Skip to content
Book Open access

BREAK-IT: Understanding Novice Approaches to an Attack Challenge Task

Jul 2026 · Annual Conference on Innovation and Technology in Computer Science Education · pp. 100-106 · 0 citations · 39 references
Computer Science

TL;DR

This paper examines how undergraduates conceptualize and identify security threats by analyzing how they attempt to find ''attacks'' in other students' code, and offers recommendations for CS instructors and curriculum committees on integrating foundational security concepts into programming assignments to help students better recognize and reason about computer security threats.

Abstract

With increasing reliance on computing systems and the growing frequency of cybersecurity incidents, it is important for CS undergraduates to develop foundational security skills before entering professional roles. In particular, students should be able to recognize and reason about potential security vulnerabilities in software. However, existing approaches to integrating security into the CS curriculum often emphasize narrow areas such as secure coding or highly technical topics like cryptography or software security, rather than fostering a broader perception of security threats. In this paper, we examine how undergraduates conceptualize and identify security threats by analyzing how they attempt to find ''attacks'' in other students' code. We conducted a think-aloud study with 15 CS undergraduates at a US-based R1 institution who had no formal training in computer security. Participants analyzed peer-developed text-based video game implementations to identify potential vulnerabilities, drawing on their prior experience implementing a similar game in an earlier ''Build-It'' task. Our analysis shows that students employed systematic, hypothesis-driven strategies, including unit testing, edge-case exploration, and controlled experimentation, while also drawing on prior experiences both inside and outside the classroom. Although most students attempted to validate whether an attack was successful, several stopped after identifying a single vulnerability, leaving additional issues unexplored. Based on these findings, we offer recommendations for CS instructors and curriculum committees on integrating foundational security concepts into programming assignments to help students better recognize and reason about computer security threats.

Read PDF

Similar papers

Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, S. Sharma · 1 citation
Conference Aug 2026

Security Analysis of IRC Server Design: Mapping Protocol Features to Attack Vectors Using the MITRE ATT&CK Framework

Internet Relay Chat (IRC) server development remains a cornerstone of computer networking education. However, these academic practices often prioritize functional concurrency over defensive design, leading to an accumulation of security vulnerabilities. This paper analyzes how functionality-first designs unconsciously...

Melisa Saritas, Yusuf Tahir Kaya, Malek Malkawi et al. · 0 citations
Preprint Sep 2026

Exploring the Role of Security Experience and ChatGPT Usage Strategies on Secure Software Engineering Education

The rapid adoption of Large Language Models (LLMs) is reshaping software engineering education, but their role in secure software engineering education remains underexplored. We report an exploratory empirical study of how 26 graduate students in a part-time MSc Cybersecurity programme used ChatGPT during a vulnerabili...

Alessio Ferrari, Minh An Nguyen, Kushal Ramkumar et al. · 0 citations
Open access 2026

Web application security using top 10 OWASP

It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.

S. Banu, H. Shanmatha, Mehdi Gheisari et al. · 0 citations
Book Open access Aug 2026

"How do security threats affect my work?" - Software Developers’ Mental Models of IT Security Threats and Mitigation Strategies

While end-user decisions primarily impact their own data, software developers’ security behavior can affect millions of users’ data. To understand developers’ decision-making processes, we explored their mental models of security threats. We conducted semi-structured interviews, based on Wash [89] with 37 professional...

Asli Yardim, Anna-Marie Ortloff, Anne Mertens et al. · 0 citations
Book Open access Aug 2026

Interactive IT Security Training: Comparing an Attacker-Centric IT Security 2D RPG and Text Policy Training

Game-based approaches are increasingly used in security awareness and training, yet their impact on recall performance compared to traditional formats remains insufficiently examined, particularly for conveying organizational security policies. Role-playing games (RPGs) offer interactive, narrative-driven experiences,...

Sangavi Shanthakumar, Markus Schöps, Tarini Saka et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.