DaeHun Nyang

dblp:13/3903 · also Daehun Nyang · DBLP profile ↗
← Back
67ranked-venue papers
5as first author
21since 2021 · last 2026
0000-0001-5183-891XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 1 first-author · 11 since 2021Computer networks · 22 · 3 first-author · 7 since 2021Systems, architecture and hardware · 8 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 first-authorDatabases, data management, data science and information retrieval · 3Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Defeating Slow-and-Low Threats via Diffusion Model-based Generative Inference
Seyed Mohammad Mehdi Mirnajafizadeh, Prashant Khanduri, DaeHun Nyang, RhongHo Jang
NSDI3
2025 SketchFeature: High-Quality Per-Flow Feature Extractor Towards Security-Aware Data Plane
Sian Kim, Seyed Mohammad Mehdi Mirnajafizadeh, Bara Kim, RhongHo Jang, DaeHun Nyang
NDSS5
2025 Enhancing Vulnerability Reports With Automated and Augmented Description Summarization
abstract
Public vulnerability databases, such as the National Vulnerability Database (NVD), document vulnerabilities and facilitate threat information sharing. However, they often suffer from short descriptions and outdated or insufficient information. In this paper, we introduceZad, a system designed to enrich NVD vulnerability descriptions by leveraging external resources.Zadconsists of two pipelines: one collects and filters supplementary data using two encoders to build a detailed dataset, while the other fine-tunes a pre-trained model on this dataset to generate enriched descriptions. By addressing brevity and improving content quality,Zadproduces more comprehensive and cohesive vulnerability descriptions. We evaluateZadusing standard summarization metrics and human assessments, demonstrating its effectiveness in enhancing vulnerability information.
Hattan Althebeiti, Mohammed Alkinoon, Manar Mohaisen, Saeed Salem, DaeHun Nyang, David Mohaisen
IEEE Trans. Big Data5
2025 SHIELD: Thwarting Code Authorship Attribution
abstract
Authorship attribution has become increasingly accurate, posing a serious privacy risk for programmers who wish to remain anonymous. In this article, we introduce SHIELD to examine the robustness of different code authorship attribution approaches against adversarial code examples. We define four attacks on attribution techniques, which include targeted and non-targeted attacks, and realize them using adversarial code perturbation. We experimented with a dataset of 200 programmers from the Google Code Jam competition to validate our methods. We target six state-of-the-art authorship attribution methods that adopt various techniques for extracting authorship traits from source code, including RNN, CNN, and code stylometry. Our experiments demonstrate the vulnerability of current authorship attribution methods against adversarial attacks. For the non-targeted attack, our experiments demonstrate the vulnerability of current authorship attribution methods against the attack with an attack success rate exceeding 98. 5% accompanied by a degradation of the identification confidence exceeding 13%. For targeted attacks, we show the possibility of impersonating a programmer using targeted adversarial perturbations with a success rate ranging from 66% to 88% for different authorship attribution techniques under several adversarial scenarios.
Mohammed Abuhamad, Changhun Jung, David Mohaisen, DaeHun Nyang
IEEE Trans. Dependable Secur. Comput.4
2024 Enhancing Network Attack Detection with Distributed and In-Network Data Collection System
Seyed Mohammad Mehdi Mirnajafizadeh, Ashwin Raam Sethuram, David Mohaisen, DaeHun Nyang, RhongHo Jang
USENIX Security Symposium4
2023 Understanding the Security and Performance of the Web Presence of Hospitals: A Measurement Study
abstract
The recent transformation of healthcare medical records from paper-based to digital and connected systems raises concerns regarding patients' security and online privacy. For instance, sensitive personal information, such as patients' names, addresses, and social security numbers, may be targeted due to the lack of proper security and privacy mechanisms. Using a total of 4,774 hospitals categorized as government, non-profit, and proprietary hospitals, this study provides the first measurement-based analysis of hospitals' websites and connects the findings with data breaches through a correlation analysis. We study the security attributes of three categories, collectively and in contrast, against domain name-, content-, and SSL certificate-level features. We find that each type of hospitals has a distinctive characteristic of its utilization of domain name registrars, top-level domain distribution, and domain creation distribution, as well as content type and HTTP request features. Security-wise, and consistent with the general population of websites, only 1% of government hospitals utilized DNSSEC, in contrast to 6% of the proprietary hospitals. Alarmingly, we found that 25% of the hospitals used plain HTTP, in contrast to 20% in the general web population. Alarmingly too, we found that 8%-84% of the hospitals, depending on their type, had some malicious contents, which are mostly attributed to the lack of maintenance. We conclude with a correlation analysis against 414 confirmed and manually vetted hospitals' data breaches. Among other interesting findings, our study highlights that the security attributes highlighted in our analysis of hospital websites are forming a very strong indicator of their likelihood of being breached. Our analyses are the first step towards understanding patient online privacy, highlighting the lack of basic security in many hospitals' websites and opening various potential research directions.
Mohammed Alkinoon, Abdulrahman Alabduljabbar, Hattan Althebeiti, RhongHo Jang, DaeHun Nyang, David Mohaisen
ICCCN5
2023 Revisiting the Deep Learning-Based Eavesdropping Attacks via Facial Dynamics from VR Motion Sensors
Soohyeon Choi, Manar Mohaisen, DaeHun Nyang, David Mohaisen
ICICS3
2023 A Robust Counting Sketch for Data Plane Intrusion Detection
Sian Kim, Changhun Jung, RhongHo Jang, David Mohaisen, DaeHun Nyang
NDSS5
2022 A Scalable and Dynamic ACL System for In-Network Defense
abstract
In-network/in-switch Access Control List (ACL) is an essential security component of modern networks. In high-speed networks, ACL rules are often placed in a switch's Ternary Content-Addressable Memory (TCAM) for timely ACL match-action and management (e.g. insertion and deletion). However, TCAM-based ACL systems are encountering an scalability issue owing to increasing demand on AI-powered autonomous defenses that detect and block attacks online, which inevitably derives finer-grained ACL rules. Existing solutions minimize the TCAM usage by partially offloading ACL matching into larger Static Random-Access Memory (SRAM) or customized hardware. Nevertheless, current SRAM-based solutions induce high management costs, especially a high rule-deployment latency, which delays time-sensitive defense actions. Also, the customized hardware approaches have its own scalability issue. To support autonomous defenses at a scale, in this paper, we propose an in-switch ACL system called PortCatcher, which breaks the trade-off between scalability and rule management latency. System-wise, we detach layer-4 port matching from TCAM for improving its memory efficiency. Algorithm-wise, we introduce a novel port (range) rule representation concept, called linear range map (LRM), which enables port (range) matching in SRAM-based hash tables. LRM guarantees not only fast and scalable port matching but also low-latency ACL management for timely defenses. With real-world ACL datasets, we show that PortCatcher saves 74%-90% TCAM space compared to state-of-the-art approaches by adding small overhead to SRAM (0.49 SRAM entry per ACL rule). Also, we deploy PortCatcher on a programmable switch to demonstrate that PortCatcher can serve 5-tuple rule matching at a line rate, where port rules are completely matched in SRAM. With a use case study, namely autonomous attack mitigation, we show that PortCatcher has a negligible rule management latency to block attack flows (i.e. 94.42% of rules deployed within 10 ms).
Changhun Jung, Sian Kim, RhongHo Jang, David Mohaisen, DaeHun Nyang
CCS5
2022 Minimizing Noise in HyperLogLog-Based Spread Estimation of Multiple Flows
abstract
Cardinality estimation has become an essential building block of modern network monitoring systems due to the increasing concerns of cyberattacks (e.g., Denial-of-Service, worm, spammer, scanner, etc.). However, the ever-increasing attack scale and the diversity of patterns (i.e., flow size distribution) will produce a biased estimation of existing solutions if apply a monotonic hypothesis for network traffic. The most representative solution is virtual HyperLogLog (vHLL), which extended the proven HLL, a single element cardinality estimation solution, to a multi-tenant version using a memory random sharing and noise elimination approach. In this paper, we show that the assumption made by vHLL’s does not work for large-scale network traffic with diverse flow distributions. To resolve the issue, we propose a novel noise elimination method, called Rank Recovery-based Spread Estimator (RRSE), which is tolerant to both attack and normal traffic scenarios while using limited computation and storage. We show that our recovery function is more reliable than state-of-the-art approaches. Moreover, we implemented RRSE in a programmable switch to show the feasibility.
Dinhnguyen Dao, RhongHo Jang, Changhun Jung, David Mohaisen, DaeHun Nyang
DSN5
2022 Systematically Evaluating the Robustness of ML-based IoT Malware Detection Systems
abstract
The rapid growth of the Internet of Things (IoT) devices is paralleled by them being on the front-line of malicious attacks. This has led to an explosion in the number of IoT malware, with continued mutations, evolution, and sophistication. Malware samples are detected using machine learning (ML) algorithms alongside the traditional signature-based methods. Although ML-based detectors improve the detection performance, they are susceptible to malware evolution and sophistication, making them limited to the patterns that they have been trained upon. This continuous trend motivates large body of literature on malware analysis and detection research, with many systems emerging constantly, outperforming their predecessors. In this paper, we systematically examine the state-of-the-art malware detection approaches, that utilize various representation and learning techniques, under a range of adversarial settings. Our analyses highlight the instability of the proposed detectors in learning patterns that distinguish the benign from the malicious software. The results exhibit that software mutations with functionality-preserving operations, such as stripping and padding, significantly deteriorate the accuracy of such detectors. Additionally, our analysis of the industry-standard malware detectors shows their instability to the malware mutations. Through extensive experiments, we highlight the gap between the capabilities of the adversary and that of the existing malware detectors. The evaluations and analyses show that the optimal malware detection system is nowhere near and calls for the community to streamline their efforts towards testing the robustness of malware detectors to different manipulation techniques.
Ahmed Abusnaina, Afsah Anwar, Sultan S. Alshamrani, Abdulrahman Alabduljabbar, RhongHo Jang, DaeHun Nyang, David Mohaisen
RAID6
2022 Understanding Internet of Things malware by analyzing endpoints in their static artifacts
Jinchun Choi, Afsah Anwar, Abdulrahman Alabduljabbar, Hisham Alasmary, Jeffrey Spaulding, An Wang 0002, Songqing Chen, DaeHun Nyang, Amro Awad, David Mohaisen
Comput. Networks8
2022 ShellCore: Automating Malicious IoT Software Detection Using Shell Commands Representation
abstract
The Linux shell is a command-line interpreter that provides users with a command interface to the operating system, allowing them to perform various functions. Although very useful in building capabilities at the edge, the Linux shell can be exploited, giving adversaries a prime opportunity to use them for malicious activities. With access to Internet of Things (IoT) devices, malware authors can abuse the Linux shell of those devices to propagate infections and launch large-scale attacks, e.g., Distributed Denial of Service. In this work, we provide a first look at the tasks managed by shell commands in Linux-based IoT malware toward detection. We analyze malicious shell commands found in IoT malware and build a neural network-based model, ShellCore, to detect malicious shell commands. Namely, we collected a large data set of shell commands, including malicious commands extracted from 2891 IoT malware samples and benign commands collected from real-world network traffic analysis and volunteered data from Linux users. Using conventional machine and deep learning-based approaches trained with a term- and character-level features, ShellCore is shown to achieve an accuracy of more than 99% in detecting malicious shell commands and files (i.e., binaries).
