VLDB 2026 Research / reviewers in the wild / expert
T. J. OConnor
dblp:241/1567
· DBLP profile ↗
12ranked-venue papers
7as first author
10since 2021 · last 2025
0000-0001-9707-1830ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 7 · 4 first-author · 7 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Evaluation of an Internet of Things Device-Based Educational Approach to Engage a More Diverse Cybersecurity WorkforceabstractCybersecurity education heavily utilizes competition-based approaches, such as capture-the-flag (CTF) games to support the need for a skilled cybersecurity workforce. Although CTFs expose students to cybersecurity work competencies, their competitive nature may contribute to the lack of diversity in cybersecurity programs. In response, we developed a technology-based, experiential learning approach utilizing Internet of Things (IoT) devices to educate learners about cybersecurity concepts. We evaluated the approach’s effectiveness in engaging and sparking interest in a diverse sample of high school students. Our results indicated that (a) all participants reported a moderate challenge-skill balance, (b) underrepresented minorities (URMs) reported significantly higher engagement than non-URMs, and (c) significantly more female students compared to male students reported increased levels of intent to pursue cybersecurity after participating in the learning activity. We present the approach, methods, results, implications, and recommendations for the use of IoT devices in cybersecurity education to train a more diverse workforce. Maureen Namukasa, Maria Chaparro Osman, Cherrise Ficke, Isabella Piasecki, T. J. OConnor, Meredith B. Carroll |
Int. J. Hum. Comput. Interact. | 5 |
| 2024 | Remote Controlled Cyber: Toward Engaging and Educating a Diverse Cybersecurity WorkforceabstractCybersecurity education has grown exponentially to support the need for a skilled cybersecurity workforce. Further, capture-the-flag competitions have popularized cybersecurity by engaging and recruiting students while exposing them to cybersecurity workforce competencies. However, the heavy reliance on competition-based educational approaches may contribute to the lack of diversity in cybersecurity programs. Cybersecurity competitions are the primary catalyst to expose and recruit students from both high school and collegiate cybersecurity education programs. In response, we propose a collaborative, experiential learning approach that leverages hackable Internet of Things (IoT) toys as a pedagogical tool for cybersecurity education. We share our detailed design, activities, experiences, and lessons learned for others to build on our initial success. Curtice Gough, Carl Mann, Cherrise Ficke, Maureen Namukasa, Meredith B. Carroll, T. J. OConnor |
SIGCSE (1) | 6 |
| 2024 | PWN Lessons Made Easy with Docker: Toward an Undergraduate Vulnerability Research Cybersecurity ClassabstractDeveloping expertise in vulnerability research is critical to closing the cybersecurity workforce shortage. However, very few institutions have adopted vulnerability research into their cybersecurity curriculum, and fewer have examined how to teach this skill to students. The recent emergence of lightweight, container-based virtualization presents a unique opportunity to address this challenge by offering reproducible environments that ease course facilitation. This paper presents an undergraduate vulnerability course design. Our approach leverages a hands-on methodology that challenges students to develop complex binary exploits over our lectures, labs, and exams. We share our detailed design, labs, experiences, lessons learned, and a lightweight virtual environment for this course for others to build on our initial success. T. J. OConnor, Alex Schmith, Christopher Stricklan, Marco M. Carvalho, Sneha Sudhakaran |
SIGCSE (1) | 1 |
| 2023 | Towards Examining The Security Cost of Inexpensive Smart Home IoT DevicesabstractA myriad of security challenges has accompanied the rapid proliferation of internet-of-things (IoT) smart-home devices. While smart-home security cameras, locks, digital speakers, and thermostats offer the promise of security, their naive implementations often introduce vulnerability into our digitally connected lives. We argue that the consumer demand for in-expensive IoT has led to a supply of grossly insecure devices. To examine this hypothesis, we examine the security of five inexpensive IoT devices from three separate vendors. In all five devices, our work uncovers immature software security efforts. Our findings discover new vulnerabilities, document legacy vulnerabilities due to software bill of materials (SBOM) issues, explore security mitigations in firmware, and examine the unsecured communication within the ecosystems of the devices. Our analysis discusses the root causes of these vulnerabilities. While these results indicate a snapshot of an immature and naive state of IoT software, there are several software development lifecycle processes that vendors can immediately implement to overcome the root causes of these vulnerabilities. T. J. OConnor, Dylan Jessee, Daniel Campos |
