Dr. Jonathan Graham is a professor at Norfolk State University specializing in cybersecurity, digital forensics, intrusion detection, machine learning, and information assurance. With extensive experience in cybersecurity education and research, he helps prepare students for technical careers in cyber defense, government, industry, and applied research.
Summary of the episode
Graham discusses the importance of strong technical foundations, hands-on labs, digital forensics, AI and machine learning, and understanding human behavior in cybersecurity.
He advises aspiring professionals to build strong math and communication skills, maintain a competitive GPA, and pursue internships, research, competitions, scholarships, and other practical learning opportunities.
Listen to the episode
Read a full transcript of the episode
Steve Bowcut:
Welcome to the Cyber Security Guide Podcast. I’m your host, Steven Bowcut. Today I’m pleased to welcome Dr. Jonathan Graham, professor at Norfolk State University.
Dr. Graham’s academic background spans mathematics, computer science, information assurance, intrusion detection, machine learning, and digital forensics.
He earned his PhD in computer science from the University of Idaho, holds a master’s degree in computer science from Jackson State University and received his bachelor’s degree in mathematics and computer science from the University of the West Indies Cave Hill campus in Barbados.
At Norfolk State, Dr. Graham has been closely involved in cybersecurity and information assurance education, including work with the Information Assurance Research and Education Development Institute IA Ready. He also teaches courses in digital forensics, computer and network forensics and structured programming.
In this episode, we’re going to discuss Norfolk State University’s cybersecurity pathways, The Value of Hands-on Learning, the Importance of Digital Forensics, the role of machine learning in cyber defense, and how students can prepare for careers in government industry and research.
With that, welcome, Dr. Graham. Welcome to the Cybersecurity Guide Podcast. Thank you for joining me today.
Jonathan Graham:
Thank you for having me.
Steve Bowcut:
All right, this will be interesting and informative for our audience. I am just totally confident. As we do on the show, if our audience has listened to previous episodes, we’d like to start with a little more background about our guests.
So Dr. Graham, tell us a little bit about your academic journey from your early studies in mathematics and computer science through your PhD in computer science and how that path eventually led you into cybersecurity and information assurance.
Jonathan Graham:
Yeah. Well, I have always loved problem solving.
Steve Bowcut:
Okay.
Jonathan Graham:
Mathematics and computer science was a natural pathway to solving problems and sciences and a way to solve problems without getting your hands too dirty. I like chemistry and physics, but you spend lots of hours in your lab. With math and computer science, you can solve the problems using pencil and paper or just a computer. So I love that.
So in Barbados where I’m from the choices were limited as to what kind of jobs you get in sciences upon graduation, but math and computer science were always good choices for jobs. So that’s why I pursued mathematics and computer science.
Then upon graduation, I briefly taught high school mathematics for one year. Then I traveled to Mississippi to Jackson State University. It was January, which was a shock to my system. The weather was cold and even more shocking to me. The sun was very bright. It was beautiful, sunlight weather, not a cloud in the sky, but it was still cold.
And my experience watching television, cold winter meet, gray, over chaos, snow. But no, it was beautiful, not a cloud in the sky kind of weather. So I spent 18 months in Jackson, Mississippi. Very interesting place. I remember my first things I did was to drive to Vicksburg, Mississippi to see the Mississippi River.
Steve Bowcut:
Oh, very good.
Jonathan Graham:
Because at home we always heard about the Mississippi River. We studied Tom Sawyer, Hackleberry Fend. So the river had this kind of magical feeling. I just had to see this river. And the river goes from the Great Plains between the river and the Rocky Mountains. So it was really great to actually go and see. I’ve seen the Mississippi River.
After I left Mississippi, I got a job as an instructor at Norfolk State University in Norfolk, Virginia. And then eventually I decided to pursue my PhD at the University of Idaho in Moscow, Idaho. Yeah, that was different. It was a beautiful – That
Steve Bowcut:
Probably made Mississippi feel warm in the winter.
