{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T16:12:55Z","timestamp":1784045575264,"version":"3.55.0"},"reference-count":60,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2019,11,22]],"date-time":"2019-11-22T00:00:00Z","timestamp":1574380800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2019,11,22]],"date-time":"2019-11-22T00:00:00Z","timestamp":1574380800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"FH St. P\u00f6lten - University of Applied Sciences"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2020,3]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Attacks on IT systems are a rising threat against the confidentiality, integrity, and availability of critical information and infrastructures. At the same time, the complex interplay of attack techniques and possible countermeasures makes it difficult to appropriately plan, implement, and evaluate an organization\u2019s defense. More often than not, the worlds of technical threats and organizational controls remain disjunct. In this article, we introduce PenQuest, a meta model designed to present a complete view on information system attacks and their mitigation while providing a tool for both semantic data enrichment and security education. PenQuest simulates time-enabled attacker\/defender behavior as part of a dynamic, imperfect information multi-player game that derives significant parts of its ruleset from established information security sources such as STIX, CAPEC, CVE\/CWE and NIST\u00a0SP\u00a0800-53. Attack patterns, vulnerabilities, and mitigating controls are mapped to counterpart strategies and concrete actions through practical, data-centric mechanisms. The gamified model considers and defines a wide range of actors, assets, and actions, thereby enabling the assessment of cyber risks while giving technical experts the opportunity to explore specific attack scenarios in the context of an abstracted IT infrastructure. We implemented PenQuest as a physical serious game prototype and successfully tested it in a higher education environment. Additional expert interviews helped evaluate the model\u2019s applicability to information security scenarios.\n<\/jats:p>","DOI":"10.1007\/s11416-019-00342-x","type":"journal-article","created":{"date-parts":[[2019,11,22]],"date-time":"2019-11-22T22:02:41Z","timestamp":1574460161000},"page":"19-61","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":40,"title":["PenQuest: a gamified attacker\/defender meta model for cyber security assessment and education"],"prefix":"10.1007","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6536-6706","authenticated-orcid":false,"given":"Robert","family":"Luh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marlies","family":"Temper","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Simon","family":"Tjoa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sebastian","family":"Schrittwieser","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Helge","family":"Janicke","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,11,22]]},"reference":[{"key":"342_CR1","first-page":"1","volume":"11","author":"S Barnum","year":"2012","unstructured":"Barnum, S.: Standardizing cyber threat intelligence information with the Structured Threat Information eXpression ($$\\text{ STIX }^{\\rm TM}$$). MITRE Corp. 11, 1\u201322 (2012)","journal-title":"MITRE Corp."