<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Blue and Red team quiz game to train high school students</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Giuseppe</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alemanno</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Daniele</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Semeraro</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Veronica</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Rossano</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Computer Science, University of Bari</institution>
          ,
          <addr-line>via Orabona, 4 - 70125 Bari -</addr-line>
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In the ever-evolving landscape of cybersecurity, human factors play a pivotal role in determining system vulnerabilities. This article introduces CyberDuel, a serious game designed to educate high school students on cybersecurity through an interactive card-based gameplay. Drawing inspiration from the inherent human inclination towards play, CyberDuel engages users in defending against cyber threats while fostering awareness and decision-making skills. The game's design ofers a non-threatening environment for users to experiment with cybersecurity scenarios. Through a detailed planning and design process, CyberDuel integrates elements to create an immersive educational experience. A user study employing the GAMEX test demonstrates the game's efectiveness in enhancing cognitive skills and learning outcomes. CyberDuel represents a promising approach to cybersecurity education, with the possibility of future development and refinement.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Cybersecurity</kwd>
        <kwd>Serious Games</kwd>
        <kwd>Cybergames</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        In the cybersecurity landscape, the human factor stands out as a crucial determinant of system
vulnerabilities, often overshadowing the efectiveness of technical defenses alone. Human
errors, such as lack of awareness, negligence in adopting secure practices and falling into social
engineering traps, can be significant openings for cyber attacks [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Consequently, in
addition to investments in cutting-edge technology solutions, it is critical to place an emphasis on
educating end users about cybersecurity. However, efectively raising awareness of cybersecurity
among individuals is a significant challenge, requiring the implementation of appropriate
educational strategies.
      </p>
      <p>
        One of the highly efective is game-based learning, which allows people to experiment in
nonthreatening scenarios and acquire knowledge through practice and social interaction both
with the environment and their peers [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>
        Games have long been studied by experts across various disciplines, leading to the emergence
of the research field known as game studies, revealing a fundamental connection between
humans and games throughout history. Scholars such as Johan Huizinga and Eugen Fink have
emphasized the innate human tendency to play, which coexists with our rational and creative
faculties [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. This innate aspect of human nature underscores the efectiveness of games
as educational tools that through their ability to incorporate competition, engagement and
immediate feedback, motivate participants and facilitate learning and development.
      </p>
      <p>
        As technology has advanced, traditional games have evolved into educational digital games,
often referred to as serious games or applied games. Unlike pure videogames, serious games are
designed with primary purposes such as education, training, and information dissemination
[
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. They cover a wide range of fields, including defense, education, scientific exploration,
healthcare, emergency management, city planning, engineering, and politics [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ][
        <xref ref-type="bibr" rid="ref10">10</xref>
        ][
        <xref ref-type="bibr" rid="ref11">11</xref>
        ][
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>
        In the context of Cybersecurity, Serious games are pivotal for educating individuals on best
practices, recognizing threats, and handling cyber incidents. By allowing learners to explore
diverse scenarios beforehand, they can make informed decisions when using the Internet or
computers in their daily activities. For example, the The Weakest Link1 [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] is a game where
players take on the role of a security expert within a company. Its primary objective is to
maintain high levels of security within the organization by addressing the various security
challenges that arise every day, in the form of multiple variable questions and answers. The
uniqueness of the game consists in the fact that the challenges are generated by the choices
of the company’s employees, where the player cannot choose the dificulty level. Also, the
decisions made by the player (the security expert) during the game can change the company’s
destiny very quickly, which is why the game is very dynamic, making the employee "the weak
link in the company". The key components of the game include:
• Security Score: this metric quantifies the player’s efectiveness in safeguarding the
company against potential threats.
• Daily Challenges: each day presents new security scenarios, accompanied by questions
and multiple solutions for the player to consider.
• Workdays: these represent the progression through diferent levels of the game, with each
workday indicating the challenges faced and those remaining to be addressed.
In the game Keep Tradition Secure2 [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] players are immersed in a college campus. His main
goal is to defend the students and catch the hacker called "Bad Bull" who threatens the campus
through a series of questions with three multiple answers. The peculiarity of the game is that it
has a large game space (the entire campus map), but remains static in story and challenges. The
main parts of the game include:
• Map: used to navigate the campus in search of the hacker.
• Challenge: once you reach the point indicated on the map, a question appears with related
answer options.
