| ]

This page collects selected academic works - peer-reviewed journal articles that reference my publications, vulnerability disclosures, or tools. Coverage spans from 2003 to 2025.

I am not a formal academic researcher and have rarely have been paid to do this work - it comes from personal interest and independent research pursued mostly alongside my professional roles. Inclusion is based on explicit citation or reference to my work or its derivatives.

Sections


Notable Citations

The 2025 USENIX Security Distinguished Paper My ZIP isn't your ZIP (Tsinghua University / Zhongguancun Laboratory) extends my anti-virus parser attack and bypass research - originally The Death of AV Defense in Depth? with Sergio Alvarez at CanSecWest - into modern semantic-gap attacks on ZIP implementations.

The same line of work is picked up at IEEE Symposium on Security and Privacy 2012 in Abusing File Processing in Malware Detectors for Fun and Profit (Oberheide / Cooke / Jahanian, University of Michigan). Separately, my 2009 TLS renegotiation disclosure (CVE-2009-3555) is analyzed directly at ACM CCS 2013 in On the Security of TLS Renegotiation (Giesen / Kohlar / Stebila, Queensland University of Technology).

The Reaves / Blue / Traynor research arc at the University of Florida cites my TLS/SSL work across a decade - AuthLoop at USENIX Security 2016, the 2017 doctoral dissertation, and a 2022 US patent for practical end-to-end cryptographic authentication over voice channels.

Doctoral dissertations at Ruhr-Universität Bochum (Bergsma, TLS protocol modeling) and Johns Hopkins University (Martin, medical device security) reference my research.

My TLS renegotiation whitepaper (CVE-2009-3555) was picked up in coordinated advisories from US-CERT, DFN-CERT, BELNET-CERT and SWITCH-CERT.

21 universities across four continents in total; full cross-index of theses at the bottom.


Data Privacy & Regulation

My work on data privacy has spanned academic publication, regulatory litigation, and direct engagement with supervisory authorities. This includes contributions on the extraterritorial enforcement of GDPR - notably the documented dialogue and complaints filed with Luxembourg's CNPD against Rocketreach, Apollo and similar US-based data brokers operating without an EU Article 27 representative - which has been referenced in subsequent legal scholarship and case law commentary on extraterritorial GDPR enforcement.

2024 · Challenges to the Extraterritorial Enforcement of Data Privacy Law - EU Case Study

M. Czerniawski, D. Svantesson - in Dataskyddet 50 år: Historia, aktuella problem och framtid (Data Protection 50 Years: History, Current Problems and Future), Centre for Professional Legal Education, Faculty of Law - ISBN 978-91-89840-02-7

DOI ↗ Repository ↗

2022 · Contribution to the Public Consultation on the EDPB Guidelines 05/2021 on the Interplay between Article 3 and Chapter V GDPR International Transfers

Amsterdam Law School Research Paper No. 2022-59

SSRN ↗


Threat Modeling & Risk

The "Attacker Pyramid" / Attacker Classification model first published on this blog and developed further in The Rise of the Vulnerability Markets - History, Impacts, Mitigations (OWASP BENELUX 2011) has been referenced in academic work on cyber threat modeling, malware evolution, and the economics of vulnerability markets.

2022 · In Defense of Offense: Information Security Research under the Right to Science

Ot van Daalen - University of Amsterdam, Institute for Information Law (IViR) - Computer Law & Security Review, Vol. 46, Article 105706 - cites The Rise of Vulnerability Markets - History, Impacts, Mitigations (OWASP BeNeLux 2011) in footnote 8

DOI ↗

2013 · Perspectives in Cyber Security: The Future of Cyber Malware

Sandeep Mittal - Indian Journal of Criminology, Vol. 41 (1) & (2)

SSRN ↗


Bluetooth & Wireless Security

Bluetooth research starting in 2006 - including BTCrack (the world's first public Bluetooth PIN and Link-key brute-force tool, co-authored with Eric Sesterhenn; FPGA implementation with David Hulton in 2007; included in BackTrack since 2008), the live demo of a remote root shell over Bluetooth on macOS 10.3.9 / 10.4, custom long-range YAGI antenna work, and the All Your Bluetooth Is Belong To Us (Hack.lu 2006) and 23C3 Bluetooth Hacking Revisited presentations - has been referenced in 30+ peer-reviewed journal articles, IEEE/ACM conference proceedings, and dissertations from 2007 to 2024.

