Loading [MathJax]/extensions/tex2jax.js

Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Authors

  • Philip Klostermeyer
  • Sabrina Amft
  • Sandra Höltervennhoff
  • Alexander Krause
  • Niklas Busch
  • Sascha Fahl

Research Organisations

External Research Organisations

  • CISPA Helmholtz Center for Information Security

Details

Original languageEnglish
Title of host publication Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security
Subtitle of host publicationCCS 2024
Pages2651-2665
Number of pages15
ISBN (electronic)9798400706363
Publication statusPublished - 9 Dec 2024
Event31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024 - Salt Lake City, United States
Duration: 14 Oct 202418 Oct 2024

Abstract

The video game market is one of the biggest for software products. Video game development has progressed in the last decades to complex and multifaceted endeavors. Games-as-a-Service significantly impacted distribution and gameplay, requiring providers and developers to consider factors beyond game functionality, including security and privacy. New security challenges emerged, including authentication, payment security, and user data or asset protection. However, the security community lacks in-depth insights into the security experiences, challenges, and practices of modern video game development. This paper aims to address this gap in research and highlights the criticality of considering security in the process. Therefore, we conducted 20 qualitative, semi-structured interviews with various roles of professional and skilled video game development experts, investigating awareness, priorities, knowledge, and practices regarding security in the industry through their first-hand experiences. We find that stakeholders are aware of the urgency of security and related issues. However, they often face obstacles, including a lack of money, time, and knowledge, which force them to put security issues lower in priority. We conclude our work by recommending how the game industry can incorporate security into its development processes while balancing other resources and priorities and illustrating ideas for future research.

Keywords

    Software Development, Usable Security, Video Games

ASJC Scopus subject areas

Cite this

Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development. / Klostermeyer, Philip; Amft, Sabrina; Höltervennhoff, Sandra et al.
Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security: CCS 2024 . 2024. p. 2651-2665.

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Klostermeyer, P, Amft, S, Höltervennhoff, S, Krause, A, Busch, N & Fahl, S 2024, Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development. in Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security: CCS 2024 . pp. 2651-2665, 31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024, Salt Lake City, United States, 14 Oct 2024. https://doi.org/10.1145/3658644.3690190
Klostermeyer, P., Amft, S., Höltervennhoff, S., Krause, A., Busch, N., & Fahl, S. (2024). Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security: CCS 2024 (pp. 2651-2665) https://doi.org/10.1145/3658644.3690190
Klostermeyer P, Amft S, Höltervennhoff S, Krause A, Busch N, Fahl S. Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security: CCS 2024 . 2024. p. 2651-2665 doi: 10.1145/3658644.3690190
Klostermeyer, Philip ; Amft, Sabrina ; Höltervennhoff, Sandra et al. / Skipping the Security Side Quests : A Qualitative Study on Security Practices and Challenges in Game Development. Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security: CCS 2024 . 2024. pp. 2651-2665
Download
@inproceedings{af469cb6d76d4b2cbb11946b7e68142a,
title = "Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development",
abstract = "The video game market is one of the biggest for software products. Video game development has progressed in the last decades to complex and multifaceted endeavors. Games-as-a-Service significantly impacted distribution and gameplay, requiring providers and developers to consider factors beyond game functionality, including security and privacy. New security challenges emerged, including authentication, payment security, and user data or asset protection. However, the security community lacks in-depth insights into the security experiences, challenges, and practices of modern video game development. This paper aims to address this gap in research and highlights the criticality of considering security in the process. Therefore, we conducted 20 qualitative, semi-structured interviews with various roles of professional and skilled video game development experts, investigating awareness, priorities, knowledge, and practices regarding security in the industry through their first-hand experiences. We find that stakeholders are aware of the urgency of security and related issues. However, they often face obstacles, including a lack of money, time, and knowledge, which force them to put security issues lower in priority. We conclude our work by recommending how the game industry can incorporate security into its development processes while balancing other resources and priorities and illustrating ideas for future research.",
keywords = "Software Development, Usable Security, Video Games",
author = "Philip Klostermeyer and Sabrina Amft and Sandra H{\"o}ltervennhoff and Alexander Krause and Niklas Busch and Sascha Fahl",
note = "Publisher Copyright: {\textcopyright} 2024 Copyright held by the owner/author(s).; 31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024 ; Conference date: 14-10-2024 Through 18-10-2024",
year = "2024",
month = dec,
day = "9",
doi = "10.1145/3658644.3690190",
language = "English",
pages = "2651--2665",
booktitle = "Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security",

}

Download

TY - GEN

T1 - Skipping the Security Side Quests

T2 - 31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024

AU - Klostermeyer, Philip

AU - Amft, Sabrina

AU - Höltervennhoff, Sandra

AU - Krause, Alexander

AU - Busch, Niklas

AU - Fahl, Sascha

N1 - Publisher Copyright: © 2024 Copyright held by the owner/author(s).

PY - 2024/12/9

Y1 - 2024/12/9

N2 - The video game market is one of the biggest for software products. Video game development has progressed in the last decades to complex and multifaceted endeavors. Games-as-a-Service significantly impacted distribution and gameplay, requiring providers and developers to consider factors beyond game functionality, including security and privacy. New security challenges emerged, including authentication, payment security, and user data or asset protection. However, the security community lacks in-depth insights into the security experiences, challenges, and practices of modern video game development. This paper aims to address this gap in research and highlights the criticality of considering security in the process. Therefore, we conducted 20 qualitative, semi-structured interviews with various roles of professional and skilled video game development experts, investigating awareness, priorities, knowledge, and practices regarding security in the industry through their first-hand experiences. We find that stakeholders are aware of the urgency of security and related issues. However, they often face obstacles, including a lack of money, time, and knowledge, which force them to put security issues lower in priority. We conclude our work by recommending how the game industry can incorporate security into its development processes while balancing other resources and priorities and illustrating ideas for future research.

AB - The video game market is one of the biggest for software products. Video game development has progressed in the last decades to complex and multifaceted endeavors. Games-as-a-Service significantly impacted distribution and gameplay, requiring providers and developers to consider factors beyond game functionality, including security and privacy. New security challenges emerged, including authentication, payment security, and user data or asset protection. However, the security community lacks in-depth insights into the security experiences, challenges, and practices of modern video game development. This paper aims to address this gap in research and highlights the criticality of considering security in the process. Therefore, we conducted 20 qualitative, semi-structured interviews with various roles of professional and skilled video game development experts, investigating awareness, priorities, knowledge, and practices regarding security in the industry through their first-hand experiences. We find that stakeholders are aware of the urgency of security and related issues. However, they often face obstacles, including a lack of money, time, and knowledge, which force them to put security issues lower in priority. We conclude our work by recommending how the game industry can incorporate security into its development processes while balancing other resources and priorities and illustrating ideas for future research.

KW - Software Development

KW - Usable Security

KW - Video Games

UR - http://www.scopus.com/inward/record.url?scp=85215536837&partnerID=8YFLogxK

U2 - 10.1145/3658644.3690190

DO - 10.1145/3658644.3690190

M3 - Conference contribution

AN - SCOPUS:85215536837

SP - 2651

EP - 2665

BT - Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security

Y2 - 14 October 2024 through 18 October 2024

ER -