ConceptioArchivearXiv CS
arXiv CSopen access

ACTING: A Platform for Cyber Ranges Federation

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

ACTING: A Platform for Cyber Ranges Federation Kyriakos Christou∗ , Maria Michalopoulou∗ , Stefano Taggi† , Matteo Merialdo† , Nikolai Stoianov‡ , Vasilis Ieropoulos∗ , Theofanis Eleftheriadis∗ , Philippos Isaia∗ , Eleni Darra¶ , Ilias Koritsas¶ , Antonis Voulgaridis¶ , Giorgos Rizos¶ , Dimitris Kavallieros¶ , Stefanos Vrochidis¶ , Konstantinos Votis¶ , x Liliana Medina∥ , João Camacho∥ , Tim Gerling∗∗ , Aimilia-Bantouna , Pavel Varbanov†† , George Sharkov†† , Christos Laoudias∗ , José Borges‡‡ , Maria K. Michael∗§ ∗ KIOS Research and Innovation Center of Excellence, University of Cyprus, Cyprus; † Nexova, Belgium; ‡ Bulgarian Defence Institute, Bulgaria; § Department of Electrical and Computer Engineering, University of Cyprus, Cyprus; ¶ Information Technologies Institute, Centre for Research and Technology Hellas, Greece; ∥ VisionSpace Portugal, Portugal; ∗∗ VisionSpace Technologies GmbH, Germany; †† European Software Institute, Cybersecurity Laboratory, Bulgaria;

arXiv:2605.12170v1 [cs.CR] 12 May 2026

‡‡ CINAMIL – Centro de Investigação, Desenvolvimento e Inovação da Academia Militar, Lisboa, Portugal; x

WINGS ICT SOLUTIONS SA, Athens, Greece

Abstract—Cyber Defence (CD) training requires interoperable cyber-range environments capable of supporting complex, multidomain exercises across distributed infrastructures. This paper presents three main contributions addressing this challenge. First, we introduce the Exercise Description Language – First Generation (EDL-FG), a structured language for formally describing cyber-range training services and exercises. EDL-FG captures both the technical infrastructure required to emulate ICT/OT environments and the scenario logic governing cyber events, injects, and participant interactions, enabling interoperable and automated scenario deployment across federated Cyber Ranges (CRs). Second, the ACTING platform introduces automated PE and scoring mechanisms that assess trainee actions during exercises through coordinated data collection and analysis across participating CRs. Third, the platform enables multi-domain cyber training scenarios that combine civilian and military operational contexts. Building upon federation capabilities established under the H2020 ECHO project, ACTING demonstrates how interoperable scenario description and automated evaluation support scalable and realistic CD training. Index Terms—Cyber Range; Cybersecurity Training; Situational Awareness; Interoperability; Defence; Federation

I. I NTRODUCTION CRs are established technologies for the controlled and realistic emulation of cyber incidents and defensive operations, supporting education, testing, and training in research and operational practice [1], [2]. Conventional CRs typically target a single domain or cybersecurity aspect, whereas contemporary cyber incidents span interconnected domains and infrastructures, where dependencies and cascading effects shape attack dynamics and response strategies. However, developing and maintaining multi-domain CR environments requires substantial expertise and resources. Federated CRs address this limitation by interconnecting independently developed CRs This work was supported by the ACTING Project, Co-funded by the European Union through the European Defence Fund (EDF) and in part by the European Union’s Horizon 2020 research and innovation programme under Grant Agreement No 739551 (KIOS CoE - TEAMING) and from the Republic of Cyprus through the Deputy Ministry of Research, Innovation and Digital Policy. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Commission. Neither the European Union nor the granting authority can be held responsible for them.

