Teaching has always been close to my heart — a passion shaped by my mother, who served as a state award–winning teacher in the government school system. Inspired by her dedication and impact, I chose to pursue a life in academia where I could blend learning, discovery, and the joy of guiding future engineers.
My academic journey began with a B.Tech. in Computer Science and Engineering from NIT Calicut, followed by an M.Tech. from the University of Kerala. I then completed my Ph.D. in Computer Science at the University of Hyderabad, with doctoral research carried out at the Center of Excellence in Cyber Security, IDRBT — an institute established by the Reserve Bank of India.
I had the privilege of being mentored by Prof. B. M. Mehtre, a pioneer behind India's first Automated Fingerprint Identification System (AFIS). Over the years, my research has led to publications in Forensic Science International (SCI, Q1) and Signal, Image and Video Processing (SCIE, Q2), as well as multiple Scopus-indexed conference papers and book chapters.
At IDRBT, I led large-scale cyber drills involving more than 25 participants at a time, helping banks improve incident response capabilities in line with RBI directives. My digital forensics experience includes the FRED forensic workstation and tools such as EnCase, Oxygen Forensics, and Paraben SIM analysis suites.
Today, my research spans image forensics and cyber defense analytics—driven by a belief that technology should enable trust, and that education empowers individuals to secure the world they build. Guided by this philosophy, I combine research with hands-on forensic practice, using tools such as Amped FIVE and Amped Authenticate to examine CCTV footage and verify the authenticity of questioned images.
NB: All academic programs completed in Regular Full-Time mode.
Combined across B.Sc.-M.Sc. Forensic Science (Sem III & V) · M.Sc. Cyber Security (Sem III) · M.Sc. Digital Forensics & Information Security (Sem III) · M.Sc. Forensic Science, Specialization III – Forensic Physics & Ballistics (Sem III). Tentative, Odd Sem 2026-27.
Full syllabi for the courses on the timetable above, plus related courses. Evaluation scheme, objectives, units, learning outcomes, and references for each.
| Th | Tu | Pr | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 2 | 0 | 0 | 2 | 2 | 50 00:45 | 50 01:30 | 100 03:00 | 200 |
This course is designed to expose students to real-world security challenges and basic internet security — protecting remote access and local computing devices, and applying tools and utilities to counter network threats and attacks.
Introduction, Computer Security, Threats, Harm, Vulnerabilities, Controls, Authentication, Access Control and Cryptography. Web attacks: Browser Attacks, Web Attacks Targeting Users, Obtaining User or Website Data, Email Attacks. Network Vulnerabilities: vulnerability scanning, open port/service identification, banner/version check, traffic probe, vulnerability probe, examples using OpenVAS and Metasploit. Network vulnerability scanning with Netcat and Socat, plus network sniffers and injection tools.
Network Defence Tools — Firewalls and Packet Filters: firewall basics, packet filter vs. firewall, how a firewall protects a network, packet characteristics to filter, stateless vs. stateful firewalls, NAT and port forwarding. VPN fundamentals. Firewall implementation on Linux and Windows. Snort as an Intrusion Detection System.
Cyber Crimes, types of cybercrime, hacking, attack vectors, cyberspace and criminal behavior, traditional problems associated with computer crime. Introduction to incident response, digital forensics, computer language, network language, and the realms of the cyber world.
Internet Crime and the IT Act: history of the internet, recognizing and defining computer crime, contemporary crimes, computers as targets, contamination/destruction of data. Indian IT Act, 2000. Firewalls and packet filters, password cracking, keyloggers and spyware, viruses and worms, trojans and backdoors, steganography, DoS/DDoS attacks, SQL injection, buffer overflow, attacks on wireless networks.
| Th | Tu | Pr | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 3 | 1 | 0 | 4 | 4 | 50 00:45 | 50 01:30 | 100 03:00 | 200 |
The primary objective is to teach students how to identify and classify various types of cybercrimes occurring in the digital realm; comprehend the fundamental principles and methodologies of Digital Forensics, including data acquisition, analysis, and preservation of digital evidence in accordance with legal standards; and gain insight into the key sections of the IT Act and related laws governing the admissibility of digital evidence in legal proceedings.
