A Data-driven Security Game to Facilitate Information Security Education

被引:2
|
作者
Lovgren, Dag Erik Homdrum [1 ]
Li, Jingyue [2 ]
Oyetoyan, Tosin Daniel [3 ]
机构
[1] Acando AS, Digital Core Trondheim, Trondheim, Norway
[2] Norwegian Univ Sci & Technol, Dept Comp Sci, Trondheim, Norway
[3] Western Norway Univ Appl Sci, Dept Comp Math & Phys, Bergen, Norway
关键词
Information security; serious game; game-based education;
D O I
10.1109/ICSE-Companion.2019.00102
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Many universities have started to educate students on how to develop secure software and systems. One challenge of teaching information security is that the curriculum can easily be outdated, because new attacks and mitigation approaches arise. It is therefore necessary to provide software developers with methods and tools that are attractive (e.g., computer games) for self-study and up-to-date information security knowledge during and after the university education. This paper presents an on-going study to develop an educational game to facilitate information security education. The game is developed as a single player Tower Defense (TD) game. The educational goal of the game is to teach developers, who are not security experts, how to choose proper mitigation strategies and patterns to defend against various security attack scenarios. One key benefit of our game is that it is data driven, meaning, it can continuously fetch data from relevant security-based online sources (e.g., Common Attack Pattern Enumeration Classification CAPEC) to stay up to date with any new information. This is done automatically. We evaluated the game by letting students play it and give comments. Evaluation results show that the game can facilitate students learning of mitigation strategies to defend against attack scenarios.
引用
收藏
页码:256 / 257
页数:2
相关论文
共 50 条
  • [21] A Framework for Data-Driven Physical Security and Insider Threat Detection
    Mavroeidis, Vasileios
    Vishi, Kamer
    Josang, Audun
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM), 2018, : 1108 - 1115
  • [22] Quantifying Security Risks in Cloud Infrastructures: A Data-driven Approach
    Tarahomi, Sousan
    Holz, Ralph
    Sperotto, Anna
    2023 IEEE 9TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT, 2023, : 346 - 349
  • [23] DATA-DRIVEN FIELD MAPPING OF SECURITY LOGS FOR INTEGRATED MONITORING
    Choi, Seungoh
    Kim, Yesol
    Yun, Jeong-Han
    Min, Byung-Gil
    Kim, Hyoung-Chun
    CRITICAL INFRASTRUCTURE PROTECTION XIII, 2019, 570 : 253 - 268
  • [24] Attack and Defense: Adversarial Security of Data-Driven FDC Systems
    Zhuo, Yue
    Yin, Zhenqin
    Ge, Zhiqiang
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (01) : 5 - 19
  • [25] Security in data-driven satellite applications: An overview and new perspectives
    Kong, Qinglei
    Liu, Jian
    Qu, Xiaodong
    Chen, Bo
    Bao, Haiyong
    Xu, Lexi
    SIGNAL PROCESSING, 2025, 228
  • [26] Data-Driven Security for Smart City Systems: Carving a Trail
    Mohamed, Nader
    Al-Jaroodi, Jameela
    Jawhar, Imad
    Kesserwan, Nader
    IEEE ACCESS, 2020, 8 : 147211 - 147230
  • [27] An efficient security data-driven approach for implementing risk assessment
    Shameli-Sendi, Alireza
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 54
  • [28] A Data-Driven Evaluation of the Current Security State of Android Devices
    Leierzopf, Ernst
    Mayrhofer, Rene
    Roland, Michael
    Studier, Wolfgang
    Dean, Lawrence
    Seiffert, Martin
    Putz, Florentin
    Becker, Lucas
    Thomas, Daniel R.
    2024 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS 2024, 2024,
  • [29] Security-Aware Data-Driven Intelligent Transportation Systems
    Malik, Jahanzaib
    Akhunzada, Adnan
    Bibi, Iram
    Talha, Muhammad
    Jan, Mian Ahmad
    Usman, Muhammad
    IEEE SENSORS JOURNAL, 2021, 21 (14) : 15859 - 15866
  • [30] Data-driven security controller design for unknown networked systems
    Hu, Songlin
    Yue, Dong
    Jiang, Zhongrui
    Xie, Xiangpeng
    Zhang, Jin
    AUTOMATICA, 2025, 171