under common operational and technical agreements, enabling multi-domain scenarios within a unified environment [3]. Recent research and CD initiatives highlight both the operational relevance and architectural complexity of Federated CRs. Federation is a multi-dimensional challenge involving technological, operational, and organizational aspects [4]. Beyond technical interconnection [5], key challenges include interoperability across heterogeneous CR infrastructures, scalability, resource management, and secure data exchange, including identity management and access control [6]. Governance, trust, legal constraints, and sustainability also affect viable federated ecosystems, while prior work emphasizes common scenario description frameworks for technology-agnostic design and cross-platform execution [7], [8]. Although prior work demonstrates the feasibility of interconnectivity, interoperability, scalability, and runtime aspects of federated environments, it focuses on specific, separate solutions, such as scenario modelling and execution, infrastructure and resource details, automation, and script parsing [9], [10]. However, complex multi-domain exercises require tighter integration of federation mechanisms with Situational Awareness (SA), PE, and realistic simulation capabilities. Challenges in scenario portability and harmonized operation across heterogeneous CR infrastructures further motivate more cohesive architectural frameworks [11]. This work introduces the capability to jointly represent the CR topology, the scenario, and the associated scoring mechanisms described above. The main contributions of this work are threefold: EDL-FG: A structured language to formally describe CR training services and exercises, specifying both the technical infrastructure required for simulation environments and the scenario logic governing cyber events and participant interactions. EDL-FG provides a common and interoperable representation that supports automated deployment, orchestration, and collaboration across federated cyber-range environments. • PE and Scoring through the ACTING Platform (AP): The AP introduces automated mechanisms for evaluating trainees during exercises. Through coordinated data col•

lection and analysis across participating CRs, it enables performance assessment, scoring, and structured feedback for trainees and instructors, supporting improved understanding of participant behaviour and training outcomes. • Cross-Domain CR Training Scenarios: The AP supports the development and execution of CR scenarios that combine civilian and military domains, enabling realistic multi-domain training exercises and cross-sector collaboration in federated environments. The remainder of this paper is structured as follows. Section II outlines the architecture and key blocks of the AP. Section III describes how these components operate together to realize the envisioned cybersecurity training environment, providing advanced features and functionalities. Section IV demonstrates how the integrated tools and data available in the AP implement scenarios addressing various needs and gaps in the defence sector. Finally, Section V concludes the paper and outlines directions for future work. II. S YSTEM A RCHITECTURE A. Requirements for Advanced Cyber Training The requirements for advanced cyber training environments can be summarised as follows: • Realistic and Adversarial Training Environments. CRs should replicate realistic threat conditions and enable controlled exposure to adversarial tactics against complex ICT and cyber-physical systems [12], [13]. • Support for Interdependent Infrastructure. Training environments must simulate multidimensional attacks across interconnected systems and critical infrastructures. • Time-Critical Decision-Making Support. CD training should support rapid decision-making under operational pressure, reflecting the time-sensitive nature of cyber incidents [12]. • Federated and Interoperable Infrastructure. CRs should aggregate heterogeneous resources and ensure scenario portability across platforms to strengthen preparedness and resilience. • Support for Joint and Coalition Operations. Training platforms must support interoperability across organisations and domains to reflect real-world operational constraints. • Automated Evaluation and Continuous Learning. Advanced environments should include automated PE, user behaviour modelling, and structured feedback to improve cyber readiness. B. Overview of the ACTING Platform The AP is an integrated digital environment that supports the discovery, customization, procurement, and consumption of cybersecurity services. It connects service providers and customer organizations through a unified framework, enabling access to Cyber Range (CR) scenarios, tabletop exercises, and training modules. As an orchestration layer, it allows providers to publish services and customers to discover, negotiate, and request them through structured workflows, while also

supporting customized services delivered collaboratively by multiple providers. The high-level architecture of the AP is shown in Fig. 1 and comprises the following building blocks. Importantly, ACTING is neither a CR infrastructure nor a Learning Management System (LMS). Rather, it acts as an aggregation and coordination layer connecting independent providers and resources. Its value depends on service providers actively publishing offerings, positioning ACTING as an enabling marketplace and orchestration environment for distributed cybersecurity training and exercise delivery. C. Main Building Blocks The ACTING Consortium is developing the ACTING Training and Simulation Platform as an integrated environment for advanced cyber capability development and exercise orchestration. It builds on core research and technical themes that enhance the effectiveness and scalability of cyber training, including CR SA for monitoring complex exercises and automated PE for objective, data-driven assessment of participant actions and outcomes. The platform also incorporates user behaviour simulation to model human and organisational interactions within CR scenarios. Another key contribution is the Scenario Development Language, which standardises and accelerates scenario creation and portability. In addition, ACTING adopts a federated approach to enable interoperable, multi-sector CR exercises. Together, these capabilities form the technological foundation of the AP. 1) Building Block 1: Service Catalogue (SC) and Service Request Manager (SRM) The SC is the central repository of platform services and the main entry point for end users. It allows Service Providers to publish and manage services, while Service Requesters can browse, search, and initiate requests. The SC supports federated publishing across providers, advanced filtering, search, and metadata tagging based on frameworks such as NICE and SFIA. It integrates with the Administration Component, Service Designer, QoS Manager, Procurement Manager, and Notification Manager, and forwards selected services to the SRM. The SRM manages the lifecycle of service requests and acts as the negotiation and approval hub between Service Requesters and Service Providers. It supports workflows from request initiation to approval, communication, and contract finalization through integration with the Procurement Manager. The SRM also interacts with the Service Broker, Notification Manager, and Services Manager, providing request status visibility, secure session handling, and role-based access control for the transition from service discovery to execution. 2) Building Block 2: Service Designer (SD) The SD is a core platform component that enables users to define and configure new services or service requests according to their role. Service Providers use it to create new offerings, while Service Requesters use it to initiate requests or customize catalogue entries by adjusting size, difficulty, duration, and features. A guided wizard supports users from high-level descriptions to technical and organizational details,