2024 · Low-power Bluetooth/RFID Devices to Track Inventory in the Supply Chain

Asian Journal of Multidisciplinary Research & Review, Vol. 5, Issue 1

thelawbrigade.com ↗

2022 · Optical Wireless Communications High-Speed Bluetooth Secure Pairing Towards Developing a Trust Protocol

Mantie N. Reid - PhD Thesis, Pace University

ProQuest ↗

2021 · A Systematic Review of Bluetooth Security Threats, Attacks & Analysis

International Journal of Computer Trends and Technology (IJCTT), vol. 69, no. 7

DOI ↗

2021 · Addressing the Security and Efficiency Challenges in Internet of Things

Xinyu Lei - PhD Dissertation, Michigan State University (Department of Computer Science and Engineering) - ProQuest 28648813

ProQuest ↗

2021 · Bluetooth Device Security

University of Zagreb

unizg.hr ↗

2020 · SecWIR: Securing Smart Home IoT Communications via Wi-Fi Routers with Embedded Intelligence

MobiSys '20 - Reference 60

DOI ↗

2020 · Detecting Bluetooth Attacks Against Smartphones by Device Status Recognition

ICAIS 2020

DOI ↗

2019 · Analysis on Bluetooth Security

International Journal of Research in Engineering, Science and Management

PDF ↗

2019 · Wi-Fi Channel Saturation as a Mechanism to Improve Passive Capture of Bluetooth Through Channel Usage Restriction

Journal of Network Technology

arXiv ↗

2018 · Bluetooth Intrusion Detection System (BIDS)

P. Satam, S. Satam, S. Hariri - AICCSA 2018

DOI ↗

2018 · Seguretat en Bluetooth: Anàlisi de Vulnerabilitats

Universitat Oberta de Catalunya

Repository ↗

2017 · Penetration Testing and Testing to Diagnose and Detect Vulnerabilities in Wireless Data Networks

E. Katsadouros

puas.gr ↗

2016 · A Strenuous Macroanalysis on the Substratals of Securing Bluetooth Mobile Workforce Devices

Indian Journal of Science and Technology, Vol. 9(48)

DOI ↗

2016 · Data Security in Telehealth and Smart Home Environment

University of Eastern Finland - Master Thesis

PDF ↗

2015 · A Review on Bluetooth Security Vulnerabilities and a Proposed Prototype Model for Enhancing Security against MITM Attack

IJRSCSE

PDF ↗

2015 · Bluetooth Security and Threats

Norwegian Defence Research Establishment (FFI)

knowledgearc.net ↗

2015 · Enhancement of Bluetooth Security Authentication Using HMAC

Diallo Alhassane Saliou - Master Thesis, International Islamic University Malaysia

ResearchGate ↗

2014 · Exploiting Bluetooth 4.0 for Secure, Cloud-Enabled Monitoring of Palliative Care Patients

Will Browne - Master Dissertation, Trinity College Dublin

PDF ↗

2013 · Ubertooth - Bluetooth Monitoring und Injection

Martin Herrmann - Technische Universität München

DOI ↗ Repository ↗

2012 · Bluetooth Security Threats and Solutions: A Survey

International Journal of Distributed and Parallel Systems (IJDPS) - Citation Page 137

DOI ↗

2012 · Analysis of Bluetooth Threats and v4.0 Security Features

S. Sandhya, K. S. Devi - ICCCA 2012

DOI ↗ Semantic Scholar ↗

2012 · Analysis and Mitigation of Vulnerabilities in Short-Range Wireless Communications for Industrial Control Systems

B. Reaves, T. Morris - International Journal of Critical Infrastructure Protection, Vol. 5, Issues 3-4

DOI ↗

2012 · Theoretical Analysis of Security Features and Weaknesses of Telecommunication Specifications for Smart Metering

