Golfing with Dragons: Building Secure Environments for CTFs
• Presentation
This session was presented by Jared Stroud and Dan Szafran of MITRE at DevSecOps Days Pittsburgh, held virtually May 11, 2023.
Publisher
Software Engineering Institute
Topic or Tag
Watch
Abstract
Capture-the-flag events remain one of the most popular ways to learn new skills in the information security field, but how do you securely deploy and monitor a competition that is designed to be hacked?
This talk will demonstrate how running CTF events are an exercise in applied DevSecOps practices. From threat modeling the attack surface to building hardened containers and monitoring resource utilization, we will cover how to approach running competitions that are meant to be hacked while maintaining the security of your core infrastructure and ensuring competitors enjoy the competition.
Part of a Collection
DevSecOps Days Pittsburgh 2023