Penn Security Lab was a facility for research and education at the Univerrsity of Pennsylvania in Philadelphia. It was directed by Carl A. Gunter, a professor at Penn, and Dave Millar, the Penn Information Security Officer. The lab was initiated in January of 2000 and closed at the end of 2004. It was initially funded by NSF and the Penn School of Engineering and Applied Science (SEAS). This page summarizes some of the contributions and people from the lab.

Projects and Contributions

  • A core aim of the lab was to improve security education at Penn. Gunter, with help from the lab interns and Dave Millar, developed and taught the first regular security courses at the graduate and undergraduate levels at Penn.
  • Another key element of the educational mission of the lab was training of interns. The first of these was Mike Clark, who set up the lab itself and originated the idea of a Virtual Honeynet, which was the first attempt to use virtualization to enhance the function of honeynets.
  • The lab had a number of further technical contributions through a series of projects funded by diverse sources that made contributions to further lab activities. The Verinet project, funded by DARPA and Cisco, was one of the first of these. The project made seminal contributions to the formal analysis of routing protocols, including the first use of formal methods to analyze ad hoc networks and the first use of formal methods in the analysis of network simulations (the Verisim system) and network event recognition (the Network Event Recongnizer Language – NERL).
  • Another project of the lab, with support from ARO and NSF, was the OpEm project, which focused on how to develop open APIs for embedded systems. This project introduced a Programmable Microwave Oven that could read a recipe in a two-dimensional barcode and a Programmable Payment Card (PPC), in which a Java smart card running the GlobalPlatform enabled custom policies on the card itself to enforce purchace policies.
  • The lab also supported research on network security through the Contessa MURI Project, where Penn researchers introduced the concepts of the shared channel model and selective verification, which provide foundations for the rigorous analysis of DoS and new countermeasures.
  • A grant from Microsoft initiated research in the lab on WSEmail, the idea of founding messaging systems on web services in which legacy protocols like SMTP and S/MIME are replaced by modern distributed computing standards like SOAP and XMLDSIG. Research in the lab considered applications, theory, and performance based on a substantial implementation using .NET.

Students and Interns

  • Watee Arsjamat (Intern) – OpEm
  • Karthikeyan Bhargavan (PhD) – Verinet
  • Nayan Bhattad (Intern) – Contessa
  • Mike Clark (Intern) – Virtual Honeynets
  • Gabriel Eichler (Undergrad) – P2P
  • Alwyn Goodloe (PhD) – OpEm and Contessa
  • Ron Lin (Undergrad) – P2P
  • Kevin Lux (Intern) – WSEmail
  • Michael J. May (PhD) – WSEmail
  • Michael McDougall (PhD) – OpEm
  • Davor Obradovic (PhD) – Verinet
  • Kaijun Tan (Staff) – Contessa
  • Yosef Weiner (Intern) – OpEm



