<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>An Approach to Phishing Attacks Modeling for Network Gamified Educational Projects*</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Siberian Federal University</institution>
          ,
          <addr-line>Svobodny av., 79, 660041, Krasnoyarsk</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Siberian State University of Science and Technology</institution>
          ,
          <addr-line>Krasnoyarsky Rabochy Av., 31, 660037 Krasnoyarsk</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Southern Federal University</institution>
          ,
          <addr-line>Bolshaya Sadovaya Str., 105/42, 344006 Rostov-on-Don</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The article presents an overview of the current state of phishing attacks on network gamified projects for undergraduate and graduate ITeducation courses. Issues are considered related to secure interaction within a gamified educational environment, in particular in the field of game cases used for information security training. The algorithm of actions for modeling the vulnerability of participants in network gamified projects to phishing attacks is presented. Also, experimental results of modeling phishing attacks on a simulation model of a social network are shown. The results can be useful in developing and applying interaction methods in online educational projects.</p>
      </abstract>
      <kwd-group>
        <kwd>IT-education</kwd>
        <kwd>Training</kwd>
        <kwd>Gamification</kwd>
        <kwd>Phishing Attack</kwd>
        <kwd>Social Network</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>
        In modern education trends, especially with the extensive integration of distance
(namely online) education processes into areas where it was rarely used before, the
number of security threats to participants in online educational projects has sharply
increased. Security threats both related to participant's actions (phishing, spam,
substitution and theft of payment card data) and with the disadvantages of known learning
environments are relevant. In the field of information security education there are
many ways to involve participants through gamification approaches [
        <xref ref-type="bibr" rid="ref1 ref2 ref3 ref4 ref5">1-5</xref>
        ].
      </p>
      <p>In all above cases, the main goal of the training gamified project is to improving
professional skills withal ensuring security in network interaction is responsibility of
the participants themselves and their common sense.</p>
      <sec id="sec-1-1">
        <title>Phishing Attacks on Online Educational Projects</title>
        <p>
          The phishing attacks explored in this article are based on various ways to recipient
spoofing in a network interaction. The main types of phishing attacks are presented in
[
          <xref ref-type="bibr" rid="ref6 ref7 ref8">6-8</xref>
          ].
        </p>
        <p>A phishing attack on the educational process can have devastating consequences
both in terms of violating its security (participants lose personal data, credit card
numbers, accounts, etc.) and reputational consequences (as example, termination of
using a current educational service). At the same time, even a successful response to
such attack by information security tools also rejects participants from educational
(especially gamified) processes, because in consequence of interacting with
information security tools the dynamics and logic of the education game can be destroyed
and participant's accounts are blocked. In view of the above issues predicting and
preventing such attacks seems to be the best tactic.
2</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>Modeling phishing attacks on educational resources</title>
      <p>
        It is known that the social network as a tool for interaction brings many additional
issues to any network project. Among these issues are: unauthorized cooperation of
participants, including phishing; substitution and deletion (destruction) of accounts of
participants in a network project as a way of introducing third parties into the project
or disrupting its functioning; suppression by the flow of external information of
project participants, decrease in involvement, intensity of information exchange; use of
project resources for actions unrelated to its main tasks, etc. [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>Therefore, adding a social network to the list of interaction tools in a networked
gamified educational project, it is necessary to take these issues into account by
modeling phishing attacks on educational resources. Moreover, gamification obviously
requires more disclosure; consequently, during modeling it is necessary to take into
account the specifics of gamification process, such as the use of common resources
and interest groups, nodes and connections that unite project's participants, and the
use of open problems in teaching methods.
2.1</p>
      <sec id="sec-2-1">
        <title>Interaction Metrics in a Network Educational Project and a Phishing</title>
      </sec>
      <sec id="sec-2-2">
        <title>Attack Model</title>
        <p>
          If we consider gamification in a network communication form as a certain level of
interaction, collaboration of various groups interacting through a social network, then
the metrics of the participant's interaction will be the number and complexity of
connections between them, the intensity of interaction, as well as formal assessments of
the impact on the social graph [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]: average vertex degree, intermediateness,
eigenvector and relative importance. If we take into account the limitations associated with
phishing attacks, then it is advisable to add the ability to assess the resistance to
primary and repeated attacks.
