WebHOLE: Developing a web-based hands-on learning environment to assist beginners in learning web application security

被引:1
|
作者
Su, Jun-Ming [1 ]
机构
[1] Natl Univ Tainan, Dept Informat & Learning Technol, Tainan, Taiwan
关键词
Cybersecurity education; Web application security; Practical hands-on ability; Hands-on learning; Web-based learning; Portfolio analysis; CYBERSECURITY EDUCATION; FRAMEWORK; KNOWLEDGE;
D O I
10.1007/s10639-023-12090-z
中图分类号
G40 [教育学];
学科分类号
040101 ; 120403 ;
摘要
With the rapid growth of web applications, web application security (WAS) has become an important cybersecurity issue. For effective WAS protection, it is necessary to cultivate and train personnel, especially beginners, to develop correct concepts and practical hands-on abilities through cybersecurity education. At present, many methods offer vulnerable web environments to support practical hands-on training, including large-scale "Capture the Flag" mode (e.g., Cyber Range), pre-configured virtual machine images (e.g., Mutillidae), pre-built stand-alone applications (e.g., WebGoat), and web-based system (e.g., Damn Vulnerable Web Application). However, beginners need not only hands-on training tools and systems but also assistance to support effective learning. Moreover, pre-built training content and exercises are usually not easy to modify and thus lack the flexibility to meet specific teaching needs. Therefore, this study proposed and developed the Web-based Hands-On Learning Environment (WebHOLE) to efficiently assist beginners in learning WAS. To improve the flexibility of the training content, a web-based authoring tool was developed in WebHOLE to create customized hands-on learning exercises. Accordingly, learners can learn and practice the WAS training content online with learning assistance provided by the hands-on learning system. The hands-on abilities of the learners can be efficiently assessed by the hands-on testing system using online exams with progressive hints and automatic grading. Furthermore, to improve the effectiveness of teaching and testing, a portfolio analysis scheme using a data mining technique was developed to identify learning barriers and problematic test items. WebHOLE was applied to an actual beginner-level WAS course for undergraduate students. The experimental results showed the benefits of WebHOLE on WAS learning, with a significant improvement in learning outcomes. Students expressed high satisfaction with WebHOLE's learning assistance, rating it with average satisfaction scores above 4.0 out of 5.0. The portfolio analysis scheme also showed the effectiveness of WebHOLE in identifying learning problems and refining test items.
引用
收藏
页码:6579 / 6610
页数:32
相关论文
共 50 条
  • [1] WebHOLE: Developing a web-based hands-on learning environment to assist beginners in learning web application security
    Jun-Ming Su
    Education and Information Technologies, 2024, 29 : 6579 - 6610
  • [2] Robotic Mission to Mars: Hands-on, minds-on, web-based learning
    Mathers, Naomi
    Goktogen, Ali
    Rankin, John
    Anderson, Marion
    ACTA ASTRONAUTICA, 2012, 80 : 124 - 131
  • [3] Developing a collaborative learning environment using a web-based design
    Neo, M
    JOURNAL OF COMPUTER ASSISTED LEARNING, 2003, 19 (04) : 462 - 473
  • [4] DEVELOPING A WEB-BASED LEARNING PROGRAM
    Godar, Susan H.
    Rimsane, Inta
    SOCIETY, INTEGRATION, EDUCATION, PROCEEDINGS, 2007, : 96 - 100
  • [5] A Web-based Lightweight Testbed for Supporting Network Security Hands-on Labs
    Liu, Wei
    Niyaz, Quamar
    Sun, Weiqing
    Javaid, Ahmad Y.
    2018 IEEE INTERNATIONAL CONFERENCE ON ELECTRO/INFORMATION TECHNOLOGY (EIT), 2018, : 498 - 503
  • [6] Web-based music learning environment
    Zhou, Yun
    INTERACTIVE LEARNING ENVIRONMENTS, 2024, 32 (07) : 3566 - 3578
  • [7] TEACHING THE BASICS OF DEEP LEARNING IN COMPUTER SCIENCE AND ENGINEERING: A HANDS-ON WEB-BASED APPROACH
    Reano, Carlos
    INTED2017: 11TH INTERNATIONAL TECHNOLOGY, EDUCATION AND DEVELOPMENT CONFERENCE, 2017, : 3967 - 3972
  • [8] Web usage mining to evaluate the transfer of learning in a web-based learning environment
    Chanchary, Farah Habib
    Haque, Indrani
    Khalid, Md. Saifuddin
    FIRST INTERNATIONAL WORKSHOP ON KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2007, : 249 - 253
  • [9] Developing an effective support system for inquiry learning in a Web-based environment
    Pedaste, M
    Sarapuu, T
    JOURNAL OF COMPUTER ASSISTED LEARNING, 2006, 22 (01) : 47 - 62
  • [10] Teaching a Hands-On CTF-Based Web Application Security Course
    Ksiezopolski, Bogdan
    Mazur, Katarzyna
    Miskiewicz, Marek
    Rusinek, Damian
    ELECTRONICS, 2022, 11 (21)