{"title":"Cybersecurity serious games development: A systematic review","authors":"Chiu Yeong Ng, Mohammad Khatim Bin Hasan","doi":"10.1016/j.cose.2024.104307","DOIUrl":null,"url":null,"abstract":"<div><div>Cybercrime tactics evolve alongside technology, prompting researchers to enhance cybersecurity training for diverse internet users. Serious games have been developed as modern training methods over the years. However, despite all efforts, cybercrime cases continue to rise. This motivated the paper to conduct a comprehensive review of cybersecurity game development from 2014 to 2024, using PRISMA guidelines. The type of games covered include serious games, gamification and entertainment games. The scope of the games studied cover basic or general cybersecurity knowledge and specific fields such as ethical hacking and computer networking. A total of 53 papers were identified and analyzed in this study. The analysis results showed that most cybersecurity games were developed for users who already possessed prior knowledge of the topics delivered, though there were quite a number of games targeting general internet users. The majority of the games seemed to focus on technical aspects more than human aspects by training users on technology-related topics such as hacking, network architectures, and more. Game design suggestions and potential features were also discussed in this paper. Considering game design aspects could help practitioners and researchers in the future when developing new games, the discussions in this paper could be beneficial in improving cybersecurity training efficacy and mitigating cybercrime risks.</div></div>","PeriodicalId":51004,"journal":{"name":"Computers & Security","volume":"150 ","pages":"Article 104307"},"PeriodicalIF":4.8000,"publicationDate":"2024-12-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computers & Security","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0167404824006138","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
Cybercrime tactics evolve alongside technology, prompting researchers to enhance cybersecurity training for diverse internet users. Serious games have been developed as modern training methods over the years. However, despite all efforts, cybercrime cases continue to rise. This motivated the paper to conduct a comprehensive review of cybersecurity game development from 2014 to 2024, using PRISMA guidelines. The type of games covered include serious games, gamification and entertainment games. The scope of the games studied cover basic or general cybersecurity knowledge and specific fields such as ethical hacking and computer networking. A total of 53 papers were identified and analyzed in this study. The analysis results showed that most cybersecurity games were developed for users who already possessed prior knowledge of the topics delivered, though there were quite a number of games targeting general internet users. The majority of the games seemed to focus on technical aspects more than human aspects by training users on technology-related topics such as hacking, network architectures, and more. Game design suggestions and potential features were also discussed in this paper. Considering game design aspects could help practitioners and researchers in the future when developing new games, the discussions in this paper could be beneficial in improving cybersecurity training efficacy and mitigating cybercrime risks.
期刊介绍:
Computers & Security is the most respected technical journal in the IT security field. With its high-profile editorial board and informative regular features and columns, the journal is essential reading for IT security professionals around the world.
Computers & Security provides you with a unique blend of leading edge research and sound practical management advice. It is aimed at the professional involved with computer security, audit, control and data integrity in all sectors - industry, commerce and academia. Recognized worldwide as THE primary source of reference for applied research and technical expertise it is your first step to fully secure systems.