| |
Additional
Sponsors |
| |
 |
| |
 |
Rules
Note: these rules are identical to those for the national contest, except
where noted.
- Student Teams
- Each
team will consist of up to eight (8) members. Each team member must be
a full-time student of the institution the team is representing and
must not be currently employed in the IT industry (security operations,
network administrator, system administrator, programmer, network
operations, help desk, etc.) as a salaried employee or as an hourly
employee for more than 20 hours per week. Team members must qualify as
full-time students as defined by the institution they are attending -
typically this means the team member must be enrolled in 12 or more
semester credit hours for undergraduates and 9 or more semester credit
hours for graduate students during the semester the competition is
held.
- Each team may have no more than two (2) graduate students as team members.
- Each
team may have one or two advisors present at the competition – these may be
faculty/staff members of the institution or a team sponsor. The advisors
may not assist or advise the team during the competition.
NOTE: The national rules only allow one
team advisor. If your team has more than one advisor at the NECCDC, you
will have to trim this to a single advisor if you win and proceed to
the national CCDC. - All team members will wear badges identifying team affiliation at all times during competition hours. Badges will be provided.
- Each
team will designate a Team Captain for the duration of the competition
to act as the team liaison between the competition staff and the teams
before and during the competition.
- If
the member of a qualifying team is unable to attend the national
competition, that team may substitute another student in their place
provided the substitute meets all stated eligibility requirements.
- Competition Systems
- Each team will start the competition with identically configured systems.
- Teams may not remove any computer, printer, or networking device from the competition area.
- Teams
will be provided the overall system architecture, network
configuration, and initial set-up prior to the event to permit planning
but no detailed information, such as patch levels and application
versions, will be provided ahead of time.
- Teams
should not assume any competition system is properly functioning or
secure; they are assuming recently hired administrator positions and
are assuming responsibility for each of their systems.
- All teams will be connected to a central router and scoring system.
- Throughout
the competition, Operations and White Team members will occasionally
need access to a team’s system(s) for scoring, troubleshooting, etc.
Teams must allow Operations and White Team members access when
requested.
- Teams must not connect any outside devices or peripherals to the competition network.
- Network
traffic generators will be used throughout the competition to generate
traffic on each team’s network. Traffic generators will generate
typical user traffic as well as suspicious or potentially malicious
traffic from random source IP addresses throughout the competition.
- Teams
must maintain specific services on the “public” IP addresses assigned
to their team – for example if a team’s web service is provided to the
“world” on 10.10.10.2, the web service must remain available at that IP
address throughout the competition. Moving services from one public IP
to another is not permitted, however teams are free to NAT addresses
inside their team networks.
- Teams are not permitted to alter the system names of their assigned systems.
- Teams are not permitted to remove or alter any labels/stickers that are present on their assigned systems.
- Teams
will have access to a “Restore from Backup” capability that will reset
any system to its initial starting configuration. This service will be
performed by the Operations Team and will cost the team 50 points per
system recovered.
- Each
team will be provided with a set of install disks for the operating
systems and major applications used in the competition network. These
may be used to reload systems, add/remove functionality, reinstall, etc.
- Systems
designated as “user workstations” are to be treated as user
workstations and may not be re-tasked for any other purpose by teams.
They must remain user workstations throughout the entire competition
unless otherwise directed by an Operations or White Team member or
indicated through competition injects. Teams may not change the
operating system on user workstations but are free to patch and secure
user workstations.
- Teams
may not modify the hardware configurations of competition systems.
Teams must not open the case of any server, printer, PC, monitor, KVM,
router, switch, firewall, or any other piece of equipment used during
the competition. All hardware related questions and issues should be
referred to the White Team.
- In
addition to user workstations each network will have one “admin
workstation”. Teams are free to modify the operating system and load
tools, scripts, or applications on this workstation; however, this
administrative workstation may not be used to provide critical services
such as SMTP, FTP, HTTP, etc.
- Servers and networking equipment may be re-tasked or reconfigured as needed.
- Competition Play
- The
competition will run over a three day period (Friday Fe bruary 29th, 2008 to
Sunday March 2nd, 2008). Registration will occur on Friday and a
mandatory meeting for all team members and faculty sponsors will be
held prior to the start of the competition.
- During
the competition team members are forbidden from entering or attempting
to enter another team’s competition workspace or room.
- All
requests for items such as software, score checks, system resets, and
service requests must be submitted on paper (typed and printed) to the
Operations Team. Requests must clearly show the requesting team,
action or item requested, and date/time requested.
- Teams
must compete without “outside assistance” from non-team members which
includes team advisors and sponsors. All private communications (calls,
emails, chat, directed emails, forum postings, conversations, requests
for assistance, etc) with non-team members including team sponsors that
would help the team gain an unfair advantage are not allowed and are
grounds for disqualification.
- No
PDAs, memory sticks, CDROMs, electronic media, or other similar
electronic devices are allowed in the room during the competition
unless specifically authorized by the Operations or White Team in
advance. All cellular calls must be made and received outside of team
rooms. Any violation of these rules will result in disqualification of the team member and a 200 point penalty assigned to the appropriate team.
- Teams
may not bring any computer, tablets, PDA, or wireless device into the
competition area. MP3 players with headphones will be allowed in the
competition area provided they are not connected to any system or
computer in the competition area.
- Printed
reference materials (books, magazines, checklists) are permitted in
competition areas and teams may bring printed reference materials to
the competition.
- Team
sponsors and observers are not competitors and are prohibited from
directly assisting any competitor through direct advice, “suggestions”,
or hands-on assistance. Any team sponsor or observers found assisting
a team will be asked to leave the competition area for the duration of
the competition and a 200 point penalty will be assessed against the
team.