      </p>
      <p>
        In the [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] Riskio is presented, a classic serious board game designed to increase awareness
and knowledge about cyber attacks. Riskio addresses the limitations of existing cybersecurity
awareness games by ofering an active learning environment where players can learn about
diferent attacks and countermeasures while playing the role of both the attacker and defender
of critical assets in a fictional organization. The main components of the Riskio game are: Card
Decks and the Game Board. The Card Decks are:
1https://www.isdecisions.com/user-security-awareness-game/
2https://keeptraditionsecure.tamu.edu/
• Attack deck: contains the most common threats and attack vectors identified in
cybersecurity reports;
• Defense deck: presents possible countermeasures and defenses against attacks;
• Information deck: provides additional details and useful information for the game.
The Game Boards represents a fictional organization and provides context for the game,
allowing players to view and interact with attacks and defenses. The paper identifies three main
limitations of existing games:
• Lack of exposure to a wide range of cyber attacks and possible countermeasures;
• Lack of opportunity for players to practice both ofensive and defensive skills;
• Dificulty easily adapting or modifying the game for diferent training needs and contexts.
      </p>
      <p>This research is motivated by the fact that there are no serious games on cybersecurity in
the Italian language intended for a teen audience, with the possibility of choosing the level of
dificulty based on their knowledge and skills and the possibility of adding new topics easily.</p>
      <p>The rest of this paper is organized as follows. Section 2 begins with an overview of the game,
followed by a discussion of its conception, unique features, and design methodology. In Section
3, we delve into the analysis of a user study conducted to evaluate the game’s efectiveness.
Finally, Section 4 concludes by presenting potential avenues for future research.</p>
    </sec>
    <sec id="sec-2">
      <title>2. The serious game CyberDuel</title>
      <p>CyberDuel combines a card game with a quiz game to introduce young students to the topic
of computer security in an interactive way. The approach used is the one commonly used
in cybersecurity contexts, a competition between the red and blue team. Users are actively
involved in the process of defending themselves against threats posed in the form of hackers.
Users assume the role of the "blue team" and must defend themselves against cyber threats
represented by the "red team" (hackers). The game is a card battle where players must select
cards in response to the hacker’s moves, make strategic decisions based on the analysis of card
attributes, and predict their opponent’s actions to maximize their chances of success based on
card scores. cards. The player who loses all his life points loses the game.</p>
      <p>In the preliminary stages of game conceptualization, we set ourselves the goal of creating
an engaging and innovative experience. We found inspiration from the basic idea of the game
Hacket, which under GPL-3.0 license control, provided us with an exciting starting point.</p>
      <p>One of the main focuses was to understand how to transform the basic idea of the game Hacket
into something new and distinctive. Hacket is a static game with a single level and with few and
very generic questions about cybersecurity, but with a very clear and explicit aesthetic, regarding
the player’s roles and the purpose of the game. CyberDuel is based on Hacket’s aesthetic, using
their patterns, colors, incorporating dynamics such as multiple dificulty levels and more diverse
content. Specifically, the game’s content has been expanded to cover important topics such
as cyberbullying, password security, data privacy, phishing attacks, social engineering tactics,
and GDPR regulations. A key aspect highlighted in CyberDuel is its accessibility to a broader
audience, in particular that of being able to change the language of the game and propose the
game to an audience of Italian teenagers. Finally, to facilitate understanding of these concepts,
the game ofers feedback after each round to help players better understand the material.</p>
      <p>
        In the development of CyberDuel, we followed an iterative design process [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] to refine and
improve the game mechanics and user experience iteratively based on testing and feedback. In
the following sections, we delineate certain facets of the planning and design phases.
      </p>
      <sec id="sec-2-1">
        <title>2.1. Planning</title>
        <p>During the planning phase, we outlined a number of specific objectives that we wanted to
achieve in our project, integrating and expanding on the basic idea to fit our original concept,
respecting the guidelines for creating a serious game, described later in the design section.</p>
        <p>An in-depth analysis of the game planning was conducted, carefully considering:
• Primary goal: educate players about cybersecurity in an interactive way, addressing the
critical need for awareness and knowledge in digital security.
• Secondary goals:
1. Enhance understanding of cybersecurity principles through practical application:
reinforce cybersecurity concepts through practical application within the game
environment.
2. Improve decision-making skills in a simulated environment to be ready for a possible
real case of hacking: the game aims to sharpen their ability to assess risks, devise
efective countermeasures, and respond swiftly to cyber threats.
• Target Audience: individuals who are interested in learning about cybersecurity, with
the properties describe in table 1.
