TASEP: A Collaborative Social Engineering Tabletop Role-Playing Game to Prevent Successful Social Engineering Attacks

08/29/2023
by   Lukas Hafner, et al.
0

Data breaches resulting from targeted attacks against organizations, e.g., by advanced persistent threat groups, often involve social engineering (SE) as the initial attack vector before malicious software is used, e.g., for persistence, lateral movement, and data exfiltration. While technical security controls, such as the automated detection of phishing emails, can contribute to mitigating SE risks, raising awareness for SE attacks through education and motivation of personnel is an important building block to increasing an organization's resilience. To facilitate hands-on SE awareness training as one component of broader SE awareness campaigns, we created a SE tabletop game called Tabletop As Social Engineering Prevention (TASEP) in two editions for (a) small and medium enterprises and (b) large corporations, respectively. Its game design is inspired by Dungeons Dragons role-playing games and facilitates LEGO models of the in-game target organizations. Participants switch roles by playing a group of SE penetration testers and conducting a security audit guided by the game master. We evaluated the created game with different student groups, achieving highly immersive and flexible training, resulting in an entertaining way of learning about SE and raising awareness.

READ FULL TEXT
research
03/15/2022

Threat Detection for General Social Engineering Attack Using Machine Learning Techniques

This paper explores the threat detection for general Social Engineering ...
research
08/17/2022

DF-Captcha: A Deepfake Captcha for Preventing Fake Calls

Social engineering (SE) is a form of deception that aims to trick people...
research
01/31/2023

Diversity Awareness in Software Engineering Participant Research

Diversity and inclusion are necessary prerequisites for shaping technolo...
research
01/03/2019

Towards Thwarting Social Engineering Attacks

Social engineering attacks represent an increasingly important attack ve...
research
06/24/2019

Evaluating the Information Security Awareness of Smartphone Users

Information security awareness (ISA) is a practice focused on the set of...
research
04/02/2019

Method of Counteraction in Social Engineering on Information Activity Objectives

The article presents a study using attacks such as a fake access point a...
research
07/30/2021

Winning the Ransomware Lottery: A Game-Theoretic Model for Mitigating Ransomware Attacks

Ransomware is a growing threat to individuals and enterprises alike, con...

Please sign up or login with your details

Forgot password? Click here to reset