Gathering Insights from Teenagers’ Hacking Experience with Authentic Cybersecurity Tools

This Work-In-Progress Paper for the Innovative Practice Category presents a novel experiment in active learning of cybersecurity. We introduced a new workshop on hacking for an existing science-popularizing program at our university. The workshop participants, 28 teenagers, played a cybersecurity game designed for training undergraduates and professionals in penetration testing. Unlike in learning environments that are simplified for young learners, the game features a realistic virtual network infrastructure. This allows exploring security tools in an authentic scenario, which is complemented by a background story. Our research aim is to examine how young players approach using cybersecurity tools by interacting with the professional game. A preliminary analysis of the game session showed several challenges that the workshop participants faced. Nevertheless, they reported learning about security tools and exploits, and 61% of them reported wanting to learn more about cybersecurity after the workshop. Our results support the notion that young learners should be allowed more hands-on experience with security topics, both in formal education and informal extracurricular events.

[1]  Elizabeth Stobert,et al.  Teaching Authentication in High Schools: Challenges and Lessons Learned , 2017, ASE @ USENIX Security Symposium.

[2]  Vitaly Ford,et al.  Capture the Flag Unplugged: an Offline Cyber Competition , 2017, SIGCSE.

[3]  Tadayoshi Kohno,et al.  Practical Lessons from Creating the Control-Alt-Hack Card Game and Research Challenges for Games In Education and Research , 2014, 3GSE.

[4]  Tina Ladabouche,et al.  GenCyber: Inspiring the Next Generation of Cyber Stars , 2016, IEEE Security & Privacy.

[5]  David Brumley,et al.  PicoCTF: A Game-Based Computer Security Competition for High School Students , 2014, 3GSE.

[6]  Ian Goldberg,et al.  Live Lesson: Netsim: Network simulation and hacking for high schoolers , 2017, ASE @ USENIX Security Symposium.

[7]  Laurence D. Merkle,et al.  Assessing the Impact of a National Cybersecurity Competition on Students' Career Interests , 2018, SIGCSE.

[8]  Jan Vykopal,et al.  Challenges Arising from Prerequisite Testing in Cybersecurity Games , 2017, SIGCSE.

[9]  Jan Vykopal,et al.  Enhancing cybersecurity skills by creating serious games , 2018, ITiCSE.

[10]  Elissa M. Redmiles,et al.  A Summary of Survey Methodology Best Practices for Security and Privacy Researchers , 2017 .

[11]  Tom Chothia,et al.  Jail, Hero or Drug Lord? Turning a Cyber Security Course Into an 11 Week Choose Your Own Adventure Story , 2017, ASE @ USENIX Security Symposium.

[12]  Jan Vykopal,et al.  KYPO Cyber Range: Design and Use Cases , 2017, ICSOFT.