• Game Genre(s):
1. card game: choose cards that represent diferent countermeasures to attacks;
2. quiz game: make informed decisions in response to evolving scenarios.
• Platform: the game is developed as a browser-based application using HTML, CSS and
TypeScript, ensuring accessibility on a wide range of devices and exploiting the Angular
framework to simplify development and improve code organisation.
• Look and Feel: the main colours of the game are blue and red, in diferent shades, mixing
cold and warm tones, symbolising the ongoing battle between the blue team (i.e. the
player) and the red team (i.e. the hacker).</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Design</title>
        <p>
          The design of a game includes the delineation of various elements according to the requirements
and resources specified during the planning phase. To enhance the design process, we have
adopted the Elemental Tetrad framework [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. This framework was chosen for its comprehensive
coverage and proven efectiveness in guiding game design, ensuring thorough consideration of
essential game elements delineated into four distinct categories:
• Mechanics:
1. Space: the game is confined to digital space, divided horizontally into two conceptual
areas: one belongs to the player and the other to the hacker, following the typical
standard of digital card games (Figure 1) . In this representation, the duelists are
arranged facing each other in a top-down perspective, similar to the layout on a real
card table.
2. Objects: cards serve as interactive objects characterized by two static attributes:
a description detailing the available counter moves for the player in response to
the opponent’s actions, and power, which indicates the efectiveness of the action
represented by the card. Additionally, life points serve as dynamic attributes in the
game, representing the quantitative measure of health of the duelists. These life
points decrease over the course of the game according to the results of each turn.
3. Actions: throughout gameplay, the player is involved in each round in the strategic
action of deciding which card maximizes their chances of success by analyzing and
comparing card descriptions. The player then performs the basic action of selecting
the card that will face the opponent’s card, initiating the clash.
4. Rules: the outcome of clashes between the player’s chosen card and the opposing
card is determined by their respective powers. If one card has greater power than
the other, it inflicts damage equal to the diference in points to the duelist who chose
the less powerful card. However, if the powers are equal, no damage is dealt. The
duel concludes in one of two ways: either when one side loses all its life points,
resulting in defeat, or when the predetermined number of rounds for the level has
ended, leading to a draw.
5. Skills: a crucial skill we expect players to possess is the mental aptitude for
decisionmaking, as the game requires a thorough understanding of card details.
6. Chance: Hacket is a very static game lacking of chance elements, consequently to
create an experience that is always full of challenging decisions and that prioritizes
player engagement in scenarios rather than rote memorization of moves, we
introduce two unpredictable elements. The first element is that the scenarios encountered
during the levels may change each time, the second element the cards presented
to the player for each scenario are randomly ordered, intensifying the demand on
players to remain attentive and responsive during the duel.
• Story: the narrative is implicit, revolving around a virtual battlefield where two characters,
the blue team member (i.e. the player) and the red team member (i.e. the hacker), engage
in an ongoing conflict. Each round represents a distinct scenario or event that the player
must navigate, contributing to an embedded narrative that evolves as players progress
through the game.
• Aesthetics: based on the Hacket game, some patterns were reused regarding the
aesthetics, but new prototypes and storyboards of the game were also defined and generated. The
mission and the challenges structure are defined in terms of:
1. mission design: the game has diferent levels and for each level is structured around
a series of cybersecurity rounds;
2. progressive complexity: the levels gradually increase in complexity, introducing new
cybersecurity threats and tactics as players advance.This structure ensures a steady
learning curve, allowing players to build upon their knowledge and skills;
A crucial point of this game, that difers from the Hacket game, is the concept of levels.
The game consists of a training level. Within this stage, the game unfolds the goal and all
its mechanisms (Figure 2), providing detailed insights and invites the player to select a
card from the hand. The instruction section can be called up from any level. Afterwards,
the player receives constructive feedback on the chosen card. Once the tutorial level
is successfully completed, an ending screen of the game is presented, taking the player
back to the home page for further exploration. The player, from the main menu, can
choose a new game with diferent dificulty levels (Figure 3). The challenges escalate
progressively, the player’s life points decrease, shifting the balance in favor of the hacker’s
life, transitioning from easy to medium to dificult level.
• Technology: CyberDuel it was completely rewritten from scratch using Angular (v17), a
TypeScript-based framework, along with HTML and CSS. In the development process,
we were inspired by the aesthetics and movements of the Hacket game. The dificulties
encountered in the porting were recreating the animations of card selection and the
diferent dynamics on the players’ scores.