},{"key":"342_CR2","doi-asserted-by":"crossref","unstructured":"Beckers, K., Pape, S.: A serious game for eliciting social engineering security requirements. In: 2016 IEEE 24th International Requirements Engineering Conference (RE), pp. 16\u201325. IEEE (2016)","DOI":"10.1109\/RE.2016.39"},{"key":"342_CR3","unstructured":"Benoit, K., Watanabe, K., Nutly, P., Obeng, A., Wang, H., Lauderdale, B., Lowe, W.: Quanteda: Quantitative Analysis of Textual Data. http:\/\/quanteda.io. R package version 0.99 (2017)"},{"key":"342_CR4","doi-asserted-by":"crossref","unstructured":"Blakley, B., McDermott, E., Geer, D.: Information security is information risk management. In: Proceedings of the 2001 Workshop on New Security Paradigms, pp. 97\u2013104. ACM (2001)","DOI":"10.1145\/508171.508187"},{"key":"342_CR5","unstructured":"BSI: Durchf\u00fchrung von Planspielen zur Informationssicherheit. Technical report (2014)"},{"key":"342_CR6","unstructured":"Caltagirone, S., Pendergast, A., Betz, C.: The Diamond Model of Intrusion Analysis. Technical report, Center for Cyber Intelligence Analysis and Threat Research, Hanover (2013)"},{"key":"342_CR7","volume-title":"Model Checking","author":"EM Clarke","year":"1999","unstructured":"Clarke, E.M., Grumberg, O., Peled, D.: Model Checking. MIT Press, Cambridge (1999)"},{"key":"342_CR8","doi-asserted-by":"publisher","unstructured":"Cook, A., Smith, R., Maglaras, L., Janicke, H.: Measuring the risk of cyber attack in industrial control systems. In: Proceedings of the 4th International Symposium for ICS & SCADA Cyber Security Research 2016, ICS-CSR\u201916, pp. 1\u201311. BCS Learning & Development Ltd., Belfast, United Kingdom (2016). https:\/\/doi.org\/10.14236\/ewic\/ICS2016.12","DOI":"10.14236\/ewic\/ICS2016.12"},{"issue":"3","key":"342_CR9","first-page":"75","volume":"18","author":"D Dicheva","year":"2015","unstructured":"Dicheva, D., Dichev, C., Agre, G., Angelova, G.: Gamification in education: a systematic mapping study. J. Educ. Technol. Soc. 18(3), 75 (2015)","journal-title":"J. Educ. Technol. Soc."},{"key":"342_CR10","unstructured":"Engebretson, P.H., Pauli, J.J., Streff, K.: Abstracting parent mitigations from the CAPEC attack pattern dictionary. In: Security and Management, pp. 245\u2013250 (2008)"},{"key":"342_CR11","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1007\/978-3-642-13675-7_13","volume-title":"Applications and Theory of Petri Nets","author":"Javier Esparza","year":"2010","unstructured":"Esparza, J., Leucker, M., Schlund, M.: Learning workflow petri nets. In: International Conference on Applications and Theory of Petri Nets, pp. 206\u2013225. Springer, New York (2010)"},{"key":"342_CR12","doi-asserted-by":"crossref","unstructured":"Fenz, S., Ekelhart, A.: Formalizing information security knowledge. In: Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, pp. 183\u2013194. ACM (2009)","DOI":"10.1145\/1533057.1533084"},{"key":"342_CR13","unstructured":"Freytag, T.: Woped\u2013workflow petri net designer. In: University of Cooperative Education, pp. 279\u2013282 (2005)"},{"key":"342_CR14","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1016\/j.compedu.2014.08.019","volume":"80","author":"MD Hanus","year":"2015","unstructured":"Hanus, M.D., Fox, J.: Assessing the effects of gamification in the classroom: a longitudinal study on intrinsic motivation, social comparison, satisfaction, effort, and academic performance. Comput. Educ. 80, 152\u2013161 (2015)","journal-title":"Comput. Educ."},{"issue":"1","key":"342_CR15","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/TPWRS.2006.889080","volume":"22","author":"AJ Holmgren","year":"2007","unstructured":"Holmgren, A.J., Jenelius, E., Westin, J.: Evaluating strategies for defending electric power networks against antagonistic attacks. IEEE Trans. Power Syst. 22(1), 76\u201384 (2007)","journal-title":"IEEE Trans. Power Syst."},{"key":"342_CR16","first-page":"80","volume":"1","author":"EM Hutchins","year":"2011","unstructured":"Hutchins, E.M., Cloppert, M.J., Amin, R.M.: Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Lead. Issues Inf. Warf. Secur. Res. 1, 80 (2011)","journal-title":"Lead. Issues Inf. Warf. Secur. Res."},{"key":"342_CR17","unstructured":"Joint Task Force Transformation Initiative: SP 800-53 rev. 4. Recommended Security Controls for Federal Information Systems and Organizations. Technical report, Gaithersburg, MD (2015)"},{"key":"342_CR18","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1613\/jair.301","volume":"4","author":"LP Kaelbling","year":"1996","unstructured":"Kaelbling, L.P., Littman, M.L., Moore, A.W.: Reinforcement learning: a survey. J. Artif. Intell. Res. 4, 237\u2013285 (1996)","journal-title":"J. Artif. Intell. Res."