<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Evaluation of Game Resources as a Purpose of Cyber Attacks for Educational Games</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vyacheslav V. Zolotarev</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maria A. Lapina</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nikolay Y. Parotkin</string-name>
          <email>nyparotkin@yandex.ru</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Elena V. Ulianova</string-name>
          <email>elenavladimirovnay@mail.ru</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="editor">
          <string-name>Yalta, Crimea</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>North Caucasus Federal University</institution>
          ,
          <addr-line>2, Kulakova Str., Stavropol, 355000</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Siberian State Institute of Science and Technology named after M.F. Reshetnev</institution>
          ,
          <addr-line>Krasnoyarsk</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>290</fpage>
      <lpage>295</lpage>
      <abstract>
        <p>Game tasks are vulnerable to methods of gaining an advantage based on the results of attacks on game resources. In such conditions, it is critical to identify, monitor, and evaluate the possibility of such attacks. It is also advisable to choose methods of preventing them in advance, designing the game environment accordingly. An example of the use of training technologies that form users' awareness of information security issues for the task of predicting the choice of an attacker's attack vector is given. The algorithm of actions of an attacker in a game environment to gain an advantage or bypass (violate) the logic of the training game is shown. Possible criteria for the selection of game resources as targets of an attack are shown. The scheme of actions for determining the target resource and the features that reduce its protection against various types of attacks are briefly described. The application of the approach is possible for multi-user games built on the simulation of various processes, including for training games of various directions. Educational games, attacks on game resources, cyberattacks, an attacker 1Proceedings of VI International Scientific and Practical Conference Distance Learning Technologies (DLT-2021), September 20-22, 2021, ORCID: 0000-0002-8054-8564 (Vyacheslav Zolotarev); 0000-0001-8117-9142 (Maria Lapina); 0000-0002-3486-0602 (Nikolay Parotkin);</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        For certain types of gaming tasks used in information security for training, there is a serious problem
of countering various cyberattacks on gaming resources. These tasks include quest game tasks [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ],
business games [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], Capture the Flag format games [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], as well as, to some extent, MOOC-made
resources of various types and university Web-resources [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ].
      </p>
      <p>Of course, the main problem of the game task, in this case, is the presence of a key, answer or hint,
integrated into the task or located on a separate game server. For quest-type games, obtaining a key
from a task by attacking game resources will mean violating the logic of the game or gaining an unfair
advantage; for other types of games - solving tasks that would otherwise require the development of
certain skills, and imbalance in the game.</p>
      <p>The attacker's task in attacking the gaming environment can be twofold. On the one hand, he is
interested in disrupting the gameplay. Perhaps he is not pursuing personal or team benefits. In this study,
the main one is the second situation, when an attacker deliberately tries to gain an advantage or violate
the logic of the game.
environment.</p>
      <p>When solving a problem of the second type, an attacker looks for a non-standard way to bypass
game tasks or obtain keys, hints, and answers by unauthorized access to them, bypassing the game</p>
      <p>2021 Copyright for this paper by its authors.</p>
      <p>
        Previously considered [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] targeted attacks on game resources aimed at the components of the game
environment:
● the logic of the game, including the rules;
● clues, answers, and hints;
● content (for substitution and destruction);
● web interfaces;
● channels of connection;
● accounts;
● means of communication for players.