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. User Study</title>
      <p>
        In this section, we present the methodology and results of our user study, which was designed to
test the efectiveness of ‘ CyberDuel’ game. We conducted a beta test involving a diverse group of
participants, assessing their cognitive skills and learning outcomes using the Gameful Experience
Scale (GAMEX) [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. The GAMEX serves as a tool to measure users’ gameful experiences in
gamified contexts. The decision to employ the GAMEX stems from its adaptability across
various contexts and its simplicity in pinpointing specific experiential qualities that must be
refined to improve the gamified application, by-passing risky trial-and-error adjustments [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ].
      </p>
      <sec id="sec-3-1">
        <title>3.1. Questionnaires</title>
        <p>After the beta test session, participants were given a questionnaire. The first part was made
up of socio-demographic data. This included age, gender, and their experience in the field of
cybersecurity (i.e. "weak", "average" and "high"). The second part was based on the GAMEX test,
comprising 27 items across six dimensions: Entertainment (Enj 1-6), Absorption (Ab 1-6), Creative
thinking (CT 1-4), Activation (Act 1-4), Absence of negative afects (ANA 1-3) and Dominance
(Dom 1-4). Participants rated their level of agreement on a 7-point Likert scale (1 = “strongly
disagree”, 7 = “strongly agree”, except for the question “Absence of negative afects” where the
values were reversed) for each question of each dimension.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Sample and Procedure</title>
        <p>The beta testing phase of our study was designed to simulate real-world usage scenarios,
providing participants with an authentic experience of the system’s capabilities. The test
involved a carefully selected group of 12 participants, including 6 males and 6 females, aged
between 15 and 25 (average 21 years old) and with diferent experiences in the cybersecurity
ifeld (4 people for each type of experience). Participant recruitment used convenience sampling,
prioritizing availability and proximity to the authors for selection.</p>
      </sec>
      <sec id="sec-3-3">
        <title>3.3. Results and Discussion</title>
        <p>After obtaining the results of the questionnaire, the mathematical average of the scores for each
question of each dimension was calculated. Subsequently, to report them on a centesimal scale
in order to define a graph, the average score of each dimension was calculated, then divided by
the total number of responses and multiplied by 100. The results of the user test are shown in
the table 2 where zero is the lowest value and 100 is the highest value.</p>
        <p>As visible from the Figure 4,
some interesting and encouraging results were obtained:
• Enjoyment: the participants demonstrated a high level of enjoyment while engaging with
the serious game, scoring an impressive 82,36. This suggests that the game successfully
captivated their interest and provided an enjoyable experience.
• Absorption: the level of absorption among the participants was notable, with a score of
66,86. This indicates that the game was efective in immersing the players in its content,
fostering deep engagement and concentration.
5,38
76,79</p>
        <p>
          Act 1
Act 2
Act 3
Act 4
• Creative Thinking: The serious game elicited a strong response in terms of creative
thinking, scoring 76,79. This suggests that it stimulated participants’ imagination and
encouraged them to explore innovative solutions within the game’s context.
• Activation: the score of 71,43 for activation indicates that the game efectively prompted
participants to become actively involved in its challenges and tasks. This suggests that it
succeeded in motivating them to participate and interact with its content.
• Absence of Negative Afect : with a score of 80,95, the game demonstrated a notable
absence of negative afect among the participants. These findings align with those of the
original researchers, suggesting that the absence of negative emotions is crucial for the
genuine emergence of the gaming experience [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ].
• Dominance: the high score of 82.46 for dominance suggests that the game efectively
empowered participants and allowed them to feel in control of their actions within the
game environment. This indicates a positive user experience, where players felt confident
and competent in navigating the challenges presented.
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusion and Future works</title>
      <p>CyberDuel educates players on cybersecurity, leveraging game-based learning to enhance
awareness and decision-making skills. The innovative design, incorporating elements like card
strategies and dynamic scenarios, engages players in a non-threatening environment.</p>
      <p>Some possible future works could include:
• Enhancing User Engagement: further research could focus on increasing user
engagement by incorporating more interactive elements, personalized feedback, or gamification
techniques to make the learning experience more immersive and enjoyable and to be able
to have greater user absorption while playing the game.
• Expanding Content and Scenarios: to develop additional levels, challenges, and
scenarios within the game to cover a broader range of cybersecurity topics and real-world
situations, catering to diferent skill levels and learning preferences of users.