        </p>
        <p>The modeling of a phishing attack in this article was based on the following idea:
visualization of the situation, namely, the availability of freely available information
on the user's page, the number and quality of connections affect the choice of an
account as a distributor of a phishing attack, as well as the success of this attack both on
the user himself and on his friends and subscribers.</p>
        <p>The procedure for the experiment was as follows:
1. Collecting user data (initial modeling involved 31 accounts actually used in
gamified networking tasks through the SEQuest project team in 2020).
2. Setting up the creation of links between user’s accounts.
3. Create n users for imitating social network users.
4. Configure a simulated phishing attack.
5. Run an experiment.</p>
        <p>Technically, the project was carried out using Selenium WebDriver, a headless
version of the Chromium browser and the PyQt5 library. All experiments on user’s
data were carried out on a simulation model of a social network of a networked
educational project.
2.2</p>
      </sec>
      <sec id="sec-2-3">
        <title>Algorithm for Modeling Connections and Accounts of Participants</title>
        <p>In order to create a user in a simulation model of a social network of a networked
educational project a general algorithm is used. The procedure for creating a user is as
follows:
1. Suppose that the project database contains the data of n users; as the information
was collected, m different types of data connecting this information were
identified. Therefore, the original matrix has dimension nхm. The matrix consists only of
0 and 1 (the type of data connecting users, such as common interests, place of
residence, etc., coincides or not), the number of values equal to 1 is estimated, then on
the basis of this estimation we calculate a satisfying value of probability pa for the
attack.
2. When re-entering matrix data types are made, the previous change to the matrix is
taken into account; thus, it is possible for the second and subsequent elements to
have a higher pa by increasing the number of matches. This parameter can be
adjusted.</p>
        <p>The algorithm creates random data sets that simulate user connections and the
probability of choosing a value for an attack. Initial data - anonymized statistics of
1000 users of the VKontakte social network system (official link is https://vk.com).</p>
        <p>Further, the average number of user connections and the average deviation from
this value are estimated. It is advisable to evaluate them on the basis of real statistics
of the simulated group of the educational project. In groups of educational projects, in
comparison with the social network in general, there are fewer participants and they
are interconnected, so it is necessary to assess the probability of a connection between
simulated accounts. The calculation is performed for each account, which allows us to
normalize the number of links, the probability of following a link depending on the
number of matches for the types of these accounts and the links already created.</p>
        <p>
          Then, the account's resistance to phishing attacks was assessed. Three types of
resistance to phishing attack are considered, since the attack itself can come from a
friend, from a subscriber, from a random account. The assessment of the primary
indicator is presented at [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ].
        </p>
        <p>Individual resistance is calculated when simulating an attack, depending on the
attack settings and account indicators by formula:
(1)
where Yz - account vulnerability, which is calculated as: 100 - Set. (1, 2, or 3);
J - the number of data types for the current account;</p>
        <p>MaxJ - the maximum number of account data types.</p>
        <p>Therefore, it becomes an ability to lower the user's stability depending on the
amount of information available to the user account and important to the attacker.
During an attack, user resistance indicators will increase by a resistance step if the
attack against the user is successful (depending on the setting). If all resistance
indicators exceed the value of 100, the user gains attack immunity.
