Case file EOSection: Scholarly workRef. EO-RESBack to the case file
Research
Papers on AI security, threat modeling and risk governance, from a D.Eng. candidate in Cybersecurity Analytics at The George Washington University.
Research areas
In plain English: the questions my doctoral research is trying to answer.
Doctoral praxis research at The George Washington University began in fall 2026; the D.Eng. is expected in September 2027.
Selected papers
In plain English: papers I have written. Most are posted on SSRN, which makes them public but not peer reviewed.
-
When Successful Checks Outlive Their Evidence: A Reproducible Case Study of Remediation Approval in Microservices
Independent research on incomplete and stale evidence in recovery decisions, using 50 action trials across five successive development stages. Includes raw synthetic data, excluded attempts, reproducible Python analyses, and Overleaf source. Available lifecycle events and late functional rechecking tied in the final eight-trial comparison. This bounded case study does not establish event-method superiority or production safety. Not peer reviewed; manuscript PDF build remains unverified.
-
BootKitty: A Critical Analysis of Modern Bootkit-Rootkit Threats and Defense Limitations in Contemporary Cybersecurity Infrastructure
Analysis of firmware-level persistence threats and the limitations of contemporary defenses against modern bootkit attacks.
-
Aligning Threat Actor TTPs to the Cyber Kill Chain: Anticipating Future Cyber Threats with the MITRE ATT&CK Framework
Structured threat modeling aligning adversary tactics to kill chain stages using MITRE ATT&CK for predictive defense planning.
-
Government Efficiency vs. Cybersecurity: A CIA Triad Analysis of the DOGE Social Security Data Incident
CIA triad framework applied to the SSA data incident, examining the tension between operational efficiency and security posture in public-sector environments.
-
The Thin Line Between Strategic Risk Acceptance and Negligence: A Critical Analysis of Cybersecurity Risk Management Failures
Examination of the boundary between informed risk acceptance and negligence in enterprise cybersecurity risk management and governance.
-
Analyzing Assessment Output in Infrastructure Systems: Reflections on the Cisco ASA Zero-Day Case
Lessons drawn from the Cisco ASA zero-day, focusing on assessment output analysis in critical infrastructure security contexts.
-
Evidence-Bounded Vulnerability Intelligence for OT/IoT Networks
The write-up of Breakwater, an end-to-end security-analytics pipeline built in GWU doctoral coursework against a containerized OT/IoT simulation network.
More preprints on SSRN
In plain English: the rest of my posted papers, listed for completeness.
Other titles listed on ORCID, 2024 to 2026, shown as ORCID lists them (some shortened). SSRN is a preprint repository, not a peer-reviewed journal.
- 2026Adversarial Machine Learning on Automotive Attack Surfaces
- 2026Governance Models and Hard Forks in Decentralized Blockchains
- 2026Risk Acceptance in Critical Infrastructure Cyber Incidents
- 2026Zero Trust Architecture in Practice: Security Fatigue
- 2025Risk Management in Cybersecurity Architecture: Addressing AI
- 2025Identity-Centric Zero Trust Architecture: A Comprehensive Framework for Modern Enterprise Security Governance
- 2025When there is no Plan: Comprehensive Incident Response
- 2025Beyond Personal Data: Redefining Privacy in the Era of IoT
- 2025Beyond the Firewall: Nation-State Information Operations
- 2025Compensating Controls and Architecting for Cyber Resilience
- 2025Global Navigation Satellite Systems: Emerging Vulnerabilities
- 2025Software Assurance Beyond Secure Coding: Lessons from 2024
- 2025Third-Party SaaS Integration Security: Lessons from Supply Chain
- 2025Threat Modeling Nation-State Attacks on Defense Contractors
- 2024Cryptographic Protocols for Electronic Voting Systems
- 2024Ransomware and Social Engineering: Critical Examination