Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Conference object
Data sources: ZENODO
addClaim

Using OWASP Juice Shop in Cybersecurity Education: A Literature Review

Authors: Rajgoli, Sarah Rukhmuddin; Kumar, Niharika Prasanna; Prakash, Aditya; Modi, Shresth; Mathur, Yashash; Upadhyay, Utsav;

Using OWASP Juice Shop in Cybersecurity Education: A Literature Review

Abstract

Abstract: Hands-on experience is essential in cybersecurity education. Without it, students learn the vocabulary but not the practical skills. OWASP Juice Shop is an intentionally vulnerable web application that enables learners to practice real-world attack techniques—such as SQL injection, broken authentication, and Cross-Site Scripting (XSS)—without affecting live production systems. This review examines how Juice Shop has been incorporated into university courses, Capture the Flag (CTF) competitions, capstone projects, and hybrid learning environments. Drawing upon published studies, it evaluates what educational practices improve learning outcomes and which approaches are less effective. Existing research indicates that students generally demonstrate greater engagement, improved practical understanding, and better knowledge retention. However, integrating an open-ended penetration testing platform into a structured academic curriculum remains challenging, and not every implementation has produced consistent success. This review identifies effective practices, highlights current research gaps, and outlines future directions for cybersecurity education research.

Powered by OpenAIRE graph
Found an issue? Give us feedback