Security operations
SOC work, SIEM tuning, incident response and vulnerability management on real production estates.
Security operations and machine learning are usually treated as separate trades. I work where they meet.
SOC work, SIEM tuning, incident response and vulnerability management on real production estates.
Network defence and IDS/IDPS, from Suricata gateways to deep-learning detectors.
Adversarial machine learning, hardening detection models against attacks designed to fool them.
I ran production security operations on the Microsoft stack for one of Sri Lanka's largest insurers, and owned the ISO/IEC 27001:2022 programme end to end.
Sri Lanka's first ISP. I worked a 24/7 shift-based NOC defending the islandwide backbone and the secure VPN services that keep banks and industrial customers connected.
Technical research and documentation across assigned projects. From September 2022 I led the intern group and coordinated tasks across the team.
Research projects, security tooling and the archives I keep. Each one carries the reasoning, not just a screenshot.
An MSc dissertation on adversarial training for deep-learning intrusion detection on the Controller Area Network. The attack that breaks the model is also the material you train it on.
A local-LLM OSINT pipeline that turns scattered recon into one prioritised, provenance-tracked brief. One scan of a low-value domain returns around 960 findings. Collection succeeds; judgment does not.
A Raspberry Pi 5 sits inline with a home's traffic and unifies Nmap, UFW and Suricata behind a deliberately simple mobile app. Protection moves from the endpoint to the gateway.
A passive Certificate Transparency audit of my own domain surfaced 600+ historical records and a spam-issuance pattern predating my ownership. The work was separating the one actionable line from the noise.
A living archive of antiques, books and historical objects, each documented with provenance, condition and valuation notes. Schema-first, like everything else I keep.
A working culinary archive of Sri Lankan home cooking alongside dishes gathered from elsewhere. Effort, diet, heat, occasion, and the story behind each one.
MSc dissertation, University of Plymouth. Sole researcher, supervised by Dr. Shaymaa Al-Juboori.
Modern vehicles run on the Controller Area Network, a protocol built for reliability, not security, with no native encryption or authentication. Deep-learning intrusion detection is the leading defence, and it inherits two crippling weaknesses.
Imperceptible noise added to network traffic can flip a malicious packet to "benign".
Strip CICIoV2024 of its 99.75% duplicate records and a 1D-CNN collapses to F1 below 0.55, while a lightweight Random Forest stays stable.
Can the very technique used to attack these models be repurposed to fix them?
My hypothesis is that adversarial training, folding FGSM- and PGD-crafted examples back into the training set, acts as targeted data augmentation. It manufactures the hard, unique examples that strict de-duplication removes, and finally lets a deep model outperform the Random Forest baseline in realistic, data-scarce conditions.
Strip the dataset back to unique signatures, measure how far the deep model falls, attack it, then fold those attacks back in as training data and re-measure.
De-duplicate CICIoV2024 down to unique CAN-bus attack signatures, recreating the regime where deep models are known to fail.
Quantify how far a 1D-CNN degrades against a Random Forest once denied redundant training data.
Generate FGSM and PGD evasion attacks with the Adversarial Robustness Toolbox.
A Multi-Strategy Adversarial Training framework that reuses the attacks as hard training examples.
Measure clean accuracy, adversarial accuracy, false-positive rate and compute cost across attack budgets.
A positive result offers a blueprint for deep learning in any data-sensitive domain where privacy law forces strict de-duplication, such as medical and financial forensics. It also speaks to automotive standards like UN Regulation No. 155.
The work is in progress and nothing here is a published result yet. The code and findings are to be open-sourced and submitted to peer-reviewed venues.
A book on the mathematics behind machine learning, rebuilt from first principles for anyone shut out by the notation. Part 1, linear algebra, is complete at 12 chapters.
Multi-strategy adversarial training for deep-learning intrusion detection on the CAN bus, evaluated on a strictly de-duplicated CICIoV2024. To be open-sourced and submitted to peer-reviewed venues.
Measuring faithfulness, prioritisation quality and provenance retention when a small local model synthesises structured, multi-tool OSINT. Existing work evaluates prose; Glean's input is normalised entity records.
Before a symbol appears, there is a picture. Before the picture, there is a problem you can actually feel.
A book on the mathematics behind machine learning, rebuilt from first principles for anyone shut out by the notation. Part 1, linear algebra, is complete at 12 chapters.
I work at the intersection of cyber security and machine learning. My MSc dissertation explores adversarial training for deep-learning intrusion detection on the Controller Area Network, the nervous system of every modern car, using the CICIoV2024 dataset and techniques from the Adversarial Robustness Toolbox.
Before Plymouth I built NetEAGLE, a Raspberry Pi network gateway combining a Flask API, mobile app, Nmap, UFW and Suricata into a single home-network defender. Earlier still, I served as a Cyber Security Engineer at Union Assurance PLC and an Associate Engineer at Lanka Communications.
When I am not reading papers I am cataloguing antiques in The Meridian, documenting Sri Lankan and global recipes in Rampe, and refining the database that powers this site.
Whether you need an engineer on your team, a collaborator on research, or a consultant on a hard security problem, my inbox is open.