Rochester Hosts Ethical Hacking Contest

College teams will face off in the second annual Collegiate Penetration Testing Competition, taking place this week at Rochester Institute of Technology (RIT) in New York. Teams of three to six members from 10 institutions will test their "offensive" hacking skills against a mock physical infrastructure to vie for cash prizes.

The goal is to gain access to the network, escalate that privilege to gain additional access, track down personally identifiable information or other valuable data, assess vulnerabilities and report back to the "client" about how to fix the systems. The event is structured to mimic how penetration testing consulting happens in the real world. After a day of penetration testing, the teams will make presentations to the judges on their findings and offer suggestions for mitigating risk.

"This mock company holds confidential data that would have a significant impact if breached," said Bill Stackpole, professor of computing security at RIT and director of the competition. "But this isn't just happening in a simulation. Real companies are facing cybersecurity threats every day and our students need to learn how to combat that."

"It's very important to have a penetrating testing contest like this because it teaches the graduates or soon-to-be graduates a new skill," added Bob Kalka, vice president of the IBM security business unit and an alumnus of RIT, in a video about last year's event. "It's not just, how do you keep the hackers out; it's how [do] you proactively figure out how they're getting in. So having a competition that [lets] students learn those techniques allows them to mentally understand the bigger picture of how to provide effective security overall."

IBM is a sponsor of the event, alongside the National Security Agency, IEEE, Amazon, Google and Facebook.

Participants will also have the chance to meet security experts and hand out resumes.

Besides Rochester, participants in the competition will include the University of Central Florida, City College of San Francisco and Tennessee Technological U, among others.

Stackpole noted that more teams wanted to participate than the competition could accommodate. "We would like to see this grow from a single event into a national tournament, with four or five regional competitions feeding to the championships at RIT."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • landscape photo with an AI rubber stamp on top

    California AI Watermarking Bill Garners OpenAI Support

    ChatGPT creator OpenAI is backing a California bill that would require tech companies to label AI-generated content in the form of a digital "watermark." The proposed legislation, known as the "California Digital Content Provenance Standards" (AB 3211), aims to ensure transparency in digital media by identifying content created through artificial intelligence. This requirement would apply to a broad range of AI-generated material, from harmless memes to deepfakes that could be used to spread misinformation about political candidates.

  • new unified Microsoft Teams app

    New Unified Teams App Consolidates Work, Personal, and Education Accounts

    Microsoft has announced that the unified Teams app is now available for Windows 11, Windows 10 and macOS users.

  • wind turbine and solar panels with glowing accents on the left and a digital shield surrounded by binary code on the right

    Educause Horizon Report: Sustainability Pressures Lead to Increased Cybersecurity Risks

    Educause recently released the 2024 Cybersecurity and Privacy Edition of its Horizon Report series, forecasting key trends, technologies, and practices shaping the future of cybersecurity and privacy in higher education.

  • network of transparent cloud icons, each containing a security symbol like a lock or shield

    Okta, OpenID Foundation Propose New Identity Security Standard

    Okta and the OpenID Foundation have announced the formation of the IPSIE Working Group — with the acronym standing for Interoperability Profiling for Secure Identity in the Enterprise — dedicated to a new identity security standard for Software-as-a-Service (SaaS) applications.