COMPSAC | 1 |
| 2023 | Toward a Labeled Dataset of IoT Malware Features
Stian Hagbø Olsen, T. J. OConnor |
COMPSAC | 2 |
| 2022 | MPO: MQTT-Based Privacy Orchestrator for Smart Home UsersabstractSecurity and privacy concerns present the most significant obstacles to consumer adoption of Internet-of- Things (IoT) devices. A lack of transparency and control complicates user trust in IoT. Additionally, a growing history of misuse and abuse exists in IoT. Notably, smart TVs have periodically scanned and collected users' private information without consent. Due to a hybrid of distributed ecosystems within IoT, users cannot easily implement traditional access control over their devices as data flows within different nodes for storage and processing. We propose MQTT-Based Privacy Orchestrator (MPO) to implement traditional access control on IoT devices. MPO enforces privacy preferences by implementing access control at an MQTT broker. We open-source and provide MPO as an add-on to the popular Home Assistant open-source home automation framework to support widespread adoption. We conducted experimental evalu-ations to validate the functionality and examine the performance of MPO. Our performance evaluation generated more than 16,686 messages, which MPO delivered in under a second. Our work demonstrates a practical solution to facilitate users' privacy preferences and enforce access control for MQTT-based devices. Ahmed Ali Alhazmi, Khulud Alawaji, T. J. OConnor |
COMPSAC | 3 |
| 2022 | Toward an Automatic Exploit Generation Competition for an Undergraduate Binary Reverse Engineering CourseabstractAnalyzing binary programs without source code is critical for cybersecurity professionals. This paper presents an undergraduate binary reverse engineering course design that culminates with a comprehensive binary exploitation competition. Our approach challenges students to develop tools that automatically detect and exploit program vulnerabilities. We hypothesize that this competition presents a unique opportunity to exercise the core competencies of binary reverse engineering. We share our detailed design, labs, experiences, and lessons learned from this course for others to build on our initial success. T. J. OConnor, Carl Mann, Tiffanie Petersen, Isaiah Thomas, Christopher Stricklan |
ITiCSE (1) | 1 |
| 2022 | HELO DarkSide: Breaking Free From Katas and Embracing the Adversarial Mindset in Cybersecurity EducationabstractThe pedagogy of cybersecurity education presents an exciting challenge. Although cyber-warfare has existed for nearly four decades, we fail to adequately model the chaos of offensive cyber attacks in the classroom. Instead, coursework focuses on studying choreographed cyber-attack patterns. In this paper, we present an undergraduate cybersecurity course design that balances theoretical learning with an emphasis on exploring offensive tactics, techniques, and procedures. Labs consist of writing payloads and channels to evade detection, cobbling together operating system internals to achieve attack functionality, and developing survivable post-exploitation tools. In the exams, students develop malware capable of avoiding static and dynamic analysis and identify the strategic and tactical flaws that lead to the discovery of highly successful attack campaigns. We believe that sharing this experience will prove valuable for instructors who wish to explore offensive cyber tactics in the classroom. T. J. OConnor |
SIGCSE (1) | 1 |
| 2021 | Teaching a Hands-On Mobile and Wireless Cybersecurity CourseabstractThe combination of theory-based and practical hands-on learning represents a powerful approach for cybersecurity education. Placing the student in the adversarial mindset strengthens this approach and is commonly exercised in network penetration testing, reverse engineering, and binary exploitation coursework. In this paper, we present an undergraduate mobile and wireless security course design that balances theoretical learning with a hands-on and adversarial thinking approach. Our course consists of inter-woven lectures and lab sessions. Labs consist of contemporary attacks against radio-frequency (RF) enabled hardware, Internet of Things (IoT) firmware, and wireless protocols. In the culmination exercise, the students attack a flawed RF protocol implemented on GnuRadio to allow students to demonstrate their knowledge synthesis. We believe that sharing this experience will prove valuable for instructors who wish to introduce adversarial thinking into mobile and wireless security courses while overcoming the challenge of remote students. T. J. OConnor, Christopher Stricklan |
