Avatar

Hi! I'm Ishtiaq, a Computer Science Ph.D. candidate at Virginia Tech.


My research falls under the broad spectrum of Internet Measurement and Security. The overarching goal of my research is to improve the management and security of important internet protocol standards such as email, DNS, and web by identifying misconfigurations, anomalies, and vulnerabilities combining data-driven, empirical, and qualitative approaches.

My PhD advisor is Dr. Taejoong Chung.

News

  • [Mar 2025] Our paper on MTA-STS got accepted to IMC 2025.
  • [Feb 2025] I will serve on the Artifact Evaluation Committee at USENIX Security Symposium 2025.
  • [Jan 2025] I will be rejoining Meta as a PhD Software Engineer Intern in Summer 2025.
  • [Aug 2024] Presented our SPF paper at USENIX Security Symposium 2024.
  • [May 2024] Passed my PhD Preliminary Exam and officially a PhD candidate now.
  • [Apr 2024] Our paper on SPF got accepted to USENIX Security Symposium 2024.
  • [Feb 2024] I will be joining Meta as a PhD Software Engineer Intern in Summer 2024.

Work Experience

  • Graduate Research/Teaching Assistant (Jan '21 - Present)

    • Department of Computer Science and Applications
      Virginia Tech, Blacksburg, VA, USA
  • PhD Software Engineer Intern (May '24 - Aug '24)

    • Browser Product Infrastructure Team
      Meta, NYC, USA
  • Instructor (May '23 - Jun '23)

    • Department of Computer Science and Applications
      Virginia Tech, Blacksburg, VA, USA
  • Lecturer (Jul '19 - Dec '20)

    • Department of Computer Science and Engineering
      United International University, Dhaka, Bangladesh
  • Software Engineer (Nov '18 - Jul '19)

    • InfoSapex Limited, Dhaka, Bangladesh

Education

  • PhD in Computer Science, Virginia Tech, Jan'21 - Present

  • MSc in Computer Science, Virginia Tech, 2023

  • BSc in Computer Science, Bangladesh University of Engineering & Technology (BUET), 2018

Publications

  • 2025

    • Unraveling the Complexities of MTA-STS Deployment and Management in Email (to appear)
      Md. Ishtiaq Ashiq, Tobias Fiebig, and Taejoong Chung
      Accepted in Proceedings of the ACM Internet Measurement Conference (IMC'25), Madison, WI, USA, Oct 2025
  • 2024

    • SPF Beyond the Standard: Management and Operational Challenges in Practice and Practical Recommendations (Paper)
      Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, and Taejoong Chung
      In Proceedings of the USENIX Security Symposium (USENIX '24), Philadelphia, PA, USA, Aug 2024
  • 2023

    • RoVista: Measuring and Understanding the Route Origin Validation (ROV) in RPKI (Paper)
      Weitong Li, Zhexiao Lin, Md. Ishtiaq Ashiq, Emile Aben, Romain Fontugne, Amreesh Phokeer, and Taejoong Chung
      In Proceedings of the ACM Internet Measurement Conference (IMC '23), Montreal, Canada, October 2023
    • You’ve Got Report: Measurement and Security Implications of DMARC Reporting (Paper)
      Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, and Taejoong Chung
      In Proceedings of the USENIX Security Symposium (USENIX '23), Anaheim, CA, USA, Aug 2023
    • Measuring TTL Violation of DNS Resolvers in the Wild (Paper)
      Protick Bhowmick, Md. Ishtiaq Ashiq, Casey Deccio, and Taejoong Chung
      In Proceedings of the Passive and Active Measurement Conference (PAM '23), Virtual, Mar 2023
  • 2022

    • Under the Hood of DANE Mismanagement in SMTP (Paper)
      Hyeonmin Lee, Md. Ishtiaq Ashiq, Moritz Muller, Roland van Rijswijk-Deij, Taekyoung Kwon, and Taejoong Chung
      In Proceedings of the USENIX Security Symposium (USENIX '22), Boston, USA, Aug 2022
  • 2021

    • Measurement and Analysis of Automated Certificate Reissuance (Paper)
      Olamide Omolola, Richard Roberts, Md. Ishtiaq Ashiq, Taejoong Chung, Dave Levin, and Alan Mislove
      In Proceedings of the Passive and Active Measurement Conference (PAM '21), Virtual, Mar 2021
  • 2019

    • Domain Flux based DGA Botnet Detection Using Feedforward Neural Network (Paper)
      Md. Ishtiaq Ashiq, Protick Bhowmick, Md. Shohrab Hossain and Husnu S. Narman
      In IEEE Military Communications Conference (MILCOM '19), Norfolk, VA, USA, Nov 2019

Projects

    • Revisiting the NXNS Attack (2022) (Report)
      Developed a scalable technique to measure patches for the attack in local resolvers leveraging BrightData proxy network.
    • Transferability of Adversarial Training in Text Domain (2021) (Code)
      Conducted a study to check transferability of adversarial training across popular adversarial frameworks; Framework: PyTorch.
    • Robustness Analysis of a Web Honeypot (2021) (Report)
      Demonstrated common web vulnerabilities in a popular web honeypot framework (SNARE-TANNER).

Skills

  • Languages

    • Python, Kotlin, TypeScript, Java, C++, C, JavaScript, HTML, CSS, Assembly (x86), familiar with R and Go
  • Frameworks and Technologies

    • Django Rest, React, Apache Spark, PyTorch, Node.js, Flask, Tensorflow, familiar with Android
  • DBMS

    • Oracle SQL, PostgreSQL, MongoDB, Redis, Elasticsearch
  • Tools

    • Docker, Vagrant, Hugo, Gulp, Buck, AWS (EC2, S3, SES), Grafana, Celery, JSP-servlets etc.
  • VCS

    • Git, Sapling

Teaching

  • Virginia Tech

    • Intermediate Software Design
      Summer 2023 (Term I)
  • United International University

    • Network Security
      Fall 2019, Spring 2020, Summer 2020, Fall 2020
    • Object Oriented Programming
      Fall 2019, Spring 2020, Summer 2020, Fall 2020
    • Object Oriented Programming Laboratory
      Fall 2019, Spring 2020, Summer 2020
    • Structured Programming Language Laboratory
      Fall 2020
    • Artificial Intelligence Laboratory
      Fall 2019

Awards & Achievements

  • Awarded University Merit List Scholarship and Dean’s List Scholarship for academic performance at BUET
  • Contributed to 3 open-source projects: Mail-in-a-Box, iRedAPD, TextAttack