Universiteit Leiden

nl en
Staff website Political Science

Hacking your own university – and getting credits for it

For a group of students, ethical hacking started as an evening hobby. Now it has become a course within the Computer Science programme. Both the university’s Security Operations Center (SOC) and the degree programme are enthusiastic about the initiative, as the students are helping to make the university’s IT environment more secure.

Hackers exploit vulnerabilities in digital systems. Sometimes with malicious intent, but they can also help organisations and system administrators identify and fix weak spots. That is exactly what the students in university lecturer Eleftheria Makri’s extracurricular course Capture the Flag: Cybersecurity in Practice are doing.

‘You do not get the chance every day to contribute to the university’s digital security,’ says student Pjotr

‘The idea actually came from the students themselves,’ says Makri. ‘They were already taking part in capture-the-flag events, which are essentially hacking competitions, and asked whether they could use a room at the university. They booked a space, ordered pizzas and got started.’ In a capture-the-flag (CTF) competition, participants try to find pieces of text hidden within vulnerable code. These pieces of text are known as ‘flags’. The challenge resembles the way hackers search systems for security weaknesses in real life.

More than just a game

Makri knew that CTF competitions were much more than a game for students in the Computer Science and Data Science and Artificial Intelligence (DSAI) programmes. ‘It seemed like a great opportunity to build on that enthusiasm and turn it into a formal course, with credits and real-world challenges.’ To make that happen, she approached the university’s ICT Shared Service Centre. The Security Operations Center (SOC) quickly embraced the idea. ‘This approach fits perfectly with our responsible disclosure policy, which encourages external parties to identify and report vulnerabilities in our systems,’ says Roy Kokkelkoren, coordinator of the SOC. ‘We also have a wide range of systems and platforms that students can investigate.’

The students then got to work. Within the framework of the university’s policy, they examined university systems for potential vulnerabilities and reported their findings according to agreed guidelines. ‘The aim was explicitly not to disrupt systems,’ says Kokkelkoren. ‘The goal was to identify potential vulnerabilities responsibly and report them.’

‘It was an adventure for us, from having the opportunity to develop our own course to actually teaching bachelor’s students,’ say teaching assistants Jayme Hebinck and Rajeck Massa

Submitting a report formed an important part of the course. ‘Of course, we had no way of knowing whether the students would actually find anything, so part of the learning experience was understanding how to report their findings properly.’ The reports were assessed by teaching assistants Jayme Hebinck and Rajeck Massa, who had also started the original pizza-and-hacking evenings, to determine whether the information would be useful to the SOC.

Everyone learned something

It turned out to be very useful. ‘The students identified several vulnerabilities of the same type,’ says Kokkelkoren. ‘It was an issue we were already aware of, but for which no solution was yet available. It was not something we had overlooked, but the students helped us identify similar vulnerabilities elsewhere in the systems. Given the scale of our infrastructure, that assistance was extremely valuable. The quality of the reporting was also very good.’

The collaboration has been a success for both sides. ‘We are very pleased with the results,’ Kokkelkoren says. ‘This is where the university’s operational activities and education come together. We learned from it, and the students learned from it. The collaboration helps us identify vulnerabilities sooner and further strengthen the university’s digital security. It also aligns perfectly with university policy. As far as we’re concerned, we would like to expand this way of working.’

Thinking outside the box

What particularly impressed Kokkelkoren was the students’ approach. ‘They think very much outside the box, often more so than IT professionals who have been working within an organisation for a long time. That fresh perspective is something we can genuinely benefit from.’

The course will continue next academic year, with a new group of students already eager to take part. ‘It’s certainly not because of the two ECTS credits they receive, as the course requires far more time and effort than that would suggest,’ says Makri. ‘They do it purely because they enjoy it and are genuinely enthusiastic about it.’

Responsible disclosure

The Security Operations Center (SOC) at Leiden University monitors the security of the university’s systems around the clock. Even so, in large and complex environments, vulnerabilities can sometimes go unnoticed. If someone discovers such a vulnerability, whether a hacker, student or other researcher, the university’s policy is to work together with the person who found it. In the IT sector, this is known as Responsible Disclosure (RD) or Coordinated Vulnerability Disclosure (CVD).

Under this approach, the discoverer will not be reported to the authorities, provided that they promptly share their findings, do not exploit or disclose the vulnerability to others, and provide sufficient information to allow the issue to be reproduced and resolved. The university regularly receives responsible disclosure reports, most of them from abroad. Now, however, some of those reports are coming from its own students.

This website uses cookies.  More information.