<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE resume PUBLIC "-//Serge Egelman//DTD Resume 1.5.1//EN"
  "http://xmlresume.sourceforge.net/dtd/resume.dtd">

<resume id="x9281cp35">

  <header>
    <name id="s.egelman">
      <firstname>Serge</firstname>
      <surname>Egelman</surname>
    </name>
    <address>612 S. Dallas Avenue	
		Pittsburgh, PA 15217
USA</address>
    <contact>
      <phone location="mobile">(434) 227-1337</phone>
      <email>serge@guanotronic.com</email>
    </contact>
  </header>


  <academics>
    <degrees>
			<degree>
				<level>PhD student</level>
				<major>Computation, Organizations, and Society</major>
				<institution>School of Computer Science, Carnegie Mellon University</institution>
				<date>
					<month>Expected May</month><year>2009</year>
				</date>
			</degree>
      <degree>
				<level>BS</level>
				<major>Computer Engineering</major>
				<date>
				  <month>May</month>
				  <year>2004</year>
				</date>
				<institution>School of Engineering and Applied Science, University of Virginia</institution>
		  </degree>
    </degrees>
  </academics>


  <pubs>
		<pub>
			<artTitle>P3P Deployment on Websites</artTitle>
			<author>Lorrie Cranor</author>
			<author name="s.egelman"/>
			<author>Steve Sheng</author>
			<author>Aleecia McDonald</author>
			<author>Abdur Chowdhury</author>
			<bookTitle>To be published in Electronic Commerce Research and
			Applications</bookTitle>
			<date>
				<year>2008</year>
			</date>
		</pub>
		<pub>
			<artTitle><link href="http://www.guanotronic.com/~serge/chi1210-egelman.pdf">You've Been Warned: An Empirical Study on the Effectiveness of
			Web Browser Phishing Warnings</link></artTitle>
			<author name="s.egelman"/>
			<author>Lorrie Cranor</author>
			<author>Jason Hong</author>
			<bookTitle>CHI '08: Proceedings of the SIGCHI conference on Human Factors in Computing Systems (Best Paper Nominee)</bookTitle>
			<date>
				<year>2008</year>
			</date>
		</pub>
		<pub>
			<artTitle>
				<link
				href="http://weis2007.econinfosec.org/papers/57.pdf">The Effect of
				Online Privacy Information on Purchasing Behavior: An Experimental
				Study</link>
			</artTitle>
			<author>Janice Tsai</author>
			<author name="s.egelman"/>
			<author>Lorrie Cranor</author>
			<author>Alessandro Acquisti</author>
			<bookTitle>Workshop on the Economics of Information Security (WEIS)</bookTitle>
			<date>
				<month>June</month>
				<year>2007</year>
			</date>
		</pub>
		<pub>
			<artTitle>
				<link
				href="http://doi.acm.org/10.1145/1240866.1241089">Security User Studies:
				Methodologies and Best Practices</link>
			</artTitle>
			<author name="s.egelman"/>
			<author>Jen King</author>
			<author>Robert C. Miller</author>
			<author>Nick Ragouzis</author>
			<author>Erika Shehan</author>
			<bookTitle>CHI '07 Extended Abstracts on Human Factors in Computing
			Systems</bookTitle>
			<date>
				<month>April</month>
				<year>2007</year>
			</date>
		</pub>
		<pub>
			<artTitle>
				<link
				href="http://lorrie.cranor.org/pubs/toolbars.html">Phinding Phish: An
				Evaluation of Anti-Phishing Toolbars</link>
			</artTitle>
			<author>Lorrie Faith Cranor</author>
			<author name="s.egelman"/>
			<author>Jason Hong</author>
			<author>Yue Zhang</author>
			<bookTitle>NDSS: Proceedings of the ISOC Symposium on Network and
			Distributed System Security.  Originally published as CyLab Technical
			Report CMU-CYLAB-06-018</bookTitle>
			<date>
				<month>February</month>
				<year>2007</year>
			</date>
		</pub>
		<pub>
			<artTitle>
				<link
				href="http://doi.ieeecomputersociety.org/10.1109/MSP.2006.165">
				Conference Report: SOUPS 2006</link>
			</artTitle>
			<author>Janice Tsai</author>
			<author name="s.egelman"/>
			<bookTitle>IEEE Security &amp; Privacy</bookTitle>
			<date>
				<month>November/December</month>
