This page collects selected academic works - peer-reviewed journal articles that reference my publications, vulnerability disclosures, or tools. Coverage spans from 2003 to 2025.
I am not a formal academic researcher and have rarely have been paid to do this work - it comes from personal interest and independent research pursued mostly alongside my professional roles. Inclusion is based on explicit citation or reference to my work or its derivatives.
Sections
- Notable Citations
- Data Privacy & Regulation
- Threat Modeling & Risk
- Bluetooth & Wireless Security
- TLS / SSL Security
- Surveillance
- Anti-Virus Security & Malware
- Vulnerability Research
- Cashback & Online Payment Vulnerabilities
- Patents
- Cited in Theses & Dissertations
Notable Citations
The 2025 USENIX Security Distinguished Paper My ZIP isn't your ZIP (Tsinghua University / Zhongguancun Laboratory) extends my anti-virus parser attack and bypass research - originally The Death of AV Defense in Depth? with Sergio Alvarez at CanSecWest - into modern semantic-gap attacks on ZIP implementations.
The same line of work is picked up at IEEE Symposium on Security and Privacy 2012 in Abusing File Processing in Malware Detectors for Fun and Profit (Oberheide / Cooke / Jahanian, University of Michigan). Separately, my 2009 TLS renegotiation disclosure (CVE-2009-3555) is analyzed directly at ACM CCS 2013 in On the Security of TLS Renegotiation (Giesen / Kohlar / Stebila, Queensland University of Technology).
The Reaves / Blue / Traynor research arc at the University of Florida cites my TLS/SSL work across a decade - AuthLoop at USENIX Security 2016, the 2017 doctoral dissertation, and a 2022 US patent for practical end-to-end cryptographic authentication over voice channels.
Doctoral dissertations at Ruhr-Universität Bochum (Bergsma, TLS protocol modeling) and Johns Hopkins University (Martin, medical device security) reference my research.
My TLS renegotiation whitepaper (CVE-2009-3555) was picked up in coordinated advisories from US-CERT, DFN-CERT, BELNET-CERT and SWITCH-CERT.
21 universities across four continents in total; full cross-index of theses at the bottom.
Data Privacy & Regulation
My work on data privacy has spanned academic publication, regulatory litigation, and direct engagement with supervisory authorities. This includes contributions on the extraterritorial enforcement of GDPR - notably the documented dialogue and complaints filed with Luxembourg's CNPD against Rocketreach, Apollo and similar US-based data brokers operating without an EU Article 27 representative - which has been referenced in subsequent legal scholarship and case law commentary on extraterritorial GDPR enforcement.
2024 · Challenges to the Extraterritorial Enforcement of Data Privacy Law - EU Case Study
2022 · Contribution to the Public Consultation on the EDPB Guidelines 05/2021 on the Interplay between Article 3 and Chapter V GDPR International Transfers
Threat Modeling & Risk
The "Attacker Pyramid" / Attacker Classification model first published on this blog and developed further in The Rise of the Vulnerability Markets - History, Impacts, Mitigations (OWASP BENELUX 2011) has been referenced in academic work on cyber threat modeling, malware evolution, and the economics of vulnerability markets.
2022 · In Defense of Offense: Information Security Research under the Right to Science
2013 · Perspectives in Cyber Security: The Future of Cyber Malware
Bluetooth & Wireless Security
Bluetooth research starting in 2006 - including BTCrack (the world's first public Bluetooth PIN and Link-key brute-force tool, co-authored with Eric Sesterhenn; FPGA implementation with David Hulton in 2007; included in BackTrack since 2008), the live demo of a remote root shell over Bluetooth on macOS 10.3.9 / 10.4, custom long-range YAGI antenna work, and the All Your Bluetooth Is Belong To Us (Hack.lu 2006) and 23C3 Bluetooth Hacking Revisited presentations - has been referenced in 30+ peer-reviewed journal articles, IEEE/ACM conference proceedings, and dissertations from 2007 to 2024.