},{"key":"342_CR19","doi-asserted-by":"crossref","unstructured":"Kissel, R.: Glossary of key information security terms. NIST Interagency Reports NIST IR 7298(3) (2013)","DOI":"10.6028\/NIST.IR.7298r2"},{"key":"342_CR20","unstructured":"Kohnfelder, L., Garg, P.: The threats to our products. Microsoft Corporation (1999). https:\/\/adam.shostack.org\/microsoft\/The-Threats-To-Our-Products.docx"},{"key":"342_CR21","first-page":"80","volume-title":"Lecture Notes in Computer Science","author":"Barbara Kordy","year":"2011","unstructured":"Kordy, B., Mauw, S., Radomirovi\u0107, S., Schweitzer, P.: Foundations of attack\u2013defense trees. In: International Workshop on Formal Aspects in Security and Trust, pp. 80\u201395. Springer, Berlin (2010)"},{"key":"342_CR22","volume-title":"Lectures on the Theory of Games","author":"HW Kuhn","year":"2009","unstructured":"Kuhn, H.W.: Lectures on the Theory of Games. Princeton University Press, Princeton (2009)"},{"key":"342_CR23","doi-asserted-by":"publisher","DOI":"10.1201\/9781420031232","volume-title":"The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments","author":"DJ Landoll","year":"2005","unstructured":"Landoll, D.J., Landoll, D.: The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments. CRC Press, Boca Raton (2005)"},{"key":"342_CR24","volume-title":"Critical Infrastructure Protection in Homeland Security: Defending a Networked Nation","author":"TG Lewis","year":"2014","unstructured":"Lewis, T.G.: Critical Infrastructure Protection in Homeland Security: Defending a Networked Nation. Wiley, Berlin (2014)"},{"key":"342_CR25","volume-title":"Some Thoughts Concerning Education","author":"J Locke","year":"1895","unstructured":"Locke, J.: Some Thoughts Concerning Education. Cambridge University Press, Cambridge (1895)"},{"key":"342_CR26","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/s11416-016-0273-3","volume":"13","author":"R Luh","year":"2016","unstructured":"Luh, R., Marschalek, S., Kaiser, M., Janicke, H., Schrittwieser, S.: Semantics-aware detection of targeted attacks: a survey. J. Comput. Virol. Hacking Tech. 13, 47\u201385 (2016)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"342_CR27","doi-asserted-by":"crossref","unstructured":"Luh, R., Schrittwieser, S., Marschalek, S.: TAON: an ontology-based approach to mitigating targeted attacks. In: Proceedings of the 18th International Conference on Information Integration and Web-Based Applications and Services. ACM (2016)","DOI":"10.1145\/3011141.3011157"},{"key":"342_CR28","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1016\/j.cose.2019.03.015","volume":"84","author":"R Luh","year":"2019","unstructured":"Luh, R., Janicke, H., Schrittwieser, S.: AIDIS: detecting and classifying anomalous behavior in ubiquitous kernel processes. Comput. Secur. 84, 120\u2013147 (2019)","journal-title":"Comput. Secur."},{"key":"342_CR29","unstructured":"Marczewski, A.: Even Ninja Monkeys Like to Play: Gamification. CreateSpace Independent Publishing Platform, Game Thinking and Motivational Design (2015). ISBN 9781514745663"},{"issue":"4","key":"342_CR30","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1037\/h0054346","volume":"50","author":"AH Maslow","year":"1943","unstructured":"Maslow, A.H.: A theory of human motivation. Psychol. Rev. 50(4), 370 (1943)","journal-title":"Psychol. Rev."