Hisham Alasmary, Afsah Anwar, Ahmed Abusnaina, Abdulrahman Alabduljabbar, Mohammed Abuhamad, An Wang 0002, DaeHun Nyang, Amro Awad, David Mohaisen
IEEE Internet Things J.7
2022 DL-FHMC: Deep Learning-Based Fine-Grained Hierarchical Learning Approach for Robust Malware Classification
abstract
The acceptance of the Internet of Things (IoT) for both household and industrial applications is accompanied by the rapid growth of IoT malware. With the increase of their attack surface, analyzing, understanding, and detecting IoT malicious behavior are crucial. Traditionally, machine and deep learning-based approaches are used for malware detection and behavioral understanding. However, recent research has shown the susceptibility of those approaches to adversarial attacks by introducing noise to the feature space. In this work, we introduce DL-FHMC, a fine-grained hierarchical learning approach for robust IoT malware detection. DL-FHMC utilizes Control Flow Graph (CFG)-based behavioral patterns for adversarial IoT malicious software detection. In particular, we extract a comprehensive list of behavioral patterns from a large dataset of malicious IoT binaries, represented by the shared execution flows, and use them as a modality for malicious behavior detection. Leveraging machine learning and subgraph isomorphism matching algorithms, DL-FHMC provides state-of-the-art performance in detecting malware samples and adversarial examples (AEs). We first highlight the caveats of CFG-based IoT malware detection systems, showing the adversarial capabilities in generating practical functionality-preserving AEs with reduced overhead using Graph Embedding and Augmentation (GEA) techniques. We then introduce Suspicious Behavior Detector, a component that extracts comprehensive behavioral patterns from three popular IoT malicious families, Gafgyt, Mirai, and Tsunami, for AEs detection with high accuracy. The proposed detector operates as a model-independent standalone module, with no prior assumptions of the adversarial attacks nor their configurations.
Ahmed Abusnaina, Mohammed Abuhamad, Hisham Alasmary, Afsah Anwar, RhongHo Jang, Saeed Salem, DaeHun Nyang, David Mohaisen
IEEE Trans. Dependable Secur. Comput.7
2022 A One-Page Text Entry Method Optimized for Rectangle Smartwatches
abstract
In this paper, we provide the design and implementation of UOIT, a text entry method optimized for smartwatches. UOIT uses only one page where a user can see and tap directly for entry without any additional actions, such as zoom-in/zoom-out and swipes, which are required in the existing entry methods. To fully utilize the constrained screen space and to address the “fat finger” problem, we use a technique called “drawing-like typing”, which reduces the 26 small alphabetic keys into 13 large keys with a dual input property. To evaluate the performance of UOIT, we conducted two user studies while varying the learning period. In the short-term experiments (i.e., two days), we observed a fast learning curve of users when using the UOIT keyboard. Moreover, with the long-term experiments (i.e., a month), we show that users can type as fast as QWERTY keyboard but with much less errors. Moreover, UOIT outperforms the state-of-the-art keyboard in both speed and error rate.
RhongHo Jang, Changhun Jung, David Mohaisen, KyungHee Lee, DaeHun Nyang
IEEE Trans. Mob. Comput.5
2021 A network-independent tool-based usable authentication system for Internet of Things devices
Changhun Jung, Jinchun Choi, RhongHo Jang, David Mohaisen, DaeHun Nyang
Comput. Secur.5
2021 Sensor-Based Continuous Authentication of Smartphones' Users Using Behavioral Biometrics: A Contemporary Survey
abstract
Mobile devices and technologies have become increasingly popular, offering comparable storage and computational capabilities to desktop computers allowing users to store and interact with sensitive and private information. The security and protection of such personal information are becoming more and more important since mobile devices are vulnerable to unauthorized access or theft. User authentication is a task of paramount importance that grants access to legitimate users at the point of entry and continuously through the usage session. This task is made possible with today's smartphones' embedded sensors that enable continuous and implicit user authentication by capturing behavioral biometrics and traits. In this article, we survey more than 140 recent behavioral biometric-based approaches for continuous user authentication, including motion-based methods (28 studies), gait-based methods (19 studies), keystroke dynamics-based methods (20 studies), touch gesture-based methods (29 studies), voice-based methods (16 studies), and multimodal-based methods (34 studies). The survey provides an overview of the current state-of-the-art approaches for continuous user authentication using behavioral biometrics captured by smartphones' embedded sensors, including insights and open challenges for adoption, usability, and performance.