2024 · Low-power Bluetooth/RFID Devices to Track Inventory in the Supply Chain
2022 · Optical Wireless Communications High-Speed Bluetooth Secure Pairing Towards Developing a Trust Protocol
2021 · A Systematic Review of Bluetooth Security Threats, Attacks & Analysis
2021 · Addressing the Security and Efficiency Challenges in Internet of Things
2020 · SecWIR: Securing Smart Home IoT Communications via Wi-Fi Routers with Embedded Intelligence
2020 · Detecting Bluetooth Attacks Against Smartphones by Device Status Recognition
2019 · Analysis on Bluetooth Security
2019 · Wi-Fi Channel Saturation as a Mechanism to Improve Passive Capture of Bluetooth Through Channel Usage Restriction
2018 · Bluetooth Intrusion Detection System (BIDS)
2018 · Seguretat en Bluetooth: Anàlisi de Vulnerabilitats
2017 · Penetration Testing and Testing to Diagnose and Detect Vulnerabilities in Wireless Data Networks
2016 · A Strenuous Macroanalysis on the Substratals of Securing Bluetooth Mobile Workforce Devices
2016 · Data Security in Telehealth and Smart Home Environment
2015 · A Review on Bluetooth Security Vulnerabilities and a Proposed Prototype Model for Enhancing Security against MITM Attack
2015 · Bluetooth Security and Threats
2015 · Enhancement of Bluetooth Security Authentication Using HMAC
2014 · Exploiting Bluetooth 4.0 for Secure, Cloud-Enabled Monitoring of Palliative Care Patients
2013 · Ubertooth - Bluetooth Monitoring und Injection
2012 · Bluetooth Security Threats and Solutions: A Survey
2012 · Analysis of Bluetooth Threats and v4.0 Security Features
2012 · Analysis and Mitigation of Vulnerabilities in Short-Range Wireless Communications for Industrial Control Systems
2012 · Theoretical Analysis of Security Features and Weaknesses of Telecommunication Specifications for Smart Metering
2011 · BlueSnarf Revisited: OBEX FTP Service Directory Traversal
2011 · A Secured Bluetooth Based Social Network
2010 · Battery-Sensing Intrusion Protection System Validation Using Enhanced Wi-Fi and Bluetooth Attack Correlation
2010 · Bluetooth Sniffing and the PS3
2010 · Effects of Wi-Fi and Bluetooth Battery Exhaustion Attacks on Mobile Devices
2010 · Taming the Blue Beast: A Survey of Bluetooth Based Threats
2009 · Secure Physical Layer using Dynamic Permutations in Cognitive OFDMA Systems
2009 · Security Issues in Pervasive Computing
2009 · Wireless Network Deployment
2008 · Towards Pervasive Computing Security
2008 · Breaking into Bluetooth
https://doi.org/10.1016/S1353-4858(08)70074-670074-6)
2007 · Studying Bluetooth Malware Propagation: The BlueBag Project
2007 · Keystroke Logging of a Wireless Keyboard
TLS Attacks & Vulnerability Analysis
Following the 2009 disclosure of the TLS renegotiation vulnerability (CVE-2009-3555), the SSL/TLS Compatibility and Hardening Report 2010/2011 (G-SEC), the SSL Audit tool (the first SSL/TLS scanner with a behavioral fingerprinting engine for SChannel, OpenSSL, NSS, Certicom and RSA BSAFE stacks), and the Harden SSL/TLS tool for Windows SCHANNEL hardening, this work has been cited across journal articles, PhD dissertations, and conference proceedings on protocol security, padding oracle attacks, and TLS hardening - including at ACM CCS.
2015 · Evaluation of TFTP DDoS Amplification Attack
2014 · Modeling and Analyzing Cryptographic Real World Protocols
2013 · On the Security of TLS Renegotiation
2013 · Classifying Network Protocol Implementation Versions: An OpenSSL Case Study
2012 · Attacks on Re-keying and Renegotiation in Key Exchange Protocols
2012 · Analysis of the Functionality, Risks and Counter-Measures of Current Padding Attacks and the Implementation of an Attack in the Open-Source Program CrypTool 2
2011 · MITM Attacks on SSL/TLS Related to Renegotiation
TLS Deployment & Hardening
2018 · TLS Sicherheit: Konzept zum Manipulationsschutz eines Zertifikatsspeichers
2017 · Metodología de Hacking Ético para Instituciones Financieras
2017 · Проблеми використання SSL/TLS (Problems of Using SSL/TLS)
2016 · A Comprehensive Survey on SSL/TLS and their Vulnerabilities
2016 · Avoidable SSLStrip Attack with HSTS Countermeasures
2015 · A Segurança das Comunicações dos Sítios Web Disponibilizados pelo Estado Português
2013 · Safe Configuration of TLS Connections - Beyond Default Settings
2013 · Ataques a las comunicaciones sin hilos y sus principales métodos de mitigación
2013 · SSL/TLS Status Survey in Asia Region - Transitioning Against the Renegotiation Vulnerability, CRIME Attacks and Untrusted X.509 Certificates
2012 · SSL/TLS: État des lieux et recommandations
2012 · SSL/TLS Status Survey in Japan - Transitioning Against the Renegotiation Vulnerability and Short RSA Key Length Problem
2012 · Countermeasures and Tactics for Transitioning Against the SSL/TLS Renegotiation Vulnerability
2010 · Cybersecurity Myths on Power Control Systems: 21 Misconceptions and False Beliefs
2010 · Problems on the Shifts to a New Specification with Countermeasures of the SSL/TLS Renegotiation Vulnerability
TLS in Applications & Constrained Environments
2024 · A Cost-Effective Zero-Trust Approach for Cloud Computing: Experimental Evaluation on AWS Platform
2022 · Network Security Protocol Performance Analysis in IoT Environment
2021 · Assessing Non-Intrusive Vulnerability Scanning Methodologies for Detecting Web Application Vulnerabilities on Large Scale
2017 · Authentication Techniques for Heterogeneous Telephone Networks
2016 · AuthLoop: End-to-end Cryptographic Authentication for Telephony over Voice Channels
2016 · Securing Medical Devices and Protecting Patient Privacy in the Technological Age of Healthcare
2015 · Optimizing TLS for Low Bandwidth Environments
2014 · SRAP: A New Authentication Protocol for Semantic Web Applications
2013 · Cyber-security Defense in Large-scale M2M System: Actual Issues and Proposed Solutions
2011 · TLS and Energy Consumption on a Mobile Device: A Measurement Study
2010 · Energy Consumption of Cryptographic Algorithms and Security Protocols on Symbian Mobile Devices
Surveillance
Cited for the Sniff'em network packet analyzer, which appears in the University of Pennsylvania eavesdropping research programme (Cronin, Sherr & Blaze) and in legal-ethics and internet-architecture scholarship as an example of accessible packet-capture tooling.
