This is a traditional research area that is continuously updated in line with modern security management models.
Zero Trust Architecture (ZTA): Focuses on eliminating the concept of a “trusted zone” within internal networks through the implementation of multi-factor authentication and dynamic access control.
Software-Defined Networking and Network Function Virtualization Security (SDN/NFV): Studies security solutions for both the control plane and data plane, including defenses against flow table poisoning attacks.
Intrusion Detection and Prevention Systems (IDS/IPS): Develops mini Security Operations Centers (SOC), honeypot systems, and real-time network traffic monitoring solutions.
Cloud and IoT Infrastructure Security: Focuses on securing virtualization environments (VMs/Docker) and resource-constrained embedded devices.
Blockchain Technology and Applications
Blockchain for Education Management: Verification of academic degrees and certificates, and digital credit accumulation systems (P-Coin).
Smart Contract Security: Source code analysis to detect logical vulnerabilities and prevent attacks leading to digital asset theft.
Distributed Systems and Data Security: Utilization of decentralized ledgers to ensure data integrity and transparency in healthcare and financial systems.
Artificial Intelligence in Information Security (AI in IS)
Focuses on “intelligentizing” defensive systems. Malware and botnet detection: Uses Deep Learning to classify malicious behaviors (Malware Analysis) without relying on traditional signature-based methods.
AI model optimization: Research on new network architectures such as Kolmogorov-Arnold Networks (KANs) to improve processing speed and reduce False Positive rates in security monitoring systems.
Adversarial Machine Learning: Protects AI models from being deceived by manipulated or adversarial input data.
Cryptography and Data Security
A specialized field focused on mathematics and security algorithms. Post-Quantum Cryptography: Preparing for the era of quantum computing through lattice-based and code-based cryptographic algorithms.
Privacy-Preserving Security: Homomorphic encryption techniques that enable computation on encrypted data, and Multi-Party Computation (MPC) for secure collaborative computation.
Web and Mobile Application Security: Vulnerability analysis, API security, and online payment protocol protection.
Legal, Policy and Standards
Risk Management and SOC: Focuses on designing incident response processes and compliance management according to international standards such as ISO/IEC 27001, as well as cybersecurity regulations in Vietnam.
Industrial Control Systems (ICS/SCADA): Ensures the security of critical infrastructure such as power grids, water treatment plants, and intelligent transportation systems.