς τόσο του δημόσιου όσο και του ιδιωτικού τομέα, προκειμένου να κατασκευάζουν Cyber Ranges με την πραγματική τους υποδομή, να τα δοκιμάζουν τακτικά απέναντι σε νέες απειλές και να επαληθεύουν τη λειτουργικότητα των μηχανισμών ανίχνευσης που διαθέτουν. | el |
| dc.format.extent | 115 | el |
| dc.language.iso | en | el |
| dc.publisher | Πανεπιστήμιο Πειραιώς | el |
| dc.rights | Αναφορά Δημιουργού-Μη Εμπορική Χρήση-Όχι Παράγωγα Έργα 3.0 Ελλάδα | * |
| dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/3.0/gr/ | * |
| dc.title | Designing a cybersecurity training environment (cyber range) : a scalable approach for real-world defense simulations and practices | el |
| dc.title.alternative | Σχεδιασμός περιβάλλοντος εκπαίδευσης κυβερνοασφάλειας (cyber range) : μία κλιμακούμενη προσέγγιση για την ανάπτυξη ρεαλιστικών προσομοιώσεων και πρακτικών άμυνας | el |
| dc.type | Master Thesis | el |
| dc.contributor.department | Σχολή Τεχνολογιών Πληροφορικής και Επικοινωνιών. Τμήμα Πληροφορικής | el |
| dc.description.abstractEN | As digitalization extends to every industry, the frequency and volume of cyber-attacks are increasing at a rate never experienced before. Ongoing shortage of cybersecurity professionals in combination with constantly evolving threat vectors illustrates the urgent need for state-of-the-art training facilities that emulate true-to-life cyber environments. It is a conventional technique such as hands-on lab practice, prepared hacking exercises, Capture the Flag (CTF) contests, and practice on virtual machines that add up to skill acquisition. These resources rapidly become obsolete as there are fresh threats emerging every day.
Cyber ranges provide a more dynamic and integrated answer by simulating networks, systems, and apps in realistic but controlled settings. They provide scalable cybersecurity training, education, and testing through the power of testing the effects of emerging threats on their updated clone of their operating environment without risking downtime or leaking sensitive data. Such facilities allow the world of cybersecurity to keep pace with the accelerated development of disruptive technologies and the increased interconnection of digital systems.
This thesis proposes both a methodology and an implementation for constructing a scalable cyber range through a virtual infrastructure. The proposed approach includes:
1. The design approach for constructing a scalable, automated and replicable cyber range environment, outlining the underlying infrastructure, technologies, procedures used to model realistic attack scenarios essential services.
2. Details of the practical realization of this environment, focusing on the deployment of the Ludus Cyber Range, system architecture, automation tools, and the configuration of a segmented enterprise-like topology.
3. Execution and evaluation of a Full-Chain Attack Lifecycle through adversary emulation and detection validation, assessing the cyber range’s functionality, reliability, and scalability in simulating realistic cyber incidents.
Through such demonstration of a series of procedures, a methodology is presented in this thesis that makes it easy to develop realistic cyber ranges. This methodology can be applied in organizations of either the private or public sectors to build cyber ranges based on their real infrastructure and keep testing them against threats as well as ensuring the reliability of detection capabilities. | el |
| dc.contributor.master | Κυβερνοασφάλεια και Επιστήμη Δεδομένων | el |
| dc.subject.keyword | Cyber-threats | el |
| dc.subject.keyword | Cyber-security | el |
| dc.subject.keyword | Simulation platforms | el |
| dc.subject.keyword | Risk analysis | el |
| dc.subject.keyword | Threat forecasting | el |
| dc.subject.keyword | Cyber range | el |
| dc.subject.keyword | Information security | el |
| dc.subject.keyword | Testbed | el |
| dc.subject.keyword | Cyber exercises | el |
| dc.subject.keyword | Training | el |
| dc.date.defense | 2026-07-23 | |