Mohammed Abuhamad, Ahmed Abusnaina, DaeHun Nyang, David Mohaisen
IEEE Internet Things J.3
2021 Contra-∗: Mechanisms for countering spam attacks on blockchain's memory pools
Muhammad Saad 0001, Joongheon Kim, DaeHun Nyang, David Mohaisen
J. Netw. Comput. Appl.3
2021 SSD-Assisted Ransomware Detection and Data Recovery Techniques
abstract
As ransomware attacks have been prevalent, it becomes crucial to make anti-ransomware solutions that defend against ransomwares. In this article, we propose a new ransomware defense system, calledSSD-Insider++, which prevents users’ files from being damaged by ransomware attacks. SSD-Insider++ is embedded into an SSD controller as a form of firmware. By being separated from a host machine, it not only provides more robust data protection than software-based ones which are vulnerable to evasion attacks, but also offers interoperability with various platforms. SSD-Insider++ is composed of two novel features, ransomware detection and perfect data recovery, which are tightly integrated with each other. The detection algorithm observes I/O patterns of a host system and decides whether the host is being attacked by ransomwares in an early stage. Once an encryption attack is detected, the recovery algorithm is triggered to recover original files by leveraging a delayed deletion feature of an SSD at a low cost. Our experimental results show that SSD-Insider++ achieves high accuracy of detecting ransomwares with 0 percent FRR/FAR in most cases and provides an instant data recovery with 0 percent data loss. The overhead of running SSD-Insider++ is negligible – only 80$n$s and 226$n$s are spent more for handling 4-KB reads and writes, respectively.
SungHa Baek, Youngdon Jung, David Mohaisen, Sungjin Lee 0001, DaeHun Nyang
IEEE Trans. Computers5
2021 Large-scale and Robust Code Authorship Identification with Deep Feature Learning
abstract
Successful software authorship de-anonymization has both software forensics applications and privacy implications. However, the process requires an efficient extraction of authorship attributes. The extraction of such attributes is very challenging, due to various software code formats from executable binaries with different toolchain provenance to source code with different programming languages. Moreover, the quality of attributes is bounded by the availability of software samples to a certain number of samples per author and a specific size for software samples. To this end, this work proposes a deep Learning-based approach for software authorship attribution, that facilitates large-scale, format-independent, language-oblivious, and obfuscation-resilient software authorship identification. This proposed approach incorporates the process of learning deep authorship attribution using a recurrent neural network, and ensemble random forest classifier for scalability to de-anonymize programmers. Comprehensive experiments are conducted to evaluate the proposed approach over the entire Google Code Jam (GCJ) dataset across all years (from 2008 to 2016) and over real-world code samples from 1,987 public repositories on GitHub. The results of our work show high accuracy despite requiring a smaller number of samples per author. Experimenting with source-code, our approach allows us to identify 8,903 GCJ authors, the largest-scale dataset used by far, with an accuracy of 92.3%. Using the real-world dataset, we achieved an identification accuracy of 94.38% for 745 C programmers on GitHub. Moreover, the proposed approach is resilient to language-specifics, and thus it can identify authors of four programming languages (e.g., C, C++, Java, and Python), and authors writing in mixed languages (e.g., Java/C++, Python/C++). Finally, our system is resistant to sophisticated obfuscation (e.g., using C Tigress) with an accuracy of 93.42% for a set of 120 authors. Experimenting with executable binaries, our approach achieves 95.74% for identifying 1,500 programmers of software binaries. Similar results were obtained when software binaries are generated with different compilation options, optimization levels, and removing of symbol information. Moreover, our approach achieves 93.86% for identifying 1,500 programmers of obfuscated binaries using all features adopted in Obfuscator-LLVM tool.
Mohammed Abuhamad, Tamer Abuhmed, David Mohaisen, DaeHun Nyang
ACM Trans. Priv. Secur.4
2021 e-PoS: Making Proof-of-Stake Decentralized and Fair
abstract
Blockchain applications that rely on the Proof-of-Work (PoW) have increasingly become energy inefficient with a staggering carbon footprint. In contrast, energy efficient alternative consensus protocols such as Proof-of-Stake (PoS) may cause centralization and unfairness in the blockchain system. To address these challenges, we propose a modular version of PoS-based blockchain systems called e-PoS that resists the centralization of network resources by extending mining opportunities to a wider set of stakeholders. Moreover, e-PoS leverages the in-built system operations to promote fair mining practices by penalizing malicious entities. We validate e-PoS 's achievable objectives through theoretical analysis and simulations. Our results show that e-PoS ensures fairness and decentralization, and can be applied to existing blockchain applications.
Muhammad Saad 0001, Zhan Qin, Kui Ren 0001, DaeHun Nyang, David Mohaisen
IEEE Trans. Parallel Distributed Syst.4
2020 Soteria: Detecting Adversarial Examples in Control Flow Graph-based Malware Classifiers
abstract
Deep learning algorithms have been widely used for security applications, including malware detection and classification. Recent results have shown that those algorithms are vulnerable to adversarial examples, whereby a small perturbation in the input sample may result in misclassification. In this paper, we systematically tackle the problem of adversarial examples detection in the control flow graph (CFG) based classifiers for malware detection using Soteria. Unique to Soteria, we use both density-based and level-based labels for CFG labeling to yield a consistent representation, a random walk-based traversal approach for feature extraction, and n-gram based module for feature representation. End-to-end, Soteria's representation ensures a simple yet powerful randomization property of the used classification features, making it difficult even for a powerful adversary to launch a successful attack. Soteria also employs a deep learning approach, consisting of an auto-encoder for detecting adversarial examples, and a CNN architecture for detecting and classifying malware samples. We evaluate the performance of Soteria, using a large dataset consisting of 16,814 IoT samples, and demonstrate its superiority in comparison with state-of-the-art approaches. In particular, Soteria yields an accuracy rate of 97.79% for detecting AEs, and 99.91% overall accuracy for classification malware families.
