• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Yasin, Affan (Yasin, Affan.) | Liu, Lin (Liu, Lin.) | Li, Tong (Li, Tong.) | Wang, Jianmin (Wang, Jianmin.) | Zowghi, Didar (Zowghi, Didar.)

收录:

SSCI EI Scopus SCIE

摘要:

Context: Security, in digitally connected organizational environments of today, involves many different perspectives, including social, physical, and technical factors. In order to understand the interactions among these correlated aspects and elicit potential threats geared towards a given organization, different security requirements analysis approaches are proposed in the literature. However, the body of knowledge is yet to unleash its full potential due to the complex nature of security problems, and inadequate ways to improve security awareness of key players in the organization. Objective: Objective(s) of the research study is to improve the security awareness of players utilizing serious games via: (i) Know-how of security concepts and security protection; (ii) guided process of identifying valuable assets and vulnerabilities in a given organizational setting; (iii) guided process of defining successful security attacks to the organization. Method: Important methods used to address the above objectives include: (i) a comprehensive review of the literature to better understand security and game design elements; (ii) designing a serious game using cyber security knowledge and game-based techniques combined with security requirements engineering concepts; (iii) using empirical evaluation (observation and survey) to verify the effectiveness of the proposed game design. Result: The solution proposed is a serious game for security requirements education, which: (i) can be an effective and fun way of learning security related concepts; (ii) mimics a real life problem setting in a presentable and understandable way; (iii) motivates players to learn more about security related concepts in future. Conclusion: From this study, we conclude that the proposed Security Requirement Education Game (SREG) has positive results and is helpful for players of the game to get an understanding of security attacks and vulnerabilities.

关键词:

Cyber security Empirical study Organizational security Requirements engineering Security awareness Security education Security requirements inception Serious game Social engineering

作者机构:

  • [ 1 ] [Yasin, Affan]Tsinghua Univ, Sch Software, Beijing, Peoples R China
  • [ 2 ] [Liu, Lin]Tsinghua Univ, Sch Software, Beijing, Peoples R China
  • [ 3 ] [Wang, Jianmin]Tsinghua Univ, Sch Software, Beijing, Peoples R China
  • [ 4 ] [Li, Tong]Beijing Univ Technol, Fac Informat Technol, Beijing, Peoples R China
  • [ 5 ] [Zowghi, Didar]Univ Technol Sydney, Fac Engn & IT, Sydney, NSW, Australia

通讯作者信息:

  • [Liu, Lin]Tsinghua Univ, Sch Software, Beijing, Peoples R China

查看成果更多字段

相关关键词:

相关文章:

来源 :

INFORMATION AND SOFTWARE TECHNOLOGY

ISSN: 0950-5849

年份: 2018

卷: 95

页码: 179-200

3 . 9 0 0

JCR@2022

ESI学科: COMPUTER SCIENCE;

ESI高被引阀值:81

JCR分区:1

被引次数:

WoS核心集被引频次: 41

SCOPUS被引频次: 42

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 2

归属院系:

在线人数/总访问数:336/2893528
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司