• DocumentCode
    704951
  • Title

    Design and evaluation of competition-based hacking exercises

  • Author

    Alashwali, Eman ; Ben-Abdallah, Hanene

  • Author_Institution
    Inf. Syst. Dept., King Abdulaziz Univ., Jeddah, Saudi Arabia
  • fYear
    2015
  • fDate
    18-20 March 2015
  • Firstpage
    998
  • Lastpage
    1007
  • Abstract
    This paper describes the design and delivery of two competition-based small offensive security exercises in an undergraduate Computer and Information Security course at the Faculty of Computing and Information Technology, King Abdulaziz University. We designed competition scenarios for two small exercises based on known attacks. The first exercise aimed to break the Windows Server 2008 password, and the second sought to break the Wired Equivalent Privacy (WEP) wireless network key (password). We present the competition scenarios and design, including the required hardware and software in each exercise. In addition, we give an overview about the attacks and possible defenses against them. We also present the results of a survey conducted to determine students´ sentiments towards these types of exercises and to measure the effectiveness of these exercises in supporting the course´s theoretical concepts from the student perspective. The results strongly suggest that the exercises were informative, motivating, stimulating, and enjoyable. This work was only the first step for us. We look forward to creating more challenging competition-based exercises and rewarding the teams that put forth superior efforts.
  • Keywords
    authorisation; computer science education; educational courses; further education; Faculty of Computing and Information Technology; King Abdulaziz University; WEP; Windows Server 2008 password; competition-based hacking exercises; competition-based small offensive security exercises; undergraduate computer and information security course; wired equivalent privacy; wireless network key; Computer crime; Dictionaries; Facebook; Servers; Software; Virtual machining; Computer hacking; Computer science education; Education; Engineering education; Information security; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Engineering Education Conference (EDUCON), 2015 IEEE
  • Conference_Location
    Tallinn
  • Type

    conf

  • DOI
    10.1109/EDUCON.2015.7096095
  • Filename
    7096095