<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>M. Calvano); i.antonio.curci@uniba.it (A. Curci); antonio.piccinno@uniba.it
(A. Piccinno); veronica.rossano@uniba.it (V. Rossano)</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Design of a Serious Game for Cybersecurity Education: Cyber Academy</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Miriana Calvano</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Antonio Curci</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Antonio Piccinno</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Veronica Rossano</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Bari "Aldo Moro", Department of Computer Science Via Edoardo Orabona</institution>
          ,
          <addr-line>4 70125 Bari</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Pisa, Department of Computer Science</institution>
          ,
          <addr-line>Largo B. Pontecorvo, 3 56127, Pisa</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2024</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>The exponential spread of technology and the increase of sophistication of internet services has brought countless advantages and has allowed huge steps towards scientific progress, but it also hides challenges, risks, and threats that individuals have to be aware of. Cybersecurity is the field of computer science that deals with threats that come from technology in all of its facets. This implies that final users have to be appropriately educated and trained in order to be able to protect themselves from all the risks that hide behind the use of daily technology. This work aims at proposing a serious game for cybersecurity education, which incorporates realistic scenarios and challenges concerning their knowledge of cybersecurity principles and techniques.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Cybersecurity Education</kwd>
        <kwd>Serious games</kwd>
        <kwd>Game-based Learning</kwd>
        <kwd>Gamification</kwd>
        <kwd>Design</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Technology and learning have always had a deep and interconnected relationship. Throughout
human history, a lot of ways have been thought and implemented with the aim to enhance our
ability to learn, understand, and communicate. Through the employment of technology the
learning process is becoming more accessible, engaging, and personalized, tailoring educational
experiences to individual needs and preferences [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. In this regard, due to the growth of available
data and, at the same time, to the increasing reliance of digital technology, new challenges
and issues emerged [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. In this context, cybersecurity has become crucial for individuals and
organizations; it refers to "the process of protecting information by preventing, detecting,
and responding to attacks" [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ]. To reduce the likelihood and impact of cyber-attacks it is
necessary to teach individuals cybersecurity related concepts, threats, and possible ways to
identify potential threats [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>
        With the objective of engaging learners by providing an immersive and more efective learning
experience, serious games are increasingly being used in a variety of fields (e.g., healthcare,
education, business. . . ) [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ][
        <xref ref-type="bibr" rid="ref7">7</xref>
        ][8][9]. In fact, many studies demonstrate that the employment
of game-based learning methodologies can positively impact the process of acquiring new
knowledge and gaining skills [10]. Defined by Kalampurtzis, serious game are "games that do
not have entertainment, enjoyment, or fun as their primary purpose [11]".
      </p>
      <p>In the current scenario, there are many serious games concerning cybersecurity and were
designed with the goal of teaching players about its main topics. Nevertheless, not always the
balance between learning and gaming aspects is ensured leading to boredom and frustration
feelings. For example, the serious game Cybercity Chronicles 1 allows players to learn basic
cybersecurity concepts, but it has too many levels leading to the loss of interest. Other important
aspects to include in the design of serious games are the user interface and the storyline, but
not always they are considered. For instance, Google XSS 2 allows users to acquire a suficient
background in the field of cybersecurity, but the user interface is too minimal and it lacks of a
storyline [12, 13].</p>
      <p>To fill the existing gaps, in this research work a novel serious game for cybersecurity, called
Cyber Academy, is presented and described. The game is being created following the iterative
game design process which consists of four phases: planning, design and implementation,
testing and evaluation [11]. This manuscript presents the planning and design phases while
exploring the main characteristics and functionalities.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Cyber Academy: planning and design</title>
      <p>Cyber Academy is a Serious Game for cybersecurity that aims to raise awareness with respect
to the most important topics of this domain. By knowing the digital risks and threats to which
an individual is subjected, it is easier to counter them and avoid being a victim of them. The
target audience of Cyber Academy encompasses people aged in the range 16 to 60 years old
with suficient familiarity with computer science and mediumhigh reading skills. Concerning
the technical aspects of the implementation of this serious game, it is planned to develop an
application for mobile devices (i.e., smartphones and tablets).</p>
      <p>Cyber Academy falls in the category of trivia games, in which the player is required to
answer to some questions about diferent topics, and she/he must get as many correct answers
as possible to win the game. This genre has been chosen because, the aim of the game is to
enhance the players’ awareness about basic cybersecurity topics while enjoying the learning
activity [? ] [14]. In this way, the balance between the learning and gaming aspects can be
guaranteed.</p>
      <sec id="sec-2-1">
        <title>2.1. Game Summary</title>
        <p>The game flow outlines the major stages, interactions, and progression that players will
experience. It will be organized in levels in which the player is allowed to learn cybersecurity
concepts. More specifically, during the levels of the game, the player will interact with an avatar
who will guide them along an educational path that include quizzes and minigames. When
planning the development of any type of game, it is important to define its story, which refers
to the narrative and the plot that provides a context, background, and purpose to the gameplay.