Universitat Politècnica de Catalunya - Master Thesis

Repository ↗

2012 · Bluetooth Security Analysis for Mobile Phones

João Alfaiate - CISTI 2012

IEEE ↗

2011 · BlueSnarf Revisited: OBEX FTP Service Directory Traversal

A. Moreno, E. Okamoto - NETWORKING 2011 Workshops

DOI ↗

2011 · A Secured Bluetooth Based Social Network

N. B.-N. I. Minar, M. Tarique - International Journal of Computer Applications

DOI ↗

2011 · Security in Bluetooth, RFID and Wireless Sensor Networks

ICCCS '11

DOI ↗

2010 · Battery-Sensing Intrusion Protection System Validation Using Enhanced Wi-Fi and Bluetooth Attack Correlation

2009 IEEE 70th Vehicular Technology Conference Fall

IEEE ↗

2010 · Bluetooth Sniffing and the PS3

Luke Vincent - College of Engineering and Computer Science

Repository ↗

2010 · Effects of Wi-Fi and Bluetooth Battery Exhaustion Attacks on Mobile Devices

2010 · Taming the Blue Beast: A Survey of Bluetooth Based Threats

John Paul Dunning - IEEE Security & Privacy, Vol. 8, Issue 2, pp. 20-27

DOI ↗

2009 · Secure Physical Layer using Dynamic Permutations in Cognitive OFDMA Systems

VTC Spring 2009 - IEEE 69th Vehicular Technology Conference

DOI ↗

2009 · Security Issues in Pervasive Computing

L. A. Mohammed, K. Munir - Risk Assessment and Management

DOI ↗

2009 · Wireless Network Deployment

Vesa Niittylä - Opinnäytetyö (Bachelor's Thesis), Lahden ammattikorkeakoulu (Lahti University of Applied Sciences)

theseus.fi ↗

2008 · Towards Pervasive Computing Security

Proceedings of the World Congress on Engineering 2008, Vol. I

PDF ↗

2008 · Breaking into Bluetooth

Ken Munro - Network Security, Vol. 2008, Issue 6

https://doi.org/10.1016/S1353-4858(08)70074-670074-6)

2007 · Studying Bluetooth Malware Propagation: The BlueBag Project

L. Carettoni, C. Merloni, S. Zanero - IEEE Security & Privacy

DOI ↗

2007 · Bluetooth Security & Hacks

Andreas Becker - RUB Seminararbeit

Repository ↗

2007 · Keystroke Logging of a Wireless Keyboard

W. Ma, A. Mbugua, D. Poon - University of British Columbia, CPEN 442 Term Project - Reference 3

PDF ↗


TLS Attacks & Vulnerability Analysis

Following the 2009 disclosure of the TLS renegotiation vulnerability (CVE-2009-3555), the SSL/TLS Compatibility and Hardening Report 2010/2011 (G-SEC), the SSL Audit tool (the first SSL/TLS scanner with a behavioral fingerprinting engine for SChannel, OpenSSL, NSS, Certicom and RSA BSAFE stacks), and the Harden SSL/TLS tool for Windows SCHANNEL hardening, this work has been cited across journal articles, PhD dissertations, and conference proceedings on protocol security, padding oracle attacks, and TLS hardening - including at ACM CCS.

2015 · Evaluation of TFTP DDoS Amplification Attack

The Cyber Academy, Edinburgh Napier University

DOI ↗

2014 · Modeling and Analyzing Cryptographic Real World Protocols

Florian Bergsma - PhD Thesis, Ruhr-Universität Bochum

d-nb.info ↗

2013 · On the Security of TLS Renegotiation

F. Giesen, F. Kohlar, D. Stebila - Queensland University - ACM CCS '13

DOI ↗

2013 · Classifying Network Protocol Implementation Versions: An OpenSSL Case Study

P. D. Martin, M. Rushanan, A. D. Rubin, M. Green, S. Checkoway - Johns Hopkins University

Repository ↗

2012 · Attacks on Re-keying and Renegotiation in Key Exchange Protocols

Rati Gelashvili - Bachelor Thesis, ETH Zürich

2012 · Analysis of the Functionality, Risks and Counter-Measures of Current Padding Attacks and the Implementation of an Attack in the Open-Source Program CrypTool 2

Alexander Colin Jüttner - Bachelor Thesis, Frankfurt School of Finance and Management

