Network & systems security



Our security research descends from BloSS, a blockchain-coordinated defence against distributed denial-of-service attacks, and from the problem at its heart: how do independent, mutually-distrusting parties turn their noisy, partial views of an attack into a reliable collective decision, with no central authority to trust? We study defence, attack, and honest evaluation as one system under stress, where both the adversary and the operating conditions keep changing.
Defending real networks means coordinating across domains that each see only a fragment of an incident, and admitting, authorising, and revoking participants without a central gatekeeper. We build the trust primitives that make this possible, decentralised identity and governance for cross-domain data sharing, and cooperative, signalling-based mitigation, and we ask when a federation of equals can match, or provably cannot match, what a central authority would achieve.
Defences are only as strong as their weakest configuration. We show this directly: a reinforcement-learning agent learns, online, to slip a command-and-control channel past an intrusion detector, and whether it succeeds is decided by the quality of the defender’s rules, not their mere presence, so robustness has to be designed in, not assumed. And because the very infrastructure that underwrites trust can fail, we build communication that stays resilient and verifiable when the network is gone: an off-grid civilian mesh with identity built in, usable by people with no technical training.
Security decisions are, in the end, economic ones. We also make the cost and value of protection explicit, so that spending on defence can be justified rather than guessed. The SEConomy framework does this step by step, mapping actors, systems, risks, and the cost attributes that connect them, and turning cybersecurity from a vague expense into a measurable economic impact.
Selected publications
- Distributed Pulse-Wave Simulator for DDoS Dataset Generation 2026
- Moving Target Offense: RL-based Adaptive Evasion Strategies for C2 Frameworks 2025
- Towards Federated Governance and Decentralized Identities for Participatory Sensing Data Mesh 2025
- Bridging Technical Capability and User Accessibility: Off-grid Civilian Emergency Communication 2025