1https://www.sicurezzanazionale.gov.it/sisr.nsf/cybercity-chronicles.html
2https://xss-game.appspot.com/
The story that Cyber Academy revolves around is set in the 21st century where chaos and
cyber-crimes reign. The story features Blue and Red as protagonists; the characters are inspired
by the role of the blue and red team in the real world. Blue is the champion of justice who helps
and teaches victims how to fight cyber-crimes, while Red represents the red Team and is Blue’s
antagonist. During the game, the user is presented with numerous threats caused by Red, that
has to face with Blue’s help with the aim to make the world a safe place.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Aesthetics</title>
        <p>The aesthetics refer to the visual and sensory elements that are included in the user interface and
that influence the gaming experience. With the objective of recalling the standard cybersecurity
colors, blue was chosen for the background because it represents the blue team that is responsible
for the defense against the attacks.</p>
      </sec>
      <sec id="sec-2-3">
        <title>2.3. Prototypes</title>
        <p>According to the ISO 9241, prototypes are a representation of a product or a system that can be
used for evaluation and further development purposes [15]. Figure 1 illustrates the horizontal
prototype of Cyber Academy and is the preliminary step to the development by allowing to
try multiple design solutions and adjust contents, titles, and button positions. This approach
resulted to be useful in analyzing how the flow of the application translates into real-life
interaction and use cases. In particular, the game allows players to choose the modality that
they want to embark on: having a guided course from level 1 to level 5 or deciding to select the
topic that they want to learn about, which happens in Step 2. Step 3-4 represent an example of
how each level is structured: there are small explanations of cybersecurity concepts followed
by challenges and quizzes. Depending the answers provided by the player, the behavior of the
game changes: as illustrated in Step 4-6, wrong answers lead to further clarifications of the
topic, while right answers are reinforced by congratulations and moving on to other concepts.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Educational Elements in Cyber Academy</title>
      <p>The necessary informative resources for defining the educational elements of Cyber Academy
are books, articles and similar apps.</p>
      <sec id="sec-3-1">
        <title>3.1. Topics</title>
        <p>The choice of the topics was based on an in-depth research of the literature and interviews with
end users to understand the most addressed areas of cybersecurity in serious games and the
current gaps.</p>
        <p>Interviews were performed with the target users of Cyber Academy by asking them how
much are familiar with technology and which is their knowledge about cyber threats.</p>
        <p>Since this serious game is conceived for people who are not familiar with cybersecurity with
respect to its technicalities, the topics range from basic notions to more complex topics [16].
The incremental cognitive dificulty was an intentional choice to keep the player engaged and
to provide them with new challenges that are slightly more arduous, but afordable in terms of
cognitive efort [ 17]. More specifically each topic is addressed by undertaking both a theoretical
approach, providing definitions and a practical one by integrating exercises and challenges. At
the current stage, it is intended to include the following topics:
• Introduction To Cybersecurity: this chapter aims at giving the player an overview of
the basics of Cybersecurity, as in the concepts of attacks, threats, and assets [18].
• Vulnerabilities: the core of this chapter is to explain players what vulnerabilities are,
which implications they have on people’s real lives and how they can be preventable [19].
• Security: this chapter is incredibly crucial for the game since the topic of the CIA triad is
addressed [20].
• Password and Privacy: this topic was chosen because it is of widespread interest and
afects everyone who benefits from any type of online service [21].
• Attacks: the most common types of attacks are involved, such as phishing, eavesdropping</p>
        <p>DDoS (Distributed Denial of Service), and malware [22, 20].</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Skills</title>
        <p>Putting players situations in which they need to dynamically act, make decisions, and evaluate
situations is key for an efective learning process. The practical skills that Cyber Academy aims
at teaching players are: to respond to critical situations; to create independently strong and
secure passwords that are easy to remember; to be aware of their technological surroundings;
to develop technical abilities in the field.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusions and Future Works</title>
      <p>Cybersecurity can be as intriguing as challenging when it comes to learning about it and all
of its numerous characteristics. Serious games can represent a highly powerful tool to train
individuals in this context.</p>
      <p>This contribution presents Cyber Academy, a serious game for cybersecurity tailored to
people who are not experts and that have basic knowledge and background experience in
terms of daily technology usage. The objective lies in making people aware about how to face
cyber-threats.</p>
      <p>Future works of this research work involve integrating AI-powered chatbots giving users
the impression that they are interacting with an entity with concrete speech skills, making the
content of the conversation more relevant and memorable. This feature would reinforce the
aspect of personalized learning fostering the symbiosis between the human and technology.
