User:Kgberg/sandbox
Edward Amoroso | |
---|---|
File:Edward Amoroso, American expert in computer security and Distinguished Research Professor at the New York University Tandon School of Engineering in the Computer Science and Engineering Department.png | |
Born | February 27, 1977 |
Nationality | American |
Alma mater | University of Arizona |
Scientific career | |
Fields | Security, operating Systems, networks |
Thesis | (2008) |
Doctoral advisor | John Hartman |
Website | engineering isis |
Justin Cappos (born February 27, 1977) is a computer scientist and cybersecurity expert whose data-security software is employed by a number of widely used open-source cloud computing projects.
Cappos is a professor in the department of Computer Science and Engineering at New York University Tandon School of Engineering. His research centers on systems, software update systems, security, and virtualization, with a focus on real-world security problems, often in large open-source projects.[1][2][3]
His Ph.D. dissertation in computer science at the University of Arizona was on the Stork Project,[4] a software package manager he built with John H. Hartman, professor in the department of computer science.
Research and Projects
While a post-doctoral researcher at the University of Washington in 2009, Cappos developed peer-to-peer computing platform Seattle,[5][6]which allows device-to-device connectivity in a decentralized network. For this and other research "Popular Science" in 2013 recognized Cappos as one of its "Brilliant 10" research scientists under 40.[7]
In 2010 he developed The Update Framework (TUF),[8] a flexible security library designed to be added to software updaters to make them resilient to compromise.[9][10]
Docker,[11] an open-source system for deploying Linux containers, integrated TUF in 2015 when it launched Docker Content Trust.[12] Docker Content Trust is an implementation of Docker's Notary project, which is built on TUF[13]. Notary can both certify the validity of the sources of Docker images, and encrypt the contents of those images.[14]
Flynn, an open-source platform as service (PaaS) for running applications in production[15] employs TUF for secure distribution of its components.[16][17][18].
In 2013, credit card processing company Square began integrating TUF with the open-source file-server RubyGems in an effort to prevent a repeat of that year's hack[19] of RubyGems.org, which interrupted the widely used Heroku cloud application architecture.[20][21]
In 2014 Cappos developed PolyPasswordHasher, a password storage scheme that prevents efficient password cracking.[22][23]
Selected Publications
- List of Publications from Microsoft Academic Search
- Justin Cappos' Publications indexed by Google Scholar
References
- ^ Cappos, Justin; Samuel, Justin; Baker, Scott; Hartman, John H. (1 January 2008). "A Look in the Mirror: Attacks on Package Managers". ACM. pp. 565–574. doi:10.1145/1455770.1455841 – via ACM Digital Library.
- ^ Cappos, J.; Wang, L.; Weiss, R.; Yang, Y.; Zhuang, Y. (1 February 2014). "BlurSense: Dynamic fine-grained access control for smartphone privacy". pp. 329–332. doi:10.1109/SAS.2014.6798970 – via IEEE Xplore.
- ^ Kuppusamy, Trishank Karthik; Torres-Arias, Santiago; Diaz, Vladimir; Cappos, Justin (1 January 2016). "Diplomat: Using Delegations to Protect Community Repositories".
{{cite journal}}
: Cite journal requires|journal=
(help) - ^ Cappos, Justin (November, 2007). "Stork: Package Management for Distributed VM Environements". Proceedings of the 21st Large Installation System Adminitration Conference (LISA '07): 79-94.
{{cite journal}}
: Check date values in:|date=
(help) - ^ Cappos, Justin; Beschastnikh, Ivan; Krishnamurthy, Arvind; Anderson, Tom (1 January 2009). "Seattle: A Platform for Educational Cloud Computing". ACM. pp. 111–115. doi:10.1145/1508865.1508905 – via ACM Digital Library.
- ^ http://www.nsf.gov/awardsearch/showAward?AWD_ID=1205415
- ^ "How Justin Cappos Created A New Way To Cloud Compute".
- ^ http://www.nsf.gov/awardsearch/showAward?AWD_ID=1345049&HistoricalAwards=false
- ^ "Presentation: When the going gets tough, get TUF going - PyCon 2016 in Portland, OR".
- ^ http://www.linux-magazine.com/Issues/2014/160/Security-Lessons-TUF
- ^ "Introducing Docker Content Trust - Docker Blog". 12 August 2015.
- ^ http://www.cioreview.com/news/docker-content-trust-protects-integrity-of-dockerized-content-nid-8372-cid-92.html
- ^ http://thenewstack.io/docker-content-trust-can-run-containers-untrusted-networks/
- ^ http://www.zdnet.com/article/docker-1-8-adds-serious-container-security/
- ^ http://www.infoworld.com/article/3101765/open-source-tools/open-source-flynn-takes-the-headaches-out-of-app-deployment.html
- ^ https://flynn.io/docs/security
- ^ "flynn/go-tuf".
- ^ "Development – Flynn".
- ^ http://venturebeat.com/2013/01/30/rubygems-org-hacked-interrupting-heroku-services-and-putting-millions-of-sites-using-rails-at-risk/
- ^ Engineering, Square (6 December 2013). "Applying The Update Framework (TUF) to RubyGems to secure it against nefarious activity".
- ^ Atlassian (29 January 2014). "Atlassian Dev Den Tech Talk Series: "Securing Rubygems with TUF"" – via YouTube.
- ^ http://www.securityweek.com/new-protection-scheme-makes-weak-passwords-virtually-uncrackable
- ^ https://blog.varonis.com/conversation-nyu-polys-professor-justin-cappos-data-security-lessons-tips-companies/
Media Citations and Commentary
- Vice (6 July 2016) Pearl, Mike "We Asked a Cybersecurity Expert if Clinton's Email System Could Have Jeopardized National Security"
- Scientific American (23 March 2016) Sneed, Annie "The Most Vulnerable Ransomware Targets Are the Institutions We Rely On Most"
- CBS News (15 August 2014) "How a password manager can help you stay more secure online"
- CNN Money Pagliery, Jose (15 August 2016) "Hacker claims to be selling stolen NSA spy tools"
- CBS News (3 December 2014) "5 counterintuitive ways to protect against hackers"
- MIT Technology Review (21 February 2013) Lim, Dawn. "Startup Red Balloon Security Offers to Protect Printers, Phones, and Other Devices from Hackers"
- PBS Newshour (18 April 2015) "The hack attack that takes your computer hostage till you pay"
- NY Daily News (4 March 2015) "Should you check your personal email at work?"
- Varonis (6 January 2015) Interview With NYU-Poly’s Professor Justin Cappos: Security Lessons From Retail Breaches
Category:New York University
Category:1977 births
Category:Living people