用AI助手带新手玩网络安全竞赛,降低入门门槛。
Can AI Lower the Barrier to Cybersecurity? A Human-Centered Mixed-Methods Study of Novice CTF Learning
- 用自研AI框架CAI辅助无经验学生参与网络安全竞赛
- 新手策略探索多、每策略执行快,学习效率提升
- 适合想快速入门网络安全的初学者和教育研究者
Capture-the-Flag(CTF)竞赛是进入进攻性网络安全的重要入口,但复杂的工具链和不透明的工作流程常让新手望而却步。近年来,安全领域的智能体式AI框架有望通过自动化与协调渗透测试任务来降低这一门槛。然而,其对新手学习过程的影响仍缺乏研究。本文开展一项以人类为中心的混合方法案例研究,探讨智能体式AI框架(即网络安全AI,CAI)如何支持新手参与基于CTF的渗透测试。一位无任何黑客经验的本科生在使用CAI辅助下尝试达成国家级网络安全挑战的性能基准。定量表现指标结合了结构化反思分析,涵盖学习进展与人机交互模式。主题分析表明,CAI通过提供概览、结构与引导显著降低了初期认知负担,提升了早期参与效率。量化结果显示,新手展现出广泛策略探索且单个策略执行时间短,可能促进对安全攻防策略层面的元级训练。同时,AI辅助教学也带来了信任、依赖与负责任使用等新挑战。本文讨论了面向人类中心的AI支持型网络安全教育的意义,并提出未来研究的开放问题。
原文摘要 · Abstract (English)
Capture-the-Flag (CTF) competitions serve as gateways into offensive cybersecurity, yet they often present steep barriers for novices due to complex toolchains and opaque workflows. Recently, agentic AI frameworks for cybersecurity promise to lower these barriers by automating and coordinating penetration testing tasks. However, their role in shaping novice learning remains underexplored. We present a human-centered, mixed-methods case study examining how agentic AI frameworks -- here Cybersecurity AI (CAI) -- mediates novice entry into CTF-based penetration testing. An undergraduate student without prior hacking experience attempted to approach performance benchmarks from a national cybersecurity challenge using CAI. Quantitative performance metrics were complemented by structured reflective analysis of learning progression and AI interaction patterns. Our thematic analysis suggest that agentic AI reduces initial entry barriers by providing overview, structure and guidance, thereby lowering the cognitive workload during early engagement. Quantitatively, the observed extensive exploration of strategies and low per-strategy execution time potetially facilitatates cybersecurity training on meta, i.e. strategic levels. At the same time, AI-assisted cybersecurity education introduces new challenges related to trust, dependency, and responsible use. We discuss implications for human-centered AI-supported cybersecurity education and outline open questions for future research.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。