Covert Eye Op App:一种基于攻击的学习方法,旨在培养移动安全意识和网络安全兴趣

Ankur Chattopadhyay, Tyler Poe, Hoang Nguyen, Abel Tsegaye, Lolar Moua
{"title":"Covert Eye Op App:一种基于攻击的学习方法,旨在培养移动安全意识和网络安全兴趣","authors":"Ankur Chattopadhyay, Tyler Poe, Hoang Nguyen, Abel Tsegaye, Lolar Moua","doi":"10.1145/3537674.3554741","DOIUrl":null,"url":null,"abstract":"This paper introduces a unique approach of teaching mobile security awareness at the high school level through a nifty offense-based learning strategy. Our approach involves creating an eye-opening experience for learners through our own mobile app, which has been designed and developed strategically, so that it requests unnecessary permissions from users and secretly exploits them in the form of a covert offensive operation, that includes recording their audio plus tracking their location. When the users notice this exploit activity orchestrated by our app and realize how their provided permissions have backfired on them, they get to learn first-hand about the ways in which a mobile app can misuse user permissions and covertly compromise user information. We have used this app to implement a hands-on experiential learning activity that is intended to teach users the importance of privacy and security in mobile devices by breaching them and making them self-discover issues with how users grant permissions to mobile apps. To our knowledge, there has been limited prior work that focuses on studying how offense-based user hacking techniques impact leaning of mobile security topics. In this paper, we attempt to address this research gap. This paper describes our mobile app, as well as our offense-based lesson plan, which has been used in several workshop sessions as a hands-on learning activity for the high school community since 2019. It also includes our learner assessment study that involves analysis of the quantitative and qualitive data that we have collected in the form of survey responses from different users at the high school level. The results from our study indicate that our offense-based learning approach using our unique app was able to successfully engage users and create a positive learning experience for the high school community by developing user awareness of mobile security related issues, plus overall interest in cybersecurity topics.","PeriodicalId":201428,"journal":{"name":"Proceedings of the 23rd Annual Conference on Information Technology Education","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Covert Eye Op App: An Offense Based Learning Approach Towards Developing Mobile Security Awareness and Interest in Cybersecurity\",\"authors\":\"Ankur Chattopadhyay, Tyler Poe, Hoang Nguyen, Abel Tsegaye, Lolar Moua\",\"doi\":\"10.1145/3537674.3554741\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper introduces a unique approach of teaching mobile security awareness at the high school level through a nifty offense-based learning strategy. Our approach involves creating an eye-opening experience for learners through our own mobile app, which has been designed and developed strategically, so that it requests unnecessary permissions from users and secretly exploits them in the form of a covert offensive operation, that includes recording their audio plus tracking their location. When the users notice this exploit activity orchestrated by our app and realize how their provided permissions have backfired on them, they get to learn first-hand about the ways in which a mobile app can misuse user permissions and covertly compromise user information. We have used this app to implement a hands-on experiential learning activity that is intended to teach users the importance of privacy and security in mobile devices by breaching them and making them self-discover issues with how users grant permissions to mobile apps. To our knowledge, there has been limited prior work that focuses on studying how offense-based user hacking techniques impact leaning of mobile security topics. In this paper, we attempt to address this research gap. This paper describes our mobile app, as well as our offense-based lesson plan, which has been used in several workshop sessions as a hands-on learning activity for the high school community since 2019. It also includes our learner assessment study that involves analysis of the quantitative and qualitive data that we have collected in the form of survey responses from different users at the high school level. The results from our study indicate that our offense-based learning approach using our unique app was able to successfully engage users and create a positive learning experience for the high school community by developing user awareness of mobile security related issues, plus overall interest in cybersecurity topics.\",\"PeriodicalId\":201428,\"journal\":{\"name\":\"Proceedings of the 23rd Annual Conference on Information Technology Education\",\"volume\":\"7 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-09-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 23rd Annual Conference on Information Technology Education\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3537674.3554741\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 23rd Annual Conference on Information Technology Education","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3537674.3554741","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

本文介绍了一种独特的方法,通过巧妙的基于攻击的学习策略,在高中阶段教授移动安全意识。我们的方法包括通过我们自己的移动应用程序为学习者创造一个大开眼界的体验,这是经过精心设计和开发的,因此它会请求用户不必要的许可,并以秘密攻击行动的形式秘密利用他们,包括记录他们的音频和跟踪他们的位置。当用户注意到我们的应用程序精心策划的这个漏洞利用活动,并意识到他们提供的权限是如何适得其反的,他们就会了解到移动应用程序滥用用户权限和秘密泄露用户信息的第一手方式。我们使用这个应用程序来实现一个动手体验式学习活动,旨在通过破坏它们,让他们自己发现用户如何授予移动应用程序权限的问题,来教导用户隐私和安全在移动设备中的重要性。据我们所知,之前有有限的工作专注于研究基于攻击的用户黑客技术如何影响移动安全主题的学习。在本文中,我们试图解决这一研究空白。本文介绍了我们的移动应用程序,以及我们基于冒犯的课程计划,自2019年以来,该计划已在几次研讨会上被用作高中社区的实践学习活动。它还包括我们的学习者评估研究,包括对我们从不同高中用户的调查反馈中收集的定量和定性数据的分析。我们的研究结果表明,使用我们独特的应用程序的基于攻击的学习方法能够成功地吸引用户,并通过培养用户对移动安全相关问题的认识,以及对网络安全主题的整体兴趣,为高中社区创造积极的学习体验。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Covert Eye Op App: An Offense Based Learning Approach Towards Developing Mobile Security Awareness and Interest in Cybersecurity
This paper introduces a unique approach of teaching mobile security awareness at the high school level through a nifty offense-based learning strategy. Our approach involves creating an eye-opening experience for learners through our own mobile app, which has been designed and developed strategically, so that it requests unnecessary permissions from users and secretly exploits them in the form of a covert offensive operation, that includes recording their audio plus tracking their location. When the users notice this exploit activity orchestrated by our app and realize how their provided permissions have backfired on them, they get to learn first-hand about the ways in which a mobile app can misuse user permissions and covertly compromise user information. We have used this app to implement a hands-on experiential learning activity that is intended to teach users the importance of privacy and security in mobile devices by breaching them and making them self-discover issues with how users grant permissions to mobile apps. To our knowledge, there has been limited prior work that focuses on studying how offense-based user hacking techniques impact leaning of mobile security topics. In this paper, we attempt to address this research gap. This paper describes our mobile app, as well as our offense-based lesson plan, which has been used in several workshop sessions as a hands-on learning activity for the high school community since 2019. It also includes our learner assessment study that involves analysis of the quantitative and qualitive data that we have collected in the form of survey responses from different users at the high school level. The results from our study indicate that our offense-based learning approach using our unique app was able to successfully engage users and create a positive learning experience for the high school community by developing user awareness of mobile security related issues, plus overall interest in cybersecurity topics.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信