3</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Experimental Results</title>
      <p>Consider the results of 12 attacks carried out with the same settings, on one
simulation of a social network, but with a return to the initial state of the results after each
attack. For 1000 accounts on a simulation model of a social network of a networked
educational project with 35 types of data connecting users and an average of 151
users exposed to the primary attack:
1. The number of attacked accounts ranges from 170 to 254.
2. The number of successfully attacked accounts ranges from 16.6% to 24.8%.
3. At the same time, the number of accounts that will not be attacked in the future
(become immune to attack) is only from 0.1% to 2.2%;
4. For users with missing matches on the original dataset, the probability of a
successful attack is only 0.3% (it is necessary to understand that in one group of the
educational project there will be a minimum or no such users); for users with matching
datatype sets (even with replay resistance) there is a 24% chance of a successful
attack.</p>
      <p>Increasing the resilience step, that is (by ability to educate users to counter
phishing attacks) dramatically increased the possibility of a re-attack failing. For example,
when entering a training condition, the number of attack-resistant accounts of the
simulation model during the first iteration of attacks was 44.1%.</p>
      <p>In addition, the difference between mass attacks and attacks across a small number
of accounts was assessed. In the case of an attack using 2.5% of nodes as attackers,
the number of successfully attacked accounts for three attacks increased to 48.1%,
even taking into account the resistance to repeated attack.</p>
      <p>Considering further possibilities of using the obtained data or changing the alleged
attack vector, it is necessary to take into account the characteristics of the platform
used to implement user interaction with the training material and grading.</p>
      <p>
        Moodle is one of such platforms, which are often used in the Russian and
worldwide education processes. Like any web-based system, it has a number of
vulnerabilities [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. Let's consider some of vulnerabilities, dividing them into four categories:
 Informational. CVE-2019-3810 allows to get information about the full name of
users when they hover over the profile picture. CVE-2019-3848 due to incorrectly
set permissions before loading information about the edited calendar event in the
modal window allows other users (with rights above the guest account) to get read
access to this information. CVE-2019-10154 a web service that retrieves messages
without being limited to the current user's conversation.
 Cross-Site Request Forgery (CSRF). CVE-2019-10186 missing session key
token when loading / unloading XML by the administrator.
 Privilege escalation. CVE-2019-3849 Users can assign themselves a promoted
role in a course or current educational context available through Learning Tools
Interoperability (LTI) by changing the request to the LTI publisher site.
 Interaction with third-party resources. CVE-2019-3850 Opening links in
comments in the same window. CVE-2019-10133 The course subgroup form contained
a redirect field unbounded by internal URLs.
      </p>
      <p>The given examples of Moodle vulnerabilities allow obtaining the necessary
information for the operation of the considered model based on identifying the context
of interaction. Also, using the profiles of the interaction participants most susceptible
to phishing attack according to the model, it is possible to access control materials on
the platform or gain access to the end nodes of the participants using additional
exploits.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Conclusion</title>
      <p>The main vulnerability of a networked gamified educational project is user’s
interactions. From the point of view of pedagogical technology, such an implementation of
the principle of open education approach, which implies free use of links in projects
and different fragments of information from the "outside world", and lack of control
over internal and external relations, may endanger online educational system.
Nevertheless, the possibilities for predicting phishing attacks on participants in online
gamified educational projects exist and are feasible.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Yasin</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fatima</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Jianmin</surname>
            ,
            <given-names>W. Improving</given-names>
          </string-name>
          <article-title>Software Security Awareness Using A Serious Game</article-title>
          .
          <source>IET Software</source>
          , vol.
          <volume>13</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>159</fpage>
          -
          <lpage>169</lpage>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Yasin</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Zowghi</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <article-title>Design and preliminary evaluation of a cyber Security Requirements Education Game (SREG)</article-title>
          .
          <source>Information and Software Technology</source>
          ,
          <volume>95</volume>
          ,
          <year>2018</year>
          , pp.
          <fpage>179</fpage>
          -
          <lpage>200</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Hart</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Margheri</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Paci</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Sassone</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          <article-title>Riskio: A Serious Game for Cyber Security Awareness and Education</article-title>
          .
          <source>Computers &amp; Security</source>
          , Vol.
          <volume>95</volume>
          ,
          <year>2020</year>
          ,
          <volume>101827</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Seaborn</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fels</surname>
            ,
            <given-names>D. I.</given-names>
          </string-name>
          <article-title>Gamification in theory and action: A survey</article-title>
          .
