Research
My dissertation ties together four studies that look unrelated but answer the same question: IoT defenses today are more complex than they need to be, built in isolation from one another, and able to flag an attack without explaining it.
Three problems this work addresses
Complexity by default
Proposed defenses routinely exceed what real IoT hardware can carry
Defense stages in isolation
Authentication, detection, and response are designed separately and never share what they learn
Detection without interpretation
A model flags an anomaly but offers nothing an analyst can act on
Studies in the dissertation
- Provenance authentication — Verifying where IoT data came from, at a cost small devices can bear
- IoT device identification — Identifying device type and identity from communication behavior
- Crypto ransomware detection — Detecting file-encrypting ransomware from system behavior traces
- IoT attack behavior visualization — Making attack behavior visible so an analyst can reason about it
Interests
Publications
TODO: add the real publication list (title, authors, venue, year, link)