      </p>
      <p>Accounts and communication tools, like web interfaces, can be used to penetrate the game
environment, unauthorized access to resources, including through attacks on these components, others
can be violated - for example, to influence the game logic through developer accounts or interfaces
management of physical components.</p>
      <p>
        In addition, it is possible to take into account the peculiarities of working with gaming technologies
in a virtual environment [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] and tracking the actions (collecting a digital footprint) of players in the
gaming space [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. It may also be of interest to take into account game-theoretic modeling for certain
types of relevant attacks, for example, phishing attacks [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>The main target of an attacker can be any type of game resource including those containing game
content, rules, and technology that implements it.</p>
      <p>
        To assess game resources as targets of cyberattacks, the following conditions are accepted:
● game resources based on imitation of various technological or other processes are more
interesting as an educational element of the game and, as a result, may be of greater interest to an
attacker. The reason for this focus on imitating resources is the data that is collected for legal access
to them. Such resources will collect and store lists of user accounts, be mentioned and discussed in
communication systems, and serve as a point of attraction for players;
● the attacker will choose those resources to which there is access and which are more valuable
to him subjectively. This behavior of an attacker can help predict his actions, evaluate the optimality
of attack algorithms from his point of view [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ];
● game resources, access to which is possible through access channels with the lowest level of
user awareness, even if one of the conditions is not met for them, can be attacked in the first wave
of an attack.
      </p>
      <p>Next, consider how you can confirm the existence of these conditions in a training game.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Selecting Game Resources for an Attack Based on the Value for the Attacker</title>
      <p>
        Earlier, in the article [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], as in some other cases [
        <xref ref-type="bibr" rid="ref10 ref11 ref12">10, 11, 12</xref>
        ]. It was shown that there are several
basic attack scenarios for imitating the game process in a training game. The following criteria were
used to evaluate the scenarios: "maximax", Bayes, Laplace, Wald, Savage, Hurwitz, Hodge-Lehmann.
The optimal strategy for the attacker was chosen. To analyze the actions of the attacker in the above
experiment, a game-theoretic model was chosen.
      </p>
      <p>The criteria for selecting the target resource in the indicated experiment were:
● value of information. Information suitable for sale as a source of profit was assessed;
● the attacker's awareness of the presence or value structure of the resource;
● the attacker's awareness of the infrastructure of the target game resource;
● meaningfulness of the attacker's actions.</p>
      <p>In the gaming environment, as a rule, these characteristics are not hidden. It is always open space
for the exchange of information between players. The ability to restrict access to certain information
about the gaming environment exists, but, as a rule, this concerns the infrastructure - the configuration
of the environment, the location of the game resource on physical servers, the logic of assigning points
for tasks, archives of digital traces, and so on. In general, collecting information about the gaming
environment is not difficult for an attacker.</p>
      <p>An attack on a game resource has a certain pattern:
- the point of entry into the game space is determined - the player's account or manager account,
service interface, resource web interface;
- the authentication mechanism is analyzed;
- the communication protocol (protocols) is analyzed;
- the possibilities of the registration and accounting system are being studied;
- the capabilities of the attack response system are being studied.</p>
      <p>Having gained a certain understanding of the protection of the gaming environment, the attacker
implements one of the types of targeted attacks on the resource, taking advantage of the vulnerabilities
of the studied components.</p>
      <p>The results of an attack can be tracked both by the player's digital footprint (changing the nature of
tasks, gaining an advantage, changing capabilities or information support), and by using the components
of the game space - web interfaces, rarely used forms of information presentation, access to files
containing certain data ...</p>
      <p>Examples of attacking actions may even include the use of analytics of the internal chats of the game
by an attacker to analyze the tasks being performed and predict the logic of access to them.</p>
      <p>Identifying strategies can point to some security issues and recommendations for gaming
environments that need to be complemented by requirements for the physical elements that implement
the gaming and learning process, namely:
● to prevent attacks on gaming resources in practice, it is necessary to protect management
accounts from identity theft attacks (two-factor authentication, control of connection logs,
biometrics);
● ensuring the protection of physical communication interfaces of the hardware from
unauthorized interception of data or the implementation of control actions, the introduction of
mechanisms for monitoring the integrity and/or encryption of transmitted data;
● protection against phishing attacks on manager and game accounts is required. Tracking of
keywords and frequency parameters, outgoing IP in in-game and external communications is
required.</p>
      <p>These requirements are partially offset by the use of organizational measures by the majority of
participants, which is possible by increasing their level of awareness of related issues of interaction
with the external one when following the instructions for using the platform.</p>
    </sec>
    <sec id="sec-3">
      <title>3. The Dependence of the Attack Vector on User Awareness</title>
      <p>
        To solve this problem, there are specialized systems for training and knowledge control - they help
to automate such activities, in particular, the Kaspersky Automated Security Awareness Platform
(ASAP) used in the study [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. It is also possible to consider the possibility of assessing attack scenarios
both at the level of theoretical modeling and at the level of related vulnerabilities [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. For example,
exploiting LMS Moodle vulnerabilities [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], such as CVE-2019-3810, CVE-2019-3848 (additional
information extraction), CVE-2019-10154 (messaging analysis), CVE-2019-10186 (obtain a session
key in certain XML handling situations), CVE-2019-3849 (privilege escalation), CVE-2019-3850
(comment handling) and CVE-2019-10133 (link handling).
