AUTOMATED DEPLOYMENT OF VULNERABLE TRAINING ENVIRONMENTS USING THE LEAST-PRIVILEGE MODEL

Authors

  • T. Babych National University of Kyiv-Mohyla Academy image/svg+xml Author
  • M. Sashnova National University of Kyiv-Mohyla Academy image/svg+xml Author
  • O. Radziievska National University of Kyiv-Mohyla Academy image/svg+xml Author
  • D. Dyakonenko National University of Kyiv-Mohyla Academy image/svg+xml Author

DOI:

https://doi.org/10.17721/2519-481X/2026/90-04

Keywords:

cybersecurity, MITRE ATT&CK, cyber range, vulnerable environment, containerization, Docker, environment isolation, modeling

Abstract

The growing number and complexity of cyberattacks impose increasingly stringent requirements on the practical training of cybersecurity professionals. At the same time, traditional lecture-based instruction is, unfortunately, often unable to provide a sufficient level of applied skills. Training-oriented cyber ranges address this problem to a certain extent, but existing solutions rarely offer automated deployment of a separate, fully isolated environment for each participant. Moreover, they frequently fail to align training scenarios with formalized descriptions of adversary techniques. The main goal of our study was therefore to substantiate, design, and ultimately implement in software a platform capable of automated deployment of vulnerable testbeds that accurately reproduce documented techniques from the MITRE ATT&CK framework, within a controlled multi-user space, while ensuring complete isolation between users through containerization technologies.

A variety of methods were employed in the course of this work, including a systematic analysis of existing cyber ranges and vulnerable testbeds, as well as a thorough comparative analysis of isolation mechanisms at both the container and virtual machine levels. In addition, object-oriented software architecture design methods were applied, together with a carefully elaborated least-privilege model for container configuration. The platform is built on a multi-tier architecture (Nginx, Django/Daphne, PostgreSQL, Redis) with dynamic orchestration of Docker containers, managed through a dedicated application programming interface.

A platform was designed and implemented that automatically creates and, subsequently, destroys isolated vulnerable testbeds on demand. It is capable of mapping each testbed to specific MITRE ATT&CK techniques and, importantly, supports the addition of entirely new laboratory scenarios without requiring changes to its core. A security configuration for containers was proposed, based on the principle of dropping unnecessary privileges, while preserving the ability to selectively relax these restrictions in order to correctly reproduce certain techniques. A comparison of the chosen container-based approach with traditional virtualization convincingly demonstrated substantially shorter deployment times and significantly lower resource consumption.

Combining containerization, automated orchestration, and scenario integration directly with the MITRE ATT&CK framework enables the creation of a scalable and, most importantly, reproducible environment suitable for practical cybersecurity training. The practical value of the platform lies in the fact that it can be readily integrated both into the educational process of higher education institutions and into professional development systems for information security specialists.

Author Biographies

References

1. Yamin, M.M., Katt, B. and Gkioulos, V. (2020) 'Cyber ranges and security testbeds: Scenarios, functions, tools and architecture', Computers & Security, 88, 101636. Available at: https://doi.org/10.1016/j.cose.2019.101636

2. Vykopal, J., Ošlejšek, R., Čeleda, P., Vizváry, M. and Tovarňák, D. (2017) 'KYPO Cyber Range: Design and use cases', in Proceedings of the 12th International Conference on Software Technologies (ICSOFT), pp. 310–321. Available at: https://doi.org/10.5220/0006428203100321

3. Beuran, R., Tang, D., Pham, C., Chinen, K., Tan, Y. and Shinoda, Y. (2018) 'Integrated framework for hands-on cybersecurity training: CyTrONE', Computers & Security, 78, pp. 43–59. Available at: https://doi.org/10.1016/j.cose.2018.06.001

4. Al-Shaer, R., Spring, J.M. and Christou, E. (2020) 'Learning the associations of MITRE ATT&CK adversarial techniques', in 2020 IEEE Conference on Communications and Network Security (CNS), pp. 1–9. Available at: https://doi.org/10.1109/CNS48642.2020.9162207

5. Bernstein, D. (2014) 'Containers and cloud: From LXC to Docker to Kubernetes', IEEE Cloud Computing, 1(3), pp. 81–84. Available at: https://doi.org/10.1109/MCC.2014.51

6. Merkel, D. (2014) 'Docker: Lightweight Linux containers for consistent development and deployment', Linux Journal, 2014(239), p. 2.

7. Combe, T., Martin, A. and Di Pietro, R. (2016) 'To Docker or not to Docker: A security perspective', IEEE Cloud Computing, 3(5), pp. 54–62. Available at: https://doi.org/10.1109/MCC.2016.100

8. Sultan, S., Ahmad, I. and Dimitriou, T. (2019) 'Container security: Issues, challenges, and the road ahead', IEEE Access, 7, pp. 52976–52996. Available at: https://doi.org/10.1109/ACCESS.2019.2911732

9. Kavak, H., Padilla, J.J., Vernon-Bido, D., Diallo, S.Y., Gore, R. and Shetty, S. (2021) 'Simulation for cybersecurity: State of the art and future directions', Journal of Cybersecurity, 7(1), tyab005. Available at: https://doi.org/10.1093/cybsec/tyab005

10. MITRE (2024) MITRE ATT&CK®. Available at: https://attack.mitre.org/

11. MITRE (2023) Getting started with ATT&CK. Available at: https://attack.mitre.org/resources/

12. IBM (2024) What is the MITRE ATT&CK framework? Available at: https://www.ibm.com/think/topics/mitre-attack

13. VulnHub (2024) VulnHub. Available at: https://www.vulnhub.com/

14. Rapid7 (2024) Metasploitable 2 exploitability guide. Available at: https://docs.rapid7.com/metasploit/metasploitable-2/

15. TryHackMe (2024) TryHackMe. Available at: https://tryhackme.com/

16. Hack The Box (2024) Hack The Box. Available at: https://www.hackthebox.com/

17. Namespaces (7) (2023) Linux man-pages. Available at: https://man7.org/linux/man-pages/man7/namespaces.7.html

18. Docker (2024) Docker overview. Available at: https://docs.docker.com/get-started/overview/

19. Capabilities (7) (2023) Linux man-pages. Available at: https://man7.org/linux/man-pages/man7/capabilities.7.html

20. Docker (2024) Docker security. Available at: https://docs.docker.com/engine/security/

21. Django Software Foundation (2024) Django documentation (Version 5.1). Available at: https://docs.djangoproject.com/en/5.1/

22. Django Channels (2024) Django Channels documentation. Available at: https://channels.readthedocs.io/en/stable/

23. Docker SDK for Python (2024) Docker SDK for Python documentation. Available at: https://docker-py.readthedocs.io/en/stable/

24. PostgreSQL Global Development Group (2024) PostgreSQL documentation. Available at: https://www.postgresql.org/docs/

25. Nginx (2024) Module ngx_http_auth_request_module. Available at: https://nginx.org/en/docs/http/ngx_http_auth_request_module.html

26. htmx (2024) htmx documentation. Available at: https://htmx.org/docs/

27. Alpine.js (2024) Alpine.js documentation. Available at: https://alpinejs.dev/

Published

2026-03-20

Issue

Section

INFORMATION TECHNOLOGIES