We present a live demonstration of the SPHERE CPS enclave, a reconfigurable industrial-control experimentation environment built to make ICS security studies repeatable and shareable across research teams. The enclave combines PLC-based control, modular I/O, SCADA/HMI interaction, and an isolated, configurable network segment, with optional integration of simulated components to emulate larger process contexts. This demo walks attendees through an end-to-end workflow using a water-treatment scenario: provisioning the control and monitoring stack, running a baseline process, introducing representative faults or adversarial manipulations, and collecting synchronized controller, network, and process telemetry for replay and offline analysis. The goal is to support evaluations of detection and response techniques that depend on coupled cyber and physical behavior, including controller-logic attacks and network-mediated disruptions. We conclude by outlining planned extensions toward richer operator-in-the-loop studies (e.g., mixed-reality interfaces) and broader cross-domain interactions spanning water and energy-related infrastructure.
Cyber-physical systems (CPS) increasingly face security threats that can disrupt critical infrastructure operations. The SPHERE CPS enclave is a modular, remotely accessible industrial control system (ICS) testbed designed to support security experimentation on programmable logic controllers (PLCs), industrial networks, and digital twin simulations. It enables researchers to investigate cyber-physical attacks, anomaly detection, and intrusion resilience strategies. Unlike general cybersecurity testbeds, SPHERE's CPS enclave provides a configurable, realistic environment for studying adversarial scenarios that bridge cyber and physical domains. The infrastructure offers controlled, reproducible experiments with customizable network topologies and hardware-in-the-loop validation. This poster presents the design philosophy, community-driven experimental goals, and deployment considerations of the SPHERE CPS enclave, demonstrating its potential for advancing CPS security research.
The IEEE Computer Society (CS) President, Hironori Washizaki, together with the Vice Presidents, reflects on the remarkable year of 2025 by reviewing the programs and activities the CS has accomplished in alignment with its strategic goals and looks ahead to the future toward the 80th anniversary.
Engaging professionals from all areas of computing, the IEEE Computer Society sets the standard for education and engagement that fuels global technological advancement.Through conferences, publications, and programs, IEEE CS empowers, guides, and shapes the future of its members, and the greater industry, enabling new opportunities to better serve our world.
To transform cybersecurity and privacy research into a highly integrated, community-wide effort, researchers need a common, rich, representative research infrastructure that meets the needs across all members of the research community and facilitates reproducible science. USC Information Sciences Institute and Northeastern University are meeting researcher needs and have been funded by the NSF mid-scale research infrastructure program to build Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE). SPHERE research infrastructure will offer access to an unprecedented variety of user-configurable hardware, software, and network resources, it will offer six user portals geared toward different populations of users, and it will support reproducible research via a combination of infrastructure services and community engagement activities.
According to the Annual Computer Security Applications Conference (ACSAC):1
In noting the 20th anniversary of the establishment of IEEE Security & Privacy Magazine, we give a retrospective view of the research papers from the Security and Privacy Symposium in 2003. These papers represent the context of security concerns and solutions of that era. In some cases they illustrate problems that were solved; in other cases they foreshadow the dominant themes of today.
In an effort to bring a portion of symposia to a broader audience, the IEEE Security & Privacy editorial board dedicates special issues to present selected papers. The contributions in this issue are from the IEEE Symposium on Security and Privacy. Since 1980, this event has been the premier forum for presenting developments in computer security and electronic privacy as well as bringing toget...
Researchers in experimental cybersecurity are increasingly sharing the code, data, and other artifacts associated with their studies. This trend is encouraged and rewarded by conferences and journals through practices such as artifact evaluation and badging. While these trends in sharing artifacts are promising, the cybersecurity community is still far from an ecosystem in which artifacts are FAIR: findable, accessible, interoperable, and reusable. The lack of established standards and best practices for sharing and reuse results in artifacts that are often difficult to find and reuse; in addition, the lack of community standards results in artifacts that may be incomplete and low-quality. In this paper we describe our experience in creating an online community hub, called SEARCCH, to promote the sharing and reuse of artifacts for cybersecurity research. Based on our experience, we offer lessons learned: issues that must be addressed to further promote FAIR principles in experimental cybersecurity.
Considering the shifting fundamentals of cybersecurity research.
Considering the wide range of technological and societal trade-offs associated with cybersecurity.
Presents the introductory editorial for this issue of the publication.
The Annual Computer Security Applications Conference (ACSAC) 2020 marked the 36th edition of ACSAC. The vision of Marshall Abrams, a beloved founder and tireless organizer of ACSAC, is to take hard problems and find practical solutions. In September 2020, Marshall died of heart failure at the age of 79. Prior to his passing, he was actively working on signing a virtual meeting vendor for the conference. As Charles Payne, ACSAC local arrangements chair, said during the tribute, Marshall asked us to focus on solving hard problems, hard problems that require the combined effort of government, industry, and academia to address; and Marshall insisted on practical solutions. With rampaging ransomware and zero-day supply-chain attacks tearing through critical national and computing infrastructures, Marshall’s longtime vision seems more relevant today than ever.
A significant cybersecurity event has recently been discovered in which malicious actors gained access to the source code for the Orion monitoring and management software made by the company SolarWinds and inserted malware into that source code. This article contains brief perspectives from a few members of the IEEE Security & Privacy editorial board regarding that incident.
Experimentation is an essential tool for developing networked and distributed systems. However, it is inherently complex due to the concurrent, asynchronous, heterogeneous, and prototype-based systems that must be integrated into representative scenarios to conduct valid evaluations. This paper offers a retrospective on the development and use of MAGI, an orchestration tool, that translates an experiment specification into an execution on an emulation-based testbed with high-level directives for message passing, remote process execution, and failure tracking, for conducting large and complex experiments. The MAGI tool has been used for more than seven years in a variety of experiments, including undergraduate education, anonymous communication, cyber-physical systems, and attacker-defender games on the DETER testbed. We hope the insights and takeaways learned from using our tool will aid in developing the next-generation experiment management tools.