EDBT 2026 Demo / reviewers in the wild / expert
Christopher Morales
dblp:326/1449 · also Christopher Morales-Gonzalez
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0001-9403-6837ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnet
Qiguang Zhang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Chongqing Lei, Christopher Morales, Xinwen Fu |
NDSS | 6 |
| 2025 | Enhancing Cybersecurity Education using Scoring Engines: A Practical Approach to Hands-On Learning and FeedbackabstractIn today's digital landscape, the demand for skilled cybersecurity professionals is higher than ever. However, many educational programs primarily focus on theoretical concepts, leaving students with insufficient practical skills. To address this gap, students need actionable feedback on their hands-on labs and assignments. We present an open-source scoring engine that provides iterative, step-by-step feedback, enabling students to solve complex cybersecurity problems progressively. Integrated into existing courses, this engine can enhance labs with detailed, structured feedback, bridging the gap between theoretical knowledge and practical application. A preliminary study with 11 students showed that all participants could complete complex tasks using the feedback provided by the engine, with limited instruction from the authors. Additionally, about 90% of the students reported high satisfaction with the structured feedback. This approach has the potential to transform cybersecurity education, making it more interactive, practical, and aligned with real-world requirements. Christopher Morales, Matthew Harper, Pranathi Rayavaram, Sashank Narain, Xinwen Fu |
SIGCSE (1) | 1 |
| 2025 | Practical Cybersecurity Education: A Course Model Using Experiential Learning TheoryabstractThe increasing sophistication of cybersecurity threats necessitates an educational approach that blends theoretical knowledge with practical experience. Many courses focus primarily on theoretical concepts, leaving students with limited hands-on experience with real-world challenges. This paper introduces a cybersecurity course model that integrates Experiential Learning Theory to provide a comprehensive hands-on learning environment. The course covers important cybersecurity topics, including SSH, VPNs, TLS, MFA, OpenID Connect, OAuth2, web server security, high availability, replication, distributed file systems, and orchestration with Docker and Kubernetes. These topics are explored through a mix of lectures, peer presentations, and weekly hands-on team practices. Over three years, the course has been offered at our large public university with 72 students enrolled, consistently receiving high course ratings between 4.8 and 5.0. This paper discusses the course design, methodology, and outcomes, offering insights for educators to replicate and adapt the model for their own institutions. Sashank Narain, Pranathi Rayavaram, Christopher Morales, Matthew Harper, Maryam Abbasalizadeh, Krishna Vellamchety, Xinwen Fu |
SIGCSE (1) | 3 |
| 2024 | Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingabstractBuilding Automation Systems (BAS) play a pivotal role in modern smart buildings, integrating sensors, controllers, and software to manage crucial functions such as HVAC, lighting, and more. The global smart building market is on the rise, underscoring the importance of securing BAS networks. This paper introduces the Building Automation System Evaluator (BASE), a specialized fuzzer designed to assess the security of BAS networks. BAS networks typically involve a BAS client communicating with a BAS server through BAS protocols (e.g., BACnet, KNX), each presenting unique challenges in BAS network fuzzing. These challenges encompass complex packet structures and sequencing in BAS protocols, closed-source clients with indeterminable code coverage, and unobservable server status with limited throughput. BASE automatically identifies protocol structures, dynamically instruments clients for code coverage analysis, and monitors responses for new coverage areas. Collected timestamps are used to estimate the input scan intervals of servers, optimizing throughput. We evaluated BASE on various BAS servers and clients, uncovering 13 new vulnerabilities. Furthermore, we present three attack case studies, highlighting the real-world security implications of these vulnerabilities in BAS systems, such as delayed fire detection, loss of climate control, and security breaches. We reported our findings to the respective vendors, who acknowledged the implications, and some have subsequently patched their systems based on our reports. Yue Zhang 0025, Zhen Ling 0001, Michael Cash, Qiguang Zhang, Christopher Morales, Qun Zhou 0002, Xinwen Fu |
CCS | 5 |
| 2024 | Evaluating the Efficacy of Productivity Tools in Engineering EducationabstractProductivity methodologies and tools are crucial in technology-focused organizations, fostering efficiency and collaboration. Industry practices, such as Scrum and Objectives and Key Results (OKRs), along with tools like Jira and Git, empower individuals and teams. Communication platforms like Zoom, Microsoft Teams, Slack, and Confluence bridge geographical gaps. Despite their significance, a noticeable gap exists in integrating these practices into academic institutions, hindering students' transitions to the professional realm. This research focuses on effectively integrating industry best practices—Scrum, OKRs, Jira, Git, Zoom, Microsoft Teams, Slack, and Confluence—into academic settings to improve students' individual and team performance in the classroom and to elevate their overall readiness for industry. The study presents practical guidelines derived from interviews with industry professionals, establishing parallels between industry and academia. These guidelines encompass supplemental learning, pairing students with experienced individuals, and recommending cost-effective tools like Discord for collaboration. Scrum principles, implemented through Taiga (a free alternative to Jira) and GitHub, along with OKRs, are endorsed for project and task tracking, providing a comprehensive framework for enhanced productivity in academic contexts. An assessment of these guidelines in an intensive cybersecurity course at a large public university reveals positive outcomes. Pairing students and leveraging Discord for communication prove effective. Methodologies like Scrum and OKRs receive positive responses, with Git emerging as a favorite for collaborative work. The role of Taiga in task accountability is acknowledged. Overall, the implementation of our guidelines demonstrates a positive impact on student and team performance, emphasizing the potential for the effective integration of industry-endorsed practices in academic settings. Christopher Morales, Matthew Harper, Pranathi Rayavaram, Manoj Yeddanapudi, Sashank Narain, Xinwen Fu |
EDUCON | 1 |
| 2024 | On building automation system securityabstractBuilding Automation Systems (BASs) are seeing increased usage in modern society due to the plethora of benefits they provide such as automation for climate control, HVAC systems, entry systems, and lighting controls. Many BASs in use are outdated and suffer from numerous vulnerabilities that stem from the design of the underlying BAS protocol. In this paper, we provide a comprehensive, up-to-date survey on BASs and attacks against seven BAS protocols including BACnet, EnOcean, KNX, LonWorks, Modbus, ZigBee, and Z-Wave. Holistic studies of secure BAS protocols are also presented, covering BACnet Secure Connect, KNX Data Secure, KNX/IP Secure, ModBus/TCP Security, EnOcean High Security and Z-Wave Plus. LonWorks and ZigBee do not have security extensions. We point out how these security protocols improve the security of the BAS and what issues remain. A case study is provided which describes a real-world BAS and showcases its vulnerabilities as well as recommendations for improving the security of it. We seek to raise awareness to those in academia and industry as well as highlight open problems within BAS security. Christopher Morales, Matthew Harper, Michael Cash, Zhen Ling 0001, Qun Zhou 0002, Xinwen Fu |
High Confid. Comput. | 1 |