Застосування спеціалізованого програмного забезпечення захисту даних в освітньому процесі підготовки фахівців цифрових технологій
Журнал
Наукові записки
ISSN
2310-371X
Дата випуску
2025-12-23
Автор(и)
Шимків, Н. І.
DOI
10.31392/NZ-udu-164-2.2025.19
Анотація
Стаття присвячена аналізу та практичному обґрунтуванню використання сучасного та актуального програмного забезпечення у підготовці фахівців з кібербезпеки в сфері цифрових технологій в умовах зростання кіберзагроз та збільшення впливу цифровізації на суспільство. Розглядається доцільність упровадження технологічних інструментів в освітній процес, що зумовлена потребою у формуванні практичних навичок реагування на інциденти, аналізу трафіку, виявлення вразливостей та моделювання реальних сценаріїв атак. Досліджено, що традиційні освітні методики вже не забезпечують достатнього рівня підготовки, оскільки сучасна кібербезпекова діяльність передбачає роботу зі складними мережевими інфраструктурами, цифровою криміналістикою, автоматизованим моніторингом та інструментами пентестингу. Проведено аналіз основних типів програмного забезпечення, що застосовується у навчанні: середовища віртуального доступу (VirtualBox, VMware Workstation), платформи для симуляції та платформи-тренажери (TryHackMe, HackTheBox), інструменти аналізу мережевого трафіку (Wireshark), комплексне програмне забезпечення для тестування безпеки (Metasploit Framework), системи моніторингу та різнотипні журнали безпеки та моніторингу мережі (Splunk, ELK Stack). Для кожного з розглянутого прикладного програмного забезпечення подано рекомендації щодо використання їх на лабораторних заняттях, під час проведення практики, та можливість моделювання інцидентів. Розкрито педагогічні і методичні властивості віртуальних середовищ, що дозволяють створювати повноцінні навчальні та симуляційні лабораторії та аналізувати функціонування реальних мереж та систем. Досліджено, що платформи типу CTF дозволяють розвинути навички етичного хакінгу, так званої кіберрозвідки (тестування на вразливості). Виділено особливість застосування прикладного програмного забезпечення Wireshark для мережевого аналізу та моніторингу мережі, що дає студентам можливість аналізувати та визначати різноманітні типи трафіку та ознаки та властивості кібератак. Metasploit Framework використовується, як один з найефективніших інструментів для демонстрації повноцінного тестування системи на проникнення, тоді як системи SIEM, зокрема Splunk та ELK, розглянуто як необхідні у формуванні компетентностей аналітика та фахівця. У статті зроблено висновок, що повноцінне та всебічне застосування програмного забезпечення для захисту даних у процесі підготовки фахівців цифрових технологій підвищує ефективність професійної підготовки, забезпечує наближення процесу здобуття освіти до реальної практики та вмінням протистояти загрозам, формує поглиблене розуміння актуальних методів атак та способів їх виявлення та усунення. Подальший розвиток методики має ґрунтуватися на розширенні практичного застосування програмного забезпечення для імітації, введення автоматизованих процесів у проведення практичних занять та можливість виділення індивідуальних освітніх траєкторій, залежно від рівня підготовки здобувачів.
This article examines and provides practical justification for integrating modern and relevant software tools into the training of cybersecurity professionals within the field of digital technologies particularly in light of the growing scale of cyber threats and the increasing societal impact of digital transformation. The appropriateness of integrating technological tools into the educational process is examined, driven by the need to develop practical skills in incident response, traffic analysis, vulnerability identification, and the simulation of real-world attack scenarios. Traditional teaching methodologies are no longer sufficient, as contemporary cybersecurity practice demands hands-on experience with complex network infrastructures, digital forensics, automated monitoring systems, and penetration testing tools. The paper analyzes key categories of software employed in cybersecurity education: virtualization environments (such as VirtualBox and VMware Workstation); simulation and gamified training platforms (including TryHackMe and HackTheBox); network traffic analysis tools (notably Wireshark); comprehensive penetration testing frameworks (such as Metasploit Framework); and security information and event management (SIEM) systems like Splunk and the ELK Stack. For each of these tools, the article offers specific recommendations for their integration into laboratory sessions, practical training, and incident simulation exercises.
The pedagogical and methodological advantages of virtual environments are explored, highlighting their capacity to support fully functional simulated laboratories that mirror real-world networks and systems. Capture-the-Flag (CTF)-style platforms are shown to effectively cultivate skills in ethical hacking and vulnerability assessment often referred to as cyber reconnaissance. Wireshark is identified as a cornerstone tool for teaching network analysis and monitoring, enabling students to inspect traffic patterns and recognize indicators of cyberattacks. Metasploit Framework is presented as one of the most effective instruments for demonstrating end-to-end penetration testing, while SIEM platforms like Splunk and ELK Stack are emphasized as critical for developing the analytical competencies required of cybersecurity specialists. The article concludes that the comprehensive and strategic use of specialized software significantly enhances the effectiveness of professional training, bridging the gap between academic instruction and real-world cybersecurity practice. It not only strengthens students’ ability to counter emerging threats but also fosters a deep, contextual understanding of contemporary attack methodologies and their detection and mitigation. Importantly, the authors propose that future pedagogical development should focus on expanding the use of simulation-based software, integrating automated workflows into practical coursework, and implementing adaptive, individualized learning pathways tailored to students’ varying levels of prior knowledge and skill.
The pedagogical and methodological advantages of virtual environments are explored, highlighting their capacity to support fully functional simulated laboratories that mirror real-world networks and systems. Capture-the-Flag (CTF)-style platforms are shown to effectively cultivate skills in ethical hacking and vulnerability assessment often referred to as cyber reconnaissance. Wireshark is identified as a cornerstone tool for teaching network analysis and monitoring, enabling students to inspect traffic patterns and recognize indicators of cyberattacks. Metasploit Framework is presented as one of the most effective instruments for demonstrating end-to-end penetration testing, while SIEM platforms like Splunk and ELK Stack are emphasized as critical for developing the analytical competencies required of cybersecurity specialists. The article concludes that the comprehensive and strategic use of specialized software significantly enhances the effectiveness of professional training, bridging the gap between academic instruction and real-world cybersecurity practice. It not only strengthens students’ ability to counter emerging threats but also fosters a deep, contextual understanding of contemporary attack methodologies and their detection and mitigation. Importantly, the authors propose that future pedagogical development should focus on expanding the use of simulation-based software, integrating automated workflows into practical coursework, and implementing adaptive, individualized learning pathways tailored to students’ varying levels of prior knowledge and skill.
Теми
Файл(и)![Ескіз]()
Вантажиться...
Назва
Shymkiv_159_166.pdf
Розмір
206.54 KB
Формат
Adobe PDF
Контрольна сума
(MD5):7a2858615a5a937338da3ac0fccd47e7