      </p>
      <p>It should be noted that such means of studying user awareness can be part of the gaming
environment. For example, by collecting a digital footprint during test tasks, you can analyze the
potential exposure of a user (or a group of users) to phishing attacks.</p>
      <p>Separately, we can consider conducting a test attack (penetration testing) for a gaming environment.
If test attack mechanisms are integrated into the game space, the player will perceive them as an element
of such space, and collecting a digital trail will give the best result.</p>
      <p>To assess the possibility of choosing an attack vector, it is possible to designate an indicator of an
increase in the level of user knowledge based on the test results before and after training. The number
of test participants is 70 people. The test results for the above typical attacks for educational gaming
environments are shown below (Table 1).</p>
      <p>If we consider these vectors of attacks, we can see that the resistance of users to a direct attack on
the web interface or through external resources, as well as through personal accounts in the social
network, will always be higher, and the most interesting for the attacker remains in this case, as well as
and in-game modeling of targeted attacks, an attack vector using email and in-game communications.</p>
      <p>Email
Websites and internet</p>
      <p>Social networks and
messengers</p>
      <p>It should be noted that when forming an attacking toolkit, an attacker must adhere to the results of a
previously obtained study of the system, but only if a targeted attack is being implemented. In the case
of a mass attack, for example, phishing or using viruses, the attacker analyzes the initial response of the
system and reacts to it.</p>
      <p>It is also possible to note situations of using fuzzing as an element of an attack when the studied web
interfaces or applications are tested by an attacker using random data sets, but such an attack is more of
theoretical interest since it is easily detected and blocked. The only dangerous situation here is when
the open web interfaces of the game space (or software services with open access) are not controlled by
the security subsystem and their response is not investigated, at least in retrospect, but even a banal
selection of authentication data such as logins and passwords for manager accounts.</p>
      <p>As a rule, a certain minimum level of implementation of protective measures is assumed, which
guarantees the successful existence of the game space in the aggressive virtual environment of the open
network by default.</p>
      <p>In addition to the attack itself, as indicated in the diagram, the attacker will be interested both in
assessing vulnerable resources (including through predicting user awareness) and in eliminating traces
of the attack. The work of an attacker with the protective mechanisms of the gaming environment can
consist in both destroying and substituting data for registering security events, distorting or destroying
a digital footprint, changing or distorting game analytics.</p>
      <p>An attacker, evaluating complex attack metrics, can also target user vulnerabilities outside the
gaming environment. For example, the theoretical assessment of the resistance of users of the gaming
environment to a phishing attack necessarily includes the work of the target user with social networks.</p>
      <p>The attacker will aim to identify the focus of users' attention, to select an attack vector using system
components for which there is low user awareness of security issues.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Future Research and Perspectives</title>
      <p>Previous studies allow us to focus on developing attack models and assessing how an attacker can
influence the gaming environment or its physical components that do not have secure interaction
interfaces. Possible attacks on certain information protection mechanisms, such as authentication, may
also be of interest for further research. It is planned to study various gaming environments for various
areas of study.</p>
      <p>The following areas of research are of particular interest: multimodal authentication systems and
their vulnerabilities when implemented in educational gaming environments; the possibility of
implementing targeted attacks on game resources and statistics of this type of attacks; study of incidents
related to game resources in educational games; changing attack vectors taking into account the massive
transition to distance learning.</p>
      <p>The authors suggest that the study of the vulnerabilities of communication protocols of video
conferencing systems that implement communication channels in gaming environments, as well as
analysis of the possibilities and methods of preventing phishing attacks, is also of significant interest.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions</title>
      <p>The conclusions made allow us to concisely formulate the order of actions of the attacker, allocate
key resources and entry points to the system that need to be protected. It is of interest to evaluate the
choice of an attack vector based on the prior knowledge of the attacker about the technologies used.
