首页> 外文期刊>Information and software technology >Design and preliminary evaluation of a cyber Security Requirements Education Game (SREG)
【24h】

Design and preliminary evaluation of a cyber Security Requirements Education Game (SREG)

机译:网络安全需求教育游戏(SREG)的设计和初步评估

获取原文
获取原文并翻译 | 示例
           

摘要

Context: Security, in digitally connected organizational environments of today, involves many different perspectives, including social, physical, and technical factors. In order to understand the interactions among these correlated aspects and elicit potential threats geared towards a given organization, different security requirements analysis approaches are proposed in the literature. However, the body of knowledge is yet to unleash its full potential due to the complex nature of security problems, and inadequate ways to improve security awareness of key players in the organization. Objective: Objective(s) of the research study is to improve the security awareness of players utilizing serious games via: (i) Know-how of security concepts and security protection; (ii) guided process of identifying valuable assets and vulnerabilities in a given organizational setting; (iii) guided process of defining successful security attacks to the organization. Method: Important methods used to address the above objectives include: (i) a comprehensive review of the literature to better understand security and game design elements; (ii) designing a serious game using cyber security knowledge and game-based techniques combined with security requirements engineering concepts; (iii) using empirical evaluation (observation and survey) to verify the effectiveness of the proposed game design. Result: The solution proposed is a serious game for security requirements education, which: (i) can be an effective and fun way of learning security related concepts; (ii) mimics a real life problem setting in a presentable and understandable way; (iii) motivates players to learn more about security related concepts in future. Conclusion: From this study, we conclude that the proposed Security Requirement Education Game (SREG) has positive results and is helpful for players of the game to get an understanding of security attacks and vulnerabilities.
机译:上下文:在当今数字连接的组织环境中,安全涉及许多不同的角度,包括社会,物理和技术因素。为了理解这些相关方面之间的相互作用并引发针对给定组织的潜在威胁,文献中提出了不同的安全需求分析方法。但是,由于安全问题的复杂性以及提高组织中主要角色的安全意识的方法不足,知识体系尚未发挥其全部潜力。目标:本研究的目的是通过以下方面提高使用严肃游戏的玩家的安全意识:(i)安全概念和安全保护方面的知识; (ii)在给定组织环境中识别有价值资产和漏洞的指导过程; (iii)为组织定义成功的安全攻击的指导过程。方法:用于实现上述目标的重要方法包括:(i)全面回顾文献以更好地理解安全性和游戏设计元素; (ii)使用网络安全知识和基于游戏的技术并结合安全需求工程概念来设计一款严肃的游戏; (iii)使用经验评估(观察和调查)来验证拟议游戏设计的有效性。结果:提出的解决方案是认真的安全需求教育游戏,它:(i)是学习安全相关概念的一种有效而有趣的方式; (ii)以表象和可理解的方式模仿现实生活中的问题; (iii)激励玩家将来更多地了解与安全相关的概念。结论:通过这项研究,我们得出结论,建议的安全需求教育游戏(SREG)取得了积极的成果,并且有助于该游戏的玩家了解安全攻击和漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号