Jonathan Graham:
Yes. Mississippi was cold in the mornings in Mississippi, like 20 degrees. By midday, it warmed up nicely to 50s, it wasn’t too bad. Moscow, it was cold, but compared to Virginia, 40 degrees in Moscow was comfortable compared to 40 degrees in Virginia.
I never realized that until I came back to Virginia and realized that the cold in Virginia was wet and damp and uncomfortable. I never knew that until I went to Moscow. But when I came out for a visit, I was shocked at how different the cold felt.
And Moscow was nice and dry cold. And the summers, my first summer there, it was a pleasant 80 degrees and everyone was saying, wow, it’s so hot. It’s more comfortable. I couldn’t believe it. But I enjoyed my time in Moscow and it was there that I got involved in cybersecurity. University of Idaho was one of the original centers of academic excellence in cybersecurity.
And my advisor, J. Miles Foss, was in charge of the cybersecurity program. So I got involved in cybersecurity and once I returned to Norfolk State, I started to develop the cybersecurity program more fully at Norfolk State.
Steve Bowcut:
Thank you for that background. In my mind, that illustrates a really important point for our audience to understand is that lots of people, everyone comes to cybersecurity from a different path. So here you are very successful in cybersecurity, but it really wasn’t even in your career path until you’re working on your PhD.
Other people come right out of high school. In fact, even before they get into college, they’re focused on cybersecurity and that’s what they want to do. So there’s an infinite number of ways to get here and we hope that our audience understands that and realize dependent, it doesn’t matter where you’re at in your career.
Cybersecurity is something that you can consider and there’ll be a pathway to get you there. So thank you. That’s a really important point. So you’ve been closely involved with the information assurance and cybersecurity education at Norfolk State, as we’ve talked about, including the work connected to the IA-ready.
And I think it would be interesting for our listeners if you were to explain to us really what that is and how has NSU built support for cybersecurity learning, applied research and student development in this field through that vehicle.
Jonathan Graham:
Okay. To become a center of academic excellence and cybersecurity through the National Security Agency and Homeland Security Program, the university must have a designated center. IA Ready is our designated cybersecurity center.
Steve Bowcut:
Got it.
Jonathan Graham:
And once we have a center that allowed us to apply to become a center of academic excellence. So at that time we had to show that the center was functioning.
We had a website, our faculty was doing active research, our students were involved in cybersecurity and the curriculum was strong and robust and prepared students for careers in cybersecurity.
So IA-Ready is a combination of academic development of students, professional activities of faculty, also having cybersecurity spread across the campus and enter the community.
Steve Bowcut:
Excellent. Okay. So thank you for that. And so that obviously just begs the question for students or families that are comparing cybersecurity programs, so what does this designation mean to them that the Center for Academic Excellence, what kind of weight should they give that?
Does it mean that you’ve got the quality of the curriculum, the faculty expertise, hands-on learning? What are the elements that people who are trying to make this choice and decision should consider when they’re thinking about various schools?
Jonathan Graham:
Well, first of all, it tells a prospective student that the curriculum is a quality curriculum that addresses all the fundamentals of cybersecurity. It also lets you know that the faculty are qualified and they’re active in the field.
Also, students are being exposed to extracurricular activities like capture the fly contests, like internships.
So it lets you know that this program is a quality program and upon graduation it’ll be recognized, especially by the US government and people in the industry who understands the designation. So it assures you that the program is a quality program in cybersecurity.
Steve Bowcut:
Excellent. And as I understand it, it does people who go to schools with that designation do tend to end up in government or military or those kinds of roles. Has that been your experience or do they equally end up in just businesses?
Jonathan Graham:
Typically government and defense contractors.
Steve Bowcut:
Defense contractors. Okay.
Jonathan Graham:
Especially in Washington, DC area without heavy military influence. It’s also in the Navy also, but mainly military government defense contractors.