PDF ↗

2011 · MITM Attacks on SSL/TLS Related to Renegotiation

Thor Siiger Prentow - Technical University of Denmark

TLS Deployment & Hardening

2018 · TLS Sicherheit: Konzept zum Manipulationsschutz eines Zertifikatsspeichers

Alpen-Adria-Universität Klagenfurt - Master Thesis - Citation Zoll11

aau.at ↗

2017 · Metodología de Hacking Ético para Instituciones Financieras

Universidad de Cuenca - Master Thesis

Repository ↗

2017 · Проблеми використання SSL/TLS (Problems of Using SSL/TLS)

T. Babenko, S. Toliupa, V. Grechko - National Aviation University (Ukraine) - Захист інформації (Information Security), Vol. 19, No. 4, pp. 298-302

nbuv.gov.ua ↗

2016 · A Comprehensive Survey on SSL/TLS and their Vulnerabilities

International Journal of Computer Applications

ResearchGate ↗

2016 · Avoidable SSLStrip Attack with HSTS Countermeasures

Kanagawa University - Computer Security Symposium 2016

PDF ↗

2015 · A Segurança das Comunicações dos Sítios Web Disponibilizados pelo Estado Português

rcaap.pt ↗

2014 · Visualization of SSL Setting Status Such as the FQDN Mismatch

IMIS 2014

DOI ↗

2013 · Safe Configuration of TLS Connections - Beyond Default Settings

J. Hötz, T. Holz - 6th Symposium on Security Analytics and Automation

DOI ↗

2013 · Ataques a las comunicaciones sin hilos y sus principales métodos de mitigación

Laura Rasal Blasco - Master Thesis, UOC

Repository ↗

2013 · SSL/TLS Status Survey in Asia Region - Transitioning Against the Renegotiation Vulnerability, CRIME Attacks and Untrusted X.509 Certificates

Yuji Suga - Internet Initiative Japan Inc. - Internet Technologies & Society (ITS) 2013 - Reference 8

ResearchGate ↗

2012 · SSL/TLS: État des lieux et recommandations

Olivier Levillain - ANSSI (Agence nationale de la sécurité des systèmes d'information) - SSTIC 2012, Symposium sur la sécurité des technologies de l'information et des communications, Rennes, France

PDF ↗ hal.science ↗

2012 · SSL/TLS Status Survey in Japan - Transitioning Against the Renegotiation Vulnerability and Short RSA Key Length Problem

IEEE Asia JCIS

DOI ↗

2012 · Countermeasures and Tactics for Transitioning Against the SSL/TLS Renegotiation Vulnerability

IEEE IMIS 2012

DOI ↗

2010 · Cybersecurity Myths on Power Control Systems: 21 Misconceptions and False Beliefs

IEEE Transactions on Power Delivery, Vol. 26, Issue 1

DOI ↗

2010 · Problems on the Shifts to a New Specification with Countermeasures of the SSL/TLS Renegotiation Vulnerability

Yuji Suga

nii.ac.jp ↗


TLS in Applications & Constrained Environments

2024 · A Cost-Effective Zero-Trust Approach for Cloud Computing: Experimental Evaluation on AWS Platform

Aref Mowloughi - Master's Thesis, University of Turku (Cyber Security, Master's Degree Programme in Information and Communication Technology)

utupub.fi ↗

2022 · Network Security Protocol Performance Analysis in IoT Environment

Dong-hee Kang, Jae-Deok Lim - Electronics and Telecommunications Research Institute (ETRI) - Journal of the Korea Institute of Information Security & Cryptology, Vol. 32, No. 5, pp. 955-963

DOI ↗ kyobobook.co.kr ↗

2021 · Assessing Non-Intrusive Vulnerability Scanning Methodologies for Detecting Web Application Vulnerabilities on Large Scale

Shaji E, Subramanian N - 2021 International Conference on System, Computation, Automation and Networking (ICSCAN) - Reference 23

DOI ↗

2017 · Authentication Techniques for Heterogeneous Telephone Networks

Bradley Galloway Reaves - PhD Dissertation, University of Florida - Reference 134

Repository ↗

2016 · AuthLoop: End-to-end Cryptographic Authentication for Telephony over Voice Channels

B. Reaves, L. Blue, P. Traynor - 25th USENIX Security Symposium

USENIX ↗

2016 · Securing Medical Devices and Protecting Patient Privacy in the Technological Age of Healthcare

