Letter from the Editor

Dear Readers:

This is the COVID-19 issue; it is abbreviated from our usual style because computer security has taken a backseat to life and death threat from the pandemic. Though computer viruses have long taken a toll on businesses and individuals, a real, biologic virus has turned out to be more expensive. Academic conferences are hard-hit by the travel restrictions and limits on large gatherings. Please check the conference websites before making travel plans. The IEEE Computer Society's Security and Privacy Symposium and Workshops will be virtual, online events at their scheduled dates during the week May 18-21, 2020. The symposium papers are now online in the Computer Society's Digital Libary: https://www.computer.org/csdl/proceedings/sp/2020/1dAAQaOrrva Help cheer up computer security researchers by voting for the "Best Paper of 2019" award! Be clean, be distant, be safe, Hilarie Orman cipher-editor @ ieee-security.org ==================================================================== News Briefs ==================================================================== News briefs from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/NewsBriefs.html ----- Cyber-Attack Hits U.S. Health Agency Amid Covid-19 Outbreak Bloomberg By Shira Stein and Jennifer Jacobs March 16, 2020 https://www.bloomberg.com/news/articles/2020-03-16/u-s-health-agency-suffers-cyber-attack-during-covid-19-response Summary: As if the reality of a pandemic were not enough bad news, some attempts to keep the public informed have suffered a denial of service attack. ---- Official Huawei Cyber Security Evaluation Centre (HCSEC) Oversight Board Annual Report 2019 A report to the National Security Adviser of the United Kingdom March 2019 https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/790270/HCSEC_OversightBoardReport-2019.pdf Summary: This report largely concerns an investigation of Huawei's software engineering processes. Notable are two summary items: "v. Further significant technical issues have been identified in Huawei's engineering processes, leading to new risks in the UK telecommunications networks; v. No material progress has been made by Huawei in the remediation of the issues reported last year, making it inappropriate to change the level of assurance from last year or to make any comment on potential future levels of assurance." o Book reviews, Conference Reports and Commentary and News items from past Cipher issues are available at the Cipher website ==================================================================== Commentary and Opinion ==================================================================== Book reviews from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/BookReviews.html, and conference reports are archived at http://www.ieee-security.org/Cipher/ConfReports.html ==================================================================== Listing of academic positions available by Cynthia Irvine ==================================================================== http://cisr.nps.edu/jobscipher.html (nothing new since E153) -------------- This job listing is maintained as a service to the academic community. If you have an academic position in computer security and would like to have in it included on this page, send the following information: Institution, City, State, Position title, date position announcement closes, and URL of position description to: irvine@cs.nps.navy.mil ==================================================================== Conference and Workshop Announcements ==================================================================== The complete Cipher Calls-for-Papers is located at http://www.ieee-security.org/CFP/Cipher-Call-for-Papers.html The Cipher event Calendar is at http://www.ieee-security.org/Calendar/cipher-hypercalendar.html Cipher calendar entries are announced on Twitter; follow ciphernews Requests for inclusion in the list should sent per instructions: http://www.ieee-security.org/Calendar/submitting.html ------------------------- Competition: What 2019 paper did most to advance the science of cybersecurity? Nominations for NSA's annual Best Science of Cybersecurity paper award are open. Were there any papers published in 2019 that you think were especially good, in the sense that they advanced the foundations of cybersecurity and/or exemplified excellence in scientific study in this multidisciplinary field? To help you remember what's been published in the past year, a table providing links to many of the relevant conferences and journals is available here: https://cps-vo.org/sos/papercompetition/sources-2019 . Last year's winning paper was Evaluating Fuzz Testing by George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, and Michael Hicks, presented at ACM CCS 2018: https://www.cs.umd.edu/~mwh/papers/fuzzeval.pdf Honorable Mentions went to Continuous Formal Verification of Amazon s2n https://link.springer.com/chapter/10.1007/978-3-319-96142-2_26 and Meltdown: Reading Kernel Memory from User Space https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-lipp.pdf Please take a few moments to honor a paper by nominating it for NSA's Best Science of Cybersecurity paper competition, which is described here: https://cps-vo.org/group/sos/papercompetition Submit your nomination here: https://cps-vo.org/group/sos/papercompetition/submit Nominations close 15 April 2020. --------------------------- CyberSECHARD 2020 2nd IFIP NTMS Workshop on Cybersecurity on Hardware, Held in conjunction with the 11th IFIP International Conference on New Technologies, Mobility and Security (NTMS 2020), Paris, France, July 6 - 8, 2020. http://www.ntms-conf.org/ntms2020/call-for-workshops/cybersechard Submission date: 20 March 2020 IoTSPT-ML 2020 10th International Workshop on Security, Privacy, Trust, and Machine Learning for Internet of Things, Held in conjunction with the 29th International Conference on Computer Communications and Networks (ICCCN 2020), Honolulu, Hawaii, USA, August 6, 2020. https://sites.google.com/uw.edu/iotspt-ml-2020 Submission date: 22 March 2020 IWSEC 2020 15th International Workshop on Security, Fukui, Japan, September 2 - 4, 2020. http://www.iwsec.org/2020/ Submission date: 23 March 2020 SecMT 2020 International Workshop on Security in Mobile Technologies, Held in conjunction with ACNS2020, Rome, Italy, June 22-25, 2020. https://spritz.math.unipd.it/events/2020/ACNS_Workshop/index.html Submission date: 25 March 2020 IEEE S&B 2020 4th IEEE Security and Privacy on the Blockchain Workshop, Held in conjunction with EuroS&P 2020, Genova, Italy, September 7-11, 2020. https://ieeesb.org Submission date: 9 April 2020 SenSys 2020 18th ACM Conference on Embedded Networked Sensor Systems, Yokohama, Japan, November 16-19, 2020. http://sensys.acm.org/2020/ Submission date: 10 April 2020 SCN 2020 12th Conference on Security and Cryptography for Networks, Amalfi, Italy, September 14 - 16, 2020. https://scn.unisa.it/ Submission date: 19 April 2020 SciSec 2020 3rd International Conference on Science of Cyber Security, Shanghai, China, August 9 - 11, 2020. http://www.sci-cs.net Submission date: 1 May 2020 CCS 2020 27th ACM Conference on Computer and Communications Security, Orlando, FL, USA, November 9 - 13, 2020. 