Seonghoon Jeong 0001

dblp:121/3719-1 · also Seong Hoon Jeong 0001 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0001-5638-2851ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 2 first-author · 1 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 J1939DB-IDS: SAE J1939 Dual-Branch Intrusion Detection System Against Novel Attacks
Hwejae Lee, Seonghoon Jeong 0001, Huy Kang Kim
IEEE Trans. Netw. Serv. Manag.2
2024 AERO: Automotive Ethernet Real-Time Observer for Anomaly Detection in In-Vehicle Networks
abstract
Automotive Ethernet enables high-bandwidth in-vehicle networking, facilitating the transmission of sensor data among electronic control units. However, the increasing connectivity and potential vulnerability inheritance in connected and autonomous vehicles expose them to security risks. To address this challenge, an intrusion detection system (IDS) capable of analyzing automotive Ethernet traffic and detecting anomalies is essential. In thisarticle, we propose automotive Ethernet real-time observer (AERO), an unsupervised network IDS designed to protect in-vehicle networks. AERO consists of three components: a feature extractor that constructs three multimodal features, a neural network for processing the extracted features, and an online anomaly detector that calculates outlier scores in real time. We evaluate the performance of AERO using the TOW-IDS automotive Ethernet intrusion dataset. The experimental results demonstrate that AERO achieves high detection performance across five different attack types and is highly applicable to automotive-grade devices for real-time anomaly detection.
Seonghoon Jeong 0001, Huy Kang Kim, Mee Lan Han, Byung Il Kwak
IEEE Trans. Ind. Informatics1
2023 Infotainment System Matters: Understanding the Impact and Implications of In-Vehicle Infotainment System Hacking with Automotive Grade Linux
abstract
An in-vehicle infotainment (IVI) system is connected to heterogeneous networks such as Controller Area Network bus, Bluetooth, Wi-Fi, cellular, and other vehicle-to-everything communications. An IVI system has control of a connected vehicle and deals with privacy-sensitive information like current geolocation and destination, phonebook, SMS, and driver's voice. Several offensive studies have been conducted on IVI systems of commercialized vehicles to show the feasibility of car hacking. However, to date, there has been no comprehensive analysis of the impact and implications of IVI system exploitations. To understand security and privacy concerns, we provide our experience hosting an IVI system hacking competition, Cyber Security Challenge 2021 (CSC2021). We use a feature-flavored infotainment operating system, Automotive Grade Linux (AGL). The participants gathered and submitted 33 reproducible and verified proofs-of-concept exploit codes targeting 11 components of the AGL-based IVI testbed. The participants exploited four vulnerabilities to steal various data, manipulate the IVI system, and cause a denial of service. The data leakage includes privacy, personally identifiable information, and cabin voice. The participants proved lateral movement to electronic control units and smartphones. We conclude with lessons learned with three mitigation strategies to enhance the security of the IVI system.
Seonghoon Jeong 0001, Minsoo Ryu, Hyunjae Kang 0001, Huy Kang Kim
CODASPY1
2022 Trading Behind-the-Scene: Analysis of Online Gold Farming Network in the Auction House System
abstract
Owing to the widespread use of smartphones, various online games based on mobile platforms are being launched. Although mobile games have the advantage of better accessibility compared to PC games, there is a limitation in that it is difficult to input specific actions. To overcome this limitation, game companies apply autoplay systems to support users. Autoplay (with macro or game bot programs) without human interaction was previously regarded as a cheating play. To provide a more comfortable and easy gaming experience to users, most mobile games currently provide autoplay functionality. Such introduction means that along with gold farming groups (GFGs), all users can use a game bot. Therefore, game companies prevent profit-producing activities of GFGs by introducing an in-game economic system in which a real money trading (RMT) is impossible. However, GFGs still operate by abusing an auction house. Our study uses the three-month transaction logs of a mobile game that introduces an auction house as an in-game economic system. We observe the abuse that makes RMTs possible through the auction house and propose a method of identifying abuse solely through a transaction log. We analyzed the GFGs using the identified abuse and confirmed that the GFG consists of a single role.
