Uploaded August 2025 | Updated September 2026, 13 hours ago
Vijay Sarvepalli (US)
Vijay Sarvepalli is a Principal Engineer at the CERT Coordination Center, part of the Software Engineering Institute at Carnegie Mellon University. He supports sponsors in areas including enterprise architecture, cybersecurity, and situational awareness, with a focus on vulnerability analysis for the Threat Analysis Directorate. His current work includes systemic vulnerability research, scalable vulnerability coordination, and threat modeling. Vijay has over 20 years of experience across electrical engineering, software engineering, and enterprise architecture. He holds an M.S. in Electrical and Computer Engineering from the University of Utah and certifications including TOGAF, ITIL, and GIAC Gold. His research has been published in IEEE, Applied Physics Journal, International Journal of Engineering, IEEE publications, and the ANTS Swarm Intelligence Conference.
--
Planning resource management in cybersecurity is difficult and is always affected by the trends. How many vulnerabilities do we expect? How much malware? How many security incidents? Unfortunately, these trends are often affected by multiple causes that are not always related. For example, a new threat actor, a new malware library, a new class of vulnerability, or a new method of finding vulnerabilities. They may be interrelated, they may be unrelated, and they may be unknown, but at the core, they influence how many vulnerabilities, malware, incidents, and other cybersecurity events occur.As an outgrowth of analyzing COVID-19 trends and causes, we developed a new method for modeling multicausal data, which can have disparate underlying causes for the changes in trends. This method has been expanded to prediction, where we predict the point at which the trend in data changes, allowing us to forecast the number of events in the future.
Vijay Sarvepalli (US)
Vijay Sarvepalli is a Principal Engineer at the CERT Coordination Center, part of the Software Engineering Institute at Carnegie Mellon University. He supports sponsors in areas including enterprise architecture, cybersecurity, and situational awareness, with a focus on vulnerability analysis for the Threat Analysis Directorate. His current work includes systemic vulnerability research, scalable vulnerability coordination, and threat modeling. Vijay has over 20 years of experience across electrical engineering, software engineering, and enterprise architecture. He holds an M.S. in Electrical and Computer Engineering from the University of Utah and certifications including TOGAF, ITIL, and GIAC Gold. His research has been published in IEEE, Applied Physics Journal, International Journal of Engineering, IEEE publications, and the ANTS Swarm Intelligence Conference.
--
Planning resource management in cybersecurity is difficult and is always affected by the trends. How many vulnerabilities do we expect? How much malware? How many security incidents? Unfortunately, these trends are often affected by multiple causes that are not always related. For example, a new threat actor, a new malware library, a new class of vulnerability, or a new method of finding vulnerabilities. They may be interrelated, they may be unrelated, and they may be unknown, but at the core, they influence how many vulnerabilities, malware, incidents, and other cybersecurity events occur.As an outgrowth of analyzing COVID-19 trends and causes, we developed a new method for modeling multicausal data, which can have disparate underlying causes for the changes in trends. This method has been expanded to prediction, where we predict the point at which the trend in data changes, allowing us to forecast the number of events in the future.