				<year>2006</year>
			</date>
		</pub>
    <pub>
      <artTitle>
        <link href="http://lorrie.cranor.org/pubs/icec06.html">
				An Analysis of P3P-Enabled Web Sites among Top-20 Search Results</link>
      </artTitle>
      <author name="s.egelman"/>
			<author>Lorrie Faith Cranor</author>
			<author>Abdur Chowdhury</author>
			<bookTitle>Proceedings of the Eighth International Conference on
			Electronic Commerce</bookTitle>
      <date>
	<month>August</month>
	<year>2006</year>
      </date>
    </pub>
		<pub>
			<artTitle>
				<link
				href="http://cups.cs.cmu.edu/soups/2006/proceedings/p133_gideon.pdf">Power
				Strips, Prophylactics, and Privacy, Oh My!</link>
			</artTitle>
			<author>Julia Gideon</author>
			<author name="s.egelman"/>
			<author>Lorrie Cranor</author>
			<author>Alessandro Acquisti</author>
			<bookTitle>Proceedings of the 2006 Symposium On Usable Privacy and
			Security</bookTitle>
			<date>
				<month>July</month>
				<year>2006</year>
			</date>
		</pub>
		<pub>
			<artTitle>
				<link href="http://cups.cs.cmu.edu/pubs/chi06.pdf">Studying The Impact
				of Privacy Information on Online Purchase Decisions</link>
			</artTitle>
			<bookTitle>Workshop on Privacy and HCI: Methodologies for Studying Privacy
			Issues at CHI2006</bookTitle>
			<author name="s.egelman"/>
			<author>Janice Tsai</author>
			<author>Lorrie Cranor</author>
			<author>Alessandro Acquisti</author>
			<date>
				<month>April</month>
				<year>2006</year>
			</date>
		</pub>
    <pub>
      <artTitle>
        <link href="http://lorrie.cranor.org/pubs/dmv.html"> The Real ID Act:
				Fixing Identity Documents with Duct Tape</link>
      </artTitle>
			<bookTitle>I/S: A Journal of Law and Policy for the Information
			Society</bookTitle>
      <author name="s.egelman"/>
			<author>Lorrie Faith Cranor</author>
      <date>
	<month>Fall/Winter</month>
	<year>2005</year>
      </date>
    </pub>
		<pub>
			<artTitle>
				<link
				href="http://www.usenix.org/publications/login/2005-12/openpdfs/sec05summaries.pdf">Conference
				Report: 14th USENIX Security Symposium</link>
			</artTitle>
			<author>Kevin Butler</author>
			<author>Ming Chow</author>
			<author>Jonathon Duerig</author>
			<author name="s.egelman"/>
			<author>Boniface Hicks</author>
			<author>Francis Hsu</author>
			<author>Stefan Kelm</author>
			<author>Mohan Rajagopalan</author>
      <bookTitle>;login:</bookTitle>
			<date><month>December</month><year>2005</year></date>
		</pub>
    <pub>
      <artTitle>
        <link href="http://www.guanotronic.com/~serge/dimacs.pdf">Report on
				DIMACS Workshop and Working Group on Usable Privacy and Security
				Software</link>
      </artTitle>
      <author name="s.egelman"/>
			<author>Ponnurangam Kumaraguru</author>
      <date>
	<month>January</month>
	<year>2005</year>
      </date>
    </pub>
    <pub>
      <artTitle>
        <link
				href="http://www.guanotronic.com/~serge/sec04reports.pdf">Conference
				Report: 13th USENIX Security Symposium</link>
      </artTitle>
      <bookTitle>;login:</bookTitle>
			<author>Alvin AuYoung</author>
			<author>Eric Cronin</author>
			<author>Marc Dougherty</author>
      <author name="s.egelman"/>
			<author>Rachel Greenstadt</author>
			<author>Stefan Kelm</author>
			<author>Zhenkai Liang</author>
			<author>Chad Mano</author>
			<author>Nick Smith</author>
			<author>Ashish Raniwala</author>
			<author>Tara Whalen</author>
			<author>Wei Xu</author>
      <date>
	<month>December</month>
	<year>2004</year>
      </date>
    </pub>
    <pub>
      <artTitle>
        <link href="http://www.guanotronic.com/~serge/login.pdf">Suing Spammers
				for Fun and Profit</link>
      </artTitle>
      <bookTitle>;login:</bookTitle>
      <author name="s.egelman"/>
      <date>
	<month>April</month>
	<year>2004</year>
      </date>
    </pub>

