Blacksburg, VA, USA
CGPA: 3.94/4. Advisor: Dr.
Danfeng (Daphne) Yao.
Thesis committee: Dr. David Evans, Dr. Naren Ramakrishnan, Dr. Patrick Schaumont, Dr. Gang Wang.
Research Focus: From Theory to Practice: Deployment-grade Tools and Methodologies for Security Compliance Measurements
#Publications: 5 conference, 1 journal, 1 tutorial, 5 posters.
2006 - 2010
CGPA: 3.64/4. Advisor: Md. Saidur Rahman.
Research Focus: Research Focus: Solving graph theoretic problems; Employing technologies to solve real-life day-to-day problems, etc.
#Publications: 2 conference papers, 1 newsletter.
Pratt Fellowship, Fall 2019 and Spring 2020
Bitshare Fellowship, Fall 2018 and Spring 2019
Champion in .Net platform, Inter University System Design Competition-2011, BUET
Dean'sList Award, BUET, Session 2009-2010
Sazzadur Rahaman, Haipeng Cai, Omar Chowdhury and Danfeng (Daphne) Yao. From Theory to Code: Identifying Logical Flaws in Cryptographic Implementations. IEEE Transactions on Dependable and Secure Computing (TDSC). 2019. [Forthcoming]
Sazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon, Ke Tian, Miles Frantz, Murat Kantarcioglu, Danfeng (Daphne) Yao. CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java Projects. ACM Conference on Computer and Communications Security (CCS'19). London, United Kingdom. November 2019. [PDF] [Source code] [Implemented in Oracle's internal code screening platform!]
Sazzadur Rahaman, Long Cheng, Danfeng (Daphne) Yao, He Li, and Jung-Min (Jerry) Park. Provably Secure Anonymous-yet-Accountable Crowdsensing with Scalable Sublinear Revocation. The 17th Privacy Enhancing Technologies Symposium (PETS). Minneapolis, MN, USA. July, 2017. [PDF]
Sazzadur Rahaman, Danfeng (Daphne) Yao. Toward Automatic Program Analysis of Cryptography Implementations for Security. 2017 IEEE Secure Development Conference. Cambridge, MA, USA. September, 2017. [PDF]
Sazzadur Rahaman, Tousif Ahmed Eshan, Sad Al Abdullah. Antibandwidth Problem for Itchy Caterpillars. 2014 International Conference on International Conference on Informatics, Electronics & Vision (ICIEV). Dhaka, Bangladesh. May, 2014. [PDF]
Mohammad Raihanul Islam, Sazzadur Rahaman, Rakibul Hasan, Ridwan Rashid Noel, Asif Salekin, and Hasan Shahid Ferdous. A Novel Approach for Constructing Emulator for Microsoft Kinect XBOX 360 Sensor in the .NET Platform. 4th International Conference on Intelligent Systems Modelling & Simulation (ISMS). Bangkok, Thailand. January, 2013. [PDF]
Sazzadur Rahaman, Na Meng and Danfeng (Daphne) Yao. Tutorial: Principles and Practices of Secure Crypto Coding In Java (90 minutes Tutorial). 2018 IEEE Secure Development Conference (SecDev'18). Cambridge, MA, USA. September, 2018.
Fahad Shaon, Sazzadur Rahaman. Systems and methods for proactive and reactive data security. U.S. Application No: 16/698,328 (filed).
Sazzadur Rahaman, Ya Xiao, Sharmin Afrose, Ke Tian, Miles Frantz, Danfeng (Daphne) Yao, Na Meng, Barton P. Miller, Fahad Shaon, Murat Kantarcioglu. Poster: Deployment-quality and Accessible Solutions for Cryptography Code Development. 2019 IEEE Symposium on Security and Privacy (IEEE S&P'19). San Francisco, CA, USA . May, 2019.
Sazzadur Rahaman, Ya Xiao, Sharmin Afrose, Ke Tian, Miles Frantz, Danfeng (Daphne) Yao, Na Meng, Barton P. Miller, Fahad Shaon, Murat Kantarcioglu. POSTER: Deployment-quality and Accessible Solutions for Cryptography Code Development. 2019 ACM Conference on Computer and Communications Security (ACM CCS'19). London, United Kingdom. November 2019.
Sharmin Afrose, Sazzadur Rahaman, Danfeng (Daphne) Yao. A Comprehensive Benchmark on Java Cryptographic API Misuses. 2019 IEEE Secure Development Conference. McLean, VA. September 2019.
Sazzadur Rahaman, Long Cheng, Danfeng (Daphne) Yao, He Li, and Jung-Min (Jerry) Park. Enabling Large-scale Anonymous-yet-Accountable Crowdsensing" (Poster). 2017 IEEE Secure Development Conference (SecDev'17). Cambridge, MA, USA. September, 2017.
Sazzadur Rahaman, Long Cheng, He Li, Danfeng (Daphne) Yao and Jung-Min (Jerry) Park. GroupSense: Scalable Crowdsensing with Privacy and Accountability. (Poster). 2016 USENIX Security (USENIX SEC'16). Austin, TX. August, 2016.
August, 2017 - Current
August, 2015 - May, 2017
• CryptoGuard: A deployment-grade tool to find cryptographic API misuses (Java, Android).
• TaintCrypt: A tool to find numerous vulnerabilities in cryptographic implementations (C/C++).
• GroupSense: Privacy-preserving scalable crowdsensing based on a new VLR-based group signature.
May, 2019 - August, 2019
May, 2017 - August, 2017
• Design and development of secure platform for big data analytics frameworks (e.g., Hadoop, Spark, etc.).
• Peer code review, source code analysis.
March, 2014 - July, 2015
• Significant contribution in architecture level design of core products (e.g., Kona Pay [news], Kona TSM).
• Following payment industry specs (e.g., GlobalPlatform, ISO/IEC, Visa, MasterCard, AmEx, EMVCo, etc.).
• Significant contribution in standardizing software engineering practices and tools.
Apr, 2012 - February, 2014
• Development, system performance monitoring, analysis & optimization, peer code reviewing.
• Wrote utility frameworks for significant reductions in boilerplate codes.
NSF CBET Division (Award no. 1645121, 1645285). Amount: $100,000
NSF CNS Division Of Computer and Network Systems (Award no. 1929701) Amount: $700,000
Office of Naval Research (ONR) (Award no. N00014-17-1-2498) Amount: $1,200,000
NSF CNS Division Of Computer and Network Systems (Award no. 1717028) Amount: $500,000
IEEE Transactions on Dependable and Secure Computing (TDSC)
PETS '18 '19 '20, SecDev '18
CCS '17 '18 '19, S&P '18 '19 '20, NDSS '19, WWW '19, AsiaCCS '17 '18, DSN '17