Fig. 1: ACTING High-level Design. enabling both simple and complex service definitions. At its core, the SD uses the concept of a Unit, which represents a basic service building block. A service may include one or more Units, supporting both simple and composite services. The following unit types are currently supported: • Content-based Training: A structured learning module or training program for developing cybersecurity skills, knowledge, or competencies. It may include instructional content, learning materials, and assessments, and can be used as standalone training or preparation for advanced exercises. • CR Scenario: An immersive, hands-on simulation of cybersecurity incidents, such as malware infection, unauthorized access, or system failure. Participants interact with a virtualized environment to detect, respond to, and mitigate threats in real time. • Tabletop Exercise: A discussion-based exercise that simulates cybersecurity events through structured dialogue. Participants work through incident response, communication, and decision-making processes to improve coordination and strategic awareness. By combining Units, the SD supports customized, modular services tailored to different training and operational objectives, improving flexibility, reusability, and alignment between providers and requesters. For CR Scenario units, users work with a visual canvas that serves as both a design workspace and

live configuration tool. The drag-and-drop interface provides building blocks such as virtual machines, network segments, traffic generators, scoring modules, and access policies, which can be arranged to create realistic exercises. Each change updates a live model that functions as both a human-readable blueprint and a machine-ready deployment manifest. The canvas also abstracts multi-site deployments, allowing users to design across federated CRs in a single unified space while the platform manages orchestration, resource allocation, locality constraints, validation, and scheduling. Overall, the SD enables providers and requesters to create and adapt CR scenarios visually and efficiently without writing infrastructure code. 3) Building Block 3: Service Development Language Translator (SDL-T) The SDL-T component transforms high-level service specifications into executable CR scenarios using the EDL-FG framework, as described in Section IV-C. This semantic transformation maps abstract scenario definitions into deployable operational configurations. Through EDL-FG validation and the ACTING workflow, it supports iterative refinement and verification of scenario elements. It also improves collaboration among technical developers, cybersecurity experts, domain specialists, and training designers through a common formalised representation that reduces ambiguity. Service components are formally described, including IT/OT infrastructures, virtual and physical assets, human and simulated actors, data flows, dependencies, roles, behaviours, interactions, and constraints for cyber-event orchestration and participant engagement. These descriptions are translated into machinereadable artefacts for orchestration and evaluation, ensuring consistency between design and execution and enabling reproducible, scalable, and measurable cyber-range scenarios. 4) Building Block 4: Service Recommendation Engine (SRE) The SRE forms the backbone of the AP during the preexecution phase. It enables CR providers to register and maintain structured information on their infrastructure capabilities, resource capacities, and availability. Using this information, the SRE manages the service-request lifecycle, including analysis, resource allocation, and activation. It also supports matchmaking by identifying suitable alternatives when requested resources are unavailable, while ensuring alignment with requester requirements and constraints. The SRE consists of two main components: the Capacity-Capability Map (CCM) and the Service Broker (SB). • Capacity-Capability Map (CCM) The CCM stores and manages CR data, including available services, capabilities, capacity, and reservation status. It enables users or requesters to design a desired CR service configuration and verifies whether it can be offered based on available capabilities, capacity, and reservations. Definition 2.1 (Cyber Range Capability): A CR Capability is a qualitative descriptor of the operational scope, purpose, and functional properties of a CR. Definition 2.2 (Cyber Range Capacity): A CR Capacity is a quantitative descriptor of measurable static CR

