COMPREHENSIVE CYBERLABORATORY FOR PENETRATION TESTING AND SECURITY LOGS ANALYSIS
DOI:
https://doi.org/10.31673/2409-7292.2026.024917Abstract
The article discusses the concept and practical implementation of a comprehensive cyber laboratory for penetration
testing and security log analysis. The relevance of the study is due to the growing number of cyber incidents in the world,
the shortage of qualified specialists and the need for integrated educational and research environments that allow for the
safe simulation of modern cyberattacks. The paper analyzes modern approaches to building cybersecurity training
environments, in particular based on virtualization, containerization (Docker) and log processing stacks (ELK, Zeek). The
proposed laboratory architecture is implemented according to the principle of a microservice model, which ensures
scalability, flexibility and isolation of components. The system consists of separate layers: frontend (React + TypeScript),
backend (Node.js + Express), attack simulation layer (Kali Linux, Metasploit, Hydra), target environment (DVWA,
MySQL, Vulnerable APIs) and monitoring layer (Zeek, Filebeat, ELK). The article describes the implemented
cyberattack scenarios – SQL Injection, XSS, CSRF, DoS and Brute Force – as well as the methodology for collecting,
transmitting and analyzing logs in real time. The experiments conducted confirmed the technical capabilities of the
platform: the average system throughput exceeds 50,000 events per second, the processing delay does not exceed 100 ms,
and the accuracy of attack detection is over 95% with a false positive rate of less than 5%. The practical value of the work
lies in the creation of a universal educational and research platform that can be used in higher education institutions,
incident response centers (SOC) and for corporate cybersecurity training. The proposed solution allows you to
simultaneously reproduce realistic attack scenarios, collect large amounts of data for research and train specialists to
respond to real incidents in a controlled environment.
Keywords: cyber lab, artificial intelligence, machine learning, cybersecurity, log analysis, global threats
References
1. Про основні засади забезпечення кібербезпеки України : Закон України від 05.10.2017 р. № 2163-VIII.
[Електронний ресурс]. Режим доступу: https://zakon.rada.gov.ua/laws/show/2163-19.
2. Trellix. The CyberThreat Report: November 2024 [Electronic resource]. 2024. Mode of access:
https://www.trellix.com/advanced-research-center/threat-reports/.
3. Cisco. 2024 Cisco Cybersecurity Readiness Index [Electronic resource]. 2024. Mode of access:
https://www.cisco.com/c/m/en_us/products/security/cybersecurity-readiness-index.html.
4. ENISA. ENISA Threat Landscape 2024 [Electronic resource] / European Union Agency for Cybersecurity.
2024. Mode of access: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024.
5. ISC2. Cybersecurity Workforce Study 2024: Is the Profession Resilient Enough? [Electronic resource]. 2024.
Mode of access: https://www.isc2.org/research.
6. NIST. Workforce Framework for Cybersecurity (NICE Framework) (NIST SP 800-181r1) [Electronic
resource] / National Institute of Standards and Technology. 2020. DOI: 10.6028/NIST.SP.800-181r1.
7. Gupta K. K. A Comparative Study of Big Data Frameworks for Security Log Analysis / K. K. Gupta, B. Gupta
// 2021 8th International Conference on Computing for Sustainable Global Development. New Delhi, 2021. P. 185–190.
8. Turnbull J. The Docker Book: Containerization is the new virtualization [Electronic resource] / James Turnbull.
2014 (Updated 2021). Mode of access: https://dockerbook.com/.
9. Yamin M. M. Cyber ranges: A systematic literature review / M. M. Yamin, B. Katt // Computers & Security.
2020. Vol. 97. Article 101951. DOI: 10.1016/j.cose.2020.101951.
10. Sultan S. Container Security: Issues, Challenges, and the Road Ahead / S. Sultan, I. Ahmad, T. Dimitriou //
IEEE Access. 2019. Vol. 7. P. 52976–52996.
11. Cloud Security Alliance. Microservices Security Guidance [Electronic resource]. 2024. Mode of access:
https://cloudsecurityalliance.org/artifacts/microservices-security-guidance/.
12. Wilson R. Optimizing ELK Stack for Real-Time Log Analysis / R. Wilson // Journal of Information Security.
2022. Vol. 12, № 3. P. 45–58.
13. Paxson V. The Zeek Network Security Monitor [Electronic resource] / V. Paxson et al. Mode of access:
https://zeek.org/.
14. Xin Y. Machine Learning and Deep Learning Methods for Network Intrusion Detection: A Survey / Y. Xin et
al. // IEEE Access. 2018. Vol. 6. P. 3376–3400.
15. MITRE Corp. MITRE ATT&CK Framework [Electronic resource]. 2024. Mode of access:
https://attack.mitre.org/.
16. NIST. Technical Guide to Information Security Testing and Assessment (NIST SP 800-115) / K. Scarfone et
al. 2008. DOI: 10.6028/NIST.SP.800-115.
17. Newman S. Building Microservices: Designing Fine-Grained Systems / Sam Newman. 2nd ed. O'Reilly Media,
2021. 612 p.
18. Metasploit. Metasploit Framework Documentation [Electronic resource]. 2024. Mode of access:
https://docs.metasploit.com/.
19. OWASP. OWASP Top 10:2021 [Electronic resource]. 2021. Mode of access: https://owasp.org/Top10/.
20. Elastic. Elastic Stack Security [Electronic resource]. 2024. Mode of access: https://www.elastic.co/elasticstack/security.
21. NIST. Application Container Security Guide (NIST SP 800-190) / M. Souppaya et al. 2017. DOI:
10.6028/NIST.SP.800-190.
22. NIST. Guide for Cybersecurity Event Recovery (SP 800-184) / M. Bartock et al. 2016. DOI:
10.6028/NIST.SP.800-184.
23. Pruncu A. Building a Cyber Range for Ethical Hacking Training / A. Pruncu, B. G. Rusu // 2022 International
Conference on Development and Application Systems (DAS). Suceava, 2022. P. 158–162.