How to play Cornucopia?
It is possible to play Cornucopia in many different ways. Here is one way explained in this Youtube video
Primary method
- A - Preparations
- A1. Obtain a deck, or print your own Cornucopia deck and separate/cut out the cards
- A2. Identify an application or application process to review; this might be a concept, design or an actual implementation
- A3. Create a data flow diagram, user stories, or other artefacts to help the review
- A4. This will help answer the question: "What are we working on"
- A5. Identify and invite a group of 3-6 architects, developers, testers and other business stakeholders together and sit around a table (try to include someone fairly familiar with application security)
- A6. Have some prizes to hand (gold stars, chocolate, pizza, beer or flowers depending upon your office culture). See our "Prizes and Swags" section for ideas.
- B - Play
One suit - Cornucopia - acts as trumps. Aces are high (i.e. they beat Kings). It helps if there is someone dedicated to documenting the results who is not playing.
- B1. Remove the Jokers and a few low-score (2, 3, 4) cards from Cornucopia suit to ensure each player will have the same number of cards
- B2. Shuffle the pack and deal all the cards
- B3. To begin, choose a player randomly who will play the first card - they can play any card from their hand except from the trump suit - Cornucopia
- B4. To play a card, each player must read it out aloud, and explain how (or not) the threat could apply (the player gets a point for attacks that work, and the group thinks it is an actionable bug) - don’t try to think of mitigations at this stage, and don’t exclude a threat just because it is believed it is already mitigated - someone record the card on the score sheet
- B5. If a player get stuck, ask them to scan the QR code on the card to access the online card page and read the section called: "What can go wrong?" or click the "more info" links if playing Copi (the online Cornucopia version) or just browse the card from the deck at cornucopia.owasp.org while playing
- B6. Play clockwise, each person must play a card in the same way; if you have any card of the matching lead suit you must play one of those, otherwise they can play a card from any other suit. Only a higher card of the same suit, or the trump suit Cornucopia, wins the hand
- B7. The person who wins the round, leads the next round (i.e. they play first), and thus defines the next lead suit
- B8. Repeat until all the cards are played
- C - Scoring
The objective is to identify applicable threats, and win hands (rounds)
- C1. Score +1 for each card you can identify as a valid threat to the application under consideration
- C2. Score +1 if you win a round
- C3. Once all cards have been played, whoever has the most points, wins
- D - Closure
- D1. Review all the applicable threats and the matching security requirements.
- D2. Use the QR codes on the cards to access the online card page and read the section called: "What are we going to do about it?" or use the "more info" links if playing Copi
- D3. Create user stories, specifications and test cases as required for your development methodology and add them directly into your issue tracking software under what you are working on
See Márk Vinkovits leading a threat modelling "talk and group session" playing Cornucopia in the OWASP track @hacktivityconf 1510.
Gameplay - Companion Guide Scenarios
We are developing game scenarios to teach threat modelling, awareness, and secure coding. They provide all the assets you need in order to run a Cornucopia game session, including vulnerable apps, presentations, posters, and cheat sheets. All you need is the OWASP Cornucopia decks. We are currently working on getting sponsors so that local OWASP chapters can reimburse their costs for printing the OWASP Cornucopia decks when they run these events locally within their chapters. Please get in touch if you would like to help in getting sponsors or need help in setting things up.
Scenarios - PwnedNext - The OWASP Cornucopia LLM Companion Guide
Image: PwnedNext
Through gamification, this OWASP Cornucopia LLM Companion Guide uses the OWASP Cornucopia Website App and Companion Edition to introduce developers and testers to threats, risks, and requirements related to AI design and development, and to teach how to mitigate AI risks. The game takes participants through a provocative scenario in which they must identify AI threats by studying an insecure AI implementation. They need to ask themselves, "What can go wrong?" and "What are we going to do about it?" Furthermore, by playing, they will get to know which tests from the OWASP AI Test Guide (AITG) and OWASP AI Security Verification Standard (AISVS) need to be considered in order to responsibly develop AI applications.
Gameplay - Modelling evil user stories
Long-time project contributor Max Alejandro Gómez Sánchez Vergaray has created a video to explain how he has trained hundreds of teams to use OWASP Cornucopia in modelling sessions at a major international bank. This approach has scaled to over two-thousand developers to date. You can read more about this approach in CyberSec Games blog post on LinkedIn: "Identifying abuse before designing architecture: Embedding Game-Based Threat Modelling into Agile Delivery at a Major Latin American Bank".
How to play EoP
Draw a diagram of the system you want to threat model before you deal the cards.
Deal the deck to 3-6 players. Play starts with the 3 of Tampering. Play clockwise, and each player in turn continues using the suit if they have a card in that suit. If the player doesn't have a card from that suit, the player can use another suit. Each round is won by the highest card played in the suit that was led, unless an Elevation of Privilege (EoP) card is played. In that case the high value EoP card wins.
To play a card, read the card, announce your threat and record it. If the player can't link the threat to the system, play proceeds.
The winner of a hand selects the card (and suit) to lead the next hand. Take a few minutes between hands to think about threats.
Points
- 1 for a threat on your card
- +1 for taking the trick
Threats should be articulated clearly, testable, and addressable. In the event that a threat leads to an argument, you can resolve it by asking the question: “Would we take an actionable bug, feature request or design change for that?” If the answer is yes, it is a real threat. (This doesn't mean that threats outside of that aren't real, it's simply a way to focus discussion on actionable threats.) Questions that start with “There's a way” should be read as “There's a way … and here's how …” while questions that start with “Your code” should be read “The code we're collectively creating … and here's how.”
The deck contains a number of special cards: trumps and open threats. EoP cards are trumps: they take the trick even if they have a lower value than the suit that was led. The ace of each suit is an open threat card. When played, the player must identify a threat not listed on another card.
When all the cards have been played, whoever has the most points wins.
Remember to have fun!
Optional variants
- You may pass cards after the third trick. This is helpful if you have cards that you can't tie to the system. Someone else may be able to.
- Double the number of points, and give one point for threats on other people's cards.
- Other players may “riff” on the threat and if they do, they get one point per additional threat.
- Limit riffing to no more than 60 seconds.
- Mark up the diagram where the threat occurs.
- Questions are listed on the threat cards to help with the aces.
Thanks to Laurie Williams for inspiration.
Alternative game rules
If you are new to the game, remove the two Joker cards to begin with. Add the Joker cards back in once people become more familiar with the process. Apart from the “trumps card game” rules described above which are very similar to the EoP, the deck can also be played as the “twenty-one card game” (also known as “pontoon” or “blackjack”) which normally reduces the number of cards played in each round.
Practice on an imaginary application, or even a future planned application, rather than trying to find fault with existing applications until the participants are happy with the usefulness of the game.
Consider just playing with one suit to make a shorter session – but try to cover all the suits for every project. Or even better just play one hand with some pre-selected cards, and score only on the ability to identify security requirements. Perhaps have one game of each suit each day for a week or so, if the participants cannot spare long enough for a full deck.
Some teams have preferred to play a full hand of cards and then discuss what is on the cards after each round (instead of after each person plays a card).
Another suggestion is that if a player fails to identify the card as relevant, allow other players to suggest ideas, and potentially let them gain the point for the card. Consider allowing extra points for especially good contributions.
You can even play by yourself. Just use the cards to act as thought-provokers. Involving more people will be beneficial though.
In Microsoft's EoP guidance, they recommend cheating as a good game strategy.