resources. Service Broker (SB) The SB processes service requests and manages their lifecycle within the platform. It also acts as a recommendation engine by analysing requests and checking whether the required resources are available. After receiving a request from the Service Request Manager, the SB queries the CCM to identify the most suitable CR or combination of CRs for federated execution. If validation succeeds and the invoice is generated, the resources are reserved in the CCM and the request is forwarded to the CR provider(s) for activation. If validation fails due to insufficient resources or unavailability, the SB proposes ranked alternatives based on predefined evaluation metrics. 5) Building Block 5: Federated Awareness Engine (FAE) The FAE provides SA capabilities within the AP by collecting and analysing data generated during cyber-range exercises. The component correlates scenario events, participant actions, and contextual information to support the assessment of team performance and decision-making throughout the exercise lifecycle. By employing a set of time-aligned metrics, the engine enables the evaluation of SA levels across federated training environments. 6) Building Block 6: Federated Performance Evaluation (FPE) The FPE framework of the AP enables automated assessment of trainee performance in cyber-range training exercises, including scenarios executed across federated CRs. It supports the collection and analysis of participant actions during exercises, providing performance metrics and structured feedback to assist instructors in evaluating trainee problemsolving and decision-making capabilities. The framework consists of two main components: the PE module deployed at each participating CR, which monitors trainee activity locally, and the FPE module, which aggregates and analyses data across multiple ranges. Through this architecture, ACTING provides a unified view of trainee performance, enabling automated reporting, visualisation of results, and recommendations for further training. 7) Building Block 7: Learning Management System The LMS supports the management and execution of training activities within the AP. It enables trainers to configure scenarios, define participant roles, and manage simulated user behaviour in cyber-range exercises. In collaboration with the US, it supports simulated user profiles, such as Blue, Red, and Grey users, schedules their actions, and orchestrates their activities during execution. The LMS also enables monitoring and interaction with ongoing exercises through integration with other ACTING components. Further details on its architecture and functionality are presented in a later section. 8) Building Block 8: Services Manager (SM) The SM is the central orchestration component of the ACTING cybersecurity training platform, responsible for managing the lifecycle of Negotiated Services across the PreExecution, Execution, and Post-Execution phases. Its core •

functions include access control, service configuration, monitoring, and execution coordination. The SM integrates with key platform subsystems—including the CR infrastructure, LMS, SA, FPE, CR Agent Manager (CRAM), Scenario Description Language (SDL), Services Catalogue, and the Service Request Manager—through well-defined interfaces and workflows. Configuration of Simulated Users, PE metrics, and SA parameters is facilitated through the SM in collaboration with the respective components. Additionally, the SM supports user and team management, action timeline configuration, virtual machine integration via Guacamole, and scenario topology visualisation, enabling near real-time synchronization and rolebased access control across federated training environments. III. M AIN F EATURES AND F UNCTIONALITIES This section presents the main features and functionalities of the AP that support advanced cybersecurity training in federated cyber-range environments. In particular, it describes the SA feature for monitoring and understanding cyber-range activities, the PE feature for automated assessment of trainee performance, and the Service Description Language Translator together with the EDL-FG, which enable the definition and interoperability of cyber-range scenarios across different infrastructures. A. Situational Awareness (SA) The SA component is a core element of the CR and AP, collecting and processing data to analyse the situational understanding of Service Consumers, or trainees, and their teams during service execution [14]. It supports informed decision-making by recording and correlating scenario events, participant actions, issued hints, and contextual information along the scenario timeline. Using predefined metrics based on team composition, participant roles, and scenario objectives, the SA component evaluates SA levels and identifies potential team strengths and weaknesses. The SA assessment also considers information provided by the CRs before exercise execution, including actionprioritisation guidelines and best practices expected from trainees and teams. The analysis incorporates performed and reported actions, achieved goals, followed strategies, and used hints, enabling a comprehensive assessment of participant performance and SA behaviour. The Federated Analytics Engine (FAE) aggregates and analyses data metrics from all federated CRs and scenarios, including single-range and federated exercises. The FA component operates within the central AP and interacts with components such as the SDL-T and Service Manager. Architecturally, FA includes two subcomponents: the FAE, which performs backend data analysis, and the FA Visualisation module, which provides an interface for accessing insights and interacting with the system. B. Performance Evaluation (PE) Evaluating trainee performance in federated CR scenarios is challenging due to the volume and diversity of generated

