(2022). Analysis and Evaluation of Capture the Flag Challenges in Secure Mobile Application Development. International Journal on Integrating Technology in Education, 11(2), 19–35. https://doi.org/10.5121/ijite.2022.11202
Περίληψη
Capture the Flag (CTF) challenges are frequently used as cybersecurity learning environments to engage students in cybersecurity education activities and learning, focusing on technical concepts. CTF challenges cover various learning topics. However, they do not always maintain a clear learning outcome. In this paper, we present a systematic approach to study and evaluate CTF challenges, then apply the evaluation methodology in two CTF challenges that relate to the development of secure mobile applications. For this proof of concept, we used the National Initiative for Cybersecurity Education (NICE) which is a cybersecurity educational framework published by the National Institute of Standards and Technology (NIST). Additional information was used for the evaluation process which included threat, vulnerability, and weakness taxonomies proposed by Open Web Application Security Project® (OWASP) and Mitre Corporation (MITRE). The evaluation methodology could be used to assess and determine the learning outcomes of other existing or upcoming CTF challenges, including though not limited to secure mobile application development.
- DOI
- 10.5121/ijite.2022.11202
- Τύπος
- Άρθρο σε Περιοδικό
- Έτος
- 2022
Σύνδεσμοι
BibTeX
@article{karagiannis2022analysis,
title = {Analysis and Evaluation of Capture the Flag Challenges in Secure Mobile Application Development},
author = {Stylianos Karagiannis and Emmanouil Magkos and George Chalavazis and Maria Nefeli Nikiforos},
url = {https://doi.org/10.5121/ijite.2022.11202},
doi = {10.5121/ijite.2022.11202},
year = {2022},
date = {2022-01-01},
journal = {International Journal on Integrating Technology in Education},
volume = {11},
number = {2},
pages = {19–35},
publisher = {Academy and Industry Research Collaboration Center (AIRCC)},
abstract = {Capture the Flag (CTF) challenges are frequently used as cybersecurity learning environments to engage students in cybersecurity education activities and learning, focusing on technical concepts. CTF challenges cover various learning topics. However, they do not always maintain a clear learning outcome. In this paper, we present a systematic approach to study and evaluate CTF challenges, then apply the evaluation methodology in two CTF challenges that relate to the development of secure mobile applications. For this proof of concept, we used the National Initiative for Cybersecurity Education (NICE) which is a cybersecurity educational framework published by the National Institute of Standards and Technology (NIST). Additional information was used for the evaluation process which included threat, vulnerability, and weakness taxonomies proposed by Open Web Application Security Project® (OWASP) and Mitre Corporation (MITRE). The evaluation methodology could be used to assess and determine the learning outcomes of other existing or upcoming CTF challenges, including though not limited to secure mobile application development.},
keywords = {},
pubstate = {published},
tppubtype = {article}
}
