Beom Heyn Kim

dblp:05/10299 · also Beom Heyn Ben Kim · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0002-8650-6082ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2024 Poster: Detecting Ransomware Attacks by Analyzing Replicated Block Snapshots Using Neural Networks
abstract
Cloud antivirus solutions address limitations of host-based malware detection such as extensive resource consumption. However, they remain vulnerable to sophisticated polymorphic and privileged malware. Also, existing solutions are not suitable to defend against destructive ransomware attacks. We propose an enhancement to existing cloud antivirus solutions that enables deep learning-based block snapshot analysis to detect evasive and privileged ransomware in virtualized environment without requiring any hardware support. Preliminary results validate the proposed approach.
Seok Min Hong, Beom Heyn Kim, Mohammad Mannan
CCS2
2022 Modulo: Finding Convergence Failure Bugs in Distributed Systems with Divergence Resync Models
Beom Heyn Kim, Taesoo Kim, David Lie
USENIX ATC1
2021 Rocky: Replicating Block Devices for Tamper and Failure Resistant Edge-based Virtualized Desktop Infrastructure
abstract
Recently, edge-based virtual desktop infrastructure (EdgeVDI), which brings the power of virtualized desktop infrastructure to cloudlets closer to users, has been considered as an attractive solution for WAN mobility. However, ransomware and wiper malware are becoming more and more prevalent, which can impose serious cybersecurity threats to EdgeVDI users. Existing tamper-resistant solutions cannot deal with cloudlet failures. In this paper, we propose Rocky, the first distributed replicated block device for EdgeVDI that can recover from tampering attacks and failures. The key enabler is replicating to store a consistent write sequence across cloudlets as an append-only immutable mutation history. In addition, Rocky uses a replication broker to allow heterogenous cloudlets to control replication rates at their pace and reduces both disk space and network bandwidth consumption by coalescing writes for both uplink and downlink. To show the feasibility of Rocky, we implemented Rocky in Java. The experimental results show that Rocky’s write and read throughputs are similar to those of a baseline device with 8.4% and 11.9% additional overheads, respectively. In addition, we could reduce repeated writes by 88.5% and 100% for editing presentation slides and a photo, respectively.
Beom Heyn Kim, Hyoungshick Kim
ACSAC1
2019 Secure Consistency Verification for Untrusted Cloud Storage by Public Blockchains
Kai Li 0017, Yuzhe Tang, Beom Heyn Kim, Jianliang Xu
SecureComm (1)3
2017 Consistency Oracles: Towards an Interactive and Flexible Consistency Model Specification
abstract
Many modern distributed storage systems emphasize availability and partition tolerance over consistency, leading to many systems that provide weak data consistency. However, weak data consistency is difficult for both system designers and users to reason about. Formal specifications offer precise descriptions of consistency behavior, but they require expertise and specialized tools to apply to real software systems. In this paper, we propose and describe consistency oracles, an alternative way of specifying the consistency model of a system that provides interactive answers, making them easier and more flexible to use in a variety of ways. A consistency oracle mimics the interface of a distributed storage system, but returns all possible values that may be returned under a given consistency model. This allows consistency oracles to be directly applied in the testing and verification of both distributed storage systems and the client software that uses those systems.
Beom Heyn Kim, Sukwon Oh, David Lie
HotOS1
2015 Caelus: Verifying the Consistency of Cloud Services with Battery-Powered Devices
abstract
Cloud storage services such as Amazon S3, Drop Box, Google Drive and Microsoft One Drive have become increasingly popular. However, users may be reluctant to completely trust a cloud service. Current proposals in the literature to protect the confidentiality, integrity and consistency of data stored in the cloud all have shortcomings when used on battery-powered devices -- they either require devices to be on longer so they can communicate directly with each other, rely on a trusted service to relay messages, or cannot provide timely detection of attacks. We propose Caelus, which addresses these shortcoming. The key insight that enables Caelus to do this is having the cloud service declare the timing and order of operations on the cloud service. This relieves Caelus devices from having to record and send the timing and order of operations to each other -- instead, they need to only ensure that the timing and order of operations both conforms to the cloud's promised consistency model and that it is perceived identically on all devices. In addition, we show that Caelus is general enough to support popular consistency models such as strong, eventual and causal consistency. Our experiments show that Caelus can detect consistency violations on Amazon's S3 service when the desired consistency requirements set by the user are stricter than what S3 provides. Caelus achieves this with a roughly 12.6% increase in CPU utilization on clients, 1.3% of network bandwidth overhead and negligible impact on the battery life of devices.
Beom Heyn Kim, David Lie
IEEE Symposium on Security and Privacy1
2011 Unicorn: two-factor attestation for data security
abstract
Malware and phishing are two major threats for users seeking to perform security-sensitive tasks using computers today. To mitigate these threats, we introduce Unicorn, which combines the phishing protection of standard security tokens and malware protection of trusted computing hardware. The Unicorn security token holds user authentication credentials, but only releases them if it can verify an attestation that the user's computer is free of malware. In this way, the user is released from having to remember passwords, as well as having to decide when it is safe to use them. The user's computer is further verified by either a TPM or a remote server to produce a two-factor attestation scheme. We have implemented a Unicorn prototype using commodity software and hardware, and two Unicorn example applications (termed as uApps, short for Unicorn Applications), to secure access to both remote data services and encrypted local data. Each uApp consists of a small, hardened and immutable OS image, and a single application. Our Unicorn prototype co-exists with a regular user OS, and significantly reduces the time to switch between the secure environment and general purpose environment using a novel mechanism that removes the BIOS from the switch time.
Mohammad Mannan, Beom Heyn Kim, Afshar Ganjali, David Lie
CCS2