'Control-Alt-Hack' game lets players try their hand at computer security

Jul 24, 2012
'Control-Alt-Hack' game lets players try their hand at computer security
Players assume the roles of characters with their own special skills. Game play involves completing missions by rolling the dice, using skills and occasionally pulling something out of a "Bag of Tricks." Credit: Control-Alt-Hack

Do you have what it takes to be an ethical hacker? Can you step into the shoes of a professional paid to outsmart supposedly locked-down systems? Now you can at least try, no matter what your background, with a new card game developed by University of Washington computer scientists.

"Control-Alt-Hack" gives teenage and young-adult players a taste of what it means to be a professional defending against an ever-expanding range of digital threats. The 's creators will present it this week in Las Vegas at 2012, an annual information-security meeting.

"Hopefully players will come away thinking differently about computer security," said creator Yoshi Kohno, a UW associate professor of and engineering.

The target audience is 15- to 30-year-olds with some knowledge of computer science, though not necessarily of computer security. The game could supplement a high school or introductory college-level computer science course, Kohno said, or it could appeal to information technology professionals who may not follow the evolution of computer security.

In the game, players work for Hackers, Inc., a small company that performs security audits and consultations for a fee. Three to six players take turns choosing a card that presents a hacking challenge that ranges in difficulty and level of seriousness.

Tamara Denning and Yoshi Kohno in the UW's Security and Privacy Research Lab play the game they created. Their game gives players a taste of what it's like to be a computer security professional. Research assistant Thomas Winegarden, a UW undergraduate, is on the left. Credit: Mary Levin, U. of Washington

In one mission, a player on a business trip gets bored and hacks the hotel minibar to disrupt its radio-tag payment system, then tells the manager. (A real project being presented at Black Hat this year exposes a in hotel keycard systems.)

"We went out of our way to incorporate humor," said co-creator Tamara Denning, a UW in computer science and engineering. "We wanted it to be based in reality, but more importantly we want it to be fun for the players."

This is not an educational game that tries to teach something specific, Denning said, but a game that's mainly designed to be fun and contains some real content as a side benefit. The team decided on an old-fashioned tabletop to make it social and encourage interaction.

Some scenarios incorporate research from Kohno's Security and Privacy Research Lab, such as security threats to cars, toy robots and implanted medical devices. The missions also touch other hot topics in computer security, such as botnets that use hundreds of hijacked computers to send spam, and vulnerabilities in online medical records.

Characters have various skills they can deploy. In addition to the predictable "software wizardry," skills include "lock picking" (for instance, breaking into a locked server room) and "social engineering" (like tricking somebody into revealing a password).

Graduate students who are current or former members of the UW lab served as loose models for many of the game's characters. Cards depict the characters doing hobbies, such as motorcycling and rock climbing, that their real-life models enjoy.

"We wanted to dispel people's stereotypes about what it means to be a computer scientist," Denning said.

The UW group licensed the game's mechanics from award-winning game designer Steve Jackson of Austin, Texas. They hired an artist to draw the characters and a Seattle firm to design the graphics. Adam Shostack, a security professional who helped develop a card game at Microsoft in 2010, is a collaborator and co-author.

Intel Corp. funded the game as a way to promote a broader awareness of computer-security issues among future and current technology professionals. Additional funding came from the National Science Foundation and the Association for Computing Machinery's Special Interest Group on Computer Science Education.

Explore further: Hackathon team's GoogolPlex gives Siri extra powers

add to favorites email to friend print save as pdf

Related Stories

Sony names Andrew House as head of games unit

Jun 29, 2011

(AP) -- Still reeling from a series of high-profile hacker attacks, Sony has named Andrew House as the president and group CEO of its video game unit, Sony Computer Entertainment.

Iconic computer game 'Civilization' joins Facebook

Jul 06, 2011

(AP) -- Long before "FarmVille" there was "Civilization," the iconic computer game in which players build a civilized world over thousands of years. Now, the game's designer, Sid Meier, is bringing his creation to Facebook.

Recommended for you

Android gains in US, basic phones almost extinct

13 hours ago

The Google Android platform grabbed the majority of mobile phones in the US market in early 2014, as consumers all but abandoned non-smartphone handsets, a survey showed Friday.

Hackathon team's GoogolPlex gives Siri extra powers

Apr 17, 2014

(Phys.org) —Four freshmen at the University of Pennsylvania have taken Apple's personal assistant Siri to behave as a graduate-level executive assistant which, when asked, is capable of adjusting the temperature ...

Microsoft CEO is driving data-culture mindset

Apr 16, 2014

(Phys.org) —Microsoft's future strategy: is all about leveraging data, from different sources, coming together using one cohesive Microsoft architecture. Microsoft CEO Satya Nadella on Tuesday, both in ...

User comments : 2

Adjust slider to filter visible comments by rank

Display comments: newest first

Mike_Syzygy
not rated yet Jul 25, 2012
When can we buy this?
antialias_physorg
not rated yet Jul 25, 2012
When can we buy this?

According to their website in fall of 2012

I'm not sure if posting the link constitutes advertising so I won't - but you can easily find it with google "Control-Alt-Hack(TM)" (don't forget the quotes).

On the site you can already download the rulebook.

More news stories

Health care site flagged in Heartbleed review

People with accounts on the enrollment website for President Barack Obama's signature health care law are being told to change their passwords following an administration-wide review of the government's vulnerability to the ...

Airbnb rental site raises $450 mn

Online lodging listings website Airbnb inked a $450 million funding deal with investors led by TPG, a source close to the matter said Friday.

Researchers uncover likely creator of Bitcoin

The primary author of the celebrated Bitcoin paper, and therefore probable creator of Bitcoin, is most likely Nick Szabo, a blogger and former George Washington University law professor, according to students ...