Lowering the Infrastructure Barrier to Hands-On Cybersecurity Education: Design and Feasibility of Kinetic Breach, a Browser-Based Gamified Investigation Simulator

Authors

Husam Abdulatef Ahmed Yousef Harpah

Faculty of Information and Communication Technology (FTMK), Universiti Teknikal Malaysia Melaka (UTeM), Melaka (Malaysia)

Muhammad Faheem Mohd Ezani

Faculty of Information and Communication Technology (FTMK), Universiti Teknikal Malaysia Melaka (UTeM), Melaka (Malaysia)

Nuridawati Mustafa

Faculty of Information and Communication Technology (FTMK), Universiti Teknikal Malaysia Melaka (UTeM), Melaka (Malaysia)

Mohd Aizat Yaacob

VireServe Sdn. Bhd., Petaling Jaya, Selangor (Malaysia)

Article Information

DOI: 10.47772/IJRISS.2026.100900253

Subject Category: Education

Volume/Issue: 10/9 | Page No: 3784-3796

Publication Timeline

Submitted: 2026-09-20

Accepted: 2026-09-25

Published: 2026-10-07

Abstract

Hands-on investigation practice is central to developing cybersecurity competencies such as log analysis and system examination, yet the realistic environments that provide it, such as cyber ranges, virtual-machine laboratories, and container testbeds, impose infrastructure, configuration, and maintenance costs that place practical experience beyond the easy reach of many beginners and resource-constrained institutions. This paper addresses that access problem through the design and technical feasibility evaluation of Kinetic Breach, a browser-delivered platform for practising cybersecurity investigation skills that requires no virtual machine, container, or laboratory software on the learner's part and only a single conventional web application on the institution's self-hosted server. Following a design-science approach, the platform integrates a simulated Linux-like investigation environment, a discovery-based assessment model that admits multiple valid evidentiary paths rather than a single scripted solution, a gamification layer to sustain engagement, and an adaptive AI guidance component that offers progressive hints without disclosing solutions and whose output is kept deliberately separate from the platform's deterministic scoring. Feasibility was assessed through systematic software verification comprising fifty-five automated tests across unit, integration, end-to-end, security, and load classes. All fifty-five tests passed; a complete investigation lifecycle executed correctly through the discovery, scoring, and progression pipeline; the tested application-level security controls behaved as intended; and the system remained stable under modest concurrency within a local environment. These results establish that an accessible, infrastructure-light, gamified, AI-guided investigation trainer is buildable and behaves as designed. The study makes no claim regarding usability, engagement, or learning gains, which require evaluation with human participants and are identified as the primary direction for future work. Kinetic Breach is thus offered as an accessible on-ramp to hands-on cybersecurity investigation and as a design foundation for subsequent educational evaluation.

Keywords

cybersecurity education, hands-on learning, gamification, AI-assisted tutoring, educational accessibility

Downloads

References

1. Ahmed Yousef Harpah, H. A., Mohd Ezani, M. F., Mustafa, N., & Yaacob, M. A. (2026). Kinetic Breach: A Browser-Based Gamified Cybersecurity Investigation Simulator (Source Code) [Computer software]. Zenodo. https://doi.org/10.5281/zenodo.22885484 [Google Scholar] [Crossref]

2. Bassner, P., Frankford, E., & Krusche, S. (2024). Iris: An AI-driven virtual tutor for computer science education. In Proceedings of the 2024 Conference on Innovation and Technology in Computer Science Education (ITiCSE 2024) (Vol. 1, pp. 394–400). Association for Computing Machinery. https://doi.org/10.1145/3649217.3653543 [Google Scholar] [Crossref]

3. Bassner, P., Lenk-Ostendorf, B., Beinstingel, R., Wasner, T., & Krusche, S. (2025). Less stress, better scores, same learning: The paradox of AI support in programming education. Computers and Education: Artificial Intelligence. Advance online publication. https://doi.org/10.1016/j.caeai.2025.100537 [Google Scholar] [Crossref]

4. Beuran, R., Tang, D., Pham, C., Chinen, K., Tan, Y., & Shinoda, Y. (2018). Integrated framework for hands-on cybersecurity training: CyTrONE. Computers & Security, 78, 43–59. https://doi.org/10.1016/j.cose.2018.06.001 [Google Scholar] [Crossref]

5. Chouliaras, N., Kantzavelou, I., Maglaras, L., Pantziou, G., & Ferrag, M. A. (2023). A novel autonomous container-based platform for cybersecurity training and research. PeerJ Computer Science, 9, e1574. https://doi.org/10.7717/peerj-cs.1574 [Google Scholar] [Crossref]

6. Dichev, C., & Dicheva, D. (2017). Gamifying education: What is known, what is believed and what remains uncertain: A critical review. International Journal of Educational Technology in Higher Education, 14, Article 9. https://doi.org/10.1186/s41239-017-0042-5 [Google Scholar] [Crossref]

7. Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75–105. https://doi.org/10.2307/25148625 [Google Scholar] [Crossref]

8. ISC2. (2024). ISC2 cybersecurity workforce study 2024. https://www.isc2.org/research [Google Scholar] [Crossref]

9. Kim, J. B., Zhong, C., & Liu, H. (2025). The impact of gamification on cybersecurity learning: Multi-study analysis. Communications of the Association for Information Systems, 56, 57–96. https://doi.org/10.17705/1CAIS.05603 [Google Scholar] [Crossref]

10. Kolb, D. A. (1984). Experiential learning: Experience as the source of learning and development. Prentice Hall. [Google Scholar] [Crossref]

11. Maniktala, M., Cody, C., Barnes, T., & Chi, M. (2020a). Avoiding help avoidance: Using interface design changes to promote unsolicited hint usage in an intelligent tutor. International Journal of Artificial Intelligence in Education, 30(4), 637–667. https://doi.org/10.1007/s40593-020-00213-3 [Google Scholar] [Crossref]

12. Maniktala, M., Cody, C., Isvik, A., Lytle, N., Chi, M., & Barnes, T. (2020b). Extending the Hint Factory for the assistance dilemma: A novel, data-driven HelpNeed predictor for proactive problem-solving help. Journal of Educational Data Mining, 12(4), 24–65. https://doi.org/10.5281/zenodo.4399683 [Google Scholar] [Crossref]

13. Martucci, L. A., Magnusson, J., Vehkajärvi, T., & Karlsson, J. (2026). The Cyber Range Lite. In L. Drevin, W. S. Leung, & S. von Solms (Eds.), Information security education: Empowering people through information security education (IFIP Advances in Information and Communication Technology, Vol. 742). Springer. https://doi.org/10.1007/978-3-031-94924-1_12 [Google Scholar] [Crossref]

14. Mills, A., White, J., & Legg, P. (2024). GoibhniUWE: A lightweight and modular container-based cyber range. Journal of Cybersecurity and Privacy, 4(3), 615–628. https://doi.org/10.3390/jcp4030029 [Google Scholar] [Crossref]

15. Mousavinasab, E., Zarifsanaiey, N., Niakan Kalhori, S. R., Rakhshan, M., Keikha, L., & Ghazi Saeedi, M. (2021). Intelligent tutoring systems: A systematic review of characteristics, applications, and evaluation methods. Interactive Learning Environments, 29(1), 142–163. https://doi.org/10.1080/10494820.2018.1558257 [Google Scholar] [Crossref]

16. Nakata, R., & Otsuka, A. (2021). CyExec*: A high-performance container-based cyber range with scenario randomization. IEEE Access, 9, 109095–109114. https://doi.org/10.1109/ACCESS.2021.3101245 [Google Scholar] [Crossref]

17. Peffers, K., Tuunanen, T., Rothenberger, M. A., & Chatterjee, S. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302 [Google Scholar] [Crossref]

18. Ryan, R. M., & Deci, E. L. (2000). Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being. American Psychologist, 55(1), 68–78. https://doi.org/10.1037/0003-066X.55.1.68 [Google Scholar] [Crossref]

19. Seaborn, K., & Fels, D. I. (2015). Gamification in theory and action: A survey. International Journal of Human-Computer Studies, 74, 14–31. https://doi.org/10.1016/j.ijhcs.2014.09.006 [Google Scholar] [Crossref]

20. Subhash, S., & Cudney, E. A. (2018). Gamified learning in higher education: A systematic review of the literature. Computers in Human Behavior, 87, 192–206. https://doi.org/10.1016/j.chb.2018.05.028 [Google Scholar] [Crossref]

21. Vykopal, J., Čeleda, P., Seda, P., Švábenský, V., & Tovařňák, D. (2021). Scalable learning environments for teaching cybersecurity hands-on. In 2021 IEEE Frontiers in Education Conference (FIE) (pp. 1–9). IEEE. https://doi.org/10.1109/FIE49875.2021.9637180 [Google Scholar] [Crossref]

22. Weitl-Harms, S., Spanier, A., Hastings, J., & Rokusek, M. (2023). A systematic mapping study on gamification applications for undergraduate cybersecurity education. Journal of Cybersecurity Education, Research and Practice, 2023(1), Article 9. https://digitalcommons.kennesaw.edu/jcerp/vol2023/iss1/9/ [Google Scholar] [Crossref]

23. Zhong, C., Kim, J. B., & Liu, H. (2024). The art of inclusive gamification in cybersecurity training. IEEE Security & Privacy, 22(5), 40–51. https://doi.org/10.1109/MSEC.2024.3427666 [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles