About
Jason L. Wright is a clinical associate professor of computer science at Idaho State University in Pocatello, Idaho. He was a member of the DARPA Cyber Grand Challenge infrastructure team, where he helped build the DECREE operating environment and built the independent scoring system used to verify the final results of the competition. He is a senior member of the IEEE.
Research interests
Education
- Ph.D., Engineering and Applied Science
- M.S., Computer Science
- B.S., Computer Science
Awards and honors
- Open Educational Resources stipend, Idaho State University
- SAINTCON Hacker's Challenge, solo winner
- DEF CON 18 Capture the Flag, winning team (ACME Pharm)
Publications
Journal and Magazine Articles
-
2027
The Cognition Gap: What the Cyber Grand Challenge Revealed About Autonomous Cyber Reasoning
A ten-year retrospective on the DARPA Cyber Grand Challenge. CGC solved the orchestration of autonomous vulnerability discovery, exploitation, and patching, but exposed a cognition gap along two axes, discovery and exploitation, that large language models are closing unevenly.
DOI: 10.1109/MSEC.2026.3740004 Accepted manuscript (PDF)
© 2026 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
-
2018
Operating System Doppelgängers: The Creation of Indistinguishable, Deterministic Environments
-
2013
Analyses of Two End-User Software Vulnerability Exposure Metrics (Extended Version)
DOI: 10.1016/j.istr.2013.02.002 Preprint as submitted, Oct. 2012 (PDF)
-
2006
Cryptography as an Operating System Service: A Case Study
Conference and Workshop Papers
-
2026
The Residual Nondeterminism Gap in Forensic Record-and-Replay
-
2018
BP: DECREE: A Platform for Repeatable and Reproducible Security Experiments
-
2017
Where Am I? Operating System and Virtualization Identification Without System Calls
-
2013
Estimating Software Vulnerabilities: A Case Study Based on the Misclassification of Bugs in MySQL Server
-
2012
Analyses of Two End-User Software Vulnerability Exposure Metrics
-
2012
Mining Bug Databases for Unidentified Software Vulnerabilities
Show 8 older papersHide older papers
-
2012
Concept of Operations for Data Fusion Visualization
-
2011
Are Vulnerability Disclosure Deadlines Justified?
-
2011
Fuzzy Logic Based Anomaly Detection for Embedded Network Security Cyber Sensor
-
2010
Neural Network Architecture Selection Analysis with Application to Cryptography Location
-
2010
The Analysis of Dimensionality Reduction Techniques in Cryptographic Object Code Classification
-
2009
Neural Network Approach to Locating Cryptography in Object Code
-
2009
Time Synchronization in Hierarchical TESLA Wireless Sensor Networks
-
2000
Transparent Network Security Policy Enforcement
Book Chapters
-
2004
Experiences Enhancing Open Source Security in the POSSE Project
Theses and Reports
-
2014
Software Vulnerabilities: Lifespans, Metrics, and Case Study
-
2008
Recommended Practice for Securing Control System Modems
Patents
-
2012
Method and System for Providing Secure One-Way Transfer of Data
Talks
-
2025
Examination of Kernel Level Anti-Cheat Measures
-
2019
Operating System Doppelgängers
-
2008
Finding Cryptography in Object Code
-
2008
When Hardware Is Wrong, or ‘They Can Fix It in Software’
-
2006
OpenBSD/sparc64
Software & Data
Teaching
- CS 2281 (formerly CS 2235): Data Structures
- CS 3310: Databases
- CS 3337: Secure Systems and Networks
- CS 4461/5561: Secure Operating Systems
- CS 4481/5581: Compilers
Show 2 older coursesHide older courses
- CS 1181: Computer Science and Programming I
- CS 4499/5599: Special Topics: Databases
Contact
- Email: jlwright@ieee.org
- GitHub: wrigjl