Hisham Alasmary, Ahmed Abusnaina, RhongHo Jang, Mohammed Abuhamad, Afsah Anwar, DaeHun Nyang, David Mohaisen
ICDCS6
2020 DFD: Adversarial Learning-based Approach to Defend Against Website Fingerprinting
abstract
The Onion Router (Tor) is designed to support an anonymous communication through end-to-end encryption. To prevent vulnerability of side channel attacks (e.g. website fingerprinting), dummy packet injection modules have been embedded in Tor to conceal trace patterns that are associated with the individual websites. However, recent study shows that current Website Fingerprinting (WF) defenses still generate patterns that may be captured and recognized by the deep learning technology. In this paper, we conduct in-depth analyses of two state-of-the-art WF defense approaches. Then, based on our new observations and insights, we propose a novel defense mechanism using a per-burst injection technique, called Deep Fingerprinting Defender (DFD), against deep learning-based WF attacks. The DFD has two operation modes, one-way and two-way injection. DFD is designed to break the inherent patterns preserved in Tor user's traces by carefully injecting dummy packets within every burst. We conducted extensive experiments to evaluate the performance of DFD over both closed-world and open-world settings. Our results demonstrate that these two configurations can successfully break the Tor network traffic pattern and achieve a high evasion rate of 86.02% over one-way client-side injection rate of 100%, a promising improvement in comparison with state-of-the-art adversarial trace's evasion rate of 60%. Moreover, DFD outperforms the state-of-the-art alternatives by requiring lower bandwidth overhead; 14.26% using client-side injection.
Ahmed Abusnaina, RhongHo Jang, Aminollah Khormali, DaeHun Nyang, David Mohaisen
INFOCOM4
2020 SketchFlow: Per-Flow Systematic Sampling Using Sketch Saturation Event
abstract
Sampling is a powerful tool to reduce the processing overhead in various systems. NetFlow uses a local table for counting records per flow, and sFlow sends out the collected packet headers periodically to a collecting server over the network. Any measurement system falls into either one of these two models. To reduce the overhead, as in sFlow, simple random sampling (SRS) has been widely used in practice because of its simplicity. However, SRS provides non-uniform sampling rates for different fine-grained flows (defined by 5-tuple), because it samples packets over an aggregated data flow (defined by switch port or VLAN). Consequently, some flows are sampled more than the designated sampling rate (resulting in over-estimation), and others are sampled fewer (resulting in under-estimation). Starting with a simple idea that "independent per-flow packet sampling provides the most accurate estimation of each flow", we introduce a new concept of per-flow systematic sampling, aiming to provide the same sampling rate across all flows. In addition, we provide a concrete sampling method called SketchFlow, which approximates the idea of the per-flow systematic sampling using a sketch saturation event. We demonstrate SketchFlow's performance in terms of accuracy, sampling rate, and overhead using real-world datasets, including a backbone network trace, I/O trace, and Twitter dataset. Experimental results show that SketchFlow outperforms SRS (i.e., sFlow) and the non-linear sampling method while requiring a small CPU overhead to measure high-speed traffic in real-time.
RhongHo Jang, DaeHong Min, Seongkwang Moon, David Mohaisen, DaeHun Nyang
INFOCOM5
2020 Assessing the effectiveness of pulsing denial of service attacks under realistic network synchronization assumptions
Jeman Park 0001, Manar Mohaisen, DaeHun Nyang, David Mohaisen
Comput. Networks3
2020 AUToSen: Deep-Learning-Based Implicit Continuous Authentication Using Smartphone Sensors
abstract
Smartphones have become crucial for our daily life activities and are increasingly loaded with our personal information to perform several sensitive tasks, including, mobile banking and communication, and are used for storing private photos and files. Therefore, there is a high demand for applying usable authentication techniques that prevent unauthorized access to sensitive information. In this article, we propose AUToSen, a deep-learning-based active authentication approach that exploits sensors in consumer-grade smartphones to authenticate a user. Unlike conventional approaches, AUToSen is based on deep learning to identify user distinct behavior from the embedded sensors with and without the user's interaction with the smartphone. We investigate different deep learning architectures in modeling and capturing users' behavioral patterns for the purpose of authentication. Moreover, we explore the sufficiency of sensory data required to accurately authenticate users. We evaluate AUToSen on a real-world data set that includes sensors data of 84 participants' smartphones collected using our designed data-collection application. The experiments show that AUToSen operates accurately using readings of only three sensors (accelerometer, gyroscope, and magnetometer) with a high authentication frequency, e.g., one authentication attempt every 0.5 s. Using sensory data of one second enables an authentication F1-score of approximately 98%, false acceptance rate (FAR) of 0.95%, false rejection rate (FRR) of 6.67%, and equal error rate (EER) of 0.41%. While using sensory data of half a second enables an authentication F1-score of 97.52%, FAR of 0.96%, FRR of 8.08%, and EER of 0.09%. Moreover, we investigate the effects of using different sensory data at variable sampling periods on the performance of the authentication models under various settings and learning architectures.
