HackEd: A Pedagogical Analysis of Online Vulnerability Discovery Exercises
Daniel Votipka, Eric Zhang, Michelle L. Mazurek
Abstract
Hacking exercises are a common tool for security education, but there is limited investigation of how they teach security concepts and whether they follow pedagogical best practices. This paper enumerates the pedagogical practices of 31 popular online hacking exercises. Specifically, we derive a set of pedagogical dimensions from the general learning sciences and educational literature, tailored to hacking exercises, and review whether and how each exercise implements each pedagogical dimension. In addition, we interview the organizers of 15 exercises to understand challenges and tradeoffs that may occur when choosing whether and how to implement each dimension. We found hacking exercises generally were tailored to students' prior security experience and support learning by limiting extraneous load and establishing helpful online communities. Conversely, few exercises explicitly provide overarching conceptual structure or direct support for metacognition to help students transfer learned knowledge to new contexts. Immediate and tailored feedback and secure development practice were also uncommon. Additionally, we observed a tradeoff between providing realistic challenges and burdening students with extraneous cognitive load, with benefits and drawbacks at any point on this axis. Based on our results, we make suggestions for exercise improvement and future work to support organizers. *378.8 Pwnable [57] *515.4 Cyber Talents [58] *528.0 XSS-Game † [59] *626.1 ‡ Backdoor [60] *949.1 Crackmes.one † [61] *1011.4 ‡ ‡ CTFlearn [62] *1267.0 HackerTest [63] *1254.5 Mr. Code † [64] *4570.2 IO Wargame [65] *7168.8 1 Visit rank for the website, in thousands -Alexa if *, otherwise, using Tranco ranking which is less prone to tampering [21]. † An organizer from this exercise was interviewed or responded via email to our review. ‡ Rating was changed based on an interview with the exercise organizer. TABLE I: Results of our pedagogical review of 31 exercises. Each column indicates whether an exercise implemented the pedagogical dimension fully ( ), partially ( ), or not at all ( ).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- Investigating Influencer VPN Ads on YouTubeOmer Akgul, Richard Roberts, Moses Namara, Dave Levin et al.S&P 2022 · 27 citations
- Compete, Collaborate, Investigate: Exploring the Social Structures of Open Source Intelligence InvestigationsYasmine Belghith, Sukrit Venkatagiri, Kurt LutherCHI 2022 · 14 citations
- Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty EcosystemOmer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali et al.USENIX Security 2023
- Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability DiscoveryKelsey R. Fulton, Samantha Katcher, Kevin Song, Marshini Chetty et al.S&P 2023
- "I'm trying to learn...and I'm shooting myself in the foot": Beginners' Struggles When Solving Binary Exploitation ExercisesJames Mattei, Christopher Pellegrini, Matthew Soto, Marina Sanusi Bohuk et al.USENIX Security 2025
Builds on5
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyKhaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew SmithS&P 2016 · 128 citations
- Build It, Break It, Fix It: Contesting Secure DevelopmentAndrew Ruef, Michael W. Hicks, James Parker, Dave Levin et al.CCS 2016 · 80 citations
Related papers
- T1GER: An Instructional Re-Design of a Cyber Range Exercise in a Commercial Security Operations CenterMagdalena Glas, Leon Kersten, Tom Mulders, Günther Pernul et al.CHI 2026 · 1 citation
- Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix ItDaniel Votipka, Kelsey R. Fulton, James Parker, Matthew Hou et al.USENIX Security 2020
- Do Hackers Dream of Electric Teachers?: A Large-Scale, In-Situ Measurement of Cybersecurity Student Behaviors and Educational Performance with AI TutorsMichael Tompkins, Nihaarika Agarwal, Ananta Soneji, Robert Wasinger et al.CCS 2026
- Train as you Fight: Evaluating Authentic Cybersecurity Training in Cyber RangesMagdalena Glas, Manfred Vielberth, Günther PernulCHI 2023 · 21 citations
- Understanding the How and the Why: Exploring Secure Development Practices through a Course CompetitionKelsey R. Fulton, Daniel Votipka, Desiree Abrokwa, Michelle L. Mazurek et al.CCS 2022 · 7 citations
