Analysis and Evaluation of Capture the Flag Challenges in Secure Mobile Application Development

Karagiannis, S., Magkos, E., Chalavazis, G., & Nikiforos, M. N. (2022). Analysis and Evaluation of Capture the Flag Challenges in Secure Mobile Application Development. International Journal on Integrating Technology in Education, 11(2), 19–35. https://doi.org/10.5121/ijite.2022.11202

Περίληψη

Capture the Flag (CTF) challenges are frequently used as cybersecurity learning environments to engage students in cybersecurity education activities and learning, focusing on technical concepts. CTF challenges cover various learning topics. However, they do not always maintain a clear learning outcome. In this paper, we present a systematic approach to study and evaluate CTF challenges, then apply the evaluation methodology in two CTF challenges that relate to the development of secure mobile applications. For this proof of concept, we used the National Initiative for Cybersecurity Education (NICE) which is a cybersecurity educational framework published by the National Institute of Standards and Technology (NIST). Additional information was used for the evaluation process which included threat, vulnerability, and weakness taxonomies proposed by Open Web Application Security Project® (OWASP) and Mitre Corporation (MITRE). The evaluation methodology could be used to assess and determine the learning outcomes of other existing or upcoming CTF challenges, including though not limited to secure mobile application development.

DOI
10.5121/ijite.2022.11202
Τύπος
Άρθρο σε Περιοδικό
Έτος
2022

Σύνδεσμοι

BibTeX

@article{karagiannis2022analysis,
title = {Analysis and Evaluation of Capture the Flag Challenges in Secure Mobile Application Development},
author = {Stylianos Karagiannis and Emmanouil Magkos and George Chalavazis and Maria Nefeli Nikiforos},
url = {https://doi.org/10.5121/ijite.2022.11202},
doi = {10.5121/ijite.2022.11202},
year  = {2022},
date = {2022-01-01},
journal = {International Journal on Integrating Technology in Education},
volume = {11},
number = {2},
pages = {19–35},
publisher = {Academy and Industry Research Collaboration Center (AIRCC)},
abstract = {Capture the Flag (CTF) challenges are frequently used as cybersecurity learning environments to engage students in cybersecurity education activities and learning, focusing on technical concepts. CTF challenges cover various learning topics. However, they do not always maintain a clear learning outcome. In this paper, we present a systematic approach to study and evaluate CTF challenges, then apply the evaluation methodology in two CTF challenges that relate to the development of secure mobile applications. For this proof of concept, we used the National Initiative for Cybersecurity Education (NICE) which is a cybersecurity educational framework published by the National Institute of Standards and Technology (NIST). Additional information was used for the evaluation process which included threat, vulnerability, and weakness taxonomies proposed by Open Web Application Security Project® (OWASP) and Mitre Corporation (MITRE). The evaluation methodology could be used to assess and determine the learning outcomes of other existing or upcoming CTF challenges, including though not limited to secure mobile application development.},
keywords = {},
pubstate = {published},
tppubtype = {article}
}

« Όλες οι δημοσιεύσεις