错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

COPYCAT: Applying Serious Games in Industry for Defending Supply Chain Attack

  • Tiange Zhao,
  • Tiago Gasiba,
  • Ulrike Lechner,
  • Maria Pinto-Albuquerque,
  • Didem Ongu

摘要

Serious games have found their application in many cases for improving cybersecurity; one of those cases is for building a successful strategy for defending against potential attacks. Our research tries to simulate supply chain attacks involving cloud data by adapting serious game frameworks. In this paper, we present the usage of a serious game called COPYCAT to help the participants raise awareness of supply chain attack threats and build a valid defense strategy against them. COPYCAT is an abbreviation of CONTAIN suPplY Chain ATtack and CONTAIN is the name of the project that is the larger context of this study. The game originates from CATS (Cloud of Assets and Threats), designed to raise cloud security awareness. In this work, CATS is adapted to the new attack scenarios specifically for data-related supply chain attacks, and the adaption is verified in two game events conducted with practitioners from the industry. This paper marks a milestone in positioning a new game dedicated to incident response. In this paper, we share the design of our serious game and the results we collected during the game events and provide insight into the topic of serious game application for training purposes to raise awareness on data-related supply chain attacks.