Cyber-crime – overview, internal and external, online and offline attacks. Cyber-crime against individuals and organizations – email spoofing, phishing, spamming, unauthorized access, DoS/DDoS, computer sabotage, malware, email bombing, salami attack, software piracy, industrial espionage, crimes on social media, banking frauds, IP frauds.
Digital Forensics – introduction, objective, methodology, rules and services, branches: Live, Disk, Network, Mobile Device Forensics etc.
Incident Response and First Responder at crime scene – role, toolkit, stages, do's and don'ts. Types and sources of digital evidence, collection principles, Best Evidence Rule, forensic readiness, ethics, search/seizure/preservation of volatile and non-volatile evidence, imaging, hashing, deleted data recovery.
IT Act 2000 – objectives, applicability, definitions, amendments; digital signature, electronic records/evidence/governance; IT (Amendment) Act 2008; cyber-crimes under Sections 43(a)-(j), 43A, 65, 66, 66A-66F, 67, 67A, 67B, 70, 70A, 70B, 80 with penalties; penal provisions for phishing, spam, malware, hacking, stalking; relevant sections of Indian Evidence Act.
| Th | Tu | Pr | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 2 | 0 | 0 | 2 | 2 | 50 00:45 | 50 01:30 | 100 03:00 | 200 |
To equip students with the basic and important concepts of incident response, incident response management, and the important steps of incident responses and handling.
Computer Security Incident, key concepts of information security, incident management, purpose, need and goals of incident response, incident response plan, signs/indicators of an incident, incident categories, prioritization, handling, estimating cost, reporting, incident response team roles and responsibilities.
18 steps of incident response/handling: identification, recording, initial response, communicating, containment, response strategy, classification, investigation, data collection, forensic analysis, evidence protection, notifying external agencies, eradication, systems recovery, documentation, damage/cost assessment, lessons learned, review & update policies.
Goals of incident response, response plan, identification, prioritization, handling, cost estimation, reporting, reporting organizations, vulnerability resources.
| L | T | P | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 4 | 0 | 0 | 4 | 4 | 50 01:30 | 50 01:30 | 100 03:00 | 200 |
A comprehensive understanding of forensic voice and video analysis — covering the history and theory of voice production, speaker recognition and profiling techniques, handling and examination of audio evidence, and forensic video examination including processing, authentication, legal admissibility, biometric analysis and CCTV forensics through related case studies.
History of voice analysis, voice production theory, interspeaker/intraspeaker variations, text-dependent/independent recognition, discriminating tests, handling and physical examination of audio recording evidences, marking of speakers, preparation of working copies.
Segregation of speech samples, auditory/spectrographic/automatic recognition techniques, enhancement and normalization, authenticity and integrity, speech signal processing, Fourier analysis, analogue-to-digital conversion, instruments, report writing, admissibility of audio evidence in court.
Definition, scope, significance in crime investigation, collection/handling/preservation of video files, frame extraction, shot-by-shot analysis, video authentication, metadata analysis, hash value generation, biometric analysis, facial biometrics.
Acquisition/handling/preservation of CCTV footage, hash generation, DVR/NVR extraction, chain of custody, authentication and enhancement, forensic tools, legal admissibility.
| Th | Tu | Pr | C | TCH | TA-1/2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 03 | 00 | 00 | 03 | 03 | 25 00:45 | 50 01:30 | 100 03:00 | 200 |
Definition & characteristics, evolution, physical/logical design, IoT components, levels and deployment techniques, applications & domains, enabling technologies, challenges in IoT.
M2M vs IoT, Software Defined Networking (SDN), Network Function Virtualization (NFV), SNMP and its limitations, network operator requirements, H/W and S/W communications (UART, SPI, I2C, JTAG).
Protocol stack for IoT, HTTP, MQTT, XMPP, COAP basics and architectures.
Interoperability, need for security, privacy & threats, attack vectors & surfaces, pen testing approaches, OWASP Top 10 for IoT, threat modeling, cloud security architecture, case study.
Introduction to IoT forensics, forensic investigation of IoT devices & components, forensic tools & techniques, standards and guidelines, case study.
| Service | Govt Agencies (MHA) | Other Govt | Private / Industries |
|---|---|---|---|
| Digital Forensic As-A-Service per Exhibit | ₹ 13,310 /- | ₹ 13,310 /- same | ₹ 13,310 /- same |