WebHOLE: Developing a web-based hands-on learning environment to assist beginners in learning web application security

被引:1
作者
Su, Jun-Ming [1 ]
机构
[1] Natl Univ Tainan, Dept Informat & Learning Technol, Tainan, Taiwan
关键词
Cybersecurity education; Web application security; Practical hands-on ability; Hands-on learning; Web-based learning; Portfolio analysis; CYBERSECURITY EDUCATION; FRAMEWORK; KNOWLEDGE;
D O I
10.1007/s10639-023-12090-z
中图分类号
G40 [教育学];
学科分类号
040101 ; 120403 ;
摘要
With the rapid growth of web applications, web application security (WAS) has become an important cybersecurity issue. For effective WAS protection, it is necessary to cultivate and train personnel, especially beginners, to develop correct concepts and practical hands-on abilities through cybersecurity education. At present, many methods offer vulnerable web environments to support practical hands-on training, including large-scale "Capture the Flag" mode (e.g., Cyber Range), pre-configured virtual machine images (e.g., Mutillidae), pre-built stand-alone applications (e.g., WebGoat), and web-based system (e.g., Damn Vulnerable Web Application). However, beginners need not only hands-on training tools and systems but also assistance to support effective learning. Moreover, pre-built training content and exercises are usually not easy to modify and thus lack the flexibility to meet specific teaching needs. Therefore, this study proposed and developed the Web-based Hands-On Learning Environment (WebHOLE) to efficiently assist beginners in learning WAS. To improve the flexibility of the training content, a web-based authoring tool was developed in WebHOLE to create customized hands-on learning exercises. Accordingly, learners can learn and practice the WAS training content online with learning assistance provided by the hands-on learning system. The hands-on abilities of the learners can be efficiently assessed by the hands-on testing system using online exams with progressive hints and automatic grading. Furthermore, to improve the effectiveness of teaching and testing, a portfolio analysis scheme using a data mining technique was developed to identify learning barriers and problematic test items. WebHOLE was applied to an actual beginner-level WAS course for undergraduate students. The experimental results showed the benefits of WebHOLE on WAS learning, with a significant improvement in learning outcomes. Students expressed high satisfaction with WebHOLE's learning assistance, rating it with average satisfaction scores above 4.0 out of 5.0. The portfolio analysis scheme also showed the effectiveness of WebHOLE in identifying learning problems and refining test items.
引用
收藏
页码:6579 / 6610
页数:32
相关论文
共 50 条
[21]   Web-based learning: Effects on learning process and outcome [J].
Khalifa, M ;
Lam, R .
IEEE TRANSACTIONS ON EDUCATION, 2002, 45 (04) :350-356
[22]   Personalisation in Web-Based Learning Environments [J].
Santally, Mohammad Issack ;
Alain, Senteni .
INTERNATIONAL JOURNAL OF DISTANCE EDUCATION TECHNOLOGIES, 2006, 4 (04) :15-35
[23]   A model for a web-based learning system [J].
Vincenza Carchiolo ;
Alessandro Longheu ;
Michele Malgeri ;
Giuseppe Mangioni .
Information Systems Frontiers, 2007, 9 :267-282
[24]   Designing web-based collaborative learning [J].
Simsek, A .
Methods and Technologies for Learning, 2005, :217-221
[25]   A Hands-on Modular Laboratory Environment to Foster Learning in Control System Security [J].
Deshmukh, Pallavi P. ;
Patterson, Cameron D. ;
Baumann, William T. .
2016 IEEE FRONTIERS IN EDUCATION CONFERENCE (FIE), 2016,
[26]   Web-based learning in a geometry course [J].
Chan, Hsungrow ;
Tsai, Pengheng ;
Huang, Tien-Yu .
EDUCATIONAL TECHNOLOGY & SOCIETY, 2006, 9 (02) :133-140
[27]   WEB-BASED LEARNING IN MECHANICAL DESIGN [J].
Yaldiz, Suleyman ;
Neseli, Suleyman .
PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON VIRTUAL LEARNING: VIRTUAL LEARNING - VIRTUAL REALITY: MODELS & METHODOLOGIES, TECHNOLOGIES, SOFTWARE SOLUTIONS, 2007, :163-170
[28]   Gamification of Web-Based Learning Services [J].
Klamma, Ralf ;
Arifin, Muhammad Abduh .
ADVANCES IN WEB-BASED LEARNING, ICWL 2017, 2017, 10473 :43-48
[29]   A general Critical Care Ultrasonography workshop: results of a novel Web-based learning program combined with simulation-based hands-on training [J].
Sekiguchi, Hiroshi ;
Bhagra, Anjali ;
Gajic, Ognjen ;
Kashani, Kianoush B. .
JOURNAL OF CRITICAL CARE, 2013, 28 (02) :217.e7-217.e12
[30]   Learner Cognitive Behavior and Influencing Factors in Web-based Learning Environment [J].
Madhusudhana, Kalla .
INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (08) :542-546