Cybersecurity, Cryptography & Network Security

I have substantial experience with cybersecurity, applied cryptography, network security, authentication systems, and privacy-preserving technologies. My work includes designing and implementing security mechanisms, analyzing software and hardware implementations, identifying and demonstrating vulnerabilities, and evaluating the effectiveness of security controls. I teach computer and network security and applied cryptography as a Lecturer in the Department of Computer Science at Johns Hopkins University. Earlier in my academic career, I also served as a course assistant for Practical Cryptographic Systems.

My research has included the design of cryptographic authentication systems. My co-authors and I designed a wearable authentication device that received a Kerberos credential from a computer terminal and transferred that credential to other terminals through low-energy electrical signals transmitted over the wearer’s skin. The device was designed to lose its cryptographic secret when removed from the wearer. This work, published at Financial Cryptography and Data Security, addressed credential handling, protection of secret material, and the practical use of authentication mechanisms in healthcare environments.

In another published project, my co-authors and I designed a secure indoor-location system using Bluetooth Low Energy beacons to support location-based authentication and access to patient records. The system used location as a secondary authentication mechanism and explored how healthcare providers could receive relevant patient information as they moved through a facility. My broader healthcare-security work includes designing cryptographic protocols implemented in production healthcare environments.

My privacy research has also addressed how to limit access to sensitive information and detect inappropriate use. I developed a Hadoop-based application for large-scale statistical analysis of electronic-medical-record audit logs as part of research integrating auditing with access control. I also developed a web application to generate reports and visualizations from the analysis. This work led to two U.S. patents concerning healthcare privacy-breach prevention. My doctoral dissertation, Securing Medical Devices and Protecting Patient Privacy in the Technological Age of Healthcare, examined the relationship between effective security controls and usable healthcare workflows.

At Independent Security Evaluators and Harbor Labs, I was engaged by companies to perform security assessments of their products both before and after market release. A substantial part of this work involved analyzing cryptographic security protections and determining whether they could be circumvented. I identified the cryptographic invariants and security policies that a product was intended to preserve, then designed and conducted tests to determine whether those properties could be violated. This work combined implementation analysis, reverse engineering, and experimental validation of identified weaknesses.

For example, at Independent Security Evaluators, I analyzed a digital-magazine distribution system used by a major Asian telecommunications provider and found multiple independent ways to bypass its digital-rights-management protections. This authorized assessment included analysis and testing of the system’s iOS and Android applications. My other cryptographic implementation work has included testing secret-splitting implementations, developing browser extensions for a cryptographic proxy system, and writing and debugging C++ and Python tests for proprietary disk-encryption software. My research publications additionally include a study of techniques for classifying network-protocol implementation versions using OpenSSL.

A significant portion of my expert-witness and consulting work has involved cryptographic technologies. I have analyzed elliptic-curve cryptography, random-number generation, hardware-accelerated cryptography, cryptographic processors and chips, secure cryptographic protocols, cryptocurrency-related systems, and cryptographic protections incorporated into medical devices. My work has included source-code review, analysis of implementations and protocols, technical analysis supporting claim construction, infringement and non-infringement analysis, validity analysis, preparation of expert reports, and deposition testimony.

My network-security experience includes both assessment and development. I performed a security assessment and wide-scale penetration test of virtualized cloud-based research systems implemented using Amazon EC2 and VMware infrastructure, including penetration testing of VMware ESXi. I developed a formal threat model addressing potential attack vectors and prepared reports documenting the testing. I also designed and implemented a real-time traffic visualization and analysis system for smart-grid networks. That system aggregated multiple traffic streams to help identify network conditions and unexpected behavior; the work was subsequently patented and incorporated into a commercial managed-security service.

In litigation and consulting engagements, I have analyzed malware-scanning gateways, endpoint-protection products, firewalls, intrusion-prevention techniques, vulnerability-assessment products, URL filtering, authentication technologies, and network-monitoring and management systems. My work has included building custom test infrastructure and conducting large-scale experiments to evaluate techniques intended to prevent exploitation of vulnerabilities. I have also analyzed wireless-network handoff and quality-of-service technologies, prepared expert reports, and testified at deposition and trial concerning networking systems. Other engagements have required malware analysis, cyber-attribution, and assessment of the reasonableness of organizational security measures.

I also served as the technical and development lead for Firmware IQ, a commercial platform that performed more than one hundred automated checks for vulnerabilities, security weaknesses, and indicators of compromise in firmware images. The platform supported examination of firmware updates before deployment and investigation of firmware extracted from potentially compromised devices. Its checks included identifying vulnerable software components, insecure configurations, hardcoded credentials, and cryptographic implementation problems such as weak key generation, improper use of initialization vectors, and deprecated ciphers.

My hands-on security work additionally includes developing an automated system capable of testing antivirus products against thousands of malware samples for Consumer Reports’ annual antivirus analysis, developing fuzz-testing tools, and identifying and demonstrating remote-code-execution vulnerabilities in medical devices. I design and operate segmented computing environments for security research and have developed and launched Technicomp Benchtop Linux, whose intended uses include security analysis and cryptography.

My work also extends to AI systems and their supporting software. I have evaluated the source code of at least ten Model Context Protocol (MCP) servers, and in 2026 I developed a module on large-language-model security for my teaching at Johns Hopkins University. My security courses require students to examine real codebases, identify potential vulnerabilities, and validate their findings by developing working exploits. I have also served on the program committee for the IEEE Symposium on Security and Privacy, reviewing research in areas including memory forensics, side-channel attacks, password vaults, differential privacy, and hardware security.


← Expert witness experience · Testimony record · Download CV (PDF)