← Research

Network & systems security

Our security research descends from BloSS, a blockchain-coordinated defence against distributed denial-of-service attacks, and from the problem at its heart: how do independent, mutually-distrusting parties turn their noisy, partial views of an attack into a reliable collective decision, with no central authority to trust? We study defence, attack, and honest evaluation as one system under stress, where both the adversary and the operating conditions keep changing.

Defending real networks means coordinating across domains that each see only a fragment of an incident, and admitting, authorising, and revoking participants without a central gatekeeper. We build the trust primitives that make this possible, decentralised identity and governance for cross-domain data sharing, and cooperative, signalling-based mitigation, and we ask when a federation of equals can match, or provably cannot match, what a central authority would achieve.

Defences are only as strong as their weakest configuration. We show this directly: a reinforcement-learning agent learns, online, to slip a command-and-control channel past an intrusion detector, and whether it succeeds is decided by the quality of the defender’s rules, not their mere presence, so robustness has to be designed in, not assumed. And because the very infrastructure that underwrites trust can fail, we build communication that stays resilient and verifiable when the network is gone: an off-grid civilian mesh with identity built in, usable by people with no technical training.

Security decisions are, in the end, economic ones. We also make the cost and value of protection explicit, so that spending on defence can be justified rather than guessed. The SEConomy framework does this step by step, mapping actors, systems, risks, and the cost attributes that connect them, and turning cybersecurity from a vague expense into a measurable economic impact.

Selected publications

All publications →