          <source>International Journal of Human-Computer Studies</source>
          ,
          <volume>74</volume>
          ,
          <fpage>14</fpage>
          -
          <lpage>31</lpage>
          ,
          <year>2015</year>
          . http://dx.doi.org/10.1016/j.ijhcs.
          <year>2014</year>
          .
          <volume>09</volume>
          .006
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Grandhi</surname>
            ,
            <given-names>S.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Galimotu</surname>
            ,
            <given-names>N.C.</given-names>
          </string-name>
          <article-title>Understanding social engineering threats in massively multiplayer online role-playing games: an issue review</article-title>
          ,
          <source>GAP Indian Journal of Forensics and Behavioural Sciences</source>
          , Volume
          <volume>1</volume>
          ,
          <string-name>
            <surname>Issue</surname>
            <given-names>1</given-names>
          </string-name>
          ,
          <fpage>66</fpage>
          -
          <lpage>71</lpage>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Kang</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chek</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Choon</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <article-title>A survey of phishing attacks: Their types, vectors and technical approaches</article-title>
          .
          <source>Expert Systems with Applications</source>
          ,
          <volume>106</volume>
          . pp.
          <fpage>1</fpage>
          -
          <lpage>20</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Chaudhry</surname>
            ,
            <given-names>J.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chaudhry</surname>
            ,
            <given-names>S. A.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Rittenhouse</surname>
            ,
            <given-names>R. G. Phishing</given-names>
          </string-name>
          <string-name>
            <surname>Attacks</surname>
          </string-name>
          and Defenses.
          <source>International Journal of Security and Its Applications</source>
          , Vol.
          <volume>10</volume>
          , No.
          <volume>1</volume>
          (
          <issue>2016</issue>
          ), pp.
          <fpage>247</fpage>
          -
          <lpage>256</lpage>
          . http://dx.doi.org/10.14257/ijsia.
          <year>2016</year>
          .
          <volume>10</volume>
          .1.
          <fpage>23</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Sahu</surname>
            ,
            <given-names>K.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dubey</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <article-title>Article: A Survey on Phishing Attacks</article-title>
          .
          <source>International Journal of Computer Applications</source>
          <volume>88</volume>
          (
          <issue>10</issue>
          ):
          <fpage>42</fpage>
          -
          <lpage>45</lpage>
          ,
          <year>February 2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Safonov</surname>
            ,
            <given-names>K.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zolotarev</surname>
            ,
            <given-names>V.V.</given-names>
          </string-name>
          <article-title>Assessment of vulnerability to phishing of participants in online gamified educational projects in the field of information security [in Russian]</article-title>
          .
          <source>Bulletin of the Krasnoyarsk State</source>
          Pedagogical University named after V.P. Astafieva,
          <volume>52</volume>
          (
          <issue>2</issue>
          ),
          <year>2020</year>
          , p.
          <fpage>76</fpage>
          -
          <lpage>84</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Basarab</surname>
            ,
            <given-names>M.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ivanov</surname>
            ,
            <given-names>I.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kolesnikov</surname>
            ,
            <given-names>A.V.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Matveev</surname>
            ,
            <given-names>V.A.</given-names>
          </string-name>
          <article-title>Detection of illegal activity in cyberspace based on the analysis of social networks: algorithms, methods and means (review) [in Russian]</article-title>
          .
          <source>Issues of Cybersecurity</source>
          , vol.
          <volume>4</volume>
          (
          <issue>17</issue>
          ),
          <year>2016</year>
          , p.
          <fpage>11</fpage>
          -
          <lpage>19</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Kuznetsov</surname>
            ,
            <given-names>M. V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Simdyanov</surname>
            <given-names>I. V.</given-names>
          </string-name>
          <article-title>Social engineering and social hackers [in Russian]</article-title>
          .
          <source>SPb.: BHV-Petersburg</source>
          ,
          <article-title>(</article-title>
          <year>2007</year>
          ), 368 p.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12. Moodle:
          <article-title>CVE security vulnerabilities, version and detailed reports</article-title>
          . https://www.cvedetails.com/product/3590/Moodle-Moodle.
          <source>html?vendor_id=2105</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>