Logo
Benutzer: Gast  Login
Autoren:
Hafner, Lukas; Wutz, Florian; Pöhn, Daniela; Hommel, Wolfgang 
Dokumenttyp:
Konferenzbeitrag / Conference Paper 
Titel:
TASEP: A Collaborative Social Engineering Tabletop Role-Playing Game to Prevent Successful Social Engineering Attacks 
Titel Konferenzpublikation:
ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security 
Konferenztitel:
International Conference on Availability, Reliability and Security (18., 2023, Benevento, Italy) 
Tagungsort:
Benevento, Italy 
Jahr der Konferenz:
2023 
Datum Beginn der Konferenz:
29.08.2023 
Datum Ende der Konferenz:
01.09.2023 
Verlagsort:
New York, NY, USA 
Verlag:
Association for Computing Machinery 
Jahr:
2023 
Seiten von - bis:
67 
Sprache:
Englisch 
Stichwörter:
awareness ; tabletop ; serious game ; education ; Social engineering ; gamification 
Abstract:
Data breaches resulting from targeted attacks against organizations, e. g., by advanced persistent threat groups, often involve social engineering (SE) as the initial attack vector before malicious software is used, e. g., for persistence, lateral movement, and data exfiltration. While technical security controls, such as the automated detection of phishing emails, can contribute to mitigating SE risks, raising awareness for SE attacks through education and motivation of personnel is an important building block to increasing an organization’s resilience. To facilitate hands-on SE awareness training as one component of broader SE awareness campaigns, we created a SE tabletop game called Tabletop As Social Engineering Prevention (TASEP) in two editions for (a) small and medium enterprises and (b) large corporations, respectively. Its game design is inspired by Dungeons & Dragons role-playing games and facilitates LEGO models of the in-game target organizations. Participants switch roles by playing a group of SE penetration testers and conducting a security audit guided by the game master. We evaluated the created game with different student groups, achieving highly immersive and flexible training, resulting in an entertaining way of learning about SE and raising awareness. 
ISBN:
979-8-4007-0772-8 
Article-ID:
67 
Fakultät:
Fakultät für Informatik 
Institut:
INF 2 - Institut für Softwaretechnologie 
Professur:
Hommel, Wolfgang 
Open Access ja oder nein?:
Nein / No