Mohammed Abuhamad, Tamer Abuhmed, David Mohaisen, DaeHun Nyang
IEEE Internet Things J.4
2020 Multi-χ: Identifying Multiple Authors from Source Code Files
abstract
Abstract Most authorship identification schemes assume that code samples are written by a single author. However, real software projects are typically the result of a team effort, making it essential to consider a finegrained multi-author identification in a single code sample, which we address with Multi-χ. Multi-χ leverages a deep learning-based approach for multi-author identification in source code, is lightweight, uses a compact representation for efficiency, and does not require any code parsing, syntax tree extraction, nor feature selection. In Multi-χ, code samples are divided into small segments, which are then represented as a sequence ofn-dimensional term representations. The sequence is fed into an RNN-based verification model to assist a segment integration process which integrates positively verified segments, i.e., integrates segments that have a high probability of being written by one author. Finally, the resulting segments from the integration process are represented using word2vec or TF-IDF and fed into the identification model. We evaluate Multi-χ with several Github projects (Caffe, Facebook’s Folly, Tensor-Flow, etc.) and show remarkable accuracy. For example, Multi-χ achieves an authorship example-based accuracy (A-EBA) of 86.41% and per-segment authorship identification of 93.18% for identifying 562 programmers. We examine the performance against multiple dimensions and design choices, and demonstrate its effectiveness.
Mohammed Abuhamad, Tamer Abuhmed, DaeHun Nyang, David Mohaisen
Proc. Priv. Enhancing Technol.3
2020 Look-Aside at Your Own Risk: Privacy Implications of DNSSEC Look-Aside Validation
abstract
The Domain Name System Security Extension (DNSSEC) leverages public-key cryptography to provide data integrity, source authentication, and denial of existence for DNS responses. To complement DNSSEC operations, DNSSEC Look-aside Validation (DLV) is designed for alternative off-path validation. Although DNS privacy attracts a lot of attention, the privacy implications of DLV are not fully investigated and understood. In this paper, we take a first in-depth look into DLV, highlighting its lax specifications and privacy implications. By performing extensive experiments over datasets of domain names under comprehensive experimental settings, our findings firmly confirm the privacy leakages caused by DLV. We discover that a large number of domains that should not be sent to DLV servers are being leaked. We explore the root causes, including the lax specifications of DLV. We also propose two approaches to fix the privacy leakages. Our approaches require trivial modifications to the existing DNS standards, and we demonstrate their cost in terms of latency and communication.
David Mohaisen, Zhongshu Gu, Kui Ren 0001, Zhenhua Li 0001, Charles A. Kamhoua, Laurent Njilla, DaeHun Nyang
IEEE Trans. Dependable Secur. Comput.7
2020 Catch Me If You Can: Rogue Access Point Detection Using Intentional Channel Interference
abstract
In this paper, we introduce a powerful hardware-based rogue access point (PrAP), which can relay back and forth traffic between a legitimate AP and a wireless station, and act as a man-in-the-middle attacker. Our PrAP is built of two dedicated wireless routers interconnected physically, and can relay traffic rapidly between a station and a legitimate AP. Through experiments, we demonstrate that the state-of-the-art time-based rogue AP (rAP) detectors cannot detect our PrAP, although perhaps effective against software-based rAP. In demonstrating that, we unveil new insight into fundamentals of time-based detectors for software-based rAPs and their operation: such techniques are only capable of detecting rAPs due to the speed of wireless AP bridging. To address the threat of such PrAPs, we propose a new tool for network administrators, a PrAP-Hunter based on intentional channel interference. Our PrAP-Hunter is highly accurate, even under heavy traffic scenarios. Using a high-performance (desktop) and low-performance (mobile phone) experimental setups of our PrAP-Hunter in various deployment scenarios, we demonstrate close to 100 percent of detection rate, compared to 60 percent detection rate by the state-of-the-art. We show that our PrAP-Hunter is fast (takes 5-10 seconds), does not require any prior knowledge, and can be deployed in the wild by real-world experiments at 10 coffee shops.
RhongHo Jang, Jeonil Kang, David Mohaisen, DaeHun Nyang
IEEE Trans. Mob. Comput.4
2019 InstaMeasure: Instant Per-flow Detection Using Large In-DRAM Working Set of Active Flows
abstract
In the zettabyte era, per-flow measurement becomes more challenging for the data center owing to the increment of both traffic volumes and the number of flows. Also, the swiftness of detection of anomalies (e.g., congestion, link failure, DDoS attack, and so on) becomes paramount. For fast and accurate traffic measurement, managing an accurate working set of active flows (WSAF) from massive volumes of packet influxes at line rates is a key challenge. WSAF is usually located in high-speed but expensive memory, such as TCAM or SRAM, and thus the number of entries to be stored is quite limited. To cope with the scalability issue of WSAF, we propose to use In-DRAM WSAF with scales, and put a compact data structure called FlowRegulator in front of WSAF to compensate for DRAM's slow access time by substantially reducing massive influxes to WSAF without compromising measurement accuracy. To verify its practicability, we further build a per-flow measurement system, called InstaMeasure, on an off-the-shelf Atom (lightweight) processor board. We evaluate our proposed system in a large scale real-world experiment (monitoring our campus main gateway router for 113 hours, and capturing 122.3 million flows). We verify that InstaMeasure can detect heavy hitters (HHs) with 99% accuracy and within 10 ms (detection is faster for heavier HHs) while providing the one million flows record with only tens of MB of DRAM memory. InstaMeasure's various performance metrics are further investigated by the packet trace-driven experiment using one-hour CAIDA dataset, where the target of measurement was all the 78 million L4 flows for one-hour.
