45 Vulnerability Discoverability Timelines from the 2019 Collegiate Penetration Testing Competition
收藏资源简介:
<em><strong>Description</strong></em> This is a collection of manually curated timelines from the 2019 Collegiate Penetration Testing Competition (CPTC). Collection and annotation are described in detail in this publication: Benjamin S. Meyers, Sultan Fahad Almassari, Brandon N. Keller, and Andrew Meneely. Examining Penetration Tester Behavior in the Collegiate Penetration Testing Competition. Forthcoming at Transactions on Software Engineering and Methodology. https://dl.acm.org/doi/10.1145/3514040 <em><strong>Included Files</strong></em> <strong><em>2019_cptc_timelines.csv</em>:</strong> Completed timelines for ten teams from the 2019 CPTC nationals competition. <strong><em>2019_cptc_timeline_columns.csv</em>:</strong> Descriptions of the columns in <strong><em>2019_cptc_</em></strong><em><strong>timelines.csv</strong></em>. <strong><em>2019_cptc_vulnerabilities.csv</em>:</strong> Brief vulnerability descriptions and CWE mappings. <em><strong>Other Resources</strong></em> Complete Splunk log data dumps are available here. These must be ingested and viewed with a Splunk instance. To request access to the CPTC team reports, please contact Brock Wagehoft (email). <em><strong>Contact</strong></em> Please contact Benjamin S. Meyers (email) with questions about this data and its collection. <em><strong>Acknowledgments</strong></em> Collection of this data has been sponsored in part by the National Science Foundation grant 1922169, and by a Department of Defense DARPA SBIR program (grant 140D63-19-C-0018).



