Wajih Ul Hassan
University of Virginia · Computer Science
Active 2016–2026
Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.
About
Wajih Ul Hassan is an Assistant Professor of Computer Science at the University of Virginia. His research primarily focuses on system security, with a specialization in developing practical solutions to protect complex networked computer systems. He employs novel data-driven approaches alongside scalable system design to enhance security measures. At UVA, he leads the DART Lab, where his work has been recognized with the prestigious NSF CAREER Award in 2024.
Research topics
- Computer Science
- Computer Security
- Geology
- Internet privacy
- Materials science
- Nanotechnology
- Physics
Selected publications
Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning
2024-05-19 · 78 citations
articleSenior authorRecently, provenance-based Intrusion Detection Systems (IDSes) have gained popularity for their potential in detecting sophisticated Advanced Persistent Threat (APT) attacks. These IDSes employ provenance graphs created from system logs to identify potentially malicious activities. Despite their potential, they face challenges in accuracy, practicality, and scalability, particularly when dealing with large provenance graphs. We present Flash, a scalable IDS that leverages graph representation le…
SoK: History is a Vast Early Warning System: Auditing the Provenance of System Intrusions
2023-05-01 · 51 citations
articleSenior authorAuditing, a central pillar of operating system security, has only recently come into its own as an active area of public research. This resurgent interest is due in large part to the notion of data provenance, a technique that iteratively parses audit log entries into a dependency graph that explains the history of system execution. Provenance facilitates precise threat detection and investigation through causal analysis of sophisticated intrusion behaviors. However, the absence of a foundationa…
FAuST: Striking a Bargain between Forensic Auditing’s Security and Throughput
2022-12-03 · 9 citations
articleSenior authorSystem logs are invaluable to forensic audits, but grow so large that in practice fine-grained logs are quickly discarded – if captured at all – preventing the real-world use of the provenance-based investigation techniques that have gained popularity in the literature. Encouragingly, forensically-informed methods for reducing the size of system logs are a subject of frequent study. Unfortunately, many of these techniques are designed for offline reduction in a central server, meaning that the u…
HADES: Detecting and Investigating Active Directory Attacks via Whole Network Provenance Analytics
IEEE Transactions on Dependable and Secure Computing · 2025-09-22 · 4 citations
preprintOpen accessDue to its crucial role in identity and access management in modern enterprise networks, Active Directory (AD) is a top target of Advanced Persistence Threat (APT) actors. Conventional intrusion detection systems (IDS) excel at identifying malicious behaviors caused by malware, but often fail to detect stealthy attacks launched by APT actors. Recent advance in provenance-based IDS (PIDS) shows promises by exposing malicious system activities in causal attack graphs. However, existing approaches…
Accurate and Scalable Detection and Investigation of Cyber Persistence Threats
IEEE Transactions on Dependable and Secure Computing · 2026-01-01 · 2 citations
preprintOpen accessSenior authorIn Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typica…
Frequent coauthors
- 27 shared
Adam Bates
- 10 shared
Riccardo Paccagnella
Carnegie Mellon University
- 9 shared
Nova Ahmed
North South University
- 9 shared
Laura S. Gaytán-Lugo
Universidad de Colima
- 9 shared
Eric Hennenfent
Institute of Electrical and Electronics Engineers
- 9 shared
Michelle L. Mazurek
University of Maryland, College Park
- 9 shared
Ombeline Leclerc-Istria
Regional Municipality of Niagara
- 9 shared
Vincent Nicomette
Centre National de la Recherche Scientifique
Labs
DART LabPI
Detecting, Analyzing, and Responding to Cyber Threats (DART) Lab
Education
Ph.D., Computer Science
University of Virginia
Awards & honors
- NSF CAREER Award
- Symantec Research Labs Graduate Fellowship
- ACM SIGSOFT Distinguished Paper Award
- Young Researcher at the Heidelberg Laureate Forum
Similar researchers at University of Virginia
- Resume-aware match score
- Save to shortlist
- AI-drafted outreach
See your match with Wajih Ul Hassan
PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.
- Free to start
- No credit card
- 30-second signup
