CyberCIEGE: Gaming for Information Assurance

نویسندگان

  • Cynthia E. Irvine
  • Michael F. Thompson
  • Ken Allen
چکیده

to apply them. Unfortunately, a disconnect often exists between principles and practice. Students sometimes feel that principles are boring or irrelevant, but without them, they can't go beyond " cookbook " remedies. In contrast, the competitive nature of matching wits with cyber-adversaries can be stimulating, but with perceptions molded by hyper-bolic news accounts, students can find critical conceptual issues elusive. As in many disciplines, effective information security requires both a practical and tacit understanding of the science and art of security engineering. Laboratory experiments can help convey these concepts, but a wide range of large-scale, realistic experiments would be too costly for most classrooms. Simulations thus provide a helpful alternative. To address the need for realistic laboratory simulations, educators and researchers have begun exploring the use of games for purposes other than entertainment, such as for education. By capturing students' imaginations and generating a sense of competition , games provide a stimulating environment in which the participant has a stake in the outcome. This emotional investment makes the student an active learner, and the visualization associated with a game can often help to teach or reinforce concepts. CyberCIEGE is a high-end, commercial-quality video game developed jointly by Rivermind and the Naval Postgraduate School's Center for Information Systems Security Studies and Research. 1–3 This dynamic, extensible game adheres to IA principles to help teach key concepts and practices. CyberCIEGE is a resource-management simulation in which the player assumes the role of a decision maker for an IT-dependent organization. The objective is to keep the organization's virtual users happy and productive while providing the necessary security measures to protect valuable information assets. Players face a limitless number of potential scenarios in which they have budgets and must make choices regarding procedural, technical , and physical security. With good choices, the organization prospers and the scenario advances; poor choices often result in disaster. Using the potential tension between strong security and user productivity , CyberCIEGE illustrates that many security choices involve risk management. Games such as Electronic Arts' The Sims and Atari's Roller-Coaster Tycoon illustrate the potential for resource-simulation tools to capture users' attention. They let players engage in planning and construction and observe the results of their choices. Cyber-CIEGE has a similar goal: players build and configure networks of computers, and their choices have visible effects on virtual users' ability to perform productive work and on attackers' ability to compromise assets. The …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

CyberCIEGE TM : An Information Assurance Teaching Tool for Training and Awareness

Good security is not intrusive and can be almost invisible to typical users, who are often unaware of or take it for granted. However, good security practice by user populations is a critical element of an organization’s information assurance strategy. This is reflected in government information assurance teaching mandates such as DoD Directive 8570.1, which outlines objectives and requirements...

متن کامل

Assurance Teaching Tool for Training and Awareness

Good security is not intrusive and can be almost invisible to typical users, who are often unaware of or take it for granted. However, good security practice by user populations is a critical element of an organization’s information assurance strategy. This is reflected in government information assurance teaching mandates such as DoD Directive 8570.1, which outlines objectives and requirements...

متن کامل

An Information Assurance Teaching Tool for Training and Awareness

Good security is not intrusive and can be almost invisible to typical users, who are often unaware of or take it for granted. However, good security practice by user populations is a critical element of an organization’s information assurance strategy. This is reflected in government information assurance teaching mandates such as DoD Directive 8570.1, which outlines objectives and requirements...

متن کامل

CyberCIEGE : An Extensible Tool for Information Assurance Education

– The purpose of CyberCIEGE is to create an extensible Information Assurance (IA) teaching and learning laboratory. Through a scenario definition language, educators can create simulations to demonstrate specific IA concepts. In addition to rigorous scientific foundations, it involves the application of abstract principles to a virtual world. This hands-on virtual laboratory provides a dynamic ...

متن کامل

Expressing an Information Security Policy within a Security Simulation Game

The Center for the Information Systems Studies and Research (CISR) at the Naval Postgraduate School has established a broad program in computer and network security education. The program, founded on a core in traditional computer science, is extended by a progression of specialized courses and a broad set of information assurance research projects. A CISR objective has been improvement of info...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IEEE Security & Privacy

دوره 3  شماره 

صفحات  -

تاریخ انتشار 2005