Taeho Kwon

dblp:09/8305 · DBLP profile ↗
← Back
5ranked-venue papers
5as first author
0since 2021 · last 2012
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 4 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Systems and software security · 79% Malware analysis · 21%
Software engineering, system software, and programming languages
4 papers
Program analysis · 63% Software maintenance and evolution · 37%

Topics — the 8 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
0.432012
Automatic Detection of Unsafe Dynamic Component Loadings · IEEE Trans. Software Eng. 2012
Detecting and analyzing insecure component usage · SIGSOFT FSE 2012
Automatic detection of unsafe component loadings · ISSTA 2010
Program analysis › dynamic analysis
dynamic binary instrumentation
0.322012
Automatic Detection of Unsafe Dynamic Component Loadings · IEEE Trans. Software Eng. 2012
Automatic detection of unsafe component loadings · ISSTA 2010
Software maintenance and evolution
code clone detection
0.112011
Modeling High-Level Behavior Patterns for Precise Similarity Analysis of Software · ICDM 2011
Program analysis
dynamic analysis
0.112010
Automatic detection of unsafe component loadings · ISSTA 2010
Software maintenance and evolution › software reuse
component reuse
0.012012
Detecting and analyzing insecure component usage · SIGSOFT FSE 2012
Software maintenance and evolution
software ecosystems
0.012012
Detecting and analyzing insecure component usage · SIGSOFT FSE 2012
Systems and software security
exploitation
0.012010
Automatic detection of unsafe component loadings · ISSTA 2010
Systems and software security › exploitation
remote code execution
0.012010
Automatic detection of unsafe component loadings · ISSTA 2010

Methods — techniques the papers use, named apart from their topics

dynamic binary instrumentation · 0.5static analysis · 0.3regular expression abstraction · 0.2clustering · 0.2offline trace analysis · 0.2
YearPublicationVenuePosition
2012 Static Detection of Unsafe Component Loadings
Taeho Kwon, Zhendong Su 0001
CC1
2012 Detecting and analyzing insecure component usage
abstract
Software is commonly built from reusable components that provide desired functionalities. Although component reuse significantly improves software productivity, insecure component usage can lead to security vulnerabilities in client applications. For example, we noticed that widely-used IE-based browsers, such as IE Tab, do not enable important security features that IE enables by default, even though they all use the same browser components. This insecure usage renders these IE-based browsers vulnerable to the attacks blocked by IE. To our knowledge, this important security aspect of component reuse has largely been unexplored.
Taeho Kwon, Zhendong Su 0001
SIGSOFT FSE1
2012 Automatic Detection of Unsafe Dynamic Component Loadings
abstract
Dynamic loading of software components (e.g., libraries or modules) is a widely used mechanism for an improved system modularity and flexibility. Correct component resolution is critical for reliable and secure software execution. However, programming mistakes may lead to unintended or even malicious components being resolved and loaded. In particular, dynamic loading can be hijacked by placing an arbitrary file with the specified name in a directory searched before resolving the target component. Although this issue has been known for quite some time, it was not considered serious because exploiting it requires access to the local file system on the vulnerable host. Recently, such vulnerabilities have started to receive considerable attention as their remote exploitation became realistic. It is now important to detect and fix these vulnerabilities. In this paper, we present the first automated technique to detect vulnerable and unsafe dynamic component loadings. Our analysis has two phases: 1) apply dynamic binary instrumentation to collect runtime information on component loading (online phase), and 2) analyze the collected information to detect vulnerable component loadings (offline phase). For evaluation, we implemented our technique to detect vulnerable and unsafe component loadings in popular software on Microsoft Windows and Linux. Our evaluation results show that unsafe component loading is prevalent in software on both OS platforms, and it is more severe on Microsoft Windows. In particular, our tool detected more than 4,000 unsafe component loadings in our evaluation, and some can lead to remote code execution on Microsoft Windows.
Taeho Kwon, Zhendong Su 0001
IEEE Trans. Software Eng.1
2011 Modeling High-Level Behavior Patterns for Precise Similarity Analysis of Software
abstract
The analysis of software similarity has many applications such as detecting code clones, software plagiarism, code theft, and polymorphic malware. Because often source code is unavailable and code obfuscation is used to avoid detection, there has been much research on developing effective models to capture runtime behavior to aid detection. Existing models focus on low-level information such as dependency or purely occurrence of function calls, and suffer from poor precision, poor scalability, or both. To overcome limitations of existing models, this paper introduces a precise and succinct behavior representation that characterizes high-level object-accessing patterns as regular expressions. We first distill a set of high-level patterns (the alphabet S of the regular language) based on two pieces of information: function call patterns to access objects and type state information of the objects. Then we abstract a runtime trace of a program P into a regular expression e over the pattern alphabet S to produce P's behavior signature. We show that software instances derived from the same code exhibit similar behavior signatures and develop effective algorithms to cluster and match behavior signatures. To evaluate the effectiveness of our behavior model, we have applied it to the similarity analysis of polymorphic malware. Our results on a large malware collection demonstrate that our model is both precise and succinct for effective and scalable matching and detection of polymorphic malware.
Taeho Kwon, Zhendong Su 0001
ICDM1
2010 Automatic detection of unsafe component loadings
abstract
Dynamic loading of software components (e.g., libraries or modules) is a widely used mechanism for improved system modularity and flexibility. Correct component resolution is critical for reliable and secure software execution, however, programming mistakes may lead to unintended or even malicious components to be resolved and loaded. In particular, dynamic loading can be hijacked by placing an arbitrary file with the specified name in a directory searched before resolving the target component. Although this issue has been known for quite some time, it was not considered serious because exploiting it requires access to the local file system on the vulnerable host. Recently such vulnerabilities started to receive considerable attention as their remote exploitation became realistic; it is now important to detect and fix these vulnerabilities. In this paper, we present the first automated technique to detect vulnerable and unsafe dynamic component loadings. Our analysis has two phases: 1) apply dynamic binary instrumentation to collect runtime information on component loading (online phase); and 2) analyze the collected information to detect vulnerable component loadings (offline phase). For evaluation, we implemented our technique to detect vulnerable and unsafe DLL loadings in popular Microsoft Windows software. Our results show that unsafe DLL loading is prevalent and can lead to serious security threats. Our tool detected more than 1,700 unsafe DLL loadings in 28 widely used software and discovered serious attack vectors for remote code execution. Microsoft has opened a Microsoft Security Response Center (MSRC) case on our reported issues and is working with us and other affected software vendors to develop necessary patches.
Taeho Kwon, Zhendong Su 0001
ISSTA1