Steve Bowcut:
Okay, perfect. Which is not a bad place to work, so thank you for that. So NSU offers a Bachelor of Science in computer science with a cybersecurity track.
So what kind of student is a good fit for that undergraduate pathway and what technical foundation does the program aim to build for students that want to move into more specialized cybersecurity topics after that?
Jonathan Graham:
I mean, there are many ways to approach cybersecurity. You can approach it from a computer science point of view. You can approach it from business, economics, policy. At Norfolk State, our focus is on computer science students.
We are looking for technical students who will be able to contribute to the field, will be able to contribute to the different cybersecurity tools, who will be able to understand the theory. We want to develop students with strong technical foundations and cybersecurity.
So we are not so much interested in policy and economics point of view. We are more interested in computer science students who can develop tools to solve problems and who are able to adjust to new kinds of attacks.
So it’s not just learning, knowing how to use these cybersecurity tools, but know how to develop those tools. That’s what we aim to do.
Steve Bowcut:
Excellent. Okay. So let’s talk a litle bit about digital forensics. You teach digital forensics and computer and network forensics. So what do students tend to find most compelling about forensics?
I always imagine that they’ve got CSI in their head that they’re going to solve crimes and sit behind a computer and track bad guys and help make arrests and all that. So give us a little more realistic view of that. What skills do they need to develop to investigate incidents effectively?
Jonathan Graham:
Yeah, cybersecurity can be boring. You can spend a lot of time learning theory. You can spend time trying to break the cryptographic protocols. You can spend time trying to penetrate the system and they could be very tedious and boring because it doesn’t magically happen like on CSI.
Digital forensics, there’s some instant gratification. For example, one of the first things you can teach them is students erase all the files from a flash drive and then use forensics to recover it.
So it’s like, “Wow, you can do that. I thought those files were gone.” Or we do criminal cases, they’re simulated criminal cases. Someone commits a crime, evidence is on the computer.
So your student has to go there, make a copy of the computer’s image and actually try to find who did it, how they did it, what did they do. So it’s a kind of fascination, something that most people can relate to from television.
And it’s almost in just a few months, students can go from knowing nothing to actually be able to solve real life problems. So it has that instant gratification compared to other aspects of cybersecurity.
Steve Bowcut:
Yeah, I can imagine that’s true. That makes sense to me. Another thing that’s on everybody’s mind is AI or machine learning or some version of that. So your research interest, as we talked about, includes intrusion detection and machine learning.
How are machine learning and data-driven methods changing the way cybersecurity professionals detect attacks, analyze threats, or respond to incidences?
Jonathan Graham:
Yeah. Artificial intelligence is moving so quickly, no one really knows where it’s going or few people have mastered exactly how they’re going to use it because within a year or two, things have changed so quickly, but you’ll find that attackers will use artificial intelligence to examine weaknesses and systems.
They will ask the AI to find them vulnerabilities, loopholes in the system so they can attack it. They’ll find that cybersecurity defenders will use the same tactics to find the same loopholes so they can patch those before the attacker finds them.
There you go. But CEI is moving so quickly, the attacker can move quickly to a level that the defender isn’t at, especially if the attackers have backing from, say, a foreign government or a powerful criminal network. So AI is changing everything.
Once you have the information to train the AI system on so it can learn from it, you just have to sit there and ask questions like, “Tell me how to attack the system.” And the AI will tell you and no one really knows where it’s going, how fast it’s going, but it’s actually going pretty quickly.
Steve Bowcut:
I guess we’ll see how it turns out. The other thing that it does, it occurs to me, is it kind of lowers that threshold or that barrier to entry for threat actors. So you don’t have to have really strong technical skills to write prompts and get AI to help you find ways to attack systems.
And then of course, as you just pointed out, the other side of that same coin is, well, other defenders have that same capability and ability to examine the systems themselves and find those weaknesses. Does that make sense?