    <pub>
      <author name="s.egelman"/>
      <date>
	<year>2000</year>
      </date>
      <bookTitle>Editorial on Linux.com</bookTitle>
			<artTitle><link
			href="http://linux.omnipotent.net/article.php?article_id=10772">Is The OSS
			Model Failing?</link></artTitle>
    </pub>

		<pub>
			<author name="s.egelman"/>
			<date>
				<year>1999</year>
			</date>
			<bookTitle><link
			href="http://search.barnesandnoble.com/bookSearch/isbnInquiry.asp?isbn=0672315734">Peter
			Norton's Complete Guide to Linux</link></bookTitle>
			<publisher>Macmillan Computer Publishing</publisher>
			<artTitle>Installation</artTitle>
		</pub>
		<pub>
			<author name="s.egelman"/>
			<date>
				<year>1999</year>
			</date>
			<bookTitle><link
			href="http://search.barnesandnoble.com/bookSearch/isbnInquiry.asp?isbn=0672315734">Peter
			Norton's Complete Guide to Linux</link></bookTitle>
			<publisher>Macmillan Computer Publishing</publisher>
			<artTitle>User Administration</artTitle>
		</pub>
  </pubs>

  <skillarea targets="technology">
    <title>Skills</title>
		<skillset>
			<title>Research Interests</title>
			<skill>Software engineering</skill>
			<skill>Privacy technologies</skill>
			<skill>Security technologies</skill>
			<skill>Usability</skill>
		</skillset>
		<skillset>
			<title>Technical Skills</title>
			<skill>Perl</skill>
			<skill>C/C++</skill>
			<skill>Java</skill>
			<skill>PHP</skill>
			<skill>Bourne shell scripting</skill>
			<skill>C#</skill>
			<skill>HTML</skill>
		</skillset>
		<skillset>
			<title>System Administration</title>
			<skill>UNIX (primarily *BSD, Linux, OS X)</skill>
			<skill>Windows</skill>
			<skill>Apache</skill>
			<skill>MySQL</skill>
			<skill>Sendmail</skill>
			<skill>CUPS</skill>
		</skillset>

  </skillarea>


  <history>
    <job targets="technology">
      <jobtitle>Researcher</jobtitle>
      <period><from><date><month>June</month><year>2004</year></date></from>
				<to><present/></to></period>
      <employer>Carnegie Mellon University</employer>
			<description>
				<para>Currently a PhD student in the Computation, Organizations, and
				Society program at CMU, I am advised by Prof. Lorrie Cranor.  I work
				primarily on privacy policy and usable privacy and security systems.
				Current areas that I work in include creating more effective web browser
				trust indicators, creating usable P3P tools, Internet
				anonymity, and detection and prevention of phishing attacks.  My
				accepted dissertation proposal was entitled "Trust Me: Designing Trustworthy
				Trust Indicators."  My committee consists of Lorrie Cranor (chair), Jim
				Herbsleb, Jason Hong, and Steve Bellovin (Columbia U.).</para>
			</description>
    </job>
    <job targets="technology">
      <jobtitle>Research Intern</jobtitle>
      <period><from><date><month>June</month><year>2006</year></date></from>
				<to><date><month>September</month><year>2006</year></date></to></period>
      <employer>Xerox PARC</employer>
			<description>
				<para>During the summer of 2006 I worked in the Computer Science Lab
				(CSL) at PARC.  My main focus was on malware detection using
				virtualization.  The project involved creating a Windows kernel driver
				that would intercept system calls (like a rootkit) on the guest
				operating system, and then reporting back the state of the guest to the
				host.  Additional work focused on writing security mechanisms to protect
				code running under a virtual machine.</para>
			</description>
    </job>

    <job targets="technology">
      <jobtitle>Researcher</jobtitle>
      <period><from><date><month>May</month><year>2003</year></date></from>
				<to><month>December</month><year>2003</year></to></period>
      <employer>University of Virginia</employer>
			<description>
				<para>I worked as a researcher in Professor Jorg Liebeherr's Multimedia
				Networks Group, in the Department of Computer Science. Specifically I
				was working on Hypercast, which is an application-layer multicast overlay
				network. I was involved in designing and implementing an encryption and
				authentication mechanism, content delivery optimizations, as well as an
				XML-based configuration utility. All of this work was done in Java under
				both Linux and Windows.</para>
			</description>
    </job>

