SGNOG13 Speakers

Speakers

Jérôme Meyer
Security researcher
Nokia

Jérôme Meyer is a security researcher at Nokia Deepfield, where he tracks DDoS botnets and proxy networks that threaten telecom and cloud providers. He recently co-authored research on the Jackskid botnet and contributed to a coordinated takedown of several major DDoS-for-hire operations. Jérôme joined Nokia over twenty years ago in Malaysia, spent nearly two decades in commercial roles across Asia-Pacific, and is now based in Paris.

 

The $30 attack box: inside the Android TV botnet ecosystem

Budget Android TV boxes routinely ship with residential proxy software installed at the factory — compromised before the subscriber unboxes them. Botnet operators then add DDoS capability on top.

Starting from Kimwolf, studied both in a controlled malware lab and through real-world Netflow telemetry, this talk traces shared code, overlapping infrastructure and reused credentials across eight botnet families — four of them demonstrably linked — spanning over three million observed devices. It covers CECbot, the first known malware to weaponise HDMI-CEC; Katana, which ships a C compiler and compiles its own rootkit on the infected box; and Jackskid, which fell back to blockchain-based domain resolution within hours of losing its C2 domains.

In October 2025 Nokia Deepfield observed a 33 Tbps attack. This is where that capacity now comes from — and it is sitting on your access network.

Tashi Phuntsho

Technology Evangelist
FLEXOPTIX / NSRC

Tashi is currently the APAC Lead and a Technology Evangelist at FLEXOPTIX GmbH.
He previously led Bhutan Telecom’s IP Network team and worked at APNIC as a Senior Network Analyst and Training Manager.
Tashi also supports NSRC workshops and engineering assistance work in the APAC region. He continues to volunteer with several regional NOG programme committees.

 

“The Puzzle Pieces (revisited) of Securing the Internet Routing”

Route leaks and to some extent route hijacks are still happening.

This talk reviews the current tools available to secure the Internet routing — including IRR filtering, ROA based ROV, BGPsec and emerging proposals like ASPA — examining how these puzzle pieces fit together and the practical challenges that stand in the way of wider adoption.

 

Thomas Weible

CTO
FLEXOPTIX

Thomas Weible is the creative brain of FLEXOPTIX. A real rebel who dreams up innovations such as the FLEXBOX. He dives deep into the inner life of optics and loves experimenting on real-life problems with our customers. For more than 18 years he has been part of the internet community and has specialized in optical networking. 

Channelmania! – future proof your DWDM network topology while keeping it flexible for 1.6T

For years IP and transport were separate concerns: the transport team ran the DWDM plant, and IP engineers cared only about what plugged into the router. That separation is over.

The old plant was built by shrinking the grid — 200 GHz to 100 GHz to 50 GHz, sometimes 25 GHz — to pack in more channels. Coherent optics reverse the direction. Higher-order modulation at 400G, 800G and now 1.6T needs more spectrum per channel, so superchannels demand a wider grid. Coherent detection is also blind to everything but its own wavelength, which opens up topologies with no filters at all — at the cost of flexibility.

This talk covers what IP engineers now need from the optical layer: how coherent detection works, why 800G and above need wider filters, and how COTS 400 GHz filters reach 1.6T while keeping 50 GHz legacy services alive.

Made by FLEXOPTIX Research – Gert and Thomas.

Jocelinn Kang

Managing Director
Nodalys

Jocelinn Kang is the founder and managing director of Nodalys, a boutique national security consultancy working across cyber security, geopolitical risk, and digital resilience. After a career in government ensuring the confidentiality of packets, she moved to a think tank to ensure the integrity of policy conversations by helping decision makers understand the strategic ‘so what’ behind technology developments. Now she continues that work independently and wants to ensure the availability of digital connectivity, because as it turns out, the global-ness of the internet relies heavily on a physical medium that is inherently exposed.

 

Maintaining agency in a geopolitical battlefield over subsea cables

This session explores how intense geopolitical friction is actively reshaping the subsea cable industry. We’ll will cut through the political noise surrounding recent cable faults in the Baltic and Taiwan, unpack how US-China tensions are directly dictating future cable routes, consortium ownership, and vendor selection. Finally, we will look at how Singapore and ASEAN are leveraging digital agreements to try to not be caught in the middle of the tensions.

