Cyber security training a survey of serious games in cyber security
Jin-Ning Tioh, Mani Mina, Doug Jacobson · 2017
Within the field of computer and information security, there has been a relatively recent surge of interest on a multitude of topics, ranging from secure programming practices, protocols and algorithm design to cryptography and ethics. However, this body of research typically focuses on the implementation or theory of security controls and mechanisms at the application, operating system, network, and physical layers. The user layer, long recognized as the weakest link in the security chain, has had little to no attention paid to it by comparison, especially from a sociotechnical perspective which is comparatively new to engineering. Thus steps have to be taken then to instill safe cyber security practices in the general computer user, overcoming their propensity to act without forethought for the consequence of their actions, including ignoring warning messages, visiting unsafe websites, and communicating with unauthenticated entities. While there are significant studies that show the importance of game-based learning for the process of cognitive development and learning concepts of students, there have been relatively few papers or attempts at presenting forms of assessing the potential of these resources. Here then, we will endeavor to present a brief overview of the necessary background as well as a concise view of the current state of serious games dealing specifically with the topic of cyber security.