Avatar

Hi! I'm Ishtiaq, a Computer Science Ph.D. candidate at Virginia Tech.


I am currently doing research in the field of network security and measurement under Dr. Taejoong Chung. The goal of my research is to improve mismanagement and security of Email, DNS, and Public Key Infrastructure (PKI) applications using a data-driven approach.

News

  • [Aug 2024] Presented our SPF paper at USENIX Security Symposium 2024.
  • [May 2024] Passed my PhD Preliminary Exam and officially a PhD candidate now.
  • [Apr 2024] Our paper on SPF got accepted to USENIX Security Symposium 2024.
  • [Feb 2024] I will be joining Meta as a PhD Software Engineer Intern in Summer 2024.
  • [Sep 2023] Our paper on ROV measurement got accepted to IMC 2023.
  • [Jun 2023] Our paper on DMARC reporting got accepted to USENIX Security Symposium 2023.
  • [Apr 2023] I will be working as a Summer Instructor at Virginia Tech in Summer-I 2023.

Work Experience

  • PhD Software Engineer Intern (May '24 - Aug '24)

    • Browser Product Infrastructure Team
      Meta, NYC, USA
  • Graduate Research/Teaching Assistant (Jan '21 - Apr '23, Jul '23 - Present)

    • Department of Computer Science and Applications
      Virginia Tech, Blacksburg, VA, USA
  • Instructor (May '23 - Jun '23)

    • Department of Computer Science and Applications
      Virginia Tech, Blacksburg, VA, USA
  • Lecturer (Jul '19 - Dec '20)

    • Department of Computer Science and Engineering
      United International University, Dhaka, Bangladesh
  • Software Engineer (Nov '18 - Jul '19)

    • InfoSapex Limited, Dhaka, Bangladesh

Education

  • Virginia Tech

    • PhD in Computer Science and Applications, Jan '21 - Present
  • Virginia Tech

    • MSc in Computer Science and Applications, Jan '21 - Dec '23
  • Bangladesh University of Engineering & Technology (BUET)

    • BSc in Computer Science and Engineering, Jul '14 - Oct '18
  • Notre Dame College

    • Higher Secondary Certificate Examination (HSC), 2013

Publications

  • 2024

    • SPF Beyond the Standard: Management and Operational Challenges in Practice and Practical Recommendations (Paper)
      Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, and Taejoong Chung
      In Proceedings of the USENIX Security Symposium (USENIX '24), Philadelphia, PA, United States, Aug 2024
  • 2023

    • RoVista: Measuring and Understanding the Route Origin Validation (ROV) in RPKI (Paper)
      Weitong Li, Zhexiao Lin, Md. Ishtiaq Ashiq, Emile Aben, Romain Fontugne, Amreesh Phokeer, and Taejoong Chung
      In Proceedings of the ACM Internet Measurement Conference (IMC '23), Montreal, Canada, October 2023
    • You’ve Got Report: Measurement and Security Implications of DMARC Reporting (Paper)
      Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, and Taejoong Chung
      In Proceedings of the USENIX Security Symposium (USENIX '23), Anaheim, CA, United States, Aug 2023
    • Measuring TTL Violation of DNS Resolvers in the Wild (Paper)
      Protick Bhowmick, Md. Ishtiaq Ashiq, Casey Deccio, and Taejoong Chung
      In Proceedings of the Passive and Active Measurement Conference (PAM '23), Virtual, Mar 2023
  • 2022

    • Under the Hood of DANE Mismanagement in SMTP (Paper)
      Hyeonmin Lee, Md. Ishtiaq Ashiq, Moritz Muller, Roland van Rijswijk-Deij, Taekyoung Kwon, and Taejoong Chung
      In Proceedings of the USENIX Security Symposium (USENIX '22), Boston, United States, Aug 2022
  • 2021

    • Measurement and Analysis of Automated Certificate Reissuance (Paper)
      Olamide Omolola, Richard Roberts, Md. Ishtiaq Ashiq, Taejoong Chung, Dave Levin, and Alan Mislove
      In Proceedings of the Passive and Active Measurement Conference (PAM '21), Virtual, Mar 2021
  • 2019

    • Domain Flux based DGA Botnet Detection Using Feedforward Neural Network (Paper)
      Md. Ishtiaq Ashiq, Protick Bhowmick, Md. Shohrab Hossain and Husnu S. Narman
      In IEEE Military Communications Conference (MILCOM '19), Norfolk, VA, USA, Nov 2019

Projects

    • Revisiting the NXNS Attack (2022) (Report)
      Developed a scalable technique to measure patches for the attack in local resolvers leveraging BrightData proxy network.
    • Understanding DNSSEC Debugging Patterns using DNSViz (2021) (Slide)
      Md. Ishtiaq Ashiq, Casey Deccio, and Taejoong Chung
      Presented in 36th DNS-OARC Workshop, Virtual, Nov 2021
    • Transferability of Adversarial Training in Text Domain (2021) (Code)
      Conducted a study to check transferability of adversarial training across popular adversarial frameworks; Framework: PyTorch.
    • Robustness Analysis of a Web Honeypot (2021) (Report)
      Demonstrated common web vulnerabilities in a popular web honeypot framework (SNARE-TANNER).

Skills

  • Languages

    • Python, Kotlin, TypeScript, Java, C++, C, JavaScript, HTML, CSS, Assembly (x86), familiar with R and Go
  • Frameworks and Technologies

    • Django Rest, React, Apache Spark, PyTorch, Node.js, Flask, Tensorflow, familiar with Android
  • DBMS

    • Oracle SQL, PostgreSQL, MongoDB, Redis, Elasticsearch
  • Tools

    • Docker, Vagrant, Hugo, Gulp, Buck, AWS (EC2, S3, SES), Grafana, Celery, JSP-servlets etc.
  • VCS

    • Git, Sapling

Teaching

  • Virginia Tech

    • Intermediate Software Design
      Summer 2023 (Term I)
  • United International University

    • Network Security
      Fall 2019, Spring 2020, Summer 2020, Fall 2020
    • Object Oriented Programming
      Fall 2019, Spring 2020, Summer 2020, Fall 2020
    • Object Oriented Programming Laboratory
      Fall 2019, Spring 2020, Summer 2020
    • Structured Programming Language Laboratory
      Fall 2020
    • Artificial Intelligence Laboratory
      Fall 2019

Awards & Achievements

  • Awarded University Merit List Scholarship and Dean’s List Scholarship for academic performance at BUET
  • Contributed to 3 open-source projects: Mail-in-a-Box, iRedAPD, TextAttack