Research

My dissertation ties together four studies that look unrelated but answer the same question: IoT defenses today are more complex than they need to be, built in isolation from one another, and able to flag an attack without explaining it.

Three problems this work addresses

Complexity by default

Proposed defenses routinely exceed what real IoT hardware can carry

Defense stages in isolation

Authentication, detection, and response are designed separately and never share what they learn

Detection without interpretation

A model flags an anomaly but offers nothing an analyst can act on

Studies in the dissertation

  • Provenance authenticationVerifying where IoT data came from, at a cost small devices can bear
  • IoT device identificationIdentifying device type and identity from communication behavior
  • Crypto ransomware detectionDetecting file-encrypting ransomware from system behavior traces
  • IoT attack behavior visualizationMaking attack behavior visible so an analyst can reason about it

Interests

IoT and embedded securityMachine learning for securityInterpretability and visual analyticsData provenance and integrityHigh-performance computing and benchmarkingTooling for data-intensive research

Publications

TODO: add the real publication list (title, authors, venue, year, link)