Top Banner
28

How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

Aug 18, 2015

Download

Internet

bugcrowd
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 2: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 3: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 4: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 5: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

THE LEARNING CURVE Sk

ill A

cqui

sitio

n

Time

IT”S TOO HARD!

I’m BORED!

Page 6: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 7: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

LINEAR PLAY GAMES

Level 1 Level 2 Level 3 Level 4 Level 5 Level 6 Level 7

Page 8: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

NON-LINEAR PLAY GAMES

Skills

Teammates

Opponents

Tools

Page 9: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

A STEEP LEARNING CURVE

Skill

Acq

uisi

tion

Time

Page 10: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

A SHALLOW LEARNING CURVE Sk

ill A

cqui

sitio

n

Time

Page 11: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

YOU DECIDE

Page 12: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

INTELLECTUAL COMPLEXITY

Time Filler Complete Immersion The ‘Grey Area’

Page 13: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 14: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 15: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

STARTING A GAME

§ Creating a Foundation of Skills

Page 16: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

STARTING A GAME

§ Creating a Foundation of Skills

§ High Reward Schedule

Page 17: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

STARTING A GAME

§ Creating a Foundation of Skills

§ High Reward Schedule

§ Make sure players are placed within their skills level

IT”S TOO HARD!

I’m BORED!

Page 18: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 19: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

MAKING A TASK ‘SEEM’ EASIER

§ Break Down Into Subtasks

IT”S TOO HARD!

Page 20: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

MAKING A TASK ‘SEEM’ EASIER

§ Break Down Into Subtasks

§ Reward more frequently

Page 21: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

MAKING A TASK EASIER (OR SEEM THAT WAY)

§ Break Down Into Subtasks

§ Reward more frequently

§ Provide outside tools for ‘practice’

Page 22: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 23: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV
Page 24: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

MAKING TASKS MORE DIFFICULT

§ Add sub-skills onto current skills

Page 25: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

MAKING TASKS MORE DIFFICULT

§ Add sub-skills onto current skills § Add things to the environment/level

Page 26: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

MAKING TASKS MORE DIFFICULT

§ Add sub-skills onto current skills § Add things to the environment/level (Portal goop) § Add elements for complexity (e.g., tools, weapons, skills)

Page 27: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

BEYOND THE BADGE!

Keep your target audience away from the ends of the curve

Know the behavior your way (linear? Repeated interaction?)

80% of training needs to be either ‘time filler’ or ‘grey area’ in design

Onboarding is KEY to getting and keeping users (foundational information)

Create roadmaps the add sub skills onto current skills (e.g., network pentesting >>> application pen testing >>> reverse engineering)

Switch team members to encourage learning and engagement

Team play keeps employees/users/crowds/humans repeatedly engaged

Provide outside resources for users to practice their skills

PRO TIP: Do not confound extrinsic and intrinsic rewards!

Page 28: How Portal Can Change Your Security Forever - Kati Rodzon at BSidesLV

THANK YOU! [email protected]