Using a CTF Activity to Teach Cloud and Web Security

dc.contributor.authorCoffman, Joel
dc.contributor.authorRomano, Zachary
dc.contributor.authorWindsor, Jennifer
dc.contributor.authorVanderpol, Mathew
dc.date.accessioned2021-12-24T17:25:46Z
dc.date.available2021-12-24T17:25:46Z
dc.date.issued2022-01-04
dc.description.abstractWhile cloud computing is an attractive option in terms of price, availability, and scalability, cloud consumers must also weigh the security concerns of a cloud environment. In particular, security breaches due to misconfiguration are common, and this prevalence starts with inadequate education and training. Consequently, we incorporated a capture the flag (CTF) activity into an existing course to illuminate the potential pitfalls and consequences of cloud misconfiguration and to encourage participants to protect against such issues in their own applications. In this paper, we report on the effectiveness of the CTF activity to achieve these goals. Our evaluation specifically focuses on participants' interests, self-perceptions, and application of essential security practices (e.g., defensive programming techniques) to defend against common types of attacks. Our results indicate that the CTF activity was perceived favorably by students, but participants performed comparably to their peers on independent assessments, including test questions related to web security and securing a web application developed as part of a course project. We examine these issues and suggest a path forward to address them, particularly by better aligning the CTF activity with the stated course outcomes in conjunction with collecting additional data in future semesters.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2022.129
dc.identifier.isbn978-0-9981331-5-7
dc.identifier.urihttp://hdl.handle.net/10125/79460
dc.language.isoeng
dc.relation.ispartofProceedings of the 55th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectIndustry, Quality, and Social Issues (IQSI)
dc.subjectcapture the flag (ctf)
dc.subjectcloud security
dc.subjecteducation
dc.titleUsing a CTF Activity to Teach Cloud and Web Security
dc.type.dcmitext

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0104.pdf
Size:
319.29 KB
Format:
Adobe Portable Document Format