DocumentCode
704951
Title
Design and evaluation of competition-based hacking exercises
Author
Alashwali, Eman ; Ben-Abdallah, Hanene
Author_Institution
Inf. Syst. Dept., King Abdulaziz Univ., Jeddah, Saudi Arabia
fYear
2015
fDate
18-20 March 2015
Firstpage
998
Lastpage
1007
Abstract
This paper describes the design and delivery of two competition-based small offensive security exercises in an undergraduate Computer and Information Security course at the Faculty of Computing and Information Technology, King Abdulaziz University. We designed competition scenarios for two small exercises based on known attacks. The first exercise aimed to break the Windows Server 2008 password, and the second sought to break the Wired Equivalent Privacy (WEP) wireless network key (password). We present the competition scenarios and design, including the required hardware and software in each exercise. In addition, we give an overview about the attacks and possible defenses against them. We also present the results of a survey conducted to determine students´ sentiments towards these types of exercises and to measure the effectiveness of these exercises in supporting the course´s theoretical concepts from the student perspective. The results strongly suggest that the exercises were informative, motivating, stimulating, and enjoyable. This work was only the first step for us. We look forward to creating more challenging competition-based exercises and rewarding the teams that put forth superior efforts.
Keywords
authorisation; computer science education; educational courses; further education; Faculty of Computing and Information Technology; King Abdulaziz University; WEP; Windows Server 2008 password; competition-based hacking exercises; competition-based small offensive security exercises; undergraduate computer and information security course; wired equivalent privacy; wireless network key; Computer crime; Dictionaries; Facebook; Servers; Software; Virtual machining; Computer hacking; Computer science education; Education; Engineering education; Information security; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Engineering Education Conference (EDUCON), 2015 IEEE
Conference_Location
Tallinn
Type
conf
DOI
10.1109/EDUCON.2015.7096095
Filename
7096095
Link To Document