2010 · Notes on Theoretical Limitations and Practical Vulnerabilities of Internet Surveillance Capture
2006 · The Eavesdropper's Dilemma
2006 · On the Reliability of Network Eavesdropping Tools
2005 · Porting and Performance Aspects from IPv4 to IPv6: The Case of OpenH323
2004 · The Layers Principle: Internet Architecture and the Law
2004 · Performance Evaluation of an IPv6-capable H323 Application
2003 · Redefining Privacy and Security in the Electronic Communication Age: A Lawyer's Ethical Duty in the Virtual World of the Internet
Anti-Virus Security & Malware
Joint research with Sergio Alvarez on anti-virus parsing engine vulnerabilities - presented as The Death of AV Defense in Depth? (CanSecWest) and resulting in remote code execution, denial-of-service, and detection bypass findings across major AV vendors - together with work on malware auto-update man-in-the-middle attacks and fuzzing methodology, has been referenced in peer-reviewed venues including IEEE Symposium on Security and Privacy, ACM Asia CCS, ESORICS, and multiple PhD theses.
AV Parser Attack Surface
Direct heirs of Death of AV Defense in Depth? - papers analyzing AV parser vulnerabilities (PE headers, ZIP files, decoder ambiguity) as attacker-controlled input processing.
2025 · My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers
2017 · Malware Detection Based on Multiple PE Headers Identification and Optimization for Specific Types of Files
2015 · Error-Correcting Codes as Source for Decoding Ambiguity
2012 · Abusing File Processing in Malware Detectors for Fun and Profit
AV Bypass & Evasion
Work on defeating AV detection, signature-based evasion, and self-protection subversion.
2016 · From Malware Signatures to Anti-Virus Assisted Attacks
2016 · A Novel Malware for Subversion of Self-Protection in Anti-Virus
2015 · Design, Implementation and Evaluation of a Novel Anti-Virus Parasitic Malware
AV Update Security
Direct heirs of my 2007 auto-update MITM work - papers analyzing the security of AV upgrade channels.
2015 · A Security Analysis Method of Antivirus Software Upgrade Process
2014 · Antivirus Security: Naked During Updates
2007 · Man-in-the-Middle Attacks on Auto-updating Software
Malware Research
Adjacent research on malware architecture (feature-distributed, IoT) and defense mechanisms (honeyclients, information-flow control) citing my work as context.
2018 · Study of Security Attacks against IoT Infrastructures
2015 · Design and Evaluation of Feature Distributed Malware Attacks against the Internet of Things (IoT)
2014 · Feature-Distributed Malware Attack: Risk and Defence
2014 · Design and Analysis of a New Feature-Distributed Malware
2011 · Making Information Flow Explicit in HiStar
2009 · Client-side Threats and a Honeyclient-based Defense Mechanism, Honeyscout
2009 · Schwachstellen in Sicherheitssoftware und deren Auswirkungen
Vulnerability Research
Cited for CSS-DIE, the CSS fuzzer I co-authored with HD Moore, Matt Murphy and Aviv Raff during the 2006 "Month of Browser Bugs" effort, and for fuzzing methodology work descending from the anti-virus parser research - both of which appear in academic surveys of fuzzing tools and feedback-driven techniques as real-world case studies.