data [15]. The AP addresses this challenge through automated collection and evaluation of trainee actions, streamlined feedback for instructors/trainers (Service Managers), and a standard PE framework for coordinating data collection across multiple CRs [16]. ACTING relies on two components for automated performance analysis. The PE component, deployed at each participating CR, collects scenario data and maps trainee actions to trainee identities. The FPE component, operating at the AP level, aggregates the data received from all PE components, provides a unified view of Service Consumer performance, generates reports on scores and incorrect responses, and recommends additional units or services for further skill development. The ACTING Federated PE framework is built around the concept of a Metric, which represents a measurable criterion for assessing trainee actions. In CR scenarios, each Unit is associated with multiple metrics, defined during service design and adjustable during pre-execution by the Service Manager. Performance scores are computed through hierarchical aggregation: metrics are first combined into Unit-level assessments, which are then aggregated into a Service-level evaluation to produce the final PE score for each trainee or team. For each service, the FPE component receives an EDL-FG configuration file describing the metrics to be evaluated, their reference solutions, and the scenario locations from which scoring data must be collected. Figure 2 shows a snippet of this configuration file. Depending on the training objectives, FPE supports four metric types: (i) time, which evaluates the duration of an activity, e.g., the time required to enable a firewall; (ii) quantity, which evaluates the number of correctly executed actions, e.g., the number of commands; (iii) sequence, which evaluates command execution and ordering against a predefined solution using fuzzy matching; and (iv) task, which evaluates task completion, e.g., blocking a specific port. For quiz-based exercises, the FPE component interacts with the LMS to retrieve completed quizzes, which are treated as another type of metric. Multiple-choice and true/false questions are graded by the LMS, while essay-type responses are evaluated by FPE using Natural Language Processing across three dimensions: (i) similarity, which measures the Similarity Score (SimS) between the Service Consumer’s answer and the reference solution, from 0, indicating low similarity, to 1, indicating identical responses; by default, FPE uses Sentence-BERT embeddings and cosine similarity; (ii) spelling, which measures Spelling Score (SpellS) correctness, from 0, indicating that every word is incorrect, to 1, indicating no spelling mistakes; and (iii) clarity score (ClarS), which combines text assessment metrics, including Flesch Reading Ease (FRE), Connectivity (Conn), Subordinate Ratio (SubR), Average Maximal Depth (AvgMaxD), Mean Dependency Distance (MDD), LSA Cohesion (LSACoh), and CoLA-based quality (QCoLA), with Gaussian distributions used to account for non-linear behaviour. Specifically, FRE is a readability test that scores English text from 0 to 100,

Fig. 2: Snippet of service configurations required for FPE. with higher scores indicating easier-to-read material; LSACoh estimates semantic coherence using Latent Semantic Analysis; and QCoLA estimates linguistic acceptability based on models trained on the Corpus of Linguistic Acceptability. ClarS is computed as follows: ClarS = QCoLA2 · w1 Conn + w2 SubR + w3 AvgMaxD  + w4 MDD + w5 LSACoh + w6 FRE The final Essay Score (ES) is computed as: ES = 0.8 SimS + 0.1 SpellS + 0.1 ClarS The weights were determined through experiments on the ASAG dataset1 . The resulting scores are displayed in near real time through the AP UI. Figure 3 shows the metrics of Scenario 2 and the respective scores of a trainee. C. ACTING Exercise Description Language - First Generation The EDL-FG is a structured language for specifying cyberrange training services and exercises. It formally describes both the technical infrastructure required for simulation and the scenario logic governing cyber events and participant interactions. Specifically, EDL-FG captures two key dimensions: (i) 1 https://github.com/DigiKlausur/ASAG-Dataset

