Cyber-physical systems (CPS) increasingly face security threats that can disrupt critical infrastructure operations. The SPHERE CPS enclave is a modular, remotely accessible industrial control system (ICS) testbed designed to support security experimentation on programmable logic controllers (PLCs), industrial networks, and digital twin simulations. It enables researchers to investigate cyber-physical attacks, anomaly detection, and intrusion resilience strategies. Unlike general cybersecurity testbeds, SPHERE's CPS enclave provides a configurable, realistic environment for studying adversarial scenarios that bridge cyber and physical domains. The infrastructure offers controlled, reproducible experiments with customizable network topologies and hardware-in-the-loop validation. This poster presents the design philosophy, community-driven experimental goals, and deployment considerations of the SPHERE CPS enclave, demonstrating its potential for advancing CPS security research.
To transform cybersecurity and privacy research into a highly integrated, community-wide effort, researchers need a common, rich, representative research infrastructure that meets the needs across all members of the research community and facilitates reproducible science. USC Information Sciences Institute and Northeastern University are meeting researcher needs and have been funded by the NSF mid-scale research infrastructure program to build Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE). SPHERE research infrastructure will offer access to an unprecedented variety of user-configurable hardware, software, and network resources, it will offer six user portals geared toward different populations of users, and it will support reproducible research via a combination of infrastructure services and community engagement activities.
Researchers in experimental cybersecurity are increasingly sharing the code, data, and other artifacts associated with their studies. This trend is encouraged and rewarded by conferences and journals through practices such as artifact evaluation and badging. While these trends in sharing artifacts are promising, the cybersecurity community is still far from an ecosystem in which artifacts are FAIR: findable, accessible, interoperable, and reusable. The lack of established standards and best practices for sharing and reuse results in artifacts that are often difficult to find and reuse; in addition, the lack of community standards results in artifacts that may be incomplete and low-quality. In this paper we describe our experience in creating an online community hub, called SEARCCH, to promote the sharing and reuse of artifacts for cybersecurity research. Based on our experience, we offer lessons learned: issues that must be addressed to further promote FAIR principles in experimental cybersecurity.
Recent events have demonstrated that critical infrastructure assets operated by networked industrial control systems are vulnerable to cyber attacks. The first step to addressing the threats is to establish and maintain reliable monitoring of the cyber security health of systems so that their true cyber security states are known. For current operational technology systems, there is growing, but limited, availability of technologies and tools that provide the needed cyber security awareness. This chapter summarizes recent efforts conducted in collaboration with members of the U.S. natural gas distribution sector to develop a set of recommended functional requirements for cyber security health monitoring and awareness of operational technology systems. The design-driven process is described and the resulting nine key recommendations for securing operational technology systems are presented.
The National Transportation Safety Board is charged with investigating transportation-related accidents and incidents in the aviation, railroad, highway, marine and pipeline infrastructure. The increasing integration of traditional information technology systems with operational technology systems increases the cyber vulnerabilities and risk. National Transportation Safety Board investigations require trustworthy data to determine accident and incident causes and remedies. This chapter explores the requirements for trust in the critical transportation infrastructure due to operational technology and information technology integration. The focus is on internal aircraft systems and their data in accident investigations. While commercial avionics systems employ very reliable serial bus architectures, these systems and their components were not designed with cyber security in mind. Cyber state mechanisms such as software attestation and data protection must be designed into systems and validated to support trust requirements for accident investigations. Additionally, it is important to ensure the secure collection of data used in investigations, employ anomaly detection techniques to detect potential cyber attacks and establish a vulnerability registry and risk assessment system as in the information technology domain to share information and address potential cyber security problems.
An important question facing critical infrastructure owners and operators is how their assets could be made to fail by the various threat actors. Designing, enumerating and analyzing failure scenarios helps explore the assumptions made on the operational side, the value of current mitigations and the need for certain types of protection mechanisms. This chapter describes the formulation of 55 failure scenarios in the natural gas distribution infrastructure. These failure scenarios highlight a range of potential threats across the natural gas infrastructure, from transmission to distribution and home metering. The chapter also describes a multi-pronged approach used to develop failure scenarios for the gas sector and compares them against the scenarios developed for the electric sector. The focus is on the concepts underlying the failure scenarios and their use, the threat model they encompass, and the assumptions, lessons learned and caveats underpinning their creation.