Paul D. Martin - PhD Thesis, The Johns Hopkins University

Repository ↗

2015 · Optimizing TLS for Low Bandwidth Environments

FPS 2014: Foundations and Practice of Security

DOI ↗

2014 · SRAP: A New Authentication Protocol for Semantic Web Applications

Marcio Ricardo Rosemberg - Dissertação de Mestrado (Master's Thesis), PUC-Rio (Pontifícia Universidade Católica do Rio de Janeiro) - Advisor: Daniel Schwabe - Reference 41

ibict.br ↗

2013 · Cyber-security Defense in Large-scale M2M System: Actual Issues and Proposed Solutions

Technische Universität Berlin - SAM 2013

PDF ↗

2011 · TLS and Energy Consumption on a Mobile Device: A Measurement Study

J. Schwenk, N. Gruschka - ISCC 2011

DOI ↗

2010 · Energy Consumption of Cryptographic Algorithms and Security Protocols on Symbian Mobile Devices

Pedro Miranda Arto - Proyecto Fin de Carrera (Ingeniero en Informática), Universidad de Zaragoza, Centro Politécnico Superior - Directors: Matti Siekkinen, Heikki Waris

unizar.es ↗


Surveillance

Cited for the Sniff'em network packet analyzer, which appears in the University of Pennsylvania eavesdropping research programme (Cronin, Sherr & Blaze) and in legal-ethics and internet-architecture scholarship as an example of accessible packet-capture tooling.

2010 · Notes on Theoretical Limitations and Practical Vulnerabilities of Internet Surveillance Capture

Eric C. Cronin, Matthew A. Blaze - University of Pennsylvania (10 September 2010) - dissertation-in-progress technical report continuing the Cronin/Sherr/Blaze eavesdropping research programme with a survey of Internet capture practice and theoretical vulnerabilities

Repository ↗

2006 · The Eavesdropper's Dilemma

Eric Cronin, Micah Sherr, Matthew A. Blaze - University of Pennsylvania Department of Computer and Information Science - Technical Report No. MS-CIS-05-24 (3 February 2006) - foundational paper of the Cronin/Sherr/Blaze eavesdropping research programme introducing the notion of fidelity in digital eavesdropping

Repository ↗

2006 · On the Reliability of Network Eavesdropping Tools

E. Cronin, M. Sherr, M. Blaze - University of Pennsylvania - IFIP International Conference on Digital Forensics (IFIP WG 11.9), Orlando FL, spring 2006 - published in Advances in Digital Forensics II (IFIP AICT vol. 222, Springer) - references Sniff'em

DOI ↗

2005 · Porting and Performance Aspects from IPv4 to IPv6: The Case of OpenH323

C. Bouras, A. Gkamas, D. Primpas - International Journal of Communication Systems - cites Sniff'em (Reference 32)

DOI ↗

2004 · The Layers Principle: Internet Architecture and the Law

Lawrence B. Solum, Minn Chung - Notre Dame Law Review, Vol. 79 (2004) - originally University of San Diego School of Law, Public Law and Legal Theory Research Paper No. 55 (June 2003) - cites Sniff'em (Reference 81)

Academia ↗

2004 · Performance Evaluation of an IPv6-capable H323 Application

C. Bouras, A. Gkamas, D. Primpas, K. Stamos - IEEE AINA 2004 - cites Sniff'em (Reference 7)

DOI ↗

2003 · Redefining Privacy and Security in the Electronic Communication Age: A Lawyer's Ethical Duty in the Virtual World of the Internet

R. Scot Hopkins, Pamela R. Reynolds - The Georgetown Journal of Legal Ethics, Vol. 16, No. 4, pp. 675-692 (Summer 2003)

ProQuest ↗


Anti-Virus Security & Malware

Joint research with Sergio Alvarez on anti-virus parsing engine vulnerabilities - presented as The Death of AV Defense in Depth? (CanSecWest) and resulting in remote code execution, denial-of-service, and detection bypass findings across major AV vendors - together with work on malware auto-update man-in-the-middle attacks and fuzzing methodology, has been referenced in peer-reviewed venues including IEEE Symposium on Security and Privacy, ACM Asia CCS, ESORICS, and multiple PhD theses.

