Provenance-based intrusion detection Digital forensics

Pratyay Sarkar

Tracing attacker behavior through provenance graphs.

Digital and IoT forensics for real-world evidence.

IACS Kolkata UBC Systopia Lab Jadavpur University
Focus

I study how system-level provenance graphs can reveal advanced persistent threats that signature-based tools miss, combining graph neural networks, sequence models, and forensic evidence design. Current threads include botnet detection, IoT forensics, and building tools that make anomaly detection legible to the people who have to trust it.

Graduated with an Integrated BS-MS in Computational Sciences from IACS Kolkata (2021 to 2026). Remote Research Intern at the Systopia Lab, University of British Columbia. Research Project Intern at Jadavpur University.

Education
2019
Krishnanagar Collegiate School

Secondary education.

2021
Krishnanagar Collegiate School

Higher secondary education.

2021 – 2026
IACS Kolkata

Integrated BS-MS in Computational Sciences.

2025 – present
Jadavpur University

Research Intern.

Research & projects
Graph ML
PIDSMaker

Reproduced OCR-APT (Aly et al., ACM CCS 2025) and ProvFusion (Yang et al., IEEE S&P 2026) within the PIDSMaker framework (Bilot et al., USENIX Security 2025), and evaluated flow and diffusion models for detecting Living-off-the-Land APT attacks. Built a GPU-accelerated 3D provenance embedding visualiser, later rebuilt as a browser-based tool with causal tracing and anomaly analysis, for diagnosing model behavior across provenance graphs with 30M+ nodes. Systopia Lab, University of British Columbia.

Thesis
IoT Forensics: ML and Service-Oriented Models

Integrated BS-MS thesis spanning a survey of IoT forensic frameworks, a cloud-based Forensics-as-a-Service architecture, supervised GNN detection on DARPA CADETS, and SeqFlow, a self-supervised GRU sequence model achieving an Attack Detection Precision of 1.0 with zero false positives on CADETS and THEIA. Supervised by Dr. Mridul Sankar Barik (Jadavpur University) and Dr. Partha Basuchowdhuri (IACS).

Digital forensics
JUBATUS

A digital forensic imaging workstation built on a custom Linux platform, featuring modular disk imaging, cryptographic hashing, and chain-of-custody logging for evidence acquisition. Jadavpur University.

IoT security
LoRaComm

An open-source, DIY-buildable LoRa mesh networking testbed built on ESP32-C3/SX1262 hardware, with AODV routing, AES-256-GCM encryption, and tamper-evident evidence logging. Research Intern, Jadavpur University.

Consulting
Mail ForensiX

A forensic email acquisition and analysis platform, developed for ASTHA SOFTTECH SOLUTIONS.

Now
Hobby projects
Networking
WireGuard + WSTunnel Proxy Bypass

A WireGuard VPN tunnel wrapped in WSTunnel, built on an Azure VPS to bypass restrictive proxy filtering and restore reliable outbound connectivity.

Self-hosted
Homelab

A ZFS-based NAS running Nextcloud, Jellyfin, Pi-hole, and an automated arr-suite media stack, Minecraft server and other self hosted services.

Hardware
Ambilight Build

A screen-sync ambient lighting rig built around WLED on a NodeMCU/ESP8266, driving a WS2812B LED strip to sync to the monitor.

Contact

Off the clock: cinephile, photographer, tech nerd.