Jonathan Graham:
One person goes ahead, the other person catches up the other person… So it all depends on motivation. If you’re motivated to protect sensitive information and you invest in resources, you might be able to stay ahead of your opponent.
Steve Bowcut:
And so it really hasn’t changed the dance that security defenders and threat actors have danced forever. It’s just sped things up as you pointed out. Things happen so quickly now.
Jonathan Graham:
Yes. As you mentioned, anyone can say, “Tell me how to attack this system or develop me a script that will attack the system for me. ” You just back and watch it happen.
Steve Bowcut:
Yeah. All right. So one of the things that nearly everyone asks about when I have these kinds of conversations with people is what’s the advantages of hands-on labs and applied learning something that students are always interested in. They want to get their hands on stuff.
So NSU cybersecurity facilities include resources such as the AI-ready that we’ve talked about, the cybersecurity complex and cloud security research infrastructure. So how do these labs and other tools help students move from theory into hands-on cybersecurity practice?
Jonathan Graham:
Yeah. Well, these labs are essential and we have some powerful equipment. We have all the major digital forensic software. We have lots of computer servers that stores lots of information that allow data science and machine learning, allow students to develop and get hands-on activities on these things.
And unlike lots of schools, we allow undergraduates to play with these machines. So we have networks that are secure networks that are isolated from the main campus so students can attack other students, simulate attacks to their heart’s content and it makes it real.
You can read a textbook. It says that attack doing this, but in practice it doesn’t happen as easily as you might think. You may spend days and hours just trying to get past the initial barrier to attack someone.
But essential to see how things happen in real life, how does it work with a real server and to be able to create your own environment and attack it or to attack someone’s environment, it lets you see what happens in the real world before any consequences.
Steve Bowcut:
Absolutely. Okay. So you also offer an online master’s program. So it’s 100% online master of science and cybersecurity. So who is that graduate program designed for and how does it help working professionals or students prepare for more advanced roles in the field?
Jonathan Graham:
Well, it’s designed for anyone who wants to move from there on the graduate field into cybersecurity. So you can come from business, sociology, political science.
As long as you have an interest in cybersecurity, that program will take you from where you are to where you need to be. So you start in the first semester with foundation courses that you may be lacking and then you get a broader view of cybersecurity.
And what it does, it allows people to bring their graduate skills into cybersecurity. So you may be a political science person, you may be a public policy person, you may be a business person, you may able to bring those skills and apply them to cybersecurity because cybersecurity is just not for computer science people alone.
Steve Bowcut:
Yeah, that’s true. And I would assume that, I mean, because it’s 100% online that you’ve designed it so that people can continue to work, so they’re continuing to earn a living and support their families as they advance their education and therefore advance their career.
Jonathan Graham:
Yeah. We have access to a lot of powerful virtual labs so students will get hands-on activities without coming to campus. So they’ll be able to get their hands dirty from the comfort of their living room.
Or you have military people who are traveling. We have quite a few military persons and they’re all over the world often, but once they have access to the internet, they’re able to continue their regular work.
Steve Bowcut:
Okay, thank you for that. So one of the things that I find most fascinating is most people know that very high percentage of attacks have some kind of a social engineering element to them in today’s world.
So NSU has emphasized social cybersecurity and cybersecurity psychology, cyber psychology. So talk to us a little bit about that and the human behavior, like you said earlier, that it’s not all about computer science.
And I’m fascinated with the idea that we need people in cybersecurity who understand why people do what they do. Why do people give up their passwords? How do these social engineering elements that are a part of almost every attack, why are they successful and how you work that into training students?
Jonathan Graham:
Right. So we look both at the victim and the attacker. As you mentioned, you look at the behavior of your victim, what makes them a victim and what kind of behavior, how can you make them to be more make them less of a victim?
So in other words, as you said, why do they do this? Why are they vulnerable to certain social attacks? What can you do to help them overcome that predisposition to those attacks? And also the attacker, what’s the psychology of the attacker? What’s the motivation of the attacker? Some attackers or other governments, some are just activists and how can you help recognize an attack?