Yuseung Noh, Seonghoon Jeong 0001, Huy Kang Kim
IEEE Trans. Games2
2021 Cybersecurity for autonomous vehicles: Review of attacks and defense
Kyounggon Kim, Jun Seok Kim, Seonghoon Jeong 0001, Jo-Hee Park, Huy Kang Kim
Comput. Secur.3
2018 Automated Reverse Engineering and Attack for CAN Using OBD-II
abstract
Controller area network (CAN) is one of the most popular in-vehicle networks. CAN allows electronic control units (ECUs) to communicate with each other. ECUs control various function of vehicle systems such as engine and transmission control. Therefore, CAN and ECUs are the high priority targets by hackers. If the CAN and the connected components are attacked, the vehicle may cause serious malfunction and fatal accidents. However, it is hard to find out the exact CAN messages to send and control the vehicle as intended by hackers. Likewise, vehicle security researchers have the same problem to find out the exact meaning of CAN messages to detect sophisticated attacks as well as attackers. It is relatively easy to detect the simple pattern of attacks such as denial of service (DoS) attack. However, CAN specification information is private information of car OEMs, to reveal the exact meaning of CAN messages, we need to analyze the messages by reverse engineering techniques, which is time-consuming and laborious tasks. To solve this problem, we developed the Automated CAN Analyzer (ACA). The ACA has automated reverse engineering functions which can help to analyze the relationship between the response data from a diagnostic query of on-board diagnostics II (OBD-II) and the related CAN traffic data. Furthermore, it supports the automated attack function that can inject fake messages into CAN bus based on pre-analyzed CAN message information. Researchers can easily confirm whether the reverse engineering results are correctly working or not through the provided automated attack function. As a result, the ACA could lower the barriers to entry to in-vehicle network research. To evaluate the ACA, we applied our approach to two real vehicles, Hyundai YF Sonata (2010 model) and KIA Soul (2014 model). In this paper, we can find out the meaning of CAN messages on both vehicles with the help of the ACA. Additionally, since modern vehicles are all equipped with OBD-II, our approach can be applied to most vehicle widely.
Tae Un Kang, Hyun Min Song, Seonghoon Jeong 0001, Huy Kang Kim
VTC Fall3
2017 OTIDS: A Novel Intrusion Detection System for In-vehicle Network by Using Remote Frame
abstract
Controller Area Network (CAN) is a bus communication protocol which defines a standard for reliable and efficient transmission between in-vehicle nodes in real-time. Since CAN message is broadcast from a transmitter to the other nodes on a bus, it does not contain information about the source and destination address for validation. Therefore, an attacker can easily inject any message to lead system malfunctions. In this paper, we propose an intrusion detection method based on the analysis of the offset ratio and time interval between request and response messages in CAN. If a remote frame having a particular identifier is transmitted, a receiver node should respond to the remote frame immediately. In attack-free state, each node has a fixed response offset ratio and time interval while these values vary in attack state. Using this property, we can measure the response performance of the existing nodes based on the offset ratio and time interval between request and response messages. As a result, our methodology can detect intrusions by monitoring offset ratio and time interval, and it allows quick intrusion detection with high accuracy.
Hyunsung Lee, Seonghoon Jeong 0001, Huy Kang Kim
PST2
2016 A Longitudinal Analysis of .i2p Leakage in the Public DNS Infrastructure
abstract
The Invisible Internet Project (I2P) is an overlay network that provides secure and anonymous communication channels. EepSites are the anonymous websites hosted in the I2P network. To access the eepSites, DNS requests of a domain name suffixed with the {\sf .i2p} pseudo top-level domain (TLD) are routed within the I2P network. However, not only that {\sf .i2p} queries are leaking in the public DNS infrastructure, but also such leakage has various plausible root causes and implications that are different from other related leakage. In this paper, we analyze the leaked {\sf .i2p} requests captured in the A and J root name servers of the public DNS, showing that a large number of queries are observed and outlining various potential directions of addressing such leakage.
Seonghoon Jeong 0001, Ah Reum Kang, Joongheon Kim, Huy Kang Kim, David Mohaisen
SIGCOMM1
2015 Analysis of Game Bot's Behavioral Characteristics in Social Interaction Networks of MMORPG
abstract
MMORPG (Massively Multiplayer Online Role-Playing Game) is one of the best platforms to observe human's behaviors. In collaboration with a leading online game company, NCSoft, we can observe all behaviors in a large-scale of commercialized MMORPG. Especially, we analyzed the behavioral differences between game bots and human users. We categorized the five groups, Bot-Bot, Bot-All, Human-Human, Human-All and All-All, and we observe the characteristics of six social interaction networks for each group. As a result, we found that there are significant differences in social behaviors between game bots and human.
Seonghoon Jeong 0001, Ah Reum Kang, Huy Kang Kim
SIGCOMM1