2017 · A Review of Fuzzing Tools and Methods
2014 · Fuzzing Analysis: Evaluation of Properties for Developing a Feedback-Driven Fuzzer Tool
2013 · Using Redundancy to Improve Security and Testing
2007 · Fuzzing: Brute Force Vulnerability Discovery
Cashback & Online Payment Vulnerabilities
Research into systemic privacy and integrity flaws in cashback and online payment platforms, originally presented at OWASP, exposed weaknesses in widely-used commercial systems.
2011 · Exposing the Lack of Privacy in File Hosting Services
Patents
The Traynor/Reaves/Blue team at the University of Florida - whose AuthLoop paper and Reaves' PhD dissertation are already indexed in this list - was granted a US patent on end-to-end cryptographic authentication for telephony over voice channels, building on the same research line that references my TLS/SSL work.
US11329831B2 - Practical end-to-end cryptographic authentication for telephony over voice channels
Cited in Theses & Dissertations
A cross-index of the doctoral, Master's, and Bachelor's theses collected above, showing academic reach across 21 universities on 4 continents (Europe, North America, South America, Asia). Each thesis appears in full within its topical section; this list gives a degree-level view.
PhD Dissertations (5)
- 2022 - Mantie N. Reid, Pace University - Optical Wireless Communications High-Speed Bluetooth Secure Pairing Bluetooth & Wireless Security
- 2021 - Xinyu Lei, Michigan State University - Addressing the Security and Efficiency Challenges in Internet of Things Bluetooth & Wireless Security
- 2017 - Bradley Galloway Reaves, University of Florida - Authentication Techniques for Heterogeneous Telephone Networks TLS in Applications & Constrained Environments
- 2016 - Paul D. Martin, Johns Hopkins University - Securing Medical Devices and Protecting Patient Privacy TLS in Applications & Constrained Environments
- 2014 - Florian Bergsma, Ruhr-Universität Bochum - Modeling and Analyzing Cryptographic Real World Protocols TLS Attacks & Vulnerability Analysis
Master's Theses (11)
- 2024 - Aref Mowloughi, University of Turku - A Cost-Effective Zero-Trust Approach for Cloud Computing on AWS TLS in Applications & Constrained Environments
- 2018 - Alpen-Adria-Universität Klagenfurt - TLS Sicherheit: Konzept zum Manipulationsschutz eines Zertifikatsspeichers TLS Deployment & Hardening
- 2017 - Universidad de Cuenca - Metodología de Hacking Ético para Instituciones Financieras TLS Deployment & Hardening
- 2016 - University of Eastern Finland - Data Security in Telehealth and Smart Home Environment Bluetooth & Wireless Security
- 2015 - Diallo Alhassane Saliou, International Islamic University Malaysia - Enhancement of Bluetooth Security Authentication Using HMAC Bluetooth & Wireless Security
- 2014 - Will Browne, Trinity College Dublin - Exploiting Bluetooth 4.0 for Secure, Cloud-Enabled Monitoring of Palliative Care Patients Bluetooth & Wireless Security
- 2014 - Kris Gundersen, University of Oslo - Fuzzing Analysis: Evaluation of Properties for Developing a Feedback-Driven Fuzzer Tool Vulnerability Research
- 2014 - Marcio Ricardo Rosemberg, PUC-Rio (Pontifícia Universidade Católica do Rio de Janeiro) - SRAP: A New Authentication Protocol for Semantic Web Applications TLS in Applications & Constrained Environments
- 2013 - Laura Rasal Blasco, Universitat Oberta de Catalunya (UOC) - Ataques a las comunicaciones sin hilos y sus principales métodos de mitigación TLS Deployment & Hardening
- 2012 - Universitat Politècnica de Catalunya - Theoretical Analysis of Security Features and Weaknesses of Telecommunication Specifications for Smart Metering Bluetooth & Wireless Security
- 2009 - Christian Clementson, Linköping University - Client-side Threats and a Honeyclient-based Defense Mechanism, Honeyscout Anti-Virus Security & Malware
Bachelor's & Diploma Theses (5)
- 2012 - Alexander Colin Jüttner, Frankfurt School of Finance and Management - Analysis of Padding Attacks and Implementation in CrypTool 2 TLS Attacks & Vulnerability Analysis
- 2012 - Rati Gelashvili, ETH Zürich - Attacks on Re-keying and Renegotiation in Key Exchange Protocols TLS Attacks & Vulnerability Analysis
- 2010 - Pedro Miranda Arto, Universidad de Zaragoza - Energy Consumption of Cryptographic Algorithms and Security Protocols on Symbian Mobile Devices TLS in Applications & Constrained Environments
- 2009 - Vesa Niittylä, Lahden ammattikorkeakoulu (Lahti University of Applied Sciences) - Wireless Network Deployment Bluetooth & Wireless Security
- 2009 - Robert Kossatz, Hochschule für Technik und Wirtschaft Dresden - Schwachstellen in Sicherheitssoftware und deren Auswirkungen Anti-Virus Security & Malware

