Independent Security Research
Request for Comments: 2026
Category: Experimental
H. R. Joshi
Mon(IoT)r Lab · Northeastern
Boston · April 2026
Subject of Elevation

Het Rutul Joshi

security researcher · systems engineer · हेत

Status of This Memo

I'm a security researcher working where internet measurement meets embedded systems — and the privacy of people who never agreed to be measured. I've hardened LIDAR firmware on aerospace hardware and exposed how smart TVs fingerprint the people who buy them.

Abstract

M.S. Computer Science at Northeastern (Khoury College), 4.0 GPA, graduating May 2027. Research apprentice in the Mon(IoT)r Lab under Prof. David Choffnes. One CRC Press book chapter, one Government of India patent, and measurement work across network privacy, EV-charging security, and the attack surface of AI agents. I founded Mukti, among the largest student open-source communities in India.

[Joshi]  ·  Experimental  ·  [Page 1]
[Joshi]  ·  Experimental  ·  [Page 2]
1.

Introduction

I learn systems by taking them apart. That instinct turned a few weekend hackathons into Mukti — one of the largest student FOSS communities in India, with 1,600+ students mentored. Everything below is the same instinct applied to systems people are forced to trust without being asked.

2.

Affiliations & trajectory

Northeastern University — Mon(IoT)r Lab

graduate research apprentice · adv. Prof. David Choffnes

I audit blackbox systems across twelve retail smart TVs on eight operating systems — how the firmware fingerprints buyers, and whether the opt-out switches do anything at all. Mon(IoT)r Lab ↗

IIT Bombay — Trust Lab (ONYX)

visiting researcher · adv. Devashish Gosain & Piyush Kumar Sharma

First empirical measurement of tunnel-based reverse-proxy services (Ngrok, Cloudflared, and peers) across distributed vantage points — their hidden topology, privacy implications, and viability as Tor relays. Lead author. Gosain ↗ · Sharma ↗

ISRO — Indian Space Research Organisation

systems & software security intern

I designed and hardened a communication protocol for LIDAR sensor data on embedded aerospace hardware — memory safety and a verified secure-boot chain, where failure means losing a satellite's eyes.

Ramaiah Institute of Technology

teaching assistant · network security

I lectured 120+ students on network security and data communication — ARP poisoning, IPv6 MITM, Snort, SambaCry — with labs that made them break the concept before trusting it.

[Joshi]  ·  Experimental  ·  [Page 3]
3.

Publications & patents

Cryptographic Bastions Published

book chapter

Cloud security, access control, and encryption primitives. Taylor & Francis ↗

ChargeGuard — DDoS mitigation for EV charging Patent

kernel-level detection · TinyML + eBPF

Early detection and in-kernel mitigation of DDoS against EV charging infrastructure, built on the Kavaach OCPP testbed.

OCPP 1.6 vs 2.0.1 — a security analysis Under review

threat exposure index · profile-downgrade attack

Why the newer, TLS-mandating revision can end up more interceptable in practice, plus a quantitative index for reasoning about the gap.

Smart-TV Privacy audit Under review

12 TVs · 8 operating systems

Which opt-outs are honored, which keep transmitting regardless, and what leaks out the side channels.

Tunnel & reverse-proxy measurement Under review

13 services · ~2,000 crowdsourced probes

A distributed-systems characterization of expose/tunnel services across a large probe campaign.

[Joshi]  ·  Experimental  ·  [Page 4]
4.

Selected systems

things I take apart: televisions, chargers, locks, satellites.

sys-01 · measurement

Distributed 20-node platform

python · ~8K LOC · 2+ TB/day

The measurement backbone behind the tunnel and reverse-proxy studies — vantage points, orchestration, and a parallel collection pipeline.

sys-02 · agent security

AI Agent Security Mesh

mcp-aware reverse proxy · semantic DLP

A reverse proxy that understands the Model Context Protocol and applies semantic data-loss prevention between an agent and the tools it reaches.

sys-03 · agent security

WhisperBridge

tor-routed local LLM · PII anonymization

Multi-agent prompt-injection defense that treats all fetched web content as untrusted before it reaches the model.

sys-04 · cloud security

EgressProbe

go · kubernetes egress auditor

Audits Kubernetes egress — what a workload can actually reach versus what its network policy claims to allow.

sys-05 · tooling

paperlab

fastapi · ollama · fully local

A local AI research workbench for reviewing measurement papers — reviewer personas, a fact-check pipeline, self-hosted search, all on a 16GB laptop.

sys-06 · covert channels

SSHRead Under review

a channel where none should exist

A covert channel riding a service deployed across most of the internet — no session, no data plane, no signature. Mechanism withheld pending peer review.

sys-07 · ev security

Kavaach

ocpp testbed · python · rpi

The de-facto OCPP testbed replicating real EV charging stations — SYN floods, billing exploits, kernel-level mitigation benchmarks.

sys-08 · wifi security

Sanjay

cli · scapy

Detects malicious Wi-Fi — Evil Twin, Honeypot, Deauth — through active and passive scanning.

[Joshi]  ·  Experimental  ·  [Page 5]
5.

Protocol support — skills

LanguagesPythonGoCBashJavaScriptSQL
Systems & infraLinuxeBPFKubernetesDockerPodmanAWS / S3embedded / RPi
MeasurementtcpdumpWiresharkScapyZeekmitmproxyTrancoOONIGlobalping
SecurityARP / IPv6 MITMSnort IDSsecure bootreverse engineeringOCPPMQTTTLSfuzzing
ML & agentsTinyMLlocal LLMs (Ollama)embeddingsmulti-agent / MCPprompt-injection defense
[Joshi]  ·  Experimental  ·  [Page 6]
6.

Honors & distinctions

Khoury Graduate Research Apprenticeship

Research on ACR systems, smart-TV privacy, and network fingerprinting.

fwd:cloudsec — Scholarship

Selected for a scholarship worth $1000. fwdcloudsec.org ↗

Founder — Mukti FOSS Community

One of the largest student open-source communities in India. 1,600+ students mentored.

Top Speaker — FOSSMeet '24 & '25

Workshops and talks on digital privacy, anonymity, and security threats. fossmeet.in ↗

Patent — ChargeGuard, Gov. of India

DDoS detection and kernel-level mitigation for EV charging infrastructure.

Book chapter — CRC Press

Cryptographic Bastions, on cloud security and encryption primitives.

7.

Authors' addresses

Let's build something resilient - FOSS, system architecture, or anything security.