A Gamified Learning Approach for IoT Security Education Using Capture-the-Flag Competitions: Architecture and Insights

Mohammad Hamad, Andreas Finkenzeller, Monowar Hasan, Marc Oliver Pahl, Sebastian Steinhorst

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Cybersecurity is one of the most critical issues for Internet of Things (IoT) systems today and in the future. Therefore, it is essential to educate students about cybersecurity and provide them with the skills needed to design and protect secure IoT systems. We share the experience we gained using a gamified learning approach to IoT security by integrating Capture the Flag (CTF) competitions into our university course. During the semester, students form teams and compete against each other in hacking various educational systems designed in a practically relevant way on our CTF platform. In our paper, we introduce the architecture of the CTF platform and provide student feedback on its effectiveness in teaching IoT security. The evaluation reflects student feedback over three semesters. We also share our lessons learned from creating and maintaining the CTF platform and discuss ideas on how to improve it further. Overall, the students engaged extensively in the CTF, had positive experiences with the provided platform and challenges, and were highly satisfied with our teaching approach. Based on the positive feedback, we believe our approach is an effective way to educate students in IoT security, and we encourage others to adopt this method.

Original languageEnglish
Title of host publicationSecure IT Systems - 29th Nordic Conference, NordSec 2024, Proceedings
EditorsLeonardo Horn Iwaya, Liina Kamm, Leonardo Martucci, Tobias Pulls
PublisherSpringer Science and Business Media Deutschland GmbH
Pages161-175
Number of pages15
ISBN (Print)9783031790065
DOIs
StatePublished - 2025
Event29th Nordic Conference on Secure IT Systems, NordSec 2024 - Karlstad, Sweden
Duration: 6 Nov 20247 Nov 2024

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume15396 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference29th Nordic Conference on Secure IT Systems, NordSec 2024
Country/TerritorySweden
CityKarlstad
Period6/11/247/11/24

Keywords

  • Active Learning
  • Capture the Flag
  • Internet-of-Things
  • Security

Fingerprint

Dive into the research topics of 'A Gamified Learning Approach for IoT Security Education Using Capture-the-Flag Competitions: Architecture and Insights'. Together they form a unique fingerprint.

Cite this