Ciência_Iscte
Publicações
Descrição Detalhada da Publicação
Bring your own bug: Enabling user-generated content in serious games for industrial cybersecurity and AppSec education
Innovations for community services: 25th International Conference, I4CS 2025, Proceedings
Ano (publicação definitiva)
2025
Língua
Inglês
País
Alemanha
Mais Informação
Web of Science®
Scopus
Google Scholar
Esta publicação não está indexada no Overton
Abstract/Resumo
This work investigates the integration of User Generated Content in a Serious Game for cybersecurity education and training in the industry. This Serious Game deals with security code reviews as part of an industrial software lifecycle, and players are invited to review vulnerable snippets to gain awareness of secure coding. We design and implement a way to include User Generated Content contributions into the Serious Game and we evaluate how this approach in cybersecurity education opens a path for a community-driven initiative to gather and share security knowledge. We develop an open contribution pipeline that allows developers to submit security-relevant code snippets in the Serious Games challenge collection, for players of the game to review, and present the technical design choices behind it: automating the integration of content, acceptance quality gates, and the potential for custom data analytics from recorded player interactions. Furthermore, we explore the voluntary contributors’ perceptions of the ease of contribution (with respect to our proposed convention for challenge snippets) and also investigate the characteristics of what is considered an effective educational snippet.
Agradecimentos/Acknowledgements
--
Palavras-chave
Code review,Secure coding,Cybersecurity,Education,Awareness,Information systems,User-generated content
Classificação Fields of Science and Technology
- Matemáticas - Ciências Naturais
- Ciências da Computação e da Informação - Ciências Naturais
Registos de financiamentos
| Referência de financiamento | Entidade Financiadora |
|---|---|
| UIDB/04466/2020 | Fundação para a Ciência e a Tecnologia |
English