AV Parser Attack Surface

Direct heirs of Death of AV Defense in Depth? - papers analyzing AV parser vulnerabilities (PE headers, ZIP files, decoder ambiguity) as attacker-controlled input processing.

2025 · My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers

Yufan You, Jianjun Chen, Qi Wang, Haixin Duan - Tsinghua University & Zhongguancun Laboratory - 34th USENIX Security Symposium (USENIX Security '25) - Distinguished Paper Award

USENIX ↗

2017 · Malware Detection Based on Multiple PE Headers Identification and Optimization for Specific Types of Files

Ton Duc Thang University

DOI ↗ jaec.vn ↗

2015 · Error-Correcting Codes as Source for Decoding Ambiguity

N. Šrndić, P. Laskov - 2015 IEEE Security and Privacy Workshops

DOI ↗

2012 · PE-Header-Based Malware Study and Detection

University of Georgia

Repository ↗

2012 · Abusing File Processing in Malware Detectors for Fun and Profit

J. Oberheide, E. Cooke, F. Jahanian - 2012 IEEE Symposium on Security and Privacy

DOI ↗

AV Bypass & Evasion

Work on defeating AV detection, signature-based evasion, and self-protection subversion.

2017 · Automatically Inferring Malware Signatures for Anti-Virus Assisted Attack

ASIA CCS '17

DOI ↗

2016 · From Malware Signatures to Anti-Virus Assisted Attacks

Technische Universität Braunschweig

arXiv ↗

2016 · A Novel Malware for Subversion of Self-Protection in Anti-Virus

Y. Luo, B. Min, V. Varadharajan, S. Nepal - Software: Practice and Experience

DOI ↗

2015 · Design, Implementation and Evaluation of a Novel Anti-Virus Parasitic Malware

Y. Luo, B. Min, V. Varadharajan, S. Nepal - SAC '15

DOI ↗

AV Update Security

Direct heirs of my 2007 auto-update MITM work - papers analyzing the security of AV upgrade channels.

2015 · A Security Analysis Method of Antivirus Software Upgrade Process

Journal of Wuhan University (Science Edition)

com.cn ↗

2014 · Antivirus Security: Naked During Updates

Byungho Min, Vijay Varadharajan, Udaya Tupakula, Michael Hitchens - Macquarie University, Sydney - Software: Practice and Experience, Vol. 44, Issue 10, pp. 1201-1222

DOI ↗

2007 · Man-in-the-Middle Attacks on Auto-updating Software

B. M. Luettmann, A. C. Bender - Bell Labs Technical Journal, Vol. 12, Issue 3, pp. 131-138

DOI ↗

Malware Research

Adjacent research on malware architecture (feature-distributed, IoT) and defense mechanisms (honeyclients, information-flow control) citing my work as context.

2018 · Study of Security Attacks against IoT Infrastructures

The University of Newcastle - ACSRC

Repository ↗

2015 · Design and Evaluation of Feature Distributed Malware Attacks against the Internet of Things (IoT)

B. Min, V. Varadharajan - ICECCS 2015

DOI ↗

2014 · Feature-Distributed Malware Attack: Risk and Defence

B. Min, V. Varadharajan - ESORICS 2014

DOI ↗

2014 · Design and Analysis of a New Feature-Distributed Malware

B. Min, V. Varadharajan - IEEE TrustCom 2014

DOI ↗

2011 · Making Information Flow Explicit in HiStar

N. Zeldovich, S. Boyd-Wickizer, E. Kohler, D. Mazières - Communications of the ACM, Vol. 54, Issue 11

DOI ↗

2009 · Client-side Threats and a Honeyclient-based Defense Mechanism, Honeyscout

Christian Clementson - Master Thesis, Linköping University

diva-portal.org ↗

2009 · Schwachstellen in Sicherheitssoftware und deren Auswirkungen

Robert Kossatz - Diplomarbeit (Diploma Thesis), Hochschule für Technik und Wirtschaft Dresden (Fakultät Elektrotechnik)

fraunhofer.de ↗


Vulnerability Research

Cited for CSS-DIE, the CSS fuzzer I co-authored with HD Moore, Matt Murphy and Aviv Raff during the 2006 "Month of Browser Bugs" effort, and for fuzzing methodology work descending from the anti-virus parser research - both of which appear in academic surveys of fuzzing tools and feedback-driven techniques as real-world case studies.