},{"key":"342_CR31","doi-asserted-by":"crossref","unstructured":"Mavroeidis, V., Bromander, S.: Cyber threat intelligence model: an evaluation of taxonomies, sharing standards, and ontologies within cyber threat intelligence. In: 2017 European Intelligence and Security Informatics Conference (EISIC), pp. 91\u201398. IEEE (2017)","DOI":"10.1109\/EISIC.2017.20"},{"key":"342_CR32","unstructured":"MITRE Corporation: CAPEC\u2014Common Attack Pattern Enumeration and Classification (CAPEC). https:\/\/capec.mitre.org\/. Accessed 22 Sept. 2015"},{"key":"342_CR33","unstructured":"MITRE Corporation: CVE\u2014Common Vulnerabilities and Exposures (CVE). https:\/\/cve.mitre.org\/. Accessed 22 Sept. 2015"},{"key":"342_CR34","unstructured":"MITRE Corporation: CWE\u2014Common Weakness Enumeration. https:\/\/cwe.mitre.org\/. Accessed 22 Sept. 2015"},{"key":"342_CR35","unstructured":"MITRE Corporation: STIX\u2014Structured Threat Information Expression | STIX Project Documentation. https:\/\/stixproject.github.io\/. Accessed 22 Sept. 2015"},{"key":"342_CR36","doi-asserted-by":"crossref","unstructured":"Miura-Ko, R.A., Yolken, B., Bambos, N., Mitchell, J.: Security investment games of interdependent organizations. In: 2008 46th Annual Allerton Conference on Communication, Control, and Computing, pp. 252\u2013260. IEEE (2008)","DOI":"10.1109\/ALLERTON.2008.4797564"},{"key":"342_CR37","unstructured":"Mobasher, B., Burke, R., Sandvig, J.J.: Model-based collaborative filtering as a defense against profile injection attacks. In: AAAI, volume\u00a06, p. 1388 (2006)"},{"key":"342_CR38","unstructured":"Morgan, S.: 2017 Cybercrime Report. Technical report, Cybersecurity Ventures (2017)"},{"key":"342_CR39","unstructured":"Munsey, C.: Economic Espionage: Competing for Trade by Stealing Industrial Secrets. https:\/\/leb.fbi.gov\/2013\/october-november\/economic-espionage-competing-for-trade-by-stealing-industrial-secrets. Accessed 15 Sept. 2015 (2013)"},{"key":"342_CR40","unstructured":"Myerson, R.B.: Game theory: analysis of conflict. Harvard University Press (1991). ISBN 9780674341159. https:\/\/books.google.at\/books?id=1w5PAAAAMAAJ"},{"key":"342_CR41","unstructured":"Nguyen, K.C., Alpcan, T., Basar, T.: Security games with incomplete information. In: International Conference on Communications, 2009. IEEE ICC\u201909. pp. 1\u20136. IEEE (2009)"},{"key":"342_CR42","unstructured":"Ponemon Institute: Cost of cyber crime study: Insights on the security investments that make a difference, Accenture (2017)"},{"key":"342_CR43","doi-asserted-by":"crossref","unstructured":"Rieb, A., Lechner, U.: Operation digital chameleon: towards an open cybersecurity method. In: Proceedings of the 12th International Symposium on Open Collaboration, p. 7. ACM (2016)","DOI":"10.1145\/2957792.2957800"},{"key":"342_CR44","unstructured":"Rieb, A.J., Hofmann, M., Laux, A., Rudel, S., Lechner, U.: Wie IT-Security Matchplays als Awarenessma\u00dfnahme die IT-Sicherheit verbessern k\u00f6nnen. In: 13. Internationale Tagung Wirtschaftsinformatik, pp. 867\u2013881 (2017)"},{"issue":"8","key":"342_CR45","doi-asserted-by":"publisher","first-page":"929","DOI":"10.1002\/sec.299","volume":"5","author":"A Roy","year":"2012","unstructured":"Roy, A., Kim, D.S., Trivedi, K.S.: Attack countermeasure trees (act): towards unifying the constructs of attack and defense trees. Secur. Commun. Netw. 5(8), 929\u2013943 (2012)","journal-title":"Secur. Commun. Netw."},{"key":"342_CR46","doi-asserted-by":"crossref","unstructured":"Roy, S., Ellis, C., Shiva, S., Dasgupta, D., Shandilya, V., Wu, Q.: A survey of game theory as applied to network security. In: 2010 43rd Hawaii International Conference on System Sciences (HICSS) pp. 1\u201310. IEEE (2010)","DOI":"10.1109\/HICSS.2010.35"},{"key":"342_CR47","unstructured":"Sauerwein, C., Sillaber, C., Mussmann, A., Breu, R.: Threat intelligence sharing platforms: an exploratory study of software vendors and research perspectives. In: Proceedings der 13. Internationalen Tagung Wirtschaftsinformatik (2017)"},{"key":"342_CR48","first-page":"29","volume":"6","author":"Y Shang","year":"2012","unstructured":"Shang, Y.: Optimal attack strategies in a dynamic botnet defense model. Appl. Math. Inf. Sci 6, 29\u201333 (2012)","journal-title":"Appl. Math. Inf. Sci"},{"issue":"11","key":"342_CR49","doi-asserted-by":"publisher","first-page":"2498","DOI":"10.1101\/gr.1239303","volume":"13","author":"P Shannon","year":"2003","unstructured":"Shannon, P., Markiel, A., Ozier, O., Baliga, N.S., Wang, J.T., Ramage, D., Amin, N., Schwikowski, B., Ideker, T.: Cytoscape: a software environment for integrated models of biomolecular interaction networks. Genome Res. 13(11), 2498\u20132504 (2003)","journal-title":"Genome Res."