    <job targets="technology">
      <jobtitle>Researcher</jobtitle>
      <date><year>2002</year></date>
      <employer>University of Virginia</employer>
			<description>
				<para>I worked as a researcher in Professor John Knight's Network
				Survivability Research Group, in the Department of Computer Science.
				This group mainly worked on creating fault resistant networks that could
				detect and recover from attacks. My main role was developing a network
				visualizer that took inputs from a variety of sensors (mainly intrusion
				detection systems and packet loggers), and made it easy for a network
				administrator to literally see all the data and thus be warned about
				irregularities. Most of the work was done in Java using VTK to program
				the OpenGL front-end.</para>
			</description>
    </job>

    <job targets="technology">
      <jobtitle>Developer</jobtitle>
      <period><from><date><year>2000</year></date></from><to><date><year>2001</year></date></to></period>
      <employer>Tovaris: The Digital Identity Company</employer>
			<description>
				<para>I worked part time doing development in C++ for the Mithril Secure
				Server (an encrypted email solution). I mostly wrote CGI code for
				administering the servers from a front-end, although I did do some work
				on the back-end. This involved getting very familiar with the OpenSSL
				libraries. Most of the development was done under OpenBSD, using g++,
				though I also did some work in perl.</para>
			</description>
    </job>

    <job targets="technology">
      <jobtitle>System Administrator</jobtitle>
      <period><from><date><year>2000</year></date></from><to><date><year>2002</year></date></to></period>
      <employer>EarthSystems.org</employer>
			<description>
				<para>I worked remotely as a part-time system administrator. My duties
				included maintaining DNS, Apache, and Sendmail under FreeBSD. I also
				troubleshooted the systems and answered technical questions.</para>
			</description>
    </job>

    <job targets="technology">
      <jobtitle>Technical Support / Developer / System Administrator</jobtitle>
      <period><from><date><year>1999</year></date></from><to><date><year>2000</year></date></to></period>
      <employer>Broadband Network Services, Inc.</employer>
			<description>
				<para>I handled all of the technical support questions via telephone and
				e-mail. I maintained and administrated all of our databases using MySQL.
				This included setting up new database customers, adding and removing
				databases, and maintaining MySQL. I used PHP, Perl, and bash to write
				scripts to aid in system administration and to automate other common
				tasks. I handled most of the website development that we were hired to
				do; this included writing scripts, HTML, and database management. My
				administrative responsibilities included maintaining our primary and
				secondary DNS, sendmail, apache, and PHP. I also aided in creating and
				removing accounts, setting up new virtual hosts, setting up and
				maintaining network monitoring, and maintaining hardware; this included
				building and configuring computers.</para>
			</description>
    </job>

    <job targets="technology">
      <jobtitle>Author</jobtitle>
			<date><year>1999</year></date>
      <employer>Waterside Prodctions, Inc.</employer>
			<description>
				<para>I was hired by Waterside Productions (Peter Norton's literary
				agent) to write two chapters for their book, Peter Norton's Complete
				Guide to Linux. The chapters were entitled "Installation" and "User
				Administration", the book was published in October of 1999 by Macmillan
				Computer Publishing.</para>
			</description>
    </job>

  </history>

  <memberships>
    <title>Professional Memberships and Activities</title>
		<membership>
			<title>Invited Expert</title>
			<description>Web Security Context (WSC) Working Group</description>
			<organization>World Wide Web Consortium (W3C)</organization>
				<period>
				<from><date><year>2007</year></date></from>
				<to><present/></to>
				</period>
		</membership>
		<membership>
			<title>Poster Session Co-Chair</title>
			<organization>Anti-Phishing Working Group eCrime Researchers Summit</organization>
				<date><year>2007</year></date>
		</membership>
		<membership>
			<title>Program Committee</title>
			<organization>CHI 2007 Workshop - Security User Studies: Methodologies and
			Best Practices</organization>
				<date><year>2007</year></date>
		</membership>
		<membership>
			<title>Program Committee</title>
			<organization>Computers, Freedom, and Privacy (CFP) Conference</organization>
				<date><year>2006</year></date>
		</membership>
		<membership>
			<title>Legislative Concerns Chair, Board of Directors</title>
			<organization>National Association of Graduate and Professional Students
			</organization>
			<period>
				<from><date><year>2006</year></date></from>
				<to><present/></to>
			</period>
		</membership>
		<membership>
			<title>Vice President for External Affairs</title>
			<organization>Carnegie Mellon University Graduate Student
			Assembly</organization>
			<period>
				<from><date><year>2006</year></date></from>
				<to><present/></to>
			</period>
		</membership>
		<membership>
			<title>Discussion Sessions Chair</title>
			<organization>Symposium on Usable Privacy and Security (SOUPS)</organization>
				<date><year>2005</year></date>
		</membership>
		<membership>
			<title>Invited Expert</title>
			<description>The Platform for Privacy Preferences (P3P) 1.1 Working Group</description>
			<organization>World Wide Web Consortium (W3C)</organization>
				<period>
				<from><date><year>2004</year></date></from>
				<to><date><year>2006</year></date></to>
				</period>
		</membership>

