A Human Study of Cognitive Biases in Web Application Security
Yuwei Yang, Skyler Grandel, Daniel Balasubramanian, Yu Huang, Kevin Leach

TL;DR
This study investigates how cognitive biases like Satisfaction of Search and Loss Aversion influence decision-making in web application security CTF challenges, revealing biases impact success and offering insights for improved cybersecurity training.
Contribution
It introduces a controlled human study analyzing cognitive biases in CTF tasks, highlighting their effect on attacker performance and suggesting strategies to leverage biases for better security education.
Findings
Participants with Satisfaction of Search bias found 25% fewer flags.
Cognitive biases significantly affect decision-making in security challenges.
Insights can inform improved cybersecurity training methods.
Abstract
Cybersecurity training has become a crucial part of computer science education and industrial onboarding. Capture the Flag (CTF) competitions have emerged as a valuable, gamified approach for developing and refining the skills of cybersecurity and software engineering professionals. However, while CTFs provide a controlled environment for tackling real world challenges, the participants' decision making and problem solving processes remain under explored. Recognizing that psychology may play a role in a cyber attacker's behavior, we investigate how cognitive biases could be used to improve CTF education and security. In this paper, we present an approach to control cognitive biases, specifically Satisfaction of Search and Loss Aversion, to influence and potentially hinder attackers' effectiveness against web application vulnerabilities in a CTF style challenge. We employ a rigorous…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security
