HOME

TheInfoList



OR:

Capture the Flag (CTF) in
computer security Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and computer network, n ...
is an exercise in which participants attempt to find text strings, called "flags", which are secretly hidden in purposefully vulnerable programs or websites. They can be used for both competitive or educational purposes. In two main variations of CTFs, participants either steal flags from other participants (attack/defense-style CTFs) or from organizers (jeopardy-style challenges). A mixed competition combines these two styles. Competitions can include hiding flags in hardware devices, they can be both online or in-person, and can be advanced or entry-level. The game is inspired by the traditional outdoor sport of the same name. CTFs are used as a tool for developing and refining cybersecurity skills, making them popular in both professional and academic settings.


Overview

Capture the Flag (CTF) is a cybersecurity competition that is used to test and develop computer security skills. It was first developed in 1996 at
DEF CON DEF CON (also written as DEFCON, Defcon, or DC) is a Computer security conference, hacker convention held annually in Las Vegas Valley, Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include comp ...
, the largest cybersecurity conference in the United States which is hosted annually in
Las Vegas Las Vegas, colloquially referred to as Vegas, is the most populous city in the U.S. state of Nevada and the county seat of Clark County. The Las Vegas Valley metropolitan area is the largest within the greater Mojave Desert, and second-l ...
, Nevada. The conference hosts a weekend of cybersecurity competitions, including their flagship CTF. Two popular CTF formats are jeopardy and attack-defense. Both formats test participant’s knowledge in cybersecurity, but differ in objective. In the Jeopardy format, participating teams must complete as many challenges of varying point values from a various categories such as cryptography, web exploitation, and reverse engineering. In the attack-defense format, competing teams must defend their vulnerable computer systems while attacking their opponent's systems. The exercise involves a diverse array of tasks, including exploitation and cracking passwords, but there is little evidence showing how these tasks translate into cybersecurity knowledge held by security experts. Recent research has shown that the Capture the Flag tasks mainly covered technical knowledge but lacked social topics like social engineering and awareness on cybersecurity.


Educational applications

CTFs have been shown to be an effective way to improve cybersecurity education through
gamification Gamification is the process of enhancing systems, services, organisations and activities through the integration of game design elements and principles in non-game contexts. The goal is to increase user engagement, motivation, competition and ...
. There are many examples of CTFs designed to teach cybersecurity skills to a wide variety of audiences, including PicoCTF, organized by the Carnegie Mellon CyLab, which is oriented towards high school students, and
Arizona State University Arizona State University (Arizona State or ASU) is a public university, public research university in Tempe, Arizona, United States. Founded in 1885 as Territorial Normal School by the 13th Arizona Territorial Legislature, the university is o ...
supported pwn.college. Beyond educational CTF events and resources, CTFs has been shown to be a highly effective way to instill cybersecurity concepts in the classroom. CTFs have been included in undergraduate computer science classes such as Introduction to Information Security at the
National University of Singapore The National University of Singapore (NUS) is a national university, national Public university, public research university in Singapore. It was officially established in 1980 by the merging of the University of Singapore and Nanyang University ...
. CTFs are also popular in military academies. They are often included as part of the curriculum for cybersecurity courses, with the
NSA The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
organized Cyber Exercise culminating in a CTF competition between the US service academies and military colleges.


Competitions

Many CTF organizers register their competition with the CTFtime platform. This allows the tracking of the position of teams over time and across competitions. These include "Plaid Parliament of Pwning", "More Smoked Leet Chicken", "Dragon Sector", "dcua", "Eat, Sleep, Pwn, Repeat", "perfect blue", "organizers" and "Blue Water". Overall the "Plaid Parliament of Pwning" and "Dragon Sector" have both placed first worldwide the most with three times each.


Community competitions

Every year there are dozens of CTFs organized in a variety of formats. Many CTFs are associated with cybersecurity conferences such as
DEF CON DEF CON (also written as DEFCON, Defcon, or DC) is a Computer security conference, hacker convention held annually in Las Vegas Valley, Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include comp ...
, HITCON, and BSides. The DEF CON CTF, an attack-defence CTF, is notable for being one of the oldest CTF competitions to exist, and has been variously referred to as the "
World Series The World Series is the annual championship series of Major League Baseball (MLB). It has been contested since between the champion teams of the American League (AL) and the National League (NL). The winning team, determined through a best- ...
", "
Superbowl The Super Bowl is the annual league championship game of the National Football League (NFL) of the United States. It has served as the final game of every NFL season since 1966 (with the exception of the Pro Bowl between the 1967 and 2009 se ...
", and "
Olympics The modern Olympic Games (Olympics; ) are the world's preeminent international sporting events. They feature summer and winter sports competitions in which thousands of athletes from around the world participate in a variety of competit ...
", of hacking by media outlets. The NYU Tandon hosted Cybersecurity Awareness Worldwide (CSAW) CTF is one of the largest open-entry competitions for students learning cybersecurity from around the world. In 2021, it hosted over 1200 teams during the qualification round. In addition to conference organized CTFs, many CTF clubs and teams organize CTF competitions. Many CTF clubs and teams are associated with universities, such as the CMU associated Plaid Parliament of Pwning, which hosts PlaidCTF, and the ASU associated
Shellphish The 2016 Cyber Grand Challenge (CGC) was a challenge created by The Defense Advanced Research Projects Agency (DARPA) in order to develop automatic defense systems that can discover, prove, and correct software flaws in real-time. The event place ...
.