This paper calls attention to a forthcoming publication produced by the Cyber Risk Economics Program within the U.S. Department of Homeland Security. It presents an overarching strategy for cyber security risk economics applied research and advanced development intended to address some of the most pressing capability gaps in government and industry.
New and innovative cybersecurity technologies are essential to ensure that information systems and critical infrastructure are secure and resilient. These technologies must also meet the needs of IT professionals and be available via channels acceptable to such users. The US Department of Homeland Security Science and Technology Directorate's cybersecurity R&D program funds top researchers in academia, industry, and government in developing new cybersecurity technologies across key areas to meet these needs.
New and innovative technologies will only make a difference if they're deployed and used. It doesn't matter how visionary a technology is unless it meets user needs and requirements and is available as a product via user-acceptable channels. One of the cybersecurity research community's biggest ongoing challenges is transitioning technology into commercial or open source products available in the marketplace. This article presents an R&D execution model to increase the success rate of technology transition along with several examples of successful technology transition from the US Department of Homeland Security Science and Technology Directorate's cybersecurity R&D program.
In the past year, there has been significant interest in promoting the idea of applying scientific principles to information security. The main point made by information security professionals who brief at conferences seems to be that our field of information security is finally mature enough to begin making significant strides towards applying the scientific approach. Audiences everywhere enthusiastically agree and thrash themselves for bypassing science all along, bemoaning the fact that we could be "so much further along" if we only did science. Of course, after the presentation is over, everyone goes back to the methods that have been used throughout our generation to generate prototypes and tools with no regard for the scientific principles involved.
In this exploratory paper, we propose that intrusion detection and fault localization techniques in MANET environments (which are commonly separate systems) should work cooperatively. We argue that an integrated approach will exhibit improved accuracy, and also minimize system overheads and redundancy. Using detection of in-band wormhole attacks as an illustrative example, we outline how an integrated approach can better distinguish malicious network attacks from "normal" network delays and outages
Policy-based cryptographic key management is powerful, flexible method of creating, distributing, protecting, and destroying cryptographic keys in accordance with an organizational policy governing information security. The Policy-Controlled Cryptographic Key Release project addressed one part of key management. The goals included: (1) developing a formal language for specifying policies indicating to whom and under what conditions a cryptographic key could be accessed; (2) implementing a prototype system for administering (i.e., enforcing) these policies; and (3) experimenting with automated verification tools which analyzed the policies for consistency and completeness. The requirements for the key release policy language and administering systems are identified; the initial language and system design are described; and the lessons learned from the project are summarized. An example key release policy is included
This document describes the proposed approach for negotiating and exchanging key recovery information within the Internet Security Association Key Management Protocol (ISAKMP).
The Adaptive Cryptographically Synchronized Authentication (ACSA) Project offers a new approach to data authentication in networks by trading off authentication strength and performance. In ACSA, the communicants select among various authentication gears to balance their performance and security needs. These gears include three basic groups: (1) conventional mechanisms that are computationally intensive but considered highly secure; (2) higher-speed, lower-strength mechanisms including Universal Message Authentication Codes (UMACs) and our novel inner-function group (IFG) with bit scattering; and (3) Partial MACs (PMACs) that calculate the authentication tag on only a subset of the message. We are implementing a prototype ACSA System based on the popular IPsec protocols and are demonstrating its effectiveness on high-speed network applications
The Dynamic Cryptographic Context Management (DCCM) project efficiently provides security for very large, dynamically changing groups of participants. The DCCM system has two novel distinguishing characteristics. First, policy plays a key role in DCCM. Groups at all levels have policies. These policies are represented; they are negotiated; they are managed; and a cryptographic context-an unambiguous set of mechanisms and configuration-is created to make particular interactions possible subject to these policies. Second, DCCM implements a scalable key management system based on One-way Function Trees (OFT) that can handle group sizes up to 100000 members and can dynamically handle members entering and leaving groups.
Michael E. Locasto合作论文数Computer Science,George Mason University3
Ulf Lindqvist合作论文数Computer Science Laboratory at SRI International2
David A. Mcgrew合作论文数Cisco Systems,2
Alan T. Sherman合作论文数Department of Computer Science and Electrical Engineering (CSEE)
University of Maryland, Baltimore County (UMBC)1
Clifford Neuman合作论文数Center for Computer Systems Security;Department of Computer Science;Information Sciences Institute;University of Southern California1
Adarshpal S Sethi合作论文数University of Delaware;Department of Computer and Information Sciences1