TY - EJOU AU - Dean, Josh AU - Lin, Yu-Zheng AU - Encinas, John Paul Martin AU - Almazyad, Ibrahim AU - Shi, Qinxuan AU - Yang, Zhanglong AU - Satam, Shalaka AU - Lei, Tingjun AU - Zhang, Jielun AU - Shao, Sicong AU - Hariri, Salim AU - Satam, Pratik TI - Federated Cybersecurity Testbed as a Service (FCTaaS): A Framework to Federate Cybersecurity Testbeds T2 - Computers, Materials \& Continua PY - VL - IS - SN - 1546-2226 AB - Rapid technological change is transforming our society with the emergence of new fields such as Autonomous Vehicles and Smart Manufacturing, posing new research questions and challenges in system design, operations, security, and training. Researchers rely on testbeds to create experimental scenarios to solve these research challenges. These testbeds aid in data collection, analysis, and observation of the research problem, and in measuring the efficacy of the proposed solution. However, the rapid pace of modern innovation makes it challenging and cost-prohibitive for these testbeds to represent state-of-the-art scenarios, which require expensive upgrades and the addition of new capabilities. In addition, a small, select community of researchers has access to these specialized testbeds, which are not used optimally during their short operational lifecycles. This paper presents FCTaaS: Federated Cybersecurity Testbed as a Service, a scalable framework that bridges the current gaps in existing federation frameworks by enabling two heterogeneous cybersecurity testbeds to participate in a single experiment, overcoming testbed geographical boundaries to address today’s research challenges. This federation allows multiple geographically isolated testbeds to work together to conduct experiments over a Virtual Private Network (VPN), while providing researchers with interfaces for testbed discovery and remote experiment design. Our experimental evaluation stresses the FCTaaS by assessing its performance in Denial-of-Service Scenarios on smart infrastructure and by evaluating intrusion detection and prevention workflows using a Suricata-based intrusion detection and intrusion prevention system (IDS/IPS) testbed. The limiting network utilization of 49% and low overhead of 1%, even under such resource-intensive attack scenarios, demonstrates the efficacy of FCTaaS across three case studies thus enabling improved experimentation while preserving visibility into attack traffic, IDS alerts, and detection-system resource stress with latency ranging from 5.63 ms between local nodes to 147 ms between disbursed nodes. KW - Federated cybersecurity testbeds; testbed-as-a-service; cyber-physical systems security; industry 4.0 security; digital twins security DO - 10.32604/cmc.2026.084915