In this way a smoother and realistic experience of use is provided to the end-users. Another
future work may concern the integration of a database, in which users’ information is stored,
applying security and privacy patterns and rules, so that players can make use of a system that
better suits their needs and to keep their progress saved. This would imply the use of external
API and the construction of a domain to communicate with.
methods approach exploring the potential and examining the efectiveness of a serious
game in the treatment of eating disorders, Journal of Eating Disorders 12 (2024) 35.
[8] T. Anderson, G. Prue, G. McDowell, P. Stark, C. Brown Wilson, L. Graham Wisener, H. Kerr,
G. Caughers, K. Rogers, L. Cook, et al., Co-design and evaluation of a digital serious game
to promote public awareness about pancreatic cancer, BMC Public Health 24 (2024) 570.
[9] F. Xiong, C. Drieschner, H. Wittges, H. Krcmar, Design and implementation of a serious
game-teaching the interdependency between business models and business processes,
in: International Conference on Interactive Collaborative Learning, Springer, 2023, pp.
503–514.
[10] A. Yasin, L. Liu, T. Li, R. Fatima, W. Jianmin, Improving software security awareness
using a serious game, IET Software 13 (2019) 159–169. doi:https://doi.org/10.1049/
iet-sen.2018.5095.
[11] G. Kalmpourtzis, Educational game design fundamentals : a journey to creating intrinsically
motivating learning experiences, 1st ed., Taylor &amp; Francis Group, 2019, p. 72.
[12] V. Barletta, M. Calvano, F. Caruso, A. Curci, V. Rossano, Serious games for cybersecurity:
Evaluating a design framework, in: EDULEARN23 Proceedings, 15th International
Conference on Education and New Learning Technologies, IATED, 2023, pp. 4810–4815. URL:
https://doi.org/10.21125/edulearn.2023.1279. doi:10.21125/edulearn.2023.1279.
[13] V. S. Barletta, M. Calvano, F. Caruso, A. Curci, A. Piccinno, Serious games for cybersecurity:
How to improve perception and human factors, in: 2023 IEEE International Conference on
Metrology for eXtended Reality, Artificial Intelligence and Neural Engineering
(MetroXRAINE), 2023, pp. 1110–1115. doi:10.1109/MetroXRAINE58569.2023.10405607.
[14] F. Cassano, A. Piccinno, T. Roselli, V. Rossano, Gamification and learning analytics to
improve engagement in university courses, in: T. Di Mascio, P. Vittorini, R. Gennari,
F. De la Prieta, S. Rodríguez, M. Temperini, R. Azambuja Silveira, E. Popescu, L. Lancia
(Eds.), Methodologies and Intelligent Systems for Technology Enhanced Learning, 8th
International Conference, Springer International Publishing, Cham, 2019, pp. 156–163.
[15] I. O. for Standardization, Iso 9241:210 - ergonomics of human-system interaction:
Humancentred design for interactive systems, 2019. URL: https://www.iso.org/standard/77520.
html.
[16] R. Matovu, J. C. Nwokeji, T. Holmes, T. Rahman, Teaching and Learning
Cybersecurity Awareness with Gamification in Smaller Universities and Colleges, in: 2022
IEEE Frontiers in Education Conference (FIE), IEEE, Uppsala, Sweden, 2022, pp. 1–9.
doi:10.1109/FIE56618.2022.9962519.
[17] M. Salazar, J. Gaviria, C. Laorden, P. G. Bringas, Enhancing cybersecurity learning through
an augmented reality-based serious game, in: 2013 IEEE Global Engineering Education
Conference (EDUCON), IEEE, Berlin, 2013, pp. 602–607. URL: http://ieeexplore.ieee.org/
document/6530167/. doi:10.1109/EduCon.2013.6530167.
[18] J. Pande, Introduction to Cyber Security, 2017.