    <membership>
			<title>Member</title>
      <organization>Association for Computing Machinery</organization>
				<period>
				<from><date><year>2004</year></date></from>
				<to><present/></to>
				</period>
    </membership>
		<membership>
			<title>Member</title>
			<organization>USENIX</organization>
				<period>
				<from><date><year>2004</year></date></from>
				<to><present/></to>
				</period>
		</membership>
    <membership>
			<title>Member</title>
      <organization>American Civil Liberties Union</organization>
				<period>
				<from><date><year>2001</year></date></from>
				<to><present/></to>
				</period>
    </membership>

  </memberships>

  <awards><title>Awards</title>
    <award targets="technology"><title>Tor Graphical User Interface Design
		Competition</title>
	  <date><year>2006</year></date>
		<description><para>
		Phase 1 Overall Winner</para></description>
   </award>
    <award targets="technology"><title>USENIX Student Stipend Recipient</title>
		<organization>USENIX</organization>
	  <date><year>2005</year></date>
		<description><para>I was awarded a student stipend to attend the 2005 USENIX
		Security Conference in Baltimore, MD.</para></description>
   </award>
    <award targets="technology"><title>USENIX Student Stipend Recipient</title>
		<organization>USENIX</organization>
	  <date><year>2004</year></date>
		<description><para>I was awarded a student stipend to attend the 2004 USENIX
		Security Conference in San Diego, CA.</para></description>
   </award>
    <award targets="technology"><title>USENIX Student Stipend Recipient</title>
		<organization>USENIX</organization>
	  <date><year>2003</year></date>
		<description><para>I was awarded a student stipend to attend the 2003 USENIX
		Security Conference in Washington, DC.</para></description>
   </award>
	 <award><title>University of Virginia Dean's List of Scholars</title>
	 <description><para>I was included on the Spring 2003  and 2004 Dean's List of Scholars.
	 </para></description></award>
	 <award><title>Publisher's Clearing House Finalist</title>
	 <description><para>I may already be a winner.</para></description>
	 </award>
  </awards>





  <!-- <interests>
    <title>Interests</title>

		<interest>
			<title>University of Virginia Quizbowl Team</title>
			<description>
				<para>Along with the rest of the team, we travel to academic trivia
				tournaments all across the country.</para>
			</description>
		</interest>
    <interest>
      <title>University of Virginia RoboCup Team</title>
      <description>
        <para>This is a student run project in the Department of Computer
				Science. The goal is to create an artificially intelligent soccer team
				(which is computer simulated), which plays each year against other teams
				from around the world at an international competition.</para>
      </description>
    </interest>

    <interest><title>University of Virginia Solar Car Team</title>
			<description>
				<para>I was part of the electrical group and was involved in designing and
				implementing a telemetry tracking system and the auxiliary
				systems.</para>
			</description>
		</interest>
    <interest><title>Charlottesville Unix Users Group</title>
			<description>
				<para>Active member in the group, I have given multiple lectures.</para>
			</description></interest>
		<interest>
			<title>Office of U.S. Senator Paul D. Wellstone</title>
			<description><para>Worked as an intern in the St. Paul office of U.S.
			Senator Paul Wellstone (D-MN). My responsibilities
			included writing letters to constituents, answering phones, and reviewing
			documents.</para></description>
		</interest>
  </interests>-->


  <lastModified>
    <date>
      <month>October</month>
      <year>2007</year>
    </date>
  </lastModified>

</resume>