In other words, certain behaviors, the technical aspect may not seem to be there, but the communication between the attacker and the victim might suggest, “Oh, an attack is about to occur.” And then another aspect is, and we were working with Sandia National Labs on this at some time, when a defender is trying to solve an attack, like say a forensic analyst, how do they think?
How do their mind work when they’re trying to solve this attack? So we had people wear devices that kind of track brain patterns, track how their mind is working more or less so that as they’re working on the problem, you can actually track and see how they approach solving the problems.
Steve Bowcut:
Oh, wow. That’s totally fascinating to me.
Jonathan Graham:
Yeah, to me also. I wasn’t heavily involved in it, but it was fascinating to see them trying to capture the workings of a person’s mind so they can teach other defenders on how to go about solving that problem.
Steve Bowcut:
Yeah, interesting. And something you said that really stuck out to me is understanding the psychology of the attacker, because I would asume this is part of what you teach people is that that will help you. If you understand their psychology, you can understand their motivations.
If you understand their motive or their motivations, then you’re much more likely to be able to predict what it is they’re trying to achieve and therefore block their attack.
So do they want to exfiltrate information because they’re just going to sell it or are they just trying to cause harm in mayhem? So you kind of have to understand who they are and what they want to predict what it is that they may be trying to do. Is that correct?
Jonathan Graham:
Yeah, that’s correct. And if you can profile behavior on the network internet, lots of people give signals out that they’re about to do some kind of attack.
So if you can profile certain behaviors and certain communication patterns, and then you might be able to say, an attack is imminent, or this person is behaving in a suspicious way, let’s track them. Right.
Steve Bowcut:
Okay, interesting. All right, so we are about out of time, but I do want to end with a question that offers some advice to prospective students.
So for students considering Norfolk State University, what advice would you give them on preparing for cybersecurity careers, including research opportunities, certifications, scholarships such as the scholarship for service and the potential pathways into government or industry roles?
If you could sit down with a student who was just the beginning of their cybersecurity academic career, what advice would you give them?
Jonathan Graham:
Well, I will start with saying you want your skills in English and math to be as strong as possible. Most people understand mathematics, but English is very important. You must be able to comprehend what you read.
So a heavy focus on English and math is a good way to get started and you want to maintain that GPA so you can get scholarships. Like our scholarship for service, you need at least a 3.2 and that scholarship pays for two years of service.
We also have scholarships through the Department of War that pays everything for four years and guarantees you a job and we have several other cybersecurity scholarships that Once you can maintain your GPA, it will support you throughout your university career. So that’s a good start.
Be prepared, maintain that GPA and then take advantage of opportunities. Every summer we tend to have internship opportunities.
You want to go out there, join industry, join government, spend your summer in an environment where people are actually working on solving real problems.
And during the school year, you want to become involved in activities like cybersecurity competitions. We also have opportunities where students can go and give talks to people in the community.
So that’s also a good opportunity. We have a cybersecurity club where you meet and you can practice for competitions where we bring professional speakers in. So that will also help to develop your skills.
Steve Bowcut:
Excellent. All right. Well, Dr. Graham, thank you so much for joining me on the show today. I sincerely appreciate your perspective on cybersecurity education at Norfolk State University and your insights into how students can prepare for these meaningful and essential careers in this field. Thank you.
Jonathan Graham:
It was a pleasure being here. Thank you for having me.
Steve Bowcut:
Oh, you bet. And for our listeners, cybersecurity is a broad and growing discipline. Some students may be drawn to programming or network defense, while others may be interested in digital forensics, intrusion detection, policy, research, or the human side of security.
Today’s conversation is a good reminder that building a strong foundation and then taking advantage of labs, faculty mentorship, research opportunities, certifications and career pathways can make a real difference.
Thanks again for listening to the Cybersecurity Guide Podcast and we’ll see you next time.