91±¬ÁÏ

Skip to content

Do you have what it takes to be an ethical hacker? Can you step into the shoes of a professional paid to outsmart supposedly locked-down systems?

Now you can at least try, no matter what your background, with a new card game developed by 91±¬ÁÏ computer scientists.

“” gives teenage and young-adult players a taste of what it means to be a computer-security professional defending against an ever-expanding range of digital threats. The game’s creators will present it this week in Las Vegas at , an annual information-security meeting.

“Hopefully players will come away thinking differently about computer security,” said creator , a 91±¬ÁÏ associate professor of computer science and engineering.

Control-Alt-Hack playing cards
Players assume the roles of characters with their own special skills. Game play involves completing missions by rolling the dice, using skills and occasionally pulling something out of a bag of tricks.

The target audience is 15- to 30-year-olds with some knowledge of computer science, though not necessarily of computer security. The game could supplement a high school or introductory college-level computer science course, Kohno said, or it could appeal to information technology professionals who may not follow the evolution of computer security.

In the game, players work for Hackers Inc., a small company that performs security audits and consultations for a fee. Three to six players take turns choosing a card that presents a hacking challenge that ranges in difficulty and level of seriousness.

In one mission, a player on a business trip gets bored and hacks the hotel minibar to disrupt its radio-tag payment system, then tells the manager. (A being presented at Black Hat this year exposes a security hole in hotel keycard systems.)

“We went out of our way to incorporate humor,” said co-creator , a 91±¬ÁÏ doctoral student in computer science and engineering. “We wanted it to be based in reality, but more importantly we want it to be fun for the players.”

This is not an educational game that tries to teach something specific, Denning said, but a game that’s mainly designed to be fun and contains some real content as a side benefit. The team decided on an old-fashioned tabletop card game to make it social and encourage interaction.

Playing the game in the 91±¬ÁÏ Security and Privacy Research Lab
Tamara Denning and Yoshi Kohno in the 91±¬ÁÏ’s Security and Privacy Research Lab, playing the game they created. Their game gives players a taste of what it’s like to be a computer security professional. Research assistant Thomas Winegarden, a 91±¬ÁÏ undergraduate, is on the left. Photo: Mary Levin, 91±¬ÁÏ Photography

Some scenarios incorporate research from Kohno’s , such as security threats to cars, toy robots and implanted medical devices. The missions also touch other hot topics in computer security, such as botnets that use hundreds of hijacked computers to send spam, and vulnerabilities in online medical records.

Characters have various skills they can deploy. In addition to the predictable “software wizardry,” skills include “lock picking” (for instance, breaking into a locked server room) and “social engineering” (like tricking somebody into revealing a password).

Graduate students who are current or former members of the 91±¬ÁÏ lab served as loose models for many of the game’s characters. Cards depict the characters doing hobbies, such as motorcycling and rock climbing, that their real-life models enjoy.

“We wanted to dispel people’s stereotypes about what it means to be a computer scientist,” Denning said.

The 91±¬ÁÏ group licensed the game’s mechanics from award-winning game designer of Austin, Texas. They hired an to draw the characters and a to design the graphics. , a security professional who helped develop a at Microsoft in 2010, is a collaborator and co-author.

Intel Corp. funded the game as a way to promote a broader awareness of computer-security issues among future computer scientists and current technology professionals. Additional funding came from the National Science Foundation and the Association for Computing Machinery’s .

Educators in the continental U.S. can apply to get a free copy of the game while supplies last. It’s scheduled to go on sale in the fall for a retail price of about $30.

###

For more information about the project, contact Kohno at yoshi@cs.washington.edu and Denning at tdenning@cs.washington.edu.

For more information about the game, visit the website at or email info@controlalthack.com.