 

Masagung Nugroho

Senior Presales Consultant
HPE Networking

 

Masagung Nugroho is a senior network professional with broad expertise across IP routing, data centre, packet-optical, AI-driven networking and SDN domains. Extensive experience with industry-leading platforms from Juniper, Nokia, and Infinera, delivering scalable service provider and enterprise network solutions. Given 15+ years’ experience with strong focus on AI-assisted operations and network automation and orchestration, leveraging Python, SDN controllers, and intent-based systems to drive operational efficiency, reliability, and lifecycle automation.

 

E2E Service Orchestration with Agentic AI

I will cover on why Agentic AI is the current trend. Agent will help us not only by answering our question but also verifying, reasoning and executing things in the system. I will have a video demo too during the session.

Richard Cziva

Network Modeling and Optimization Engineer
Meta

Richard Cziva is a Network Modeling and Optimization Engineer at Meta in their Network Planning team. He works on datacenter network physical design. https://www.linkedin.com/in/rcziva/

 

“Loom: Automating the Physical Design of AI Data-Center Networks”

Physical network design—deciding how thousands of network devices and millions of fibers are distributed across data centers, racks, and failure domains—has traditionally been a manual, time-consuming process performed by design engineers. Yet we are seeing exponentially increasing demand to fulfill the capacity required by AI workloads. At Meta, we developed Loom, a system to automate and optimize the end-to-end physical network design pipeline. Loom orchestrates two core components: a device placement component (Planogram) which places network devices across the physical floorplan subject to dimensional and failure-domain constraints; and a fiber design component, which generates end-to-end fiber connectivity satisfying the variety of connectivity patterns driven by physical constraints. Together, these components accelerate end-to-end physical network design from months to hours, allowing us to produce more complex and efficient designs with fewer resources.

Yin Chao

Principal Solution Architect
Tencent

 

Chao Yin Loong a Principal Solution Architect with Tencent CDN Edge One product architecture team. He archtected thousnads of web apps to be onboarded to tencent edgeone CDNs for both accelerating their delivery and protecting if from web applications attacks.

 

Agentic AI for Frictionless CDN Migration

CDN vendor lock-in doesn’t live in your traffic — it lives in your configuration. Every CDN models delivery rules, caching, security policy and edge logic differently, so hand-porting thousands of rules has meant months of expert effort with a high risk of silent breakage. That friction is what keeps organisations tied to their incumbent.

This talk shows an agentic approach to removing it. A fleet of specialised harnesses — analysers, converters, mapping discovery, importers and self-healing agents — reads each platform’s own source and APIs to derive exact, grounded mappings, cutting a migration from months to minutes. A self-healing loop diagnoses failed rules and re-fixes them against the live API.

Working through a real migration spanning delivery rules, WAF and IP-group security, and edge functions, we cover the neutral intermediate model, the converter pipeline, the subtle traps — operator semantics, silent no-ops, rule-versus-zone scope — and the log tracing and spoof tests that confirm parity before cut-over.

 

Aris Cahyadi Risdianto

Professional Officer
Singapore Institute of Technology (SIT)

Aris is a former system/network engineer/administrator who has been involved in designing, implementing, migrating, and maintaining IP networks for enterprises and service providers. He is very interested in Future Internet Architecture and Open-source Networking (including SDN, NFV, and Cloud computing), so he selected them as topics for his PhD degree and is actively contributing to Open-source Networking Projects. His current role is providing professional services for ICT research and education at Singapore Institute of Technology (SIT) and conducting 5G research at Future Communication Translation Lab (FCTLab). Before his current role, he was also a Senior Researcher at the National University of Singapore (NUS) that help to build Future Internet, Cloud Computing, and Cyber Security Testbeds. Apart from that, he is also contributing to the Internet community, where he became an APNIC community trainer.

 

“How Can a Network Engineer Learn and Contribute in the Era of AI?”

This presentation discusses how network engineers can learn, adapt, and contribute to the growth of AI by understanding both AI Networking and Networking for AI. It highlights the fast-growing AI and cloud hub, AI-ready telecom infrastructure, data centre deployment, and relevant ICT skills frameworks to support them. The presentation distinguishes between applying AI/ML to improve network operations (e.g., anomaly detection, traffic prediction, root cause analysis, and automation) and designing high-performance networks to support AI infrastructures or workloads (e.g., distributed training, GPU interconnects, and large-scale inference). It will conclude by proposing industry-aligned learning pathways, certifications, specialized programmes, and skills-based authentic assessments to prepare network engineers for emerging AI infrastructure roles.

