«Συγκριτική ανάλυση εργαλείων εκμάθησης ασφάλειας βασισμένων σε προκλήσεις, στα πεδία των κινητών εφαρμογών, και Συσχέτιση με το εκπαιδευτικό πλαίσιο του NIST»
Date Issued
September 22, 2021
Type
Πτυχιακή Εργασία
Abstract
The present paper concerns the study and evaluation of Capture The Flag (CTF) exercises that present significant vulnerabilities in mobile applications. The main goal is to correlate the cognitive categories and skills available from the existing educational frameworks in order to explore the educational benefits of such exercises. Vulnerabilities, and more specifically the analysis and assessment of the effects of threats, are studied in order to highlight how each exercise is related to some of the vulnerabilities. At the same time, new users have the opportunity, utilizing exercises offered through work, to perform exercises on mobile devices gaining knowledge and technical experience. In this way they can form a proper response to vulnerabilities and breaches of security in this particular field.
The research contribution of this paper is based on the creation and promotion of educational methodology, which correlates the vulnerabilities of mobile devices and applications with the vulnerabilities presented by the exercises. The purpose is to educate new users using well-known security frameworks such as the National Initiative for Cybersecurity Education (NICE), a training framework from NIST. More specifically, we are investigating the possible association of the NIST framework with two virtual labs that report and present vulnerabilities for mobile applications by analyzing the challenges of such an association. The purpose is to create a methodology for classifying the exercises selected with the existing educational contexts.
Subjects