• Integration of Advanced Technologies: to explore integrating emerging technologies
like virtual reality (VR) or augmented reality (AR) to enhance the gaming experience and
provide a more realistic and interactive learning environment.
• Long-term Impact Assessment: to conduct longitudinal studies to evaluate the game’s
long-term impact on users’ cybersecurity knowledge, skills, and behaviors, tracking
progress and retention of information over time.
• Collaboration and Partnerships: to collaborate with cybersecurity experts, educational
institutions, and industry partners to gather feedback, validate efectiveness, and ensure
alignment with current cybersecurity practices and trends.
• Accessibility and Localization: to adapt the game to be accessible to a wider audience
by translating it into multiple languages, optimizing for diferent devices, and ensuring
inclusivity for users with diverse learning needs.
• Larger Participant Pool: to obtain a larger range of feedback and diferent perspectives
for a more comprehensive understanding of the game’s impact.</p>
      <p>By exploring these avenues for future research and development, the CyberDuel project can
continue to evolve and make a significant impact in educating individuals about cybersecurity
through innovative and engaging game-based learning experiences.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Acknowledgement</title>
      <p>This work has been partially funded by the OSCAR project, number 101132432, funded by
the European Union. Views and opinions expressed are however those of the author(s) only
and do not necessarily reflect those of the European Union. Neither the European Union nor
the granting authority can be held responsible for them. The research activities has been
developed within the National Laboratory “Informatica e Scuola” constituted under CINI, the
Italian inter-university consortium on Informatics. The authors wish to express their gratitude
to the student Fabio Caiulo who designed and developed the game together with Giuseppe
Alemanno and Daniele Semeraro.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Online Resources</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Chrysanthou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Pantis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Patsakis</surname>
          </string-name>
          ,
          <article-title>The anatomy of deception: Measuring technical and human factors of a large-scale phishing campaign</article-title>
          ,
          <source>Computers &amp; Security</source>
          (
          <year>2024</year>
          )
          <fpage>103780</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Pollini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T. C.</given-names>
            <surname>Callari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Tedeschi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Ruscio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Save</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Chiarugi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Guerri</surname>
          </string-name>
          ,
          <article-title>Leveraging human factors in cybersecurity: an integrated methodological approach</article-title>
          , Cognition,
          <source>Technology &amp; Work</source>
          <volume>24</volume>
          (
          <year>2022</year>
          )
          <fpage>371</fpage>
          -
          <lpage>390</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
            <surname>Joinson</surname>
          </string-name>
          ,
          <string-name>
            <surname>T. van Steen</surname>
          </string-name>
          ,
          <article-title>Human aspects of cyber security: Behaviour or culture change?, Cyber Security: A Peer-Reviewed Journal 1 (</article-title>
          <year>2018</year>
          )
          <fpage>351</fpage>
          -
          <lpage>360</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>V.</given-names>
            <surname>Zimmermann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Renaud</surname>
          </string-name>
          ,
          <article-title>Moving from a 'human-as-problem” to a 'human-as-solution” cybersecurity mindset</article-title>
          ,
          <source>International Journal of Human-Computer Studies</source>
          <volume>131</volume>
          (
          <year>2019</year>
          )
          <fpage>169</fpage>
          -
          <lpage>187</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>M.</given-names>
            <surname>Prensky</surname>
          </string-name>
          ,
          <article-title>Digital game-based learning</article-title>
          ,
          <source>Comput. Entertain</source>
          .
