DEVELOPING CYBERSECURITY SKILLS THROUGH GAMIFICATION: INTEGRATING THE CAPTURE-THE-FLAG METHODOLOGY INTO UNIVERSITY TRAINING
Ключевые слова:
gamification; capture the flag (CTF); cybersecurity skills; serious games; active learning; motivation; self-efficacyАннотация
Traditional lecture-based formats of cybersecurity instruction are repeatedly reported to produce low engagement and weak knowledge retention, while the labour market requires graduates with operational, practice-ready skills. Gamification — the use of game design elements in non-game contexts — and, above all, Capture-the-Flag (CTF) exercises have become the most widespread response to this problem. This article systematizes the empirical evidence on gamified cybersecurity training published in 2011–2026 and substantiates a didactic framework for the purposeful development of cybersecurity skills of university students on the basis of gamification. The framework is grounded in experiential learning theory and the concept of self-efficacy and consists of four interconnected blocks: target skills, game mechanics, scenario design, and assessment with feedback. A three-loop model of curricular integration (micro-challenges within classes, a semester-long gamified laboratory cycle, and annual CTF events) is proposed, and the conditions limiting the effectiveness of gamification — entry barriers for novices, fragmentary topic coverage and assessment validity — are analysed together with mitigation measures. The framework is intended for implementation in cybersecurity-related programmes of higher education institutions, including the universities of Uzbekistan.