Selected Work
I've designed and deployed end-to-end detection and response systems within Security Operations Center (SOC) environments, integrating tools such as SIEM, IDS/IPS, and SOAR to simulate and counter real-world attack scenarios aligned with the MITRE ATT&CK framework.
HIPAA-aware SOC simulation with segmented VLANs (Medical, Admin, DMZ), 17 custom detection rules, and 8 MITRE ATT&CK scenarios — including ransomware simulation and DICOM data exfiltration. SOAR playbooks trigger automated responses upon breach detection.
ML pipeline for automotive CAN bus intrusion detection. Architecture combines Rule Sentinel + LightGBM + TCN Autoencoder with SHAP explainability. Achieved F1 = 99.5% in-domain; cross-domain AUC improved from 0.54 to 0.93 via MMD fine-tuning.
XGBoost integrated with Suricata IDS to classify network alerts using the UNSW-NB15 dataset. Achieved high-accuracy threat detection with significantly reduced false positives compared to baseline rule-only detection.
Real-time counterfeit product detection system. Manufacturers generate SHA-256 QR codes stored on-chain; end users scan to instantly verify product authenticity, preventing tampered or fraudulent goods from reaching consumers.
AI-powered voice assistant that answers health queries in local languages with spoken responses. Designed for low-literacy and rural users, covering hygiene, nutrition, maternal health, and common diseases.