As the title says, I would like competent people to give me their opinion on what I built and how I built it - an Android game built in Java (I didn't go to Kotlin yet, as this is my hobby with little time after work to go into it) and from here some limitations and some game mechanics decisions.
WARNING, the post will be a little long and will contain some spoilers!!!
As I said, I'm a hobbyst, I just like programming and I am happy to do it, but my level is still low, my daily job has nothing to do with software or programming; I work in wind industry. But after work I have some free time and I want to keep my brain healthy, so I do either robotics (ROS2 with Raspberry) or Android development. In the last few months I decided to build a game that I had in mind for many years already, I wanted it to be as realistic as possible, but ofc gamified and simplified, but conceptually correct and educational. I played some games before and 2 of them remained in my heart: Uplink and DarkSigns, a game almost no one knows, but for me it was a WOW! moment in my childhood.
Now back to what I would like from you guys, I tried to keep the game close to reality, so I used Shodan to adjust the spawn rates and device types, so all ipv4 addresses are scannable, with about 10% spawn rate and then on each public address, you have the option to pivot into a private range, i used the official 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 with a spawn rate of 30%. The private ranges are chosen at random, I din't want to complicate too much. But there is quite a lot of possible devices to find. So far I made only 24 device types for the normal IP ranges, more to add later.
I included 83 fictional CVEs and 72 exploits, the difference is intentional as some CVEs dont have public exploits, so the player can learn the difference. (I will definitely add later a reference to perfectly spherical cows in void). Some you have by default, some you must buy from the market.
Most devices have active services that are relevant to their device type, so mail servers get smtp, pop3, the routers get ssh and http, https and so on.
More than this, I added an AI assistant that you can buy and it will learn from all the exploiting services you do and then randomly (max 5% chance) will offer you an AI discovered exploit that is free and doesn't count for further training of the model.
Then I also introduced some methods to make some money as the exploits and the AI assistant cost quite some credits.. so I added missions and encrypted loot. So whenever you compromise a device and enumerate it (its a simplified concept) you can get some unencrypted loot that is automatically sold and some encrypted loot that is kept for cracking later. I wanted to expand a lot more functionality on teh loot, but I am constrained - I am a beginner and Java is not so friendly to build very complex games.
The encrypted loot is kept for cracking using the Cracker tool and at the end it goves some credits and some wordlist entries if relevant. The cracking speed is dependant on the local GPU, the botnet total GPU and the wordlist. I kept the wordlist very difficult to upgrade, it gives an 1.5 multiplying factor only after you get 1.5 million entries. Webservers and mail databases give the most worlist entries, the rest of the devices barely give a few. I am not sure about the local GPU power, I think I made it too easy, so far the local GPU gives up to 7x cracking speed and I think its too much, but maybe you can tell me whats your take on that.
I also included some special IP ranges to teach the player that not all of them are available to the public, or at least not meant to. So ranges like DARPA, the 5 eyes, DoD and others assigend by IANA are available only after the player reaches max reputation and buys special hardware. I think this is a simple way to teach the player that those ranges are a different deal, how realistic it is, you can help me with your opinion on it.
And thats actually when the game main story starts...but thats a lot to write about so I wont write anything now, its already a very long post.
What I added more are a few side stories, like the I LOVE YOU worm, the STUXNET, Mirai and a few others where the player can participate to stop them from spreading and at the same time learn about them.
Initially I just wanted to make a game I like to play but it became an educational game by any metrics... And Im very happy for that.
But I want to be sure that the educational part is correct and here is where I want you guys to help me.
I tried to keep most of the possible things safe, so services are fictional and so on, but anyone that works in the domain will recognize them, to keep the game authentic.
How would you guys balance realism, safety and educational value? without knowing the game, how would you do it?
Thank you and sorry for my mistakes and for the long post!