Yakov Shafranovich, CISSP

Yakov Shafranovich, CISSP

Baltimore City County, Maryland, United States
579 followers 500+ connections

About

My current passion is application security and vulnerability research.

I also have…

Experience

Education

Volunteer Experience

  • Business Mentor

    The Jewish Entreprenuer

    - Present 9 years

    Economic Empowerment

  • Invited Expert

    Invited Expert

    W3C

    - 2 years 1 month

    Science and Technology

    Invited expert participating in the CSVW Working Group

  • Board Member, Webmaster and Technical Advisor

    Fallstaff Improvement Association, Inc.

    - 3 years 3 months

    Politics

    Maintain the association's website; curate open data for the use of the association

  • Technical Advisor

    The Society for the Preservation of Hebrew Books (HebrewBooks.org)

    - Present 19 years 5 months

    Education

    Advise on technology projects

  • Member

    Member

    Internet Engineering Task Force

    - Present 23 years 5 months

    Science and Technology

    Participate in standards development, review and publish Internet standards

  • Co-Chair

    IRTF Anti-Spam Research Group

    - 10 months

    Science and Technology

    Coordinated and managed Internet-wide anti-spam research efforts for the IRTF / IETF, including standards development, review and publishing; presenting at public conferences and coordinating between the ASRG and several large ISPs. Work culminated in multiple anti-spam email standards still in use today (DKIM, SPF, ARF, etc.).

Licenses & Certifications

Publications

  • RFC 9116: A File Format to Aid in Security Vulnerability Disclosure ("security.txt")

    Internet Engineering Task Force

    When security vulnerabilities are discovered by researchers, proper reporting channels are often lacking. As a result, vulnerabilities may be left unreported. This document defines a machine-parsable format ("security.txt") to help organizations describe their vulnerability disclosure practices to make it easier for researchers to report vulnerabilities.

    See publication
  • Bluetooth Data Exchange Between Android Phones Without Pairing

    Arxiv.org

    In this paper we describe a novel method of exchanging data between Bluetooth smartphones on the Android platform without requiring any pairing of the devices. We discuss our approach of encoding and decoding data inside the UUIDs used by the Bluetooth Service Discovery Protocol (SDP). Future research remains to be done on the latency, bandwidth and compatibility of this approach, as well as the possibility of utilizing other protocols in conjunction with this method.

    See publication
  • RFC 6922 - The application/sql Media Type

    Internet Engineering Task Force (IETF)

    This document registers the application/sql media type to be used for the Structured Query Language (SQL).

    See publication
  • High-Content Screening Data Management for Drug Discovery in a Small- to Medium-Size Laboratory

    Journal of Laboratory Automation (JALA)

    High-content screening (HCS) technology provides a powerful vantage point to approach biological problems; it allows analysis of cell parameters, including changes in cell or protein movement, shape, or texture. As part of a collaborative pilot research project to improve bioscience research data integration, we identified HCS data management as an area ripe for advancement. A primary goal was to develop an integrated data management and analysis system suitable for small- to medium-size HCS…

    High-content screening (HCS) technology provides a powerful vantage point to approach biological problems; it allows analysis of cell parameters, including changes in cell or protein movement, shape, or texture. As part of a collaborative pilot research project to improve bioscience research data integration, we identified HCS data management as an area ripe for advancement. A primary goal was to develop an integrated data management and analysis system suitable for small- to medium-size HCS programs that would improve research productivity and increase work satisfaction. A system was developed that uses Labmatrix, a Web-based research data management platform, to integrate and query data derived from a Cellomics STORE database. Focusing on user expectations, several barriers to HCS productivity were identified and reduced or eliminated. The impact of the project on HCS research productivity was tested through a series of 18 lab-requested integrated data queries, 7 of which were fully enabled, 7 partially enabled, and 4 enabled through data export to standalone data analysis tools. The results are limited to one laboratory, but this pilot suggests that through an “implementation research” approach, a network of small- to medium-size laboratories involved in HCS projects could achieve greater productivity and satisfaction in drug discovery research.

    Other authors
    See publication
  • RFC 5965 - An Extensible Format for Email Feedback Reports

    Internet Engineering Task Force (IETF)

    This document defines an extensible format and MIME type that may be used by mail operators to report feedback about received email to other parties. This format is intended as a machine-readable replacement for various existing report formats currently used in Internet email.

    Other authors
    See publication
  • RFC 4180 - Common Format and MIME Type for Comma-Separated Values (CSV) Files

    Internet Engineering Task Force (IETF)

    This RFC documents the format used for Comma-Separated Values (CSV) files and registers the associated MIME type "text/csv".

    See publication
  • The War on Spam

    Information Security Journal

    The Internet is now indispensable to business at the cost of Internet abuse. Spam cascaded from an annoying trickle to a raging flood of ads, viruses, spyware, and phishing scams that pour into millions of inboxes everyday all over the world. With upwards of 80% of all e-mail traffic now spam, it's no wonder that organizations worldwide are looking for new ways to eradicate this blight. This article will discuss some of the newer developments in the "battle of the inbox."

    See publication

Languages

  • English

    Native or bilingual proficiency

Organizations

  • Shaftek Enterprises / IDN

    Consultant - Owner

    - Present

    Working on a wide variety of consulting projects using technology to solve real world problems. Engagements include advising on technology purchasing, troubleshooting campus-wide networking issues, digital printing and publishing, and others.

View Yakov’s full profile

  • See who you know in common
  • Get introduced
  • Contact Yakov directly
Join to view full profile

Explore collaborative articles

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Explore More

Add new skills with these courses