Logo
User: Guest  Login
Authors:
Hafner, Lukas; Wutz, Florian; Pöhn, Daniela; Hommel, Wolfgang 
Document type:
Konferenzbeitrag / Conference Paper 
Title:
TASEP: A Collaborative Social Engineering Tabletop Role-Playing Game to Prevent Successful Social Engineering Attacks 
Title of conference publication:
ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security 
Conference title:
International Conference on Availability, Reliability and Security (18., 2023, Benevento, Italy) 
Venue:
Benevento, Italy 
Year of conference:
2023 
Date of conference beginning:
29.08.2023 
Date of conference ending:
01.09.2023 
Place of publication:
New York, NY, USA 
Publisher:
Association for Computing Machinery 
Year:
2023 
Pages from - to:
67 
Language:
Englisch 
Keywords:
awareness ; tabletop ; serious game ; education ; Social engineering ; gamification 
Abstract:
Data breaches resulting from targeted attacks against organizations, e. g., by advanced persistent threat groups, often involve social engineering (SE) as the initial attack vector before malicious software is used, e. g., for persistence, lateral movement, and data exfiltration. While technical security controls, such as the automated detection of phishing emails, can contribute to mitigating SE risks, raising awareness for SE attacks through education and motivation of personnel is an important building block to increasing an organization’s resilience. To facilitate hands-on SE awareness training as one component of broader SE awareness campaigns, we created a SE tabletop game called Tabletop As Social Engineering Prevention (TASEP) in two editions for (a) small and medium enterprises and (b) large corporations, respectively. Its game design is inspired by Dungeons & Dragons role-playing games and facilitates LEGO models of the in-game target organizations. Participants switch roles by playing a group of SE penetration testers and conducting a security audit guided by the game master. We evaluated the created game with different student groups, achieving highly immersive and flexible training, resulting in an entertaining way of learning about SE and raising awareness. 
ISBN:
979-8-4007-0772-8 
Article ID:
67 
Department:
Fakultät für Informatik 
Institute:
INF 2 - Institut für Softwaretechnologie 
Chair:
Hommel, Wolfgang 
Open Access yes or no?:
Nein / No