Maryam Rostamipoor

Maryam Rostamipoor

Research Assistant at Hexlab

Department of Computer Science, Stony Brook University

About

I am a Ph.D. candidate in Computer Science at Stony Brook University, advised by Dr. Michalis Polychronakis, and a Security Researcher with over 10 years of combined research and industry experience in cloud, container, and application security. My work focuses on scalable defenses against data leakage in cloud-native and serverless environments, with expertise in program analysis, vulnerability discovery, and secure software design. I leverage Python, Go, Rust, Kubernetes, and CodeQL to design and implement security tools, applying them in projects on Kubernetes secret protection, serverless memory safety, and container hardening—translating cutting-edge research into practical security solutions.

. I have a proven record of building tools for Kubernetes secret protection, serverless memory safety, and container hardening—translating cutting-edge research into practical security solutions.

I designed and developed KubeKeeper, a framework that prevents Kubernetes Secret leakage by applying encryption and fine-grained access control. I also created LeakLess, a selective in-memory encryption approach for developer-annotated sensitive data in serverless platforms, mitigating memory disclosure and transient execution attacks. In the area of software security and container hardening, I developed Confine, a binary analysis tool that automatically generates fine-grained Seccomp profiles by extracting system call argument values to help reduce container attack surfaces.

Prior to my Ph.D., I was the Head of Software Security at Sadad Electronic Payment Company, where I led a team of security engineers in penetration testing, secure coding, and enhancing the security of web and mobile applications.

I’m passionate about protecting user data and building secure systems, and I’m driven by the challenge of solving real-world cybersecurity problems. Outside of research, I love cooking, yoga, working out, and spending time with friends—it keeps me grounded and inspired.

Interests

  • Cloud Computing & Kubernetes Security
  • Binary Analysis & System Call Filtering
  • Web & Mobile Application Penetration Testing

Education

  • Ph.D. in Computer Science, 2026

    Stony Brook University

  • M.S. in Computer Science, 2023

    Stony Brook University

  • M.E. in Information Security Engineering, 2013

    Amirkabir University of Technology

  • B.E. in Computer Engineering, 2011

    Shiraz University of Technology

News

2025

  • April: Awarded the Catacosinos Fellowship for academic excellence and research potential
  • February: KubeKeeper accepted to IEEE EuroS&P 2025
  • February: Selected for the 2025 CRA-WP Grad Cohort for Women & IDEALS
  • January: Awarded the 2025 Internet Society NDSS Fellowship

2024

  • August: LeakLess accepted to NDSS 2025

2023

  • August: Awarded Graduate Assistance in Areas of National Need (GAANN) Fellowship
  • August: Awarded Graduate Students in STEM Leadership & Life Design Fellowship

2022

  • September: Confine accepted to the Computers & Security Journal

2020

  • October: Accepted a full funded Ph.D. offer from Stony brook University