乐播传媒 student team scores high in global cybersecurity competition
School of Computing undergraduates, graduate students rank #13 among 114 competitors
Learning about cybersecurity is a critical part of any computer science curriculum 鈥 but fighting off real-time cyber-attacks puts those skills to the test.
For the , students from around the world build what they hope is a secure software-and-hardware system, defend it against other teams, and then try to hack into those teams' creations.
Last year, 乐播传媒 participated in the competition for the first time, finishing at #26 overall and #2 in New York 鈥 respectable for students doing the work on their own time.
This spring, the School of Computing at the Thomas J. Watson College of Engineering and Applied Science followed MITRE鈥檚 recommendation to make eCTF a formal part of the curriculum. A dozen students signed up and committed time outside of class, while two other students also participated without registering for the course.
This year's challenge was to design and implement a secure storage solution for a chip foundry. The system needed to allow users with various roles to access the proper data without leaking sensitive chip designs to unauthorized parties.
鈥淭he students work very hard,鈥 said Associate Professor Aravind Prakash, who serves as team advisor. 鈥淭his is not like any other course, because we don't have a set number of hours that you need to put in. There were weekends when they would come work in the lab to do their software development or attacks.鈥
The result? Binghamton ranked #13 among 114 competitors, and it was the only New York university in the top 20.
Team co-captain Samruddhi 鈥淪ammy鈥 Deshpande, a computer science master鈥檚 student, also took part in the 2025 competition, and she thinks that made it easier to see weaknesses in other teams鈥 code base and design. They also tapped into new artificial intelligence tools.
鈥淲e knew what our previous mistakes were, and how not to repeat those mistakes,鈥 she said. 鈥淎I helped us to come up with new ideas, and really does well for the authentication side of things, but it also made it much harder to streamline into one specific goal.鈥
is a not-for-profit organization that operates federally funded research and development centers to provide technical expertise, stability, and continuity to government agencies. It advances technology in national defense, aviation safety, GPS, financial systems, healthcare, and cybersecurity.
The eCTF competition includes not just software but also hardware, which can offer different ways to break into a system and get to the valuable information inside.
Students started designing the firmware in January. The attack phase began on March 15, and it withstood all attacks for the first month. On April 15, the final day of the attack phase, four top-ranked teams captured three of the team鈥檚 five flags through hardware fault injection, which physically disrupts how a circuit board operates, causing malfunctions and bypassing security protocols.
Friendly rivalries
Even though they鈥檙e meant to be rivals, other teams generally keep things friendly. At an awards ceremony earlier this spring at MITRE鈥檚 Bedford campus in Massachusetts, Binghamton students spent some face-to-face time with other competitors who offered insights into their strategies.
鈥淲e'll try this fall to learn how to do better hardware attacks,鈥 said team co-captain and doctoral student Pratik Kamble. 鈥淚f we can do that, I think we will be among the top teams next year. We were 26th last year, and now we are 13th 鈥 so it's half. Maybe we can halve that again next year.鈥
Nathan Brauning, a senior this fall, said having tasks that they needed to complete by a certain deadline taught the students how to work as a team.
鈥淲e also learned how to think like an attacker or think like a defender from a cybersecurity standpoint,鈥 he said. 鈥淧articipating in eCTF is good for that, because it forces you to compete with other schools. You're not just taking a class 鈥 we want to do better than other universities.鈥
Applying cybersecurity principles in real-world situations offered key experience outside of the classroom, according to Sky Jiang 鈥26, who earned his degree in May.
鈥淭here were a lot of concepts that we applied in this competition,鈥 he said. 鈥淪ome are concepts that we would go over during classes, like cryptographic ideas, such as symmetric and asymmetric keys or the Diffie-Hellman key exchange method, as well as stuff like buffer overflows, which other groups took advantage of during the attack phase.鈥
Michael Florentino, a junior this fall, appreciated how he needed to read and review other people鈥檚 code 鈥 something he hadn鈥檛 done very much yet in his undergraduate career.
鈥淚鈥檇 be checking multiple documents and sending code back to other people, telling them what I thought they could do better or what they should change,鈥 he said. 鈥淕etting that skill in a team environment was very valuable.鈥
Hands-on experience
Some students joined the eCTF team with no cybersecurity background and faced a steeper learning curve, but they enjoyed working on both hardware and software hacking.
鈥淚 would go to the lab where we have the board set up, and I鈥檇 watch our team captains do what they're doing so I can try to learn from them,鈥 said Bonnie Chen, a junior this fall.
Arianna Carchi 鈥26, who is returning for her master鈥檚 degree this fall, praised the unique opportunity that the eCTF competition offers to students.
鈥淭his was the first year in this competition for most of us, so the first month was tough, just trying to learn everything from MITRE,鈥 she said. 鈥淚t鈥檚 one of the best classes you can take if you want to learn cybersecurity, because it goes beyond the concepts. You get to do something hands-on 鈥 you actually work on something physical when you do hardware attacks on other schools.鈥
As the team鈥檚 advisor, Prakash is already looking ahead to next year, and he鈥檚 hoping to shepherd the team to an even higher ranking. Among the lessons they learned: Prepare students before the semester begins, agree on a complete security design before implementation, avoid separating students into defense-only and attack-only roles, use graded checkpoints to sustain engagement, and provision hardware infrastructure early.
鈥淔rom my discussions with the organizers at MITRE, they are happy not only that we participated, but that our trajectory is going up and we are able to finish strong,鈥 he said.