Resume-aware faculty matching

Find professors who actually fit you

Review faculty evidence in public, then use the workspace to turn your background into a shortlist, outreach, and meeting prep.

Profile-awarePaper evidenceSix agents
Engin Kirda

Engin Kirda

Northeastern University · Electrical and Energy Engineering

Active 2000–2025

h-index62
Citations16.5k
Papers24639 last 5y
Funding$2.0M

Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.

See your match with Engin Kirda — sign in to PhdFit.Sign in

About

Engin Kirda is a professor at Northeastern University, serving in the Khoury College of Computer Sciences and the College of Engineering. He is the director of the Information Assurance Program, a joint PhD program offered by these colleges. His research focuses on security issues that have the potential to affect a large number of people, including malware analysis and detection, web security, social network security, reverse engineering, and intrusion detection. Professor Kirda is the co-founder and co-director of the International Secure Systems Lab, a collaborative effort of European and U.S. researchers dedicated to web security, malware and vulnerability analysis, and intrusion detection. He has contributed to the development of tools such as Anubis, FIRE, and Pixy, which are used for malware analysis, detecting hacked internet services, and vulnerability assessments for web pages, respectively. His academic background includes a PhD from the Technical University of Vienna, earned in 2002. He has been recognized as an IEEE Fellow and has received numerous awards for his contributions to cybersecurity research.

Research topics

  • Computer Science
  • Artificial Intelligence
  • Computer Security
  • Computer hardware
  • Human–computer interaction
  • Computer network
  • Operating system

Selected publications

  • DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis

    2022 IEEE Symposium on Security and Privacy (SP) · 2021 · 47 citations

    Senior authorCorresponding

    Microcontroller-based embedded devices are at the core of Internet-of-Things (IoT) and Cyber-Physical Systems (CPS). The security of these devices is of paramount importance. Among the approaches to securing embedded devices, dynamic firmware analysis (e.g., vulnerability detection) gained great attention lately, thanks to its offline nature and low false-positive rates. However, regardless of the analysis and emulation techniques used, existing dynamic firmware analyzers share a major limitatio…

  • On the Complexity of the Web’s PKI: Evaluating Certificate Validation of Mobile Browsers

    IEEE Transactions on Dependable and Secure Computing · 2023-03-13 · 11 citations

    article

    Digital certificates are frequently used to secure communications between users and web servers. Critical to the Web’s PKI is the secure validation of digital certificates. Nonetheless, certificate validation itself is complex and error-prone. Moreover, it is also undermined by particular constraints of mobile browsers. However, these issues have long been overlooked. In this article, we undertook the first systematic and large-scale study of the certificate validation mechanism within popular m…

  • Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies

    2024-09-29 · 6 citations

    articleSenior author

    Modern web applications involve multiple HTTP processors on the traffic path, each acting as a reverse proxy and processing client requests. Even when such proxies are secure in isolation, when combined into complex systems, minor HTTP parsing discrepancies between them can lead to various severe attacks such as cache poisoning and HTTP request smuggling attacks.

  • OAuth 2.0 Redirect URI Validation Falls Short, Literally

    Annual Computer Security Applications Conference · 2023-12-02 · 6 citations

    articleOpen accessSenior author

    OAuth 2.0 requires a complex redirection trail between websites and Identity Providers (IdPs). In particular, the "redirect URI" parameter included in the popular Authorization Grant Code flow governs the callback endpoint that users are routed to, together with their security tokens. The protocol specification, therefore, includes guidelines on protecting the integrity of the redirect URI.

  • AIM: Automatic Interrupt Modeling for Dynamic Firmware Analysis

    IEEE Transactions on Dependable and Secure Computing · 2023-12-05 · 5 citations

    articleSenior author

    The security of microcontrollers, which drive modern IoT and embedded devices, continues to raise major concerns. Within a microcontroller (MCU), the firmware is a monolithic piece of software that contains the whole software stack, whereas a variety of peripherals represent the hardware. As MCU firmware contains vulnerabilities, it is ideal to test firmware with off-the-shelf software testing techniques, such as dynamic symbolic execution and fuzzing. Nevertheless, no emulator can emulate the d…

Recent grants

Frequent coauthors

Labs

  • Northeastern University Systems Security LabPI

Education

  • Ph.D., Computer Science

    University of California, Santa Barbara

    2002
  • M.S., Computer Science

    University of California, Santa Barbara

    1998
  • B.S., Computer Engineering

    Middle East Technical University

    1996

Awards & honors

  • Sy and Laurie Sternberg Interdisciplinary Chaired Professors…
  • IEEE Fellow (2025)

Similar researchers at Northeastern University

  • Resume-aware match score
  • Save to shortlist
  • AI-drafted outreach

See your match with Engin Kirda

PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.

  • Free to start
  • No credit card
  • 30-second signup