论文标题
“ Perihack”:为网络安全意识设计严肃的游戏
'PeriHack': Designing a Serious Game for Cybersecurity Awareness
论文作者
论文摘要
本文描述了网络安全严重游戏“ Perihack”的设计过程。 Perihack是根据CC(BY-NC-SA)许可证公开发布的,是针对两名球员或团队的董事会和纸牌游戏,这些球员或团队模拟了红色团队(攻击者)与蓝色团队(后卫)之间的斗争。游戏要求玩家探索寻找漏洞的样本网络,然后链接不同的攻击,以利用不同性质的可能弱点,这可能包括技术和社会工程学利用。同时,它还通过提供有限的资源来评估和优先考虑不同的关键漏洞来模拟蓝色团队的预算水平限制。该游戏是通过年龄和6-11框架的镜头讨论的,主要设计为网络安全和技术与技术领域的学生的学习工具。
This paper describes the design process for the cybersecurity serious game 'PeriHack'. Publicly released under a CC (BY-NC-SA) license, PeriHack is a board and card game for two players or teams that simulates the struggle between a red team (attackers) and a blue team (defenders). The game requires players to explore a sample network looking for vulnerabilities and then chain different attacks to exploit possible weaknesses of different nature, which may include both technical and social engineering exploits. At the same time, it also simulates budget level constraints for the blue team by providing limited resources to evaluate and prioritize different critical vulnerabilities. The game is discussed via the lenses of the AGE and 6-11 Frameworks and was primarily designed as a learning tool for students in the cybersecurity and technology related fields.