TASEP: A Collaborative Social Engineering Tabletop Role-Playing Game to Prevent Successful Social Engineering Attacks

被引:1
作者
Hafner, Lukas [1 ]
Wutz, Florian [1 ]
Poehn, Daniela [1 ]
Hommel, Wolfgang [1 ]
机构
[1] Univ Bundeswehr Munchen, RI CODE, Neubiberg, Germany
来源
18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023 | 2023年
关键词
Social engineering; gamification; tabletop; serious game; education; awareness;
D O I
10.1145/3600160.3605005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Data breaches resulting from targeted attacks against organizations, e. g., by advanced persistent threat groups, often involve social en-gineering (SE) as the initial attack vector before malicious software is used, e. g., for persistence, lateral movement, and data exfiltration. While technical security controls, such as the automated detection of phishing emails, can contribute to mitigating SE risks, raising awareness for SE attacks through education and motivation of personnel is an important building block to increasing an organiza-tion's resilience. To facilitate hands-on SE awareness training as one component of broader SE awareness campaigns, we created a SE tabletop game called Tabletop As Social Engineering Preven-tion (TASEP) in two editions for (a) small and medium enterprises and (b) large corporations, respectively. Its game design is inspired by Dungeons & Dragons role-playing games and facilitates LEGO models of the in-game target organizations. Participants switch roles by playing a group of SE penetration testers and conducting a security audit guided by the game master. We evaluated the created game with different student groups, achieving highly immersive and flexible training, resulting in an entertaining way of learning about SE and raising awareness.
引用
收藏
页数:20
相关论文
共 36 条
[1]  
Abt CC., 1987, Serious Games
[2]   An Academic Review of Current Industrial and Commercial Cyber Security Social Engineering Solutions [J].
Aldawood, Hussain ;
Skinner, Geoffrey .
PROCEEDINGS OF 2019 THE 3RD INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP 2019) WITH WORKSHOP 2019 THE 4TH INTERNATIONAL CONFERENCE ON MULTIMEDIA AND IMAGE PROCESSING (ICMIP 2019), 2019, :110-115
[3]   A Serious Game for Eliciting Social Engineering Security Requirements [J].
Beckers, Kristian ;
Pape, Sebastian .
2016 IEEE 24TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE), 2016, :16-25
[4]  
Block Florian, 2008, 2008 IEEE International Workshop on Horizontal Interactive Human Computer Systems (TABLETOP), P17, DOI 10.1109/TABLETOP.2008.4660178
[5]   You Have my Sword; and my Bow; and my Axe: Player Perceptions of Odd Shaped Dice for Dungeons & Dragons [J].
Borodina, Kamilla ;
Aslam, Hamna ;
Brown, Joseph Alexander .
PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON THE FOUNDATIONS OF DIGITAL GAMES (FDG'19), 2019,
[6]  
BrickLink, 2023, Studio 2.0
[7]  
CAINE RN, 1990, EDUC LEADERSHIP, V48, P66
[8]  
Chang Y. L. B., 2014, P 9 ACM INT C INT TA, P185, DOI DOI 10.1145/2669485.2669496
[9]  
Costantino G, 2018, VEH TECHNOL CONFE
[10]  
Decusatis Casimer, 2022, Gamify 2022: Proceedings of the 1st International Workshop on Gamification of Software Development, Verification, and Validation, P10, DOI 10.1145/3548771.3561409