<node id="689123">
  <nid>689123</nid>
  <type>event</type>
  <uid>
    <user id="28475"><![CDATA[28475]]></user>
  </uid>
  <created>1774210422</created>
  <changed>1774210518</changed>
  <title><![CDATA[Ph.D. Dissertation Defense - Mingxuan Yao]]></title>
  <body><![CDATA[<p><strong>Title</strong><em>:&nbsp; From Evidence to Remediation: Automated Forensic Pipelines for Proactive Cyberthreats Intervention</em></p><p><strong>Committee:</strong></p><p>Dr. Brendan Saltaformaggio, ECE, Chair, Advisor</p><p>Dr. Frank Li, ECE</p><p>Dr. Saman Zonouz, ECE</p><p>Dr. Christopher Kruegel, UCSB</p><p>Dr. Giovanni Vigna, UCSB</p>]]></body>
  <field_summary_sentence>
    <item>
      <value><![CDATA[From Evidence to Remediation: Automated Forensic Pipelines for Proactive Cyberthreats Intervention ]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[<p>Traditional cyber forensics is reactive: investigators collect evidence after an incident, address a single case, and leave adversaries free to redeploy. This dissertation introduces the evidence-to-remediation paradigm, a proactive forensic science that extracts comprehensive evidence from a single reported incident and generates remediation strategies that scale across entire platforms. I demonstrate this paradigm through three systems. MARSEA conducts the first large-scale study of malware abusing web applications as command-and-control infrastructure; deployed on 10,000 samples, it revealed 893 malware in 97 families abusing 29 web applications and enabled the takedown of 50% of malicious content. VADER targets Dead Drop Resolver malware that encodes C&amp;C addresses as manipulated payloads on benign platforms; by extracting de-manipulation recipes from binaries, it enables providers to proactively scan for unknown dead drops, uncovering 57.1% additional dead drops across 100,000 samples and achieving 94.4% removal. COCO generalizes the paradigm to blockchain fraud, tracing entire campaigns from a single report; applied to 157 fraud contracts, it uncovered over 1.28 million associated contracts linked to 91 Deceptive Creator Wallets responsible for around $2.09 billion in illicit profits, leading to collaboration with the U.S. FBI and Etherscan. Together, these systems establish a generalizable framework that shifts cyber forensics from reactive investigation to automated, evidence-driven intervention at ecosystem scale.</p>]]></value>
    </item>
  </field_summary>
  <field_time>
    <item>
      <value><![CDATA[2026-04-06T14:00:00-04:00]]></value>
      <value2><![CDATA[2026-04-06T16:00:00-04:00]]></value2>
      <rrule><![CDATA[]]></rrule>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_time>
  <field_fee>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_fee>
  <field_extras>
      </field_extras>
  <field_audience>
          <item>
        <value><![CDATA[Public]]></value>
      </item>
      </field_audience>
  <field_media>
      </field_media>
  <field_contact>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_contact>
  <field_location>
    <item>
      <value><![CDATA[Room C0903, CODA]]></value>
    </item>
  </field_location>
  <field_sidebar>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_sidebar>
  <field_phone>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_phone>
  <field_url>
    <item>
      <url><![CDATA[]]></url>
      <title><![CDATA[]]></title>
            <attributes><![CDATA[]]></attributes>
    </item>
  </field_url>
  <field_email>
    <item>
      <email><![CDATA[]]></email>
    </item>
  </field_email>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <links_related>
          <item>
        <url>https://gatech.zoom.us/my/mingxuanyao</url>
        <link_title><![CDATA[Zoom link]]></link_title>
      </item>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>434381</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[ECE Ph.D. Dissertation Defenses]]></item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>1788</tid>
        <value><![CDATA[Other/Miscellaneous]]></value>
      </item>
      </field_categories>
  <field_keywords>
          <item>
        <tid>100811</tid>
        <value><![CDATA[Phd Defense]]></value>
      </item>
          <item>
        <tid>1808</tid>
        <value><![CDATA[graduate students]]></value>
      </item>
      </field_keywords>
  <field_userdata><![CDATA[]]></field_userdata>
</node>