RhongHo Jang, Seongkwang Moon, Youngtae Noh, David Mohaisen, DaeHun Nyang
ICDCS5
2019 Distributed Network Resource Sharing AP in Inter-WLAN Environments
abstract
As the number of wireless device deployments grows, it is desirable to share the highly limited wireless bandwidth efficiently and cooperatively. In WLAN, using a central controller for resource sharing and management is a common practice in mid-size and large-size network. However, in case of small businesses (i.e., restaurants, coffee shops, etc.), business owners cannot afford to obtain the controller. To realize the bandwidth sharing among Access Points (AP) in a distribute manner, seamless handoff of mobile devices (i.e., smartphones and tablets) between small-business owned Access Points (APs) via association control and maintain stable TCP connection are essential but quite challenging. This poster proposes a novel way to cooperatively share wireless resources among the APs. This includes an efficient association control between stations and APs, dedicated virtual access point per station, and tunneling support maintaining existing TCP connection after relocation to another AP.
Jinho Son, Hyunwoo Jo, DaeHun Nyang, Youngtae Noh
MobiSys3
2019 Analyzing endpoints in the internet of things malware: poster
abstract
The lack of security measures in the Internet of Things (IoT) devices and their persistent online connectivity give adversaries an opportunity to target them or abuse them as intermediary targets for volumetric attacks such as Distributed Denial-of-Service (DDoS) campaigns. In this paper, we analyze IoT malware with a focus on endpoints to understand the affinity between the dropzones and their target IP addresses, and to understand the different patterns among them. Towards this goal, we reverse-engineer 2,423 IoT malware samples to obtain IP addresses. We further augment additional information about the endpoints from Internet-wide scanners, including Shodan and Censys. We then perform a deep data-driven analysis of the dropzones and their target IP addresses and further examine the attack surface of the target device space.
Jinchun Choi, Afsah Anwar, Hisham Alasmary, Jeffrey Spaulding, DaeHun Nyang, David Mohaisen
WiSec5
2019 A cost-effective anomaly detection system using in-DRAM working set of active flows table: poster
abstract
In the zettabyte era, per-flow measurement becomes more challenging owing to the growth of both traffic volumes and the number of flows. Also, swiftness of detection of anomalies becomes paramount. For fast and accurate anomaly detection, managing an accurate working set of active flows (WSAF) from massive volumes of packet influxes at line rates is a key challenge. WSAF is usually located in a very fast but expensive memory, such as TCAM or SRAM, and thus the number of entries to be stored is quite limited. To cope with the scalability issue of WSAF, we propose to use In-DRAM WSAF with scales, and put a compact data structure called FlowRegulator in front of WSAF to compensate for DRAM's slow access time by substantially reducing massive influxes to WSAF without compromising measurement accuracy. We evaluated our system in a large scale real-world experiment. As one key application, FlowRegulator detected heavy hitters with 99.8% accuracy.
RhongHo Jang, Seongkwang Moon, Youngtae Noh, David Mohaisen, DaeHun Nyang
WiSec5
2019 Code authorship identification using convolutional neural networks
Mohammed Abuhamad, Ji-su Rhim, Tamer Abuhmed, Sanggil Kang, DaeHun Nyang
Future Gener. Comput. Syst.6
2019 Analyzing and Detecting Emerging Internet of Things Malware: A Graph-Based Approach
abstract
The steady growth in the number of deployed Internet of Things (IoT) devices has been paralleled with an equal growth in the number of malicious software (malware) targeting those devices. In this paper, we build a detection mechanism of IoT malware utilizing control flow graphs (CFGs). To motivate for our detection mechanism, we contrast the underlying characteristics of IoT malware to other types of malware—Android malware, which are also Linux-based—across multiple features. The preliminary analyses reveal that the Android malware have high density, strong closeness and betweenness, and a larger number of nodes. We show that IoT malware samples have a large number of edges despite a smaller number of nodes, which demonstrate a richer flow structure and higher complexity. We utilize those various characterizing features as a modality to build a highly effective deep learning-based detection model to detect IoT malware. To test our model, we use CFGs of about 6000 malware and benign IoT disassembled samples, and show a detection accuracy of $\approx 99.66$ %.
Hisham Alasmary, Aminollah Khormali, Afsah Anwar, Jeman Park 0001, Jinchun Choi, Ahmed Abusnaina, Amro Awad, DaeHun Nyang, David Mohaisen
IEEE Internet Things J.8
2019 Transparency in the New gTLD Era: Evaluating the DNS Centralized Zone Data Service
abstract
The centralized zone data service (CZDS) was introduced by the Internet Corporation for Assigned Names and Numbers (ICANN) to facilitate sharing and access to zone data of the new generic Top-Level Domains (gTLDs). CZDS aims to improve the security and transparency of the naming system of the Internet. In this paper, we investigate CZDS's transparency by measurement and evaluation. By requesting access to zone data of all gTLDs listed in the CZDS portal, we analyze various aspects of CZDS, including access status, responsiveness and provided reasons for granting access or denial. Among other findings, we find that while a large percent of the gTLD admins respond within a reasonable time, more than 10% of them have a long request-to-decision waiting time, and sometimes requests go unanswered even after six months of a request. Furthermore, we find that denial cases were for unjustified reasons, where administrators who denied the requests have asked for information that was already provided in the request form. We discuss implications, and how to enforce better outcomes of CZDS using insight from our measurement and evaluation.