- An
unbiased Red Team will probe, scan, and attempt to penetrate or disrupt
each team’s daily operations throughout the competition.
- Team
members will not initiate any contact with members of the Red Team
during the hours of live competition. Team members are free to talk to
Red Team members, Operations staff, White Team members, other
competitors, etc. outside of competition hours.
- On
occasion, Operations Team members may escort individuals (VIPs, press,
etc) through the competition area including team rooms.
- Only Operations Team members will be allowed in competition areas outside of competition hours.
- All
individuals involved with the competition will be issued badges which
must be worn at all times individuals are in the competition area.
- Teams
are permitted to replace applications and services provided they
continue to provide the same content, data, and functionality of the
original service. For example, one mail service may be replaced with
another provided the new service still supports standard SMTP commands,
supports the same user set, and preserves any pre-existing messages
users may have stored in the original service. Failure to preserve
pre-existing data during a service migration will result in a 50 point
penalty for each user and service affected.
- Teams
are free to examine their own systems but no offensive activity against
other teams, the Operations Team, the White Team, or the Red Team will
be tolerated. This includes port scans, unauthorized connection
attempts, vulnerability scans, etc. Any team performing offensive
activity against other teams, the Operations Team, the White Team, the
Red Team, or any global asset will be immediately disqualified
from the competition. If there are any questions or concerns during
the competition about whether or not specific actions can be considered
offensive in nature contact the Operations Team before performing those
actions.
- Each
team may change passwords for administrator level and user level
accounts. Any password changes to user accounts must be provided to
the White Team with a minimum of 15 minutes advance warning prior to
the changes being implemented (unless the password changes are part of
a competition tasking). Failure to notify the White Team of user level
password changes can result in service check failures. Teams are
required to provide modified passwords in the electronic format
specified. Please note that the White Team will not error check the
provided password changes – they will simply upload the provided
changes.
- Teams
are allowed to use active response mechanisms such as TCP resets when
responding to suspicious/malicious activity. Any active mechanisms
that interfere with the functionality of the scoring engine or manual
scoring checks are exclusively the responsibility of the teams. Any
firewall rule, IDS, IPS, or defensive action that interferes with the
functionality of the scoring engine or manual scoring checks are
exclusively the responsibility of the teams.
- The
White Team will provide a mechanism to show teams the official status
of their critical services during the last scored service check.
- Scoring
- Scoring
will be based on keeping required services up, controlling/preventing
un-authorized access, and completing business tasks that will be
provided throughout the competition. Teams accumulate points by
successfully completing injects and maintaining services. Teams lose
points by violating service level agreements, usage of recovery
services, and successful penetrations by the Red Team.
- Scores
will be maintained by the White Team, but will not be shared until the
end of the competition. There will be no running totals provided
during the competition. Team standings will be provided at the
beginning of day two and three but without specific scores.
- Any
team action that interrupts the scoring system is exclusively the fault
of that team and will result in a lower score. Should any question
arise about specific scripts or how they are functioning, the Team
Captain should immediately contact the competition officials to address
the issue.
- Any team that tampers with or interferes with the scoring or operations of another team’s systems will be disqualified.
- Teams
are strongly encouraged to provide incident reports for each Red Team
incident they detect. Incident reports can be completed as needed
throughout the competition and presented to the White Team for
collection. Incident reports must contain a description of what
occurred (including source and destination IP addresses, timelines of
activity, passwords cracked, etc), a discussion of what was affected,
and a remediation plan. A thorough incident report that correctly
identifies a successful Red Team attack will reduce the Red Team
penalty by up to 50 percent – no partial points will be given for
incomplete or vague incident reports.
- Internet Usage
- Competition
systems will have direct access to the Internet for the purposes of
research and downloading patches. Internet activity will be monitored
and any team member caught viewing inappropriate or unauthorized
content will be immediately disqualified from
the competition. This includes direct contact with outside sources
through AIM/chat/email or any other non-public services. For the
purposes of this competition inappropriate content includes pornography
or explicit materials, pirated media files or software, sites
containing key generators and pirated software, etc. If there are any
questions or concerns during the competition about whether or not
specific materials are unauthorized contact the Operations Team
immediately.
- Internet
resources such as FAQs, how-to’s, existing forums and responses, and
company websites are completely valid for competition use provided
there is no fee required to access those resources and access to those
resources has not been granted based on a previous purchase or fee.
Only resources that could reasonably be available to all teams are
permitted. For example, accessing Cisco resources through a CCO account
would not be permitted but searching a public Cisco support forum would
be permitted.
- Teams
may not use any external, private electronic staging area or FTP site
for patches, software, etc. during the competition. All Internet
resources used during the competition must be freely available to all
other teams.
- Public
sites such as Security Focus or Packetstorm are acceptable. Only public
resources that every team could access if they chose to are permitted.
- No peer to peer or distributed file sharing clients or servers are permitted on competition networks.
- All
network activity that takes place on the competition network may be
logged and is subject to release. Competition officials are not
responsible for the security of any personal information, including
login credentials that competitors place on the competition network.
- Questions and Dispute
- Team
captains are encouraged to work with the contest staff to resolve any
questions or disputes regarding the rules of the competition or scoring
methods before the competition begins.
- Protests
by any team will be presented by the Team Captain to the competition
officials as soon as possible. The competition officials will be the
final arbitrators for any protests or questions arising before, during,
or after the competition and rulings by the competition officials are
final.
- In
the event of an individual disqualification, that team member must
leave the competition area immediately upon notification of
disqualification and must not re-enter the competition area at any
time. Disqualified individuals are also ineligible for individual
awards or team trophies.
- In
the event of a team disqualification, the entire team must leave the
competition area immediately upon notice of disqualification and is
ineligible for any individual or team award.
|