computational and network resources used to simulate or emulate ICT/OT infrastructures and (ii) the scenario screenplay, including storylines, events, injects, and expected participant actions. By formalizing these elements, EDL-FG supports collaboration among cyber-range providers, trainers, and service consumers, while enabling automation in deployment, cyberincident orchestration, and participant performance assessment [9], [17]. Figure 4 presents an excerpt from an EDL-FG file generated from a real scenario, illustrating representative assets from the topology and the corresponding event–inject– action chain. EDL-FG is implemented as an extensible YAML-based data structure, selected for its readability, flexibility, and compatibility with modern orchestration frameworks. The language supports hierarchical object definitions and extensible schemas, enabling the gradual inclusion of new attributes and entities as cyber-range capabilities evolve. Through YAML schemas aligned with JSON Schema standards, EDL-FG enables automated validation of exercise descriptions, ensuring structural consistency and correct data typing. The data model represents multiple abstraction layers, including services, training units, infrastructure assets (e.g., compute, network, and custom assets), and scenario elements such as storylines, events, and injects. This structure allows complex and cascading cyber simulations to be defined consistently across single or federated cyber-range environments. The ACTING EDL-FG is deliberately designed as a unifying semantic layer that bridges multiple established cybersecurity frameworks and standards. Rather than reinventing concepts, it reuses and refers to classes, taxonomies, and labels from these frameworks and extends them with additional semantics, cross-references, and domain-specific literals tailored to the AP specifics. Such concepts include: • Cyber Data Exchange Model (CDEM) and BONES [18]: EDL-FG adopts foundational object classes and relationships for representing cyber environments, such as assets, networks, communication flows, and observable effects. • MITRE ATT&CK [19] and MITRE DEFEND [20] contribute standardised vocabularies for adversarial behaviours and defensive countermeasures. Within EDLFG, these vocabularies are used to formally annotate scenario actions, attack paths, and mitigation strategies, enabling precise mapping between simulated events and real-world tactics, techniques, and procedures. • Common Weakness Enumerations (CWEs) [21] is used to describe vulnerabilities as structured weaknesses, allowing the scenario designer to link system misconfigurations or software flaws to prerequisites for executing the planned events. • High-Level Architecture [22] principles inform the modelling of distributed simulation components and interactions, particularly for synchronising simulation entities, e.g., red team tools, blue team monitoring systems, and physical devices, within a federated CR. • TOSCA [23] contributes concepts for service topology and orchestration, which EDL-FG leverages to describe

how compute assets, services, and dependencies are deployed, configured, and managed across the CR infrastructure. • The NIST NICE framework [24] provides a structured approach for representing the relationships among roles, skills, and learning objectives. What distinguishes ACTING EDL-FG is not just the aggregation of these frameworks, but the way it interconnects them through explicit cross-references and validation rules. For example, a single scenario element—such as a phishing attack implemented on a specific enterprise architecture—can simultaneously reference: (i) mitre attack technique; (ii) associated cwes representing exploited weaknesses; (iii) defensive measures from mitre defend; (iv) affected assets defined via CDEM; and (v) roles responsible for detection and response via nice. In addition, EDL-FG introduces new literals and extensions to capture CR service–specific requirements that are not fully addressed by existing standards. These include: (i) temporal and conditional constructs for orchestrating events (triggers); (ii) interaction options between simulated users and simulated systems; (iii) evaluation metrics and sa scoring mechanisms; and (iv) abstractions for hybrid (simulated and emulated) IT/OT components. By combining standardised vocabularies with these extensions, EDL-FG creates a shared, formalised language that improves communication among multidisciplinary stakeholders, such as cybersecurity experts, scenario designers, educators, and system engineers. It ensures that scenario design, execution, and evaluation are consistent, reproducible, and semantically aligned with real-world cybersecurity knowledge and practices. In combination with the SDL-T, EDL-FG establishes a structured framework for the design, validation, and execution of cybersecurity training services. By separating the conceptual description of exercises from the execution logic, this approach enables automation, interoperability across federated CRs, and improved reproducibility of cybersecurity training scenarios, while supporting the future evolution of EDL-FG towards a standardised language for describing cyber exercises and simulation-based cybersecurity training environments. D. User Simulator The User Simulator (US) resides within the CR and simulates benign and malicious human-generated network traffic. Simulated profiles may represent: (a) Blue users, who exhibit benign behaviour and respond to social-engineering and network events based on predefined profiles, such as basic or advanced IT users; (b) Red users, who act as malicious actors performing social-engineering or network-based attacks, such as phishing or distributed denial-of-service (DDoS) attacks; and (c) Grey users, who perform neutral activities such as file creation or web browsing. Before exercise execution, the simulated-user configuration is defined, including the number of users, their roles, and the actions each user will perform with corresponding timestamps.

Fig. 3: Visualisation of different metric scores for a trainee completing a unit of Scenario 2.