 

Vincent Phelan

Head of Network Architecture & Automation
Standard Chartered Bank

Vincent Phelan is Head of Network Architecture & Automation at Tier 1 systemic bank in Singapore, where he leads six teams spanning architecture, software engineering, automation, and security compliance across a global network infrastructure estate.

He builds internal platforms that treat network infrastructure as software — replacing manual governance with executable architecture, Git-backed compliance, and continuous validation.

His work includes designing and shipping a Network Digital Twin platform that validates the compliance posture of thousands of devices daily against organisation-specific security standards, and a multi-source correlation engine that validates whether declared network segmentation intent matches actual implementation across firewalls, load balancers, IPAM, and contract approval systems.

Vincent presented at AutoCon4 on network configuration and security automation, where his talk was featured by the Network Automation Forum. Before banking, he held infrastructure architecture roles across pharmaceutical (Sanofi), Aerospace (Honeywell), and telecommunications (BT, SITA), giving him a cross-industry perspective on how large organisations struggle with — and occasionally solve — network operations at scale.

He is a self-taught engineer who builds working systems as the primary method of communicating architectural vision.
Based in Singapore, originally from the Netherlands.

 

Scalable Micro Segmentation: When Manifest-state meets reality

“Every organisation claims to have network segmentation. Few can prove that what was approved matches what is deployed — and fewer still can detect when they drift apart.

This talk shares hard-won lessons from implementing manifest-driven network segmentation at a systemic bank.

Instead of managing thousands of firewall rules with lost provenance, we declared segmentation as application-to-application intent — consumer, publisher, protocol — abstracting the network layer so that IP addresses are resolved at deploy time, not maintained by hand.

We then built continuous validation that correlates declared intent against multiple enforcement layers — firewall rules, load balancer configs, IPAM allocations, and contract approvals — keyed on application identity.

The result: daily, automated proof of whether segmentation intent matches production reality, with organisational drift detected the day it happens rather than at the next quarterly audit.

The talk covers the messy reality that vendor presentations skip; what happens when app teams treat missing enforcement as implicit permission, why every application believes it deserves an exception, how non-prod environments with relaxed rules create technical debt at go-live, and where network segmentation yields diminishing returns compared to identity-based controls.

Practical guidance on what “”good enough”” segmentation looks like when perfect granularity creates more risk than it mitigates.

No vendor products. No lab demos. Production experience from a regulated environment with real numbers.”

Dave Phelan

Senior Network Analyst
APNIC

Dave comes to APNIC having worked in the Australian ISP and MSP community for the last 20 years in roles as diverse as carrier transmission networks, to System Administration, to core, edge and customer networks. Having built a corporate ISP network from the ground up, he comes with an understanding of traps and pitfalls that most networks have, and do experience.

 

“The Internet By the Numbers – SG Edition”

This is a presentation on the numbers that make up the internet. RPKI, IPv6, Security. Attached is a similar presentation that was presented for IDNOG. Numbers for SG would be updated closer to the date to ensure accuracy and currency.

 

Terence Chia

ACE
Infocomm Media Development Authority (IMDA)

Terence Chia leads IMDA’s Connectivity, Cybersecurity & Resilience Group, which works to secure Singapore’s digital infrastructure and oversee its regulatory and technological aspects, including spectrum management, satellite regulations, and standards development.

Terence has spent two decades in the Singapore Public Service across policy, strategy, and operational roles — including dealing with security matters in the Ministry of Home Affairs and National Security Coordination Secretariat, manpower/HR matters and, more recently, industry development work in growing Singapore’s pipeline of scarce tech talent.

Terence holds the CPTIA and GCFA certifications and serves on the GIAC Advisory Council. His biggest learnings, though, have come from working alongside his team and stakeholders in preventing, responding to, and building back better from cybersecurity incidents.

Terence holds Bachelor’s degrees in Electrical Engineering and Economics from Stanford University and an MBA from IESE Business School.”

 

Can (A)I Hack It? Reflections of a Regulator

“AI is changing cybersecurity faster than most frameworks can keep up and regulators, defenders, and attackers are all working out where its real limits lie. In “”Can (A)I Hack It? Reflections of a Regulator”” Terence looks back on his route into cyber regulation and shares a view you rarely get to hear: how frontier AI tools actually hold up when tested against AI-powered threats.

From CTF challenges to shaping cybersecurity codes of practice, he’ll cover what delivered, what fell short, and the questions security professionals should be asking as AI takes on a bigger role on both sides of the fight. Practical, current, and grounded in real experience.”