ITiCSE (1) | 1 |
| 2021 | Towards Binary Diversified Challenges For A Hands-On Reverse Engineering CourseabstractThe balance of a practical hands-on and theoretical approach for reverse engineering coursework offers a strong approach for cybersecurity education. This balance is key to helping students build the skills necessary to contribute to the industry upon graduation. However, the remote learning demands of the current pandemic present a challenge to this approach. Inappropriate collaboration between students poses a threat to the educational benefits of practice-based learning. Specifically, inappropriate collaboration can threaten the development of critical problem skills gained during individual work. Further, relying on instructors to create unique challenges for each student fails to scale. To overcome these challenges, we have implemented a binary diversification system that produces unique reverse engineering challenges per student. In this paper, we present the technical details and lessons learned implementing this approach. We believe that sharing our approach will benefit cybersecurity education instructors looking to overcome the challenges of remote-learning cybersecurity coursework. Christopher Stricklan, T. J. OConnor |
ITiCSE (1) | 2 |
| 2019 | Blinded and confused: uncovering systemic flaws in device telemetry for smart-home internet of thingsabstractThe always-on, always-connected nature of smart home devices complicates Internet-of-Things (IoT) security and privacy. Unlike traditional hosts, IoT devices constantly send sensor, state, and heartbeat data to cloud-based servers. These data channels require reliable, routine communication, which is often at odds with an IoT device's storage and power constraints. Although recent efforts such as pervasive encryption have addressed protecting data intransit, there remains little insight into designing mechanisms for protecting integrity and availability for always-connected devices. This paper seeks to better understand smart home device security by studying the vendor design decisions surrounding IoT telemetry messaging protocols, specifically, the behaviors taken when an IoT device loses connectivity. To understand this, we hypothesize and evaluate sensor blinding and state confusion attacks, measuring their effectiveness against an array of smart home IoT device types. Our analysis uncovers pervasive failure in designing telemetry that reports data to the cloud, and buffering that fails to properly cache undelivered data. We uncover that 22 of 24 studied devices suffer from critical design flaws that (1) enable attacks to transparently disrupt the reporting of device status alerts or (2) prevent the uploading of content integral to the device's core functionality. We conclude by considering the implications of these findings and offer directions for future defense. While the state of the art is rife with implementation flaws, there are several countermeasures IoT vendors could take to reduce their exposure to attacks of this nature. T. J. OConnor, William Enck, Bradley Reaves |
WiSec | 1 |
| 2019 | HomeSnitch: behavior transparency and control for smart home IoT devicesabstractThe widespread adoption of smart home IoT devices has led to a broad and heterogeneous market with flawed security designs and privacy concerns. While the quality of IoT device software is unlikely to be fixed soon, there is great potential for a network-based solution that helps protect and inform consumers. Unfortunately, the encrypted and proprietary protocols used by devices limit the value of traditional network-based monitoring techniques. In this paper, we present HomeSnitch, a building block for enhancing smart home transparency and control by classifying IoT device communication by semantic behavior (e.g., heartbeat, firmware check, motion detection). HomeSnitch ignores payload content (which is often encrypted) and instead identifies behaviors using features of connection-oriented application data unit exchanges, which represent application-layer dialog between clients and servers. We evaluate HomeSnitch against an independent labeled corpus of IoT device network flows and correctly detect over 99% of behaviors. We further deployed HomeSnitch in a home environment and empirically evaluated its ability to correctly classify known behaviors as well as discover new behaviors. Through these efforts, we demonstrate the utility of network-level services to classify behaviors of and enforce control on smart home devices. T. J. OConnor, Reham Mohamed 0002, Markus Miettinen, William Enck, Bradley Reaves, Ahmad-Reza Sadeghi |
WiSec | 1 |