Fig. 4: Sample of EDL-FG CR Scenario Description

During execution, users follow the scenario timeline, and after each action, relevant information is forwarded to the FA component for reporting to the trainer. Through the FAE user interface, trainers may also dynamically modify simulated-user timelines or behaviours during the exercise. IV. C ROSS -D OMAIN T RAINING S CENARIOS This section presents three representative cybersecurity training scenarios (sub-sections IV-A, IV-B, IV-C) implemented within the AP. These scenarios illustrate how stakeholders can design, orchestrate, and execute federated cyberrange exercises within the ACTING ecosystem. The section demonstrates the platform’s operational capabilities and flexibility in supporting diverse cyber-defence training environments, focusing on the types of exercises that can be deployed rather than the detailed scenario-development methodology. It also highlights the platform’s ability to support complex, multi-partner training activities across the exercise lifecycle, from scenario conception to coordinated execution. A. Scenario 1: Combined cyber-attacks against joint HQ, Land and Navy CIS systems In Scenario 1, the network infiltration phase uses social engineering through strategically placed USB devices containing malware designed to exploit autorun vulnerabilities. Using PowerShell-based intrusion techniques, the malware establishes covert access to compromised hosts and enables lateral movement across the Command and Control (C2) network, allowing the adversary to manipulate operational data across interconnected systems. After persistence is established, the attacker modifies shared calendars, tampers with logistics databases, disrupts maintenance schedules, and falsifies asset coordinates in the Common Relevant Picture, resulting in degraded SA, disrupted unit coordination, and reduced mission readiness. B. Scenario 2: Space and Maritime Sectors The ACT-SC-02 scenario presents a refined cyber-physical attack that demonstrates the complex interplay between spacebased infrastructure and maritime operations. Through its two interconnected storylines—GNSS signal manipulation and a

Fig. 5: ACT-SC-01 network topology diagram subsequent ransomware attack—the scenario highlights how modern threat actors can exploit vulnerabilities across multiple sectors to produce cascading operational effects. By mapping these events to established cybersecurity frameworks, the scenario provides a comprehensive training environment that enables satellite operators and maritime personnel to detect, respond to, and mitigate such advanced threats. This realistic approach to CD training enhances the resilience of critical infrastructure while promoting cross-sector collaboration and strengthening incident response capabilities.

Fig. 6: ACT-SC-02: Cyber-range environment C. Scenario 3: Military Base Classified Information Theft This fictional training scenario focuses on detecting and containing a simulated targeted breach in a high-security military environment. Following an initial foothold, the exercise focuses on identifying anomalous authentication patterns and

lateral movement across a simulated internal network. Participants should use representative Military Command & Control (C2) servers and SIEM aggregation tools to analyse deviations in access-control logs and audit trails. The technical challenge lies in distinguishing between standard operational traffic and unauthorised access to fictional classified data repositories, especially as white-team injects escalate the severity of the simulated data exposure. The primary objectives involve identifying potentially compromised accounts and tracing the simulated attacker’s path through secure access segments. Once the breach scope is established, participants should isolate affected assets while following representative military Standard Operating Procedures (SOPs). This includes technical mitigation and formal escalation through a simulated chain of command, ensuring that grid security and military intelligence stakeholders are informed about the integrity of the fictional classified systems.

Fig. 7: ACT-SC-03: Cascading effect for cyber-attack in the civilian sector V. C ONCLUSIONS This paper presented three key contributions to interoperability and scalability in cyber-range training environments. First, it introduced EDL-FG, a structured approach for describing cyber-range exercises through infrastructure configuration and scenario logic. Second, it presented the AP’s automated PE and scoring mechanisms for assessing trainee actions across participating CRs. Third, it demonstrated support for multi-domain cyber-training scenarios combining civilian and military contexts. Overall, ACTING advances federated cyber training through automated PE, SA, and coordinated scenario execution across distributed infrastructures. Future work will include systematic empirical evaluation with quantitative measurements, baselines, and validation, while further developing EDL-FG into a mature exercise-description language and introducing adaptive scenarios that adjust complexity based on trainee performance. R EFERENCES [1] E. C. S. O. (ECSO), “Understanding cyber ranges: From hype to reality,” European Cyber Security Organisation, Tech. Rep., Mar. 2020. [2] N. Chouliaras, G. Kittes, I. Kantzavelou, L. Maglaras, G. Pantziou, and M. A. Ferrag, “Cyber ranges and testbeds for education, training, and research,” Applied Sciences, vol. 11, no. 4, 2021.

