Text size
  • Small
  • Medium
  • Large
  • Standard
  • Blue text on blue
  • High contrast (Yellow text on black)
  • Blue text on beige

    HATCH: Hack And Trick Capricious Humans - A Serious Game on Social Engineering

    HCI 2016 - Fusion!

    Proceedings of the 30th International BCS Human Computer Interaction Conference (HCI 2016)

    Bournemouth University, Poole, UK, 11 - 15 July 2016


    Kristian Beckers, Sebastian Pape, Veronika Fries


    Social engineering is the illicit acquisition of information about computer systems by primarily non-technical means. Although the technical security of most critical systems is usually being regarded in penetration tests, such systems remain highly vulnerable to attacks fromsocial engineers that exploit human behavioural patterns to obtain information (e.g., phishing). To achieve resilience against these attacks, we need to train people to teach them how these attacks work and how to detect them. We propose a serious game that helps players to understand how social engineering attackers work. The game can be played based on the real scenario in the company/department or based on a generic office scenario with personas that can be attacked. Our game trains people in realising social engineering attacks in an entertaining way, which shall cause a lasting learning effect.


    PDF filePDF Version of this Paper (699kb)