2001-100 Spadina Rd.
Toronto, ON M5R 2T7
Canada
+1 (647) 890-1452
shardy@aculei.net
| Seeking employment in the field of computer security at a
position that encourages learning and developing my skills.
|
|
Worcester Polytechnic Institute, Worcester, MA.
|
|
Worcester Polytechnic Institute, Worcester, MA.
|
|
Boston Latin School, Boston, MA. |
|
January 2008 -- Present |
Symantec (formerly MessageLabs)
|
|
Senior Malware Analyst Responsible for the detection and prevention of malware as part of the MessageLabs Research and Response team. Response focused on working with the AV Operations team to detect malware and improve the antivirus scanning engine and associated tools. AV engine development included heuristics and proof-of-concept tools written in Perl, C, and C++. Malware analysis and detection included reverse engineering using disassemblers and debuggers (IDA Pro, OllyDbg), as well as related tools and utilities. Research included analysis of malware trends, studying new types of malware, integrating the antivirus engine with Web and IM scanning services, and developing new techniques and related intellectual property for the purpose of stopping malicious software. | |
|
November 2004 -- January 2008 |
Imperfect Networks / Spirent Communications
|
|
Lead Vulnerability Researcher Responsible for the research and development of existing and new network-based attacks, and management of the threat development team. Research focused on analysis of threats using techniques including network protocol analysis, protocol and binary reverse engineering, and behavioral modeling. Development included both specialized threat creation from advisories and existing exploits, writing proof-of-concept exploit code in multiple languages including C and Perl, writing fuzzing tools suited for particular protocols, and use of existing automated threat tools. Was directly responsible for the addition of WiFi capabilities to the ThreatEx appliance, including creating the wireless protocols and the suite of wireless attacks. Additionally assisted in a number of roles which contributed to the success of the startup company (Imperfect Networks), including on-site sales engineering support in customer security labs; coordinating with representatives from vendors of other vulnerability databases and security products; and performing audits, penetration testing, and general security testing as part of Spirent's professional services. | |
|
January 2001 -- August 2003 |
Cryptography and Information Security Research Laboratory
|
|
System Administrator Managed lab resources, including system administration and network security for more than ten Solaris and Linux workstations, two Linux servers, and an OpenBSD firewall. | |
|
Summer 2002 |
Force Matrix Software
|
|
Lead Software Developer Was responsible for the design and development of proof of concept bioinformatics software written in assembly language to be run on NVIDIA graphics cards. | |
|
June 2000 -- August 2001 |
Institute for Data Communications Systems
|
|
Software Developer Was responsible for the design, creation, testing, and documentation of a software package in Java to generate elliptic curves suitable for use in cryptography, as part of the ELIAS elliptic curve cryptography library. | |
|
April 2001 -- Present |
aculei animi
|
|
System Administrator Am responsible for all aspects of administration, support, and security for multiple production level servers (OpenBSD, NetBSD) used to provide roughly one hundred users with free Internet services (email, web hosting, data storage, messaging, secondary DNS, secondary MX). | |
|
GIAC Reverse Engineering Malware (GREM) Gold (ISC)2 CISSP |
|
Languages: C, Java, Perl, C++, Scheme, Pascal, Prolog, BASIC, Intel x86 ASM, NVIDIA ASM, Cg, Shell Scripting (sh, bash), Maple, SQL. |
|
Operating Systems: Windows (9x/NT/2000/XP), BSD (Open/Net/Free), Linux, Solaris. |
|
Eta Kappa Nu -- National Computer and Electrical Engineering Honor Society, inducted in 2003
|
|
|
|
"Distributed Cracking of Elliptic Curve Cryptosystems." Rubi-Con 4 (April 2002)
|
References available upon request.