},{"issue":"1","key":"342_CR50","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1016\/j.compedu.2008.06.011","volume":"52","author":"RS Shaw","year":"2009","unstructured":"Shaw, R.S., Chen, C.C., Harris, A.L., Huang, H.-J.: The impact of information richness on information security awareness training effectiveness. Comput. Educ. 52(1), 92\u2013100 (2009)","journal-title":"Comput. Educ."},{"key":"342_CR51","unstructured":"Shostack, A.: Elevation of privilege: drawing developers into threat modeling. In: 3GSE (2014)"},{"key":"342_CR52","doi-asserted-by":"crossref","unstructured":"Stoneburner, G., Goguen, A.Y., Feringa, A.: SP 800\u201330. Risk Management Guide for Information Technology Systems, Technical report (2002)","DOI":"10.6028\/NIST.SP.800-30"},{"key":"342_CR53","unstructured":"Syed, Z., Padia, A., Finin, T., Mathews, M.L., Joshi, A.: UCO: a unified cybersecurity ontology. In: Proceedings of the AAAI Workshop on Artificial Intelligence for Cyber Security. AAAI Press (2016)"},{"key":"342_CR54","unstructured":"Symantec: Internet Security Threat Report Volume 20. Symantec (2015)"},{"key":"342_CR55","unstructured":"Symantec: Internet Security Threat Report Volume 23. Symantec (2018)"},{"issue":"4","key":"342_CR56","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1108\/09685229810227649","volume":"6","author":"ME Thomson","year":"1998","unstructured":"Thomson, M.E., von Solms, R.: Information security awareness: educating your users effectively. Inf. Manag. Comput. Secur. 6(4), 167\u2013173 (1998)","journal-title":"Inf. Manag. Comput. Secur."},{"key":"342_CR57","unstructured":"Undercoffer, J., Pinkston, J., Joshi, A., Finin, T.: A target-centric ontology for intrusion detection. In: 18th International Joint Conference on Artificial Intelligence, pp. 9\u201315 (2004)"},{"key":"342_CR58","doi-asserted-by":"crossref","unstructured":"Wang, J.A., Guo, M.: OVM: an ontology for vulnerability management. In: Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies, p. 34. ACM (2009)","DOI":"10.1145\/1558607.1558646"},{"key":"342_CR59","doi-asserted-by":"publisher","unstructured":"Wen, Z.A., Li, Y., Wade, R., Huang, J., Wang, A.: What.hack: Learn phishing email defence the fun way. In: Proceedings of the 2017 CHI Conference Extended Abstracts on Human Factors in Computing Systems, CHI EA\u201917, pp. 234\u2013237, New York, NY, USA, 2017. ACM. ISBN 978-1-4503-4656-6. https:\/\/doi.org\/10.1145\/3027063.3048412","DOI":"10.1145\/3027063.3048412"},{"key":"342_CR60","unstructured":"You, X.Z., Shiyong, Z.: A kind of network security behavior model based on game theory. In: Proceedings of the Fourth International Conference on Parallel and Distributed Computing, Applications and Technologies, 2003. PDCAT\u20192003. pp. 950\u2013954. IEEE (2003)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-019-00342-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-019-00342-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-019-00342-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,21]],"date-time":"2020-11-21T01:13:23Z","timestamp":1605921203000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-019-00342-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,11,22]]},"references-count":60,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,3]]}},"alternative-id":["342"],"URL":"https:\/\/doi.org\/10.1007\/s11416-019-00342-x","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,11,22]]},"assertion":[{"value":"10 July 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 November 2019","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 November 2019","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}