Supply Chain Security

Software Supply Chain Security

Problem statement

Modern software is assembled through interconnected ecosystems, automation platforms, and third-party artifacts. This creates security risks that are difficult to observe, attribute, and prioritize.

Current effort

I study how to identify, model, and assess risks in software supply chains, with emphasis on CI/CD automation, software metadata, and ecosystem-level security practices.

Reproducible Builds

Reproducible Builds

Problem statement

Software artifacts often cannot be rebuilt bit-for-bit from their source and declared build environment, which weakens transparency and independent verification.

Current effort

I investigate reproducible packaging practices in open-source ecosystems and the technical or social factors that prevent reliable rebuilds.

Dependency Analysis

Dependency Bloating and Software Debloating

Problem statement

Software often ships as a black box containing or referencing more resources than it actually needs, increasing maintenance and security exposure.

Current effort

I explore dependency modeling and debloating strategies that help developers understand what is included in software artifacts and reduce unnecessary attack surface.

AI Security Analysis

AI-Assisted Security Analysis

Problem statement

Security analysts need scalable techniques to inspect code, configurations, and distributed systems without losing context or explainability.

Current effort

I study how AI-based methods can support vulnerability analysis, code understanding, and attack detection in software systems.

Collaborations

I am open to collaborations on software supply chain security, reproducible builds, dependency analysis, and adjacent software security topics.

Start a conversation