Hello, I'm
Security Engineer professional. I work on Software and Application Security, performing pentesting, reverse engineering, and ensure secure code practices.
Chinmay Lohani Developer

Chinmay Lohani

Security Engineer with interest in Application Security and experience in Secure Software Development.

ABOUT ME

I am a Security Engineer currently pursuing Masters in Security Informatics from Johns Hopkins University. I am a technology enthusiast with interest in Application Security, Pentesting, Reverse Engineering and using Machine Learning for Security.

I have a good foundation in the Cybersecurity Frameworks namely, NIST, MITRE, OWASP, and have worked with tools like Burpsuite, Owasp ZAP, Wireshark, Metasploit, Ghidra, NMap, OpenSSL, Lynis, Microsoft Threat Modeling Tool, Valgrind, etc and have implemented proof-of-exploitations for games like Duke Nukem.

I have Bachelor in Technology from IIITS, India in Computer Science and Engineering and am apt in Secure Software Development Life Cycle (SDLC) integration and Cloud Computing. I am an active CTF participant and a Kaggle Contributor. I am apt in competitive programming in C/C++, and Python languages.

PROJECTS

ALLPUBLISHEDSECURITYMLWEBBLOCKCHAIN
PUBLISHED
SECURITY
ML

Assuring Safe Navigation & Network
Operations of Autonomous Ships

Presented at IEEE CCWC 2024, I implemented an ML Security Monitor for battleship infrastructure. The model achieved 98.5% accuracy in detecting cyber threats in ICS networks, validating its effectiveness through penetration tests on power systems and weapon controls.

Created at: November 30, 2023
SECURITY

Penetration Testing and Vulnerability Assessment
of OpenEMR

Performed security testing of OpenEMR, identifying vulnerabilities like SQLi, DoS, buffer overflows and XSS. Used tools including Burp Suite, OWASP ZAP, SQLMAP, and Wireshark to detect issues. Documented proof of exploitation along with remediation recommendations.

Created at: October 14, 2023
SECURITY

Angband

Developed proof-of-concept exploit achieving root access by reverse engineering Angband game binary to locate format string vulnerability. Used IDA Pro and GDB to analyze vulnerability and craft input to exploit stack overflow, redirect code execution flow, and open remote shell.

Created at: November 14, 2023
SECURITY

Duke Nukem II

Exploited buffer overflow in Duke Nukem game binary to achieve remote root shell access. Reverse engineered binary using Ghidra to identify vulnerable function and crafted malicious input. Developed proof-of-concept demonstrating arbitrary code execution via shellcode injection and redirecting control flow using buffer overflow technique.

Created at: September 20, 2023
SECURITY

Open-Source Web Server Security Assessment

Conducted threat modeling on an open-source web server using SciTool Understand and Microsoft Threat Modeling Tool. Produced an executive summary detailing risks and employed Ghidra and Veles for reverse engineering, bolstering the system's security posture.

Created at: August 30, 2023
SECURITY
ML

Intrusion Detection System for IoT

Simulated DDoS attack in IoT devices, like flooding on CoAP network using Cooja simulator, leveraged the simulation data to train an ML model for detection of unusual traffic.

Created at: March 24, 2023
ML

Deep Learning based Disease Classifier for X-Rays

Application resulting from Rocketseat's Next Level Week #04. The application allows calculating the company's NPS (Net Promoter Score) through satisfaction surveys sent to users by email.

Created at: December 10, 2023
SECURITY
WEB
BLOCKCHAIN

Blockchain based e-voting System

Designed and built a tamper-proof, decentralized e-voting system on Ethereum blockchain through commit-reveal mechanisms. Hardened system security by building Solidity smart contracts with audited OpenZeppelin libraries, optimized consensus algorithms, IPFS integration and MetaMask identity management resulting in enhanced transparency, scalability, and reduced gas costs by 8%.

Created at: December 1, 2022
ML

Card Fraud Detection

Investigated anonymized card data, identified feature relationships through visualizations, and engineered ensemble models to detect credit card fraud with 99.9% accuracy, reducing false positives by 20%.

Created at: October 24, 2022
WEB
BLOCKCHAIN

OpenZepplin Supply chain

Developed blockchain-based supply chain system using Solidity, OpenZeppelin, Truffle, and Web3, integrating web interfaces for server-chain communication. Enhanced efficiency by 10% and improved security.

Created at: August 16, 2022
WEB

News-Aggregator

Developed a MERN-based web application for integrating news from assorted sources of varying genres by applying several information retrieval techniques, resulting in 30% reduction in similar sentences by applying cosine-based similarity detection.

Created at: February 20, 2022
WEB

IRS Library Manager

Developed an Information-Retrieval System for a large database of books with user-friendly interface using Flask. This gives an easy and extended version to library-management systems built for large scale institutions.

Created at: November 5, 2021
WEB

GATEWAY application for societies

Developed and presented a management system for apartments in the area, facilitating easy communication, complaint and announcement forums, and other utilities to provide a smoother management experience for residents of a community.

Created at: July 12, 2021

EXPERIENCE