Resume-aware faculty matching

Find professors who actually fit you

Review faculty evidence in public, then use the workspace to turn your background into a shortlist, outreach, and meeting prep.

Profile-awarePaper evidenceSix agents
Wajih Ul Hassan

Wajih Ul Hassan

University of Virginia · Computer Science

Active 2016–2026

h-index13
Citations1.1k
Papers3719 last 5y
Funding

Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.

See your match with Wajih Ul Hassan — sign in to PhdFit.Sign in

About

Wajih Ul Hassan is an Assistant Professor of Computer Science at the University of Virginia. His research primarily focuses on system security, with a specialization in developing practical solutions to protect complex networked computer systems. He employs novel data-driven approaches alongside scalable system design to enhance security measures. At UVA, he leads the DART Lab, where his work has been recognized with the prestigious NSF CAREER Award in 2024.

Research topics

  • Computer Science
  • Computer Security
  • Geology
  • Internet privacy
  • Materials science
  • Nanotechnology
  • Physics

Selected publications

  • Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning

    2024-05-19 · 78 citations

    articleSenior author

    Recently, provenance-based Intrusion Detection Systems (IDSes) have gained popularity for their potential in detecting sophisticated Advanced Persistent Threat (APT) attacks. These IDSes employ provenance graphs created from system logs to identify potentially malicious activities. Despite their potential, they face challenges in accuracy, practicality, and scalability, particularly when dealing with large provenance graphs. We present Flash, a scalable IDS that leverages graph representation le…

  • SoK: History is a Vast Early Warning System: Auditing the Provenance of System Intrusions

    2023-05-01 · 51 citations

    articleSenior author

    Auditing, a central pillar of operating system security, has only recently come into its own as an active area of public research. This resurgent interest is due in large part to the notion of data provenance, a technique that iteratively parses audit log entries into a dependency graph that explains the history of system execution. Provenance facilitates precise threat detection and investigation through causal analysis of sophisticated intrusion behaviors. However, the absence of a foundationa…

  • FAuST: Striking a Bargain between Forensic Auditing’s Security and Throughput

    2022-12-03 · 9 citations

    articleSenior author

    System logs are invaluable to forensic audits, but grow so large that in practice fine-grained logs are quickly discarded – if captured at all – preventing the real-world use of the provenance-based investigation techniques that have gained popularity in the literature. Encouragingly, forensically-informed methods for reducing the size of system logs are a subject of frequent study. Unfortunately, many of these techniques are designed for offline reduction in a central server, meaning that the u…

  • HADES: Detecting and Investigating Active Directory Attacks via Whole Network Provenance Analytics

    IEEE Transactions on Dependable and Secure Computing · 2025-09-22 · 4 citations

    preprintOpen access

    Due to its crucial role in identity and access management in modern enterprise networks, Active Directory (AD) is a top target of Advanced Persistence Threat (APT) actors. Conventional intrusion detection systems (IDS) excel at identifying malicious behaviors caused by malware, but often fail to detect stealthy attacks launched by APT actors. Recent advance in provenance-based IDS (PIDS) shows promises by exposing malicious system activities in causal attack graphs. However, existing approaches…

  • Accurate and Scalable Detection and Investigation of Cyber Persistence Threats

    IEEE Transactions on Dependable and Secure Computing · 2026-01-01 · 2 citations

    preprintOpen accessSenior author

    In Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typica…

Frequent coauthors

  • Adam Bates

    27 shared
  • Riccardo Paccagnella

    Carnegie Mellon University

    10 shared
  • Nova Ahmed

    North South University

    9 shared
  • Laura S. Gaytán-Lugo

    Universidad de Colima

    9 shared
  • Eric Hennenfent

    Institute of Electrical and Electronics Engineers

    9 shared
  • Michelle L. Mazurek

    University of Maryland, College Park

    9 shared
  • Ombeline Leclerc-Istria

    Regional Municipality of Niagara

    9 shared
  • Vincent Nicomette

    Centre National de la Recherche Scientifique

    9 shared

Labs

  • DART LabPI

    Detecting, Analyzing, and Responding to Cyber Threats (DART) Lab

Education

  • Ph.D., Computer Science

    University of Virginia

Awards & honors

  • NSF CAREER Award
  • Symantec Research Labs Graduate Fellowship
  • ACM SIGSOFT Distinguished Paper Award
  • Young Researcher at the Heidelberg Laureate Forum

Similar researchers at University of Virginia

  • Resume-aware match score
  • Save to shortlist
  • AI-drafted outreach

See your match with Wajih Ul Hassan

PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.

  • Free to start
  • No credit card
  • 30-second signup