Research Interest
My broader research interest lies in improving the security and resilience of emerging wireless and mobile systems under realistic deployment conditions. With this overarching goal, I study how attacks against modern communication systems can be detected, measured, and characterized using observations available to practical defenders. My work combines wireless protocol analysis, network measurement, intrusion detection, and security-oriented machine learning to understand both the capabilities and limitations of defense mechanisms in real-world environments.
One major direction of my research focuses on the security of modern Wi-Fi networks. In this area, I investigate rogue access points, evil twin attacks, forced disconnections, malicious network steering, and deceptive captive portals. My work explores endpoint-based detection mechanisms that combine wireless management events, network-path behavior, transport and application-layer metadata, and workflow-aware state tracking. Rather than relying on a single anomaly, these systems identify coordinated attack sequences and multiple forms of supporting evidence. This research aims to develop practical detection techniques that remain effective across different devices, network environments, and deployment constraints.
In addition, I investigate the security of 5G systems, particularly pre-authentication attacks that manipulate downlink communication while a user device remains connected to a legitimate base station. My work examines whether such attacks can be detected by a passive monitor and under what conditions their artifacts are observable, ambiguous, or indistinguishable from benign network failures. By systematically studying these detectability boundaries, I aim to clarify which defenses are technically feasible and where fundamental visibility limitations remain.
Across these efforts, my research seeks to bridge protocol-level security analysis with deployable detection and measurement systems. The broader goal is to provide a clearer understanding of emerging wireless threats and to support the design of communication systems that are more secure, measurable, and robust against evolving attacks.
