Experiences in Cyber Security Education: The MIT Lincoln Laboratory Capture-the-Flag Exercise
Experiences in Cyber Security Education: The MIT Lincoln Laboratory Capture-the-Flag Exercise
复制标题
网络安全教育经验:麻省理工学院林肯实验室夺旗演习
DOI:
--
复制
发表时间:
2011
期刊:
影响因子:
--
通讯作者:
Nickolai Zeldovich
中科院分区:
文献类型:
--
作者:
Joseph Werther;M. Zhivich;T. Leek;Nickolai Zeldovich
Many popular and well-established cyber security Capture the Flag (CTF) exercises are held each year in a variety of settings, including universities and semiprofessional security conferences. CTF formats also vary greatly, ranging from linear puzzle-like challenges to team-based offensive and defensive free-for-all hacking competitions. While these events are exciting and important as contests of skill, they offer limited educational opportunities. In particular, since participation requires considerable a priori domain knowledge and practical computer security expertise, the majority of typical computer science students are excluded from taking part in these events. Our goal in designing and running the MIT/LL CTF was to make the experience accessible to a wider community by providing an environment that would not only test and challenge the computer security skills of the participants, but also educate and prepare those without an extensive prior expertise. This paper describes our experience in designing, organizing, and running an education-focused CTF, and discusses our teaching methods, game design, scoring measures, logged data, and lessons learned.