[3] M. M. Yamin and B. Katt, “Modelling Attack and Defense Scenarios on Federated Cyber Ranges,” in IEEE International Conference on Cyber Security and Resilience (CSR), 2025, pp. 771–776. [4] C. Lal, M. M. Yamin, and G. Spathoulas, “Navigating cyber range federations: an exploration of current landscape, obstacles, and prospects: C. lal et al.” International Journal of Information Security, vol. 25, no. 2, p. 53, 2026. [5] C. Virág, J. Čegan, T. Lieskovan, and M. Merialdo, “The current state of the art and future of european cyber range ecosystem,” in 2021 IEEE International Conference on Cyber Security and Resilience (CSR), 2021, pp. 390–395. [6] B. Nicodème, “Federated cyber range challenges,” Master’s Thesis, Université Libre de Bruxelles, 2020, master in Cybersecurity: Corporate Strategies. [7] M. Park, H. Lee, Y. Kim, K. Kim, and D. Shin, “Design and implementation of multi-cyber range for cyber training and testing,” Applied Sciences, vol. 12, no. 24, 2022. [8] N. Oikonomou et al., “Echo federated cyber range: Towards nextgeneration scalable cyber ranges,” in 2021 IEEE International Conference on Cyber Security and Resilience (CSR), 2021, pp. 403–408. [9] M. M. Yamin and B. Katt, “Modeling and executing cyber security exercise scenarios in cyber ranges,” Computers & Security, vol. 116, p. 102635, 2022. [10] G. S. Rizos, N. Kopalidis, N. Mengidis, A. Lalas, and K. Votis, “From Concept to Deployment: An AI Assistant for Generating and Configuring Cyber Range Scenarios,” in IEEE International Conference on Cyber Security and Resilience (CSR), 2025, pp. 777–782. [11] M. N. Katsantonis, A. Manikas, I. Mavridis, and D. Gritzalis, “Cyber range design framework for cyber security education and training,” International Journal of Information Security, vol. 22, no. 4, pp. 1005– 1027, 2023. [12] M. Glas, M. Vielberth, and G. Pernul, “Train as you fight: Evaluating authentic cybersecurity training in cyber ranges,” in CHI conference, 2023, pp. 1–19. [13] Y. Shin, H. Kwon, J. Jeong, and D. Shin, “A study on designing cyber training and cyber range to effectively respond to cyber threats,” Electronics, vol. 13, no. 19, 2024. [14] H. Alavizadeh, J. Jang-Jaccard, S. Y. Enoch, H. Al-Sahaf, I. Welch, S. A. Camtepe, and D. D. Kim, “A survey on cyber situation-awareness systems: Framework, techniques, and insights,” ACM Computing Surveys, vol. 55, no. 5, pp. 1–37, 2022. [15] V. Švábenskỳ, J. Vykopal, P. Čeleda, K. Tkáčik, and D. Popovič, “Student assessment in cybersecurity training automated by pattern mining and clustering,” Education and information technologies, vol. 27, no. 7, pp. 9231–9262, 2022. [16] V. Švábenskỳ, J. Vykopal, P. Čeleda, and J. Dovjak, “Automated feedback for participants of hands-on cybersecurity training,” Education and Information Technologies, vol. 29, no. 9, pp. 11 555–11 584, 2024. [17] G. Costa, E. Russo, and A. Armando, “Automating the generation of cyber range virtual scenarios with VSDL,” arXiv preprint arXiv:2001.06681, 2020. [18] “Reference for Cyber Modeling & Simulation Study Group, Cyber Data Exchange Model (DEM) Base Objects, Networks, Effects, & Specifications (BONES),” https://cdn.ymaws.com/www.sisostandards. org/resource/resmgr/reference documents /siso-ref-072-2024.pdf, 2024, sISO-REF-072-2024. [19] The MITRE Corporation, “MITRE ATT&CK,” https://attack.mitre.org/, accessed: 2026-05-05. [20] “MITRE D3FEND,” https://d3fend.mitre.org/, accessed: 2026-05-05. [21] “Common Weakness Enumeration (CWE),” https://cwe.mitre.org/, accessed: 2026-05-05. [22] IEEE Standards Association, “IEEE Standard for Modeling and Simulation (M&S) High Level Architecture (HLA)–Framework and Rules,” https://standards.ieee.org/ieee/1516/6687/, 2025, iEEE 1516-2025, accessed: 2026-05-05. [23] OASIS, “TOSCA Simple Profile in YAML Version 1.3,” https://docs.oasis-open.org/tosca/TOSCA-Simple-Profile-YAML/ v1.3/os/TOSCA-Simple-Profile-YAML-v1.3-os.html, 2020, oASIS Standard, 26 February 2020, accessed: 2026-05-05. [24] National Institute of Standards and Technology, “NICE: Advancing Cyber Education and Workforce,” https://www.nist.gov/itl/ applied-cybersecurity/nice/about, 2017, accessed: 2026-05-05.

Record · ID 178793 · SHA-256 80badf449bc62719
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.