2017 · A Review of Fuzzing Tools and Methods

James Fell - cites CSS-DIE alongside Mangleme and Hamachi as foundational browser fuzzers of the Month-of-Browser-Bugs era

PDF ↗

2014 · Fuzzing Analysis: Evaluation of Properties for Developing a Feedback-Driven Fuzzer Tool

Kris Gundersen - Master Thesis

PDF ↗

2013 · Using Redundancy to Improve Security and Testing

Hui Xue - University of Illinois at Urbana-Champaign

ProQuest ↗

2007 · Fuzzing: Brute Force Vulnerability Discovery

M. Sutton, A. Greene, P. Amini - Addison-Wesley Professional - ISBN 978-0-321-44611-4 - cites CSS-DIE in the Web Browser Fuzzing chapters as one of the major browser fuzzers of the period

oreilly.com ↗


Cashback & Online Payment Vulnerabilities

Research into systemic privacy and integrity flaws in cashback and online payment platforms, originally presented at OWASP, exposed weaknesses in widely-used commercial systems.

2011 · Exposing the Lack of Privacy in File Hosting Services

KU Leuven, Belgium - LEET '11

libis.be ↗


Patents

The Traynor/Reaves/Blue team at the University of Florida - whose AuthLoop paper and Reaves' PhD dissertation are already indexed in this list - was granted a US patent on end-to-end cryptographic authentication for telephony over voice channels, building on the same research line that references my TLS/SSL work.

US11329831B2 - Practical end-to-end cryptographic authentication for telephony over voice channels

Patrick G. Traynor, Bradley G. Reaves, Logan E. Blue - University of Florida Research Foundation - filed 2017, granted 2022

Google Patents ↗


Cited in Theses & Dissertations

A cross-index of the doctoral, Master's, and Bachelor's theses collected above, showing academic reach across 21 universities on 4 continents (Europe, North America, South America, Asia). Each thesis appears in full within its topical section; this list gives a degree-level view.

PhD Dissertations (5)

Master's Theses (11)

  • 2024 - Aref Mowloughi, University of Turku - A Cost-Effective Zero-Trust Approach for Cloud Computing on AWS TLS in Applications & Constrained Environments
  • 2018 - Alpen-Adria-Universität Klagenfurt - TLS Sicherheit: Konzept zum Manipulationsschutz eines Zertifikatsspeichers TLS Deployment & Hardening
  • 2017 - Universidad de Cuenca - Metodología de Hacking Ético para Instituciones Financieras TLS Deployment & Hardening
  • 2016 - University of Eastern Finland - Data Security in Telehealth and Smart Home Environment Bluetooth & Wireless Security
  • 2015 - Diallo Alhassane Saliou, International Islamic University Malaysia - Enhancement of Bluetooth Security Authentication Using HMAC Bluetooth & Wireless Security
  • 2014 - Will Browne, Trinity College Dublin - Exploiting Bluetooth 4.0 for Secure, Cloud-Enabled Monitoring of Palliative Care Patients Bluetooth & Wireless Security
  • 2014 - Kris Gundersen, University of Oslo - Fuzzing Analysis: Evaluation of Properties for Developing a Feedback-Driven Fuzzer Tool Vulnerability Research
  • 2014 - Marcio Ricardo Rosemberg, PUC-Rio (Pontifícia Universidade Católica do Rio de Janeiro) - SRAP: A New Authentication Protocol for Semantic Web Applications TLS in Applications & Constrained Environments
  • 2013 - Laura Rasal Blasco, Universitat Oberta de Catalunya (UOC) - Ataques a las comunicaciones sin hilos y sus principales métodos de mitigación TLS Deployment & Hardening
  • 2012 - Universitat Politècnica de Catalunya - Theoretical Analysis of Security Features and Weaknesses of Telecommunication Specifications for Smart Metering Bluetooth & Wireless Security
  • 2009 - Christian Clementson, Linköping University - Client-side Threats and a Honeyclient-based Defense Mechanism, Honeyscout Anti-Virus Security & Malware

Bachelor's & Diploma Theses (5)