The Relevance of Social Engineering Competitions in Cybersecurity Education
摘要
Current cybersecurity education programs, curricula, and competitions are predominantly technical in nature, emphasizing coding, penetration testing, forensics and the like. As important as these technically focused aspects are, they are just a one-sided disciplinary contribution to the cybersecurity discourse. Often downplayed is the human-socio-behavioral aspect of cyberattacks, specifically social engineering (SE). Cybercriminals use SE, or psychological persuasion techniques, to trick authorized personnel into getting access to information and systems, which results in millions of dollars in damages. This paper provides a competition case study where students are exposed to the relevance of SE in cyberattacks. The SE-PTC (penetration testing competition) was grounded in the liberal arts, which offered a timely and unique platform for students to learn about SE topics, such as OSINT, phishing, and vishing, in a hands-on, engaging, and ethical manner. This paper details the virtual SE-PTC event which took place virtually in summer 2021 and hosted 1 high school, 8 undergraduate, and 5 graduate teams. It details students’ experiences, preparations, group formation and dynamics, strategies and adaptations, and learning benefits. It also shares insights from government, industry, and nonprofit representatives who engaged in the competition and their thoughts on training the next generation workforce in SE. The success and positive student responses from the SE-PTC provide a case study, demonstrating that experiential learning can be used to teach students about SE.