[19] P. Sangaroonsilp, H. K. Dam, A. Ghose, On privacy weaknesses and vulnerabilities in
software systems, in: Proceedings of the 45th International Conference on Software
Engineering, ICSE ’23, IEEE Press, 2023, p. 1071–1083. doi:10.1109/ICSE48619.2023.
00097.
[20] M. De Vincenzi, G. Costantino, I. Matteucci, F. Fenzl, C. Plappert, R. Rieke, D. Zelle, A
systematic review on security attacks and countermeasures in automotive ethernet, ACM
Comput. Surv. 56 (2024). URL: https://doi.org/10.1145/3637059. doi:10.1145/3637059.
[21] S. Komanduri, R. Shay, P. G. Kelley, M. L. Mazurek, L. Bauer, N. Christin, L. F. Cranor,
S. Egelman, Of passwords and people: measuring the efect of password-composition
policies, in: Proceedings of the SIGCHI Conference on Human Factors in Computing
Systems, CHI ’11, Association for Computing Machinery, New York, NY, USA, 2011, p.
2595–2604. doi:10.1145/1978942.1979321.
[22] G. Desolda, L. S. Ferro, A. Marrella, T. Catarci, M. F. Costabile, Human factors in phishing
attacks: A systematic literature review, ACM Comput. Surv. 54 (2021). doi:10.1145/
3469886.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Pagano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Angelelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Calvano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Curci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Piccinno</surname>
          </string-name>
          ,
          <article-title>Quantum computing for learning analytics: An overview of challenges and integration strategies</article-title>
          ,
          <source>in: Proceedings of the 2nd International Workshop on Quantum Programming for Software Engineering, QP4SE</source>
          <year>2023</year>
          ,
          <article-title>Association for Computing Machinery</article-title>
          , New York, NY, USA,
          <year>2023</year>
          , p.
          <fpage>13</fpage>
          -
          <lpage>16</lpage>
          . URL: https://doi.org/10.1145/3617570.3617867. doi:
          <volume>10</volume>
          .1145/3617570.3617867.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>V. S.</given-names>
            <surname>Barletta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Cassano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Pagano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Piccinno</surname>
          </string-name>
          ,
          <article-title>New perspectives for cyber security in software development: when end-user development meets artificial intelligence</article-title>
          ,
          <source>in: 2022 International Conference on Innovation and Intelligence for Informatics, Computing, and Technologies (3ICT)</source>
          ,
          <year>2022</year>
          , pp.
          <fpage>531</fpage>
          -
          <lpage>534</lpage>
          . doi:
          <volume>10</volume>
          .1109/3ICT56508.
          <year>2022</year>
          .
          <volume>9990622</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>C. C.</given-names>
            <surname>Editor</surname>
          </string-name>
          , Cybersecurity - glossary: Csrc,
          <year>2021</year>
          . URL: https://csrc.nist.gov/glossary/term/ cybersecurity.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M. T.</given-names>
            <surname>Baldassarre</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. S.</given-names>
            <surname>Barletta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Caivano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Raguseo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Scalera</surname>
          </string-name>
          ,
          <article-title>Teaching cyber security: The hack-space integrated model</article-title>
          , volume
          <volume>2315</volume>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>M. T.</given-names>
            <surname>Baldassarre</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. S.</given-names>
            <surname>Barletta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Caivano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Piccinno</surname>
          </string-name>
          ,
          <article-title>A visual tool for supporting decision-making in privacy oriented software development</article-title>
          ,
          <source>in: Proceedings of the International Conference on Advanced Visual Interfaces</source>
          ,
          <source>AVI '20</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2020</year>
          . doi:
          <volume>10</volume>
          .1145/3399715.3399818.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>V.</given-names>
            <surname>Rossano</surname>
          </string-name>
          , G. Calvano,
          <article-title>Promoting sustainable behavior using serious games: Seadventure for ocean literacy</article-title>
          ,
          <source>IEEE Access 8</source>
          (
          <year>2020</year>
          )
          <fpage>196931</fpage>
          -
          <lpage>196939</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>M. M. Guala</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Bikic</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Bul</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Clinton</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Mejdal</surname>
            ,
            <given-names>H. N.</given-names>
          </string-name>
          <string-name>
            <surname>Nielsen</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          <string-name>
            <surname>Stenager</surname>
            ,
            <given-names>A</given-names>
          </string-name>
          . Sø- gaard
          <string-name>
            <surname>Nielsen</surname>
          </string-name>
          ,
          <article-title>“maze out”: a study protocol for a randomised controlled trial using a mix</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>