Skip to content
Book Open access

BREAK-IT: Understanding Novice Approaches to an Attack Challenge Task

Jul 2026 · Annual Conference on Innovation and Technology in Computer Science Education · pp. 100-106 · 0 citations · 39 references
Computer Science

TL;DR

This paper examines how undergraduates conceptualize and identify security threats by analyzing how they attempt to find ''attacks'' in other students' code, and offers recommendations for CS instructors and curriculum committees on integrating foundational security concepts into programming assignments to help students better recognize and reason about computer security threats.

Abstract

With increasing reliance on computing systems and the growing frequency of cybersecurity incidents, it is important for CS undergraduates to develop foundational security skills before entering professional roles. In particular, students should be able to recognize and reason about potential security vulnerabilities in software. However, existing approaches to integrating security into the CS curriculum often emphasize narrow areas such as secure coding or highly technical topics like cryptography or software security, rather than fostering a broader perception of security threats. In this paper, we examine how undergraduates conceptualize and identify security threats by analyzing how they attempt to find ''attacks'' in other students' code. We conducted a think-aloud study with 15 CS undergraduates at a US-based R1 institution who had no formal training in computer security. Participants analyzed peer-developed text-based video game implementations to identify potential vulnerabilities, drawing on their prior experience implementing a similar game in an earlier ''Build-It'' task. Our analysis shows that students employed systematic, hypothesis-driven strategies, including unit testing, edge-case exploration, and controlled experimentation, while also drawing on prior experiences both inside and outside the classroom. Although most students attempted to validate whether an attack was successful, several stopped after identifying a single vulnerability, leaving additional issues unexplored. Based on these findings, we offer recommendations for CS instructors and curriculum committees on integrating foundational security concepts into programming assignments to help students better recognize and reason about computer security threats.

Read PDF

Similar papers

Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, S. Sharma · 1 citation
Conference Aug 2026

Security Analysis of IRC Server Design: Mapping Protocol Features to Attack Vectors Using the MITRE ATT&CK Framework

Internet Relay Chat (IRC) server development remains a cornerstone of computer networking education. However, these academic practices often prioritize functional concurrency over defensive design, leading to an accumulation of security vulnerabilities. This paper analyzes how functionality-first designs unconsciously...

Melisa Saritas, Yusuf Tahir Kaya, Malek Malkawi et al. · 0 citations
Preprint Sep 2026

Exploring the Role of Security Experience and ChatGPT Usage Strategies on Secure Software Engineering Education

The way students engage with ChatGPT may be more informative than whether they use it, and this report suggests that the way students engage with ChatGPT may be more informative than whether they use it, to guide students toward effective LLM use in secure software engineering education.

Alessio Ferrari, Minh An Nguyen, Kushal Ramkumar et al. · 0 citations
Open access 2026

Web application security using top 10 OWASP

It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.

S. Banu, H. Shanmatha, Mehdi Gheisari et al. · 0 citations
Book Open access Aug 2026

"How do security threats affect my work?" - Software Developers’ Mental Models of IT Security Threats and Mitigation Strategies

This work conducted semi-structured interviews with professional software developers and categorized the threats they discussed using the STRIDE threat modeling approach, finding distinct roles through which developers engage with security threats, including collaborator, end-user, tool-user, and business roles.

Asli Yardim, Anna-Marie Ortloff, Anne Mertens et al. · 0 citations
Book Open access Aug 2026

Interactive IT Security Training: Comparing an Attacker-Centric IT Security 2D RPG and Text Policy Training

This work develops a 2D IT security role-playing serious game designed to convey corporate policies within a fictional organizational scenario, and shows that game-based and hybrid formats did not improve overall policy recall compared to text-based training.

Sangavi Shanthakumar, Markus Schöps, Tarini Saka et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.