          <volume>1</volume>
          (
          <year>2000</year>
          )
          <article-title>21</article-title>
          . URL: https: //api.semanticscholar.org/CorpusID:207742354.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>K.</given-names>
            <surname>Salen</surname>
          </string-name>
          ,
          <string-name>
            <surname>E. Zimmerman,</surname>
          </string-name>
          <article-title>The Game Design Reader: A Rules of Play Anthology, Chapter 3: Interstital: Urban Invasion : Nature and Significance of Play as a Cultural Phenomenon, The Definition of Play and The Classification of Games, The</article-title>
          MIT Press,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>I.</given-names>
            <surname>Schousboe</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          Winther-Lindqvist,
          <article-title>Children's Play</article-title>
          and Development:
          <string-name>
            <surname>Cultural-Historical</surname>
            <given-names>Perspectives</given-names>
          </string-name>
          ,
          <source>Chapter</source>
          <volume>15</volume>
          :
          <string-name>
            <surname>Play</surname>
          </string-name>
          ,
          <source>But Not Simply Play: The Anthropology of Play</source>
          ,
          <year>2013</year>
          . doi:
          <volume>10</volume>
          .1007/
          <fpage>978</fpage>
          -94-007-6579-5.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>D.</given-names>
            <surname>Michael</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <article-title>Serious games: Games that educate, train, and inform (</article-title>
          <year>2006</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Y. M.</given-names>
            <surname>Arif</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Ayunda</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N. M.</given-names>
            <surname>Diah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. B.</given-names>
            <surname>Garcia</surname>
          </string-name>
          ,
          <article-title>A systematic review of serious games for health education: Technology, challenges, and future directions, Transformative Approaches to Patient Literacy and Healthcare Innovation (</article-title>
          <year>2024</year>
          )
          <fpage>20</fpage>
          -
          <lpage>45</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Feng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. A.</given-names>
            <surname>González</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Mutch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Amor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Cabrera-Guerrero</surname>
          </string-name>
          ,
          <article-title>Exploring spiral narratives with immediate feedback in immersive virtual reality serious games for earthquake emergency training</article-title>
          ,
          <source>Multimedia Tools and Applications</source>
          <volume>82</volume>
          (
          <year>2023</year>
          )
          <fpage>125</fpage>
          -
          <lpage>147</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>N.</given-names>
            <surname>Stathakarou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Kononowicz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Swain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Karlgren</surname>
          </string-name>
          , et al.,
          <article-title>Game elements in the design of simulations in military trauma management training: Protocol for a systematic review</article-title>
          ,
          <source>JMIR Research Protocols</source>
          <volume>12</volume>
          (
          <year>2023</year>
          )
          <article-title>e45969</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>V.</given-names>
            <surname>Rossano</surname>
          </string-name>
          , G. Calvano,
          <article-title>Promoting sustainable behavior using serious games: Seadventure for ocean literacy</article-title>
          ,
          <source>IEEE Access 8</source>
          (
          <year>2020</year>
          )
          <fpage>196931</fpage>
          -
          <lpage>196939</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>W.</given-names>
            <surname>Hill</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Fanuel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Yuan</surname>
          </string-name>
          ,
          <article-title>Comparing serious games for cyber security education</article-title>
          ,
          <source>in: Proceedings of the 2020 ASEE Southeastern Section Conference</source>
          , Auburn, AL, USA,
          <year>2020</year>
          , pp.
          <fpage>8</fpage>
          -
          <lpage>9</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>M.</given-names>
            <surname>Calvano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Caruso</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Curci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Piccinno</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Rossano</surname>
          </string-name>
          , et al.,
          <article-title>A rapid review on serious games for cybersecurity education: Are" serious" and gaming aspects well balanced?</article-title>
          , in: IS-EUD Workshops,
          <year>2023</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Hart</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Margheri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Paci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sassone</surname>
          </string-name>
          ,
          <article-title>Riskio: A serious game for cyber security awareness and education</article-title>
          ,
          <source>Computers &amp; Security</source>
          <volume>95</volume>
          (
          <year>2020</year>
          )
          <fpage>101827</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>C.</given-names>
            <surname>Larman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. R.</given-names>
            <surname>Basili</surname>
          </string-name>
          ,
          <article-title>Iterative and incremental developments. a brief history</article-title>
          ,
          <source>Computer</source>
          <volume>36</volume>
          (
          <year>2003</year>
          )
          <fpage>47</fpage>
          -
          <lpage>56</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>J.</given-names>
            <surname>Schell</surname>
          </string-name>
          ,
          <article-title>The Art of Game Design: A Book of Lenses, Chapter 5: The Game Consists of Elements, 3rd ed., A K Peters/</article-title>
          CRC Press,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>R.</given-names>
            <surname>Eppmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bekk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Klein</surname>
          </string-name>
          ,
          <article-title>Gameful experience in gamification: Construction and validation of a gameful experience scale [gamex]</article-title>
          ,
          <source>Journal of interactive marketing 43</source>
          (
          <year>2018</year>
          )
          <fpage>98</fpage>
          -
          <lpage>115</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          <string-name>
            <surname>•</surname>
          </string-name>
          <article-title>The sources for the original idea of the games is available on this GitHub (Hacket), under GPL-3.0 license control</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          <string-name>
            <surname>•</surname>
          </string-name>
          <article-title>The sources for CyberDuel game is is available on this GitHub (CyberDuel), under GPL-3.0 license control</article-title>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>