Published July 25, 2026 | Version v1

Using OWASP Juice Shop in Cybersecurity Education: A Literature Review

Description

Abstract: Hands-on experience is essential in cybersecurity education. Without it, students learn the vocabulary but not the practical skills. OWASP Juice Shop is an intentionally vulnerable web application that enables learners to practice real-world attack techniques—such as SQL injection, broken authentication, and Cross-Site Scripting (XSS)—without affecting live production systems. This review examines how Juice Shop has been incorporated into university courses, Capture the Flag (CTF) competitions, capstone projects, and hybrid learning environments. Drawing upon published studies, it evaluates what educational practices improve learning outcomes and which approaches are less effective. Existing research indicates that students generally demonstrate greater engagement, improved practical understanding, and better knowledge retention. However, integrating an open-ended penetration testing platform into a structured academic curriculum remains challenging, and not every implementation has produced consistent success. This review identifies effective practices, highlights current research gaps, and outlines future directions for cybersecurity education research.

Files

263 ICDTE Conference 6(4) 225-230.pdf

Files (545.5 kB)

Name Size Download all
md5:14b55f76f7518d531e57411c4370ce58
545.5 kB Preview Download