To read this content please select one of the options below:

Security questions education: exploring gamified features and functionalities

Nicholas Micallef (University of New South Wales Canberra at ADFA, Canberra, Australia)
Nalin Asanka Gamagedara Arachchilage (University of New South Wales Canberra at ADFA, Canberra, Australia)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 9 July 2018

329

Abstract

Purpose

Security questions are one of the techniques used to recover forgotten passwords. However, security questions have both security and memorability limitations. To limit their security vulnerabilities, stronger answers need to be used. As serious games can motivate users to change their security behaviour, the purpose of this paper is to explore the features and functionalities that users would require in a serious game that educates them to provide stronger answers to security questions.

Design/methodology/approach

A lab study was conducted to collect users’ feedback on the desired game features and functionalities. In Stage 1, participants selected security questions/answers. In Stage 2, participants played a game and evaluated the usability and the provided features.

Findings

The main findings reveal that most participants found the current features and functionalities to be desirable; socially oriented functionalities (e.g. getting help from other players) did not seem desirable because users feared that their acquaintances could gain access to their security questions.

Originality/value

This research recommends that designers of serious games for security education should: use intrinsic rewards to motivate users to have a better learning experience; provide easier challenges during the training period and provide harder challenges only when the game determines that the users learned to play the game; and design their games for mobile devices because even users who usually do not play games would play a security education game on a mobile device.

Keywords

Citation

Micallef, N. and Arachchilage, N.A.G. (2018), "Security questions education: exploring gamified features and functionalities", Information and Computer Security, Vol. 26 No. 3, pp. 365-378. https://doi.org/10.1108/ICS-03-2018-0033

Publisher

:

Emerald Publishing Limited

Copyright © 2018, Emerald Publishing Limited

Related articles