Government-supported competitions

Governmentally supported CTF competitions include the
DARPA The Defense Advanced Research Projects Agency (DARPA) is a research and development agency of the United States Department of Defense responsible for the development of emerging technologies for use by the military. Originally known as the Adva ...
Cyber Grand Challenge The 2016 Cyber Grand Challenge (CGC) was a challenge created by The Defense Advanced Research Projects Agency (DARPA) in order to develop automatic defense systems that can discover, prove, and correct software flaws in real-time. The event plac ...
and ENISA
European Cybersecurity Challenge The European Cybersecurity Challenge (ECSC) is an annual cybersecurity competition organized by the European Union Agency for Cybersecurity The European Union Agency for Cybersecurity – self-designation ENISA from the abbreviation of its or ...
. In 2023, the
US Space Force The United States Space Force (USSF) is the space force branch of the United States Department of Defense. It is one of the six United States Armed Forces, armed forces of the United States and one of the eight uniformed services of the Unite ...
-sponsored Hack-a-Sat CTF competition included, for the first time, a live orbital satellite for participants to exploit.


Corporate-supported competitions

Corporations and other organizations sometimes use CTFs as a training or evaluation exercise. The benefits of CTFs are similar to those of using CTFs in an educational environment. In addition to internal CTF exercises, some corporations such as
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
and
Tencent Tencent Holdings Ltd. ( zh, s=腾讯, p=Téngxùn) is a Chinese Multinational corporation, multinational technology Conglomerate (company), conglomerate and holding company headquartered in Shenzhen. It is one of the highest grossing multimed ...
host publicly accessible CTF competitions.


In popular culture

* In ''
Mr. Robot ''Mr. Robot'' is an American drama thriller television series created by Sam Esmail for USA Network. It stars Rami Malek as Elliot Alderson, a cybersecurity engineer and hacker with social anxiety disorder, clinical depression, and dissoci ...
'', a qualification round for the DEF CON CTF competition is depicted in the season 3 opener "eps3.0_power-saver-mode.h". The logo for DEF CON can se seen in the background. * In ''
The Undeclared War ''The Undeclared War'' is a British near-future Thriller (genre), thriller television mini-series, aired from 30 June 2022 on Channel 4. The series is written by Peter Kosminsky. Channel 4 announced on 12 February 2025 that a second series con ...
'', a CTF is depicted in the opening scene of the series as a recruitment exercise used by
GCHQ Government Communications Headquarters (GCHQ) is an intelligence and security organisation responsible for providing signals intelligence (SIGINT) and information assurance (IA) to the government and armed forces of the United Kingdom. Primar ...
. * ''
Go Go Squid! ''Go Go Squid!'' () is a Chinese e-sport romance comedy television series directed by Li Qingrong and Xiang Xujing. The series was first aired in 2019, starring Yang Zi and Li Xian. It was an adaptation of Mo Bao Fei Bao's novel "Honey Stewed Sq ...
'', a Chinese television series, is based around training for and competing in highly stylized CTF competitions .


See also

*
Wargame (hacking) In hacking, a wargame (or war game) is a cyber-security challenge and mind sport in which the competitors must exploit or defend a vulnerability in a system or application, and/or gain or prevent access to a computer system A computer is ...
* Cyberwarfare preparedness *
Hackathon A hackathon (also known as a hack day, hackfest, datathon or codefest; a portmanteau of '' hacking'' and ''marathon'') is an event where people engage in rapid and collaborative engineering over a relatively short period of time such as 24 or 48 h ...
s *
Competitive programming Competitive programming or sport programming is a mind sport involving participants trying to program according to provided specifications. The contests are usually held over the Internet or a local network. Competitive programming is recogn ...
* Cybersecurity in popular culture *
Privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...


References

{{reflist


External links


ctftime.org
- an archive of historic, current, and future CTF competitions. Hacking (computer security) Computer security Cyberwarfare Computer science competitions