This assessment predicts an attacker's actions and vulnerabilities in existing gaming environments.</p>
      <p>The study of user awareness as an element of predicting the targets of an attack has also practical
application as a study of the dynamics of changes in the landscape of security threats. Using these
approaches, the security service can tune and adjust both the configuration of the environment and the
registration and accounting system, including such protective technologies as a honeypot and/or
honeynet.</p>
      <p>In general, it should be noted that the study of attacks on educational games is necessary since at the
moment there is a tendency to increase the danger of their use due to the opening of interfaces, access</p>
    </sec>
    <sec id="sec-6">
      <title>6. Acknowledgments</title>
      <p>This work was supported by the Russian Foundation for Basic Research, project No. 19-013-00711.</p>
    </sec>
    <sec id="sec-7">
      <title>7. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>E.</given-names>
            <surname>Ishchukova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Maro</surname>
          </string-name>
          and
          <string-name>
            <given-names>G.</given-names>
            <surname>Veselov</surname>
          </string-name>
          ,
          <article-title>Development of information security quest based on the use of information and communication technologies</article-title>
          . ACM International Conference Proceeding Series, No
          <volume>3357632</volume>
          .
          <year>2019</year>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>V.</given-names>
            <surname>Roblek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Kresal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Pejic</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Meško</surname>
          </string-name>
          ,
          <article-title>Early warning systems as a paradigm for understanding organizational behavior. In extreme environments 5th International Symposium: Co-creating responsible futures in the digital age</article-title>
          .
          <source>2018</source>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>E.</given-names>
            <surname>Trickel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Disperati</surname>
          </string-name>
          and
          <string-name>
            <given-names>E.</given-names>
            <surname>Gustafson</surname>
          </string-name>
          ,
          <article-title>Shall We Play a Game? CTF-as-a-service for</article-title>
          <source>Security Education USENIX Workshop on Advances in Security Education (ASE)</source>
          .
          <year>2017</year>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>R.</given-names>
            <surname>Klemke</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Eradze</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Antonaci</surname>
          </string-name>
          ,
          <article-title>The Flipped MOOC: Using Gamification and Learning Analytics in MOOC Design</article-title>
          .
          <source>A Conceptual Approach Education Sciences</source>
          <volume>8</volume>
          (
          <issue>1</issue>
          )
          <fpage>25</fpage>
          .
          <fpage>2018</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>V.</given-names>
            <surname>Tikhomirov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Dneprovskaya</surname>
          </string-name>
          and
          <string-name>
            <given-names>E.</given-names>
            <surname>Yankovskaya</surname>
          </string-name>
          <article-title>Development of University's WebServices Smart Education</article-title>
          and Smart e-Learning,
          <source>Smart Innovation, Systems and Technologies</source>
          <volume>41</volume>
          <fpage>265</fpage>
          -
          <lpage>271</lpage>
          .
          <year>2015</year>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>K.</given-names>
            <surname>Safonov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Zolotarev</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Derben</surname>
          </string-name>
          ,
          <article-title>Analysis of attack strategies on game resources for technological processes training games</article-title>
          .
          <source>IOP Conference Series: Materials Science and Engineering</source>
          <volume>822</volume>
          (
          <issue>1</issue>
          )
          <fpage>012027</fpage>
          .
          <fpage>2020</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Karagiannis</surname>
          </string-name>
          , E. Magkos,
          <article-title>Adapting CTF challenges into virtual cybersecurity learning environments</article-title>
          .
          <source>Information and Computer Security</source>
          ,
          <year>2020</year>
          . DOI:
          <volume>10</volume>
          .1108/ICS-04-2019-0050.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>B.</given-names>
            <surname>Krylov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Abramov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Khlobystova</surname>
          </string-name>
          ,
          <source>Automated Player Activity Analysis for a Serious Game About Social Engineering. Studies in Systems, Decision and Control</source>
          ,
          <year>2021</year>
          . V. 337, PP.
          <fpage>587</fpage>
          -
          <lpage>599</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>F.</given-names>
            <surname>Tchakounte</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Nyassi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Duplex</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Udagepola</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Atemkeng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Game</given-names>
            <surname>Theoretical</surname>
          </string-name>
          <article-title>Model for Anticipating Email Spear-Phishing Strategies</article-title>
          .
          <source>ICST Transactions on Scalable Information Systems</source>
          ,
          <year>2020</year>
          . pp.
          <fpage>1</fpage>
          -
          <lpage>24</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>S.</given-names>
            <surname>Hart</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Margheri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Paci</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Sassone</surname>
          </string-name>
          ,
          <article-title>Riskio: A Serious Game for Cyber Security Awareness</article-title>
          and
          <source>Education Computers &amp; Security 95 101827</source>
          . 2020
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Ali Zani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Norman</surname>
          </string-name>
          , and
          <string-name>
            <given-names>N.</given-names>
            <surname>Ghani</surname>
          </string-name>
          ,
          <article-title>A review of security awareness approach: Towards achieving communal awareness</article-title>
          .
          <source>In Cyber Influence and Cognitive Threats Academic Press 97- 127</source>
          .
          <year>2020</year>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>S.</given-names>
            <surname>Sherbakov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Lapina</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Lapin</surname>
          </string-name>
          , &amp; J.
          <string-name>
            <surname>Rugelj</surname>
          </string-name>
          ,
          <article-title>Methodological support of game modeling in the educational process</article-title>
          .
          <source>Paper presented at the CEUR Workshop Proceedings SLET-2019. Proceedings of the International Scientific Conference Innovative Approaches to the Application of Digital Technologies in Education</source>
          ,
          <volume>2861</volume>
          ,
          <year>2020</year>
          , PP.
          <fpage>351</fpage>
          -
          <lpage>361</lpage>
          . http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2861</volume>
          /
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>Kaspersky</given-names>
            <surname>Automated Security Awareness Platform</surname>
          </string-name>
          <string-name>
            <surname>URL</surname>
          </string-name>
          : https://k-asap.com/ru/
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>V.V.</given-names>
            <surname>Zolotarev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.B.</given-names>
            <surname>Arkhipova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.Y.</given-names>
            <surname>Parotkin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.P.</given-names>
            <surname>Lvova</surname>
          </string-name>
          ,
          <article-title>Strategies of social engineering attacks on information resources of gamified online education projects</article-title>
          .
          <source>CEUR Workshop Proceedings</source>
          .
          <year>2021</year>
          . Vol.
          <volume>2861</volume>
          : International Scientific Conference on
          <article-title>Innovative Approaches to the Application of Digital Technologies in Education (SLET-</article-title>
          <year>2020</year>
          ), Stavropol,
          <fpage>12</fpage>
          -
          <lpage>13</lpage>
          Nov.
          <year>2020</year>
          . PP.
          <volume>386</volume>
          -
          <fpage>391</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <article-title>Moodle: CVE security vulnerabilities, version, and detailed reports</article-title>
          . https://www.cvedetails.com/product/3590/Moodle-Moodle.
          <source>html?vendor_id=2105</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>