Jeman Park 0001, Jinchun Choi, DaeHun Nyang, David Mohaisen
IEEE Trans. Netw. Serv. Manag.3
2018 Large-Scale and Language-Oblivious Code Authorship Identification
abstract
Efficient extraction of code authorship attributes is key for successful identification. However, the extraction of such attributes is very challenging, due to various programming language specifics, the limited number of available code samples per author, and the average code lines per file, among others. To this end, this work proposes a Deep Learning-based Code Authorship Identification System (DL-CAIS) for code authorship attribution that facilitates large-scale, language-oblivious, and obfuscation-resilient code authorship identification. The deep learning architecture adopted in this work includes TF-IDF-based deep representation using multiple Recurrent Neural Network (RNN) layers and fully-connected layers dedicated to authorship attribution learning. The deep representation then feeds into a random forest classifier for scalability to de-anonymize the author. Comprehensive experiments are conducted to evaluate DL-CAIS over the entire Google Code Jam (GCJ) dataset across all years (from 2008 to 2016) and over real-world code samples from 1987 public repositories on GitHub. The results of our work show the high accuracy despite requiring a smaller number of files per author. Namely, we achieve an accuracy of 96% when experimenting with 1,600 authors for GCJ, and 94.38% for the real-world dataset for 745 C programmers. Our system also allows us to identify 8,903 authors, the largest-scale dataset used by far, with an accuracy of 92.3%. Moreover, our technique is resilient to language-specifics, and thus it can identify authors of four programming languages (e.g. C, C++, Java, and Python), and authors writing in mixed languages (e.g. Java/C++, Python/C++). Finally, our system is resistant to sophisticated obfuscation (e.g. using C Tigress) with an accuracy of 93.42% for a set of 120 authors.
Mohammed Abuhamad, Tamer Abuhmed, David Mohaisen, DaeHun Nyang
CCS4
2018 Digitalseal: a Transaction Authentication Tool for Online and Offline Transactions
abstract
We introduce DigitalSeal, a transaction authentication tool that works in both online and offline use scenarios. Digi-talSeal is a digital scanner that reads transaction information sent by an issuing entity of the DigitalSeal reader for authentication, and the information is encoded using a specially crafted bar-code. DigitalSeal views various pieces of transaction information for users to verify and proceed with transaction authentication. DigitalSeal is generic, and is capable of reading information viewed on paper, computer monitors (similarly, kiosk monitors), and mobile phones. A prototype of DigitalSeal is built using a Arduino UNO, four LLS05-A sensors, four TCRT5000 sensors, a 1602 LCD and a 9V battery.
Changhun Jung, Jeonil Kang, David Mohaisen, DaeHun Nyang
ICASSP4
2018 SSD-Insider: Internal Defense of Solid-State Drive against Ransomware with Perfect Data Recovery
abstract
Ransomware is a malware that encrypts victim's data, where the decryption key is released after a ransom is paid by the data owner to the attacker. Many ransomware attacks were reported recently, making anti-ransomware a crucial need in security operation, and an issue for the security community to tackle. In this paper, we propose a new approach to defending against ransomware inside NAND flash-based SSDs. To realize the idea of defense-inside-SSDs, both a lightweight detection technique and a perfect recovery algorithm to be used as a part of SSDs firmware should be developed. To this end, we propose a new set of lightweight behavioral features on ran-somware's overwriting pattern, which are invariant across various ransomwares. Our features rely on observing the block I/O request headers only, and not the payload. For perfect and instant recovery, we also propose using the delayed deletion feature of SSDs, which is intrinsic to NAND flash. To demonstrate their feasibility, we implement our algorithms atop an open-channel SSD as a working prototype called SSD-Insider. In experiments using eight real-world and two in-house ransomwares with various background applications running, SSD-Insider achieved a detection accuracy 0% FRR/FAR in most scenarios, and only 5% FAR when heavy overwriting resembling ransomware's data wiping occurs. SSD-Insider detects ransomware activity within 10s, and recovers instantly an infected SSD within 1s with 0% data loss. The additional software overheads incurred by the SSD-Insider is just 147 ns and 254 ns for 4-KB reads and writes, respectively, which is negligible considering NAND chip latency (50-1000 μs).
SungHa Baek, Youngdon Jung, David Mohaisen, Sungjin Lee 0001, DaeHun Nyang
ICDCS5
2018 Timing is Almost Everything: Realistic Evaluation of the Very Short Intermittent DDoS Attacks
abstract
Distributed Denial-of-Service (DDoS) is a big threat to the security and stability of Internet-based services today. Among the recent advanced application-layer DDoS attacks, the Very Short Intermittent DDoS (VSI-DDoS) is the attack, which can bypass existing detection systems and significantly degrade the QoS experienced by users of web services. However, in order for the VSI-DDoS attack to work effectively, bots participating in the attack should be tightly synchronized, an assumption that is difficult to be met in reality. In this paper, we conducted a quantitative analysis to understand how a minimal deviation from perfect synchronization in botnets affects the performance and effectiveness of the VSI-DDoS attack. We found that VSI-DDoS became substantially less effective. That is, it lost 85.7% in terms of effectiveness under about 90ms synchronization inaccuracy, which is a very small inaccuracy under normal network conditions.
Jeman Park 0001, DaeHun Nyang, David Mohaisen
PST2
2018 Understanding the Hidden Cost of Software Vulnerabilities: Measurements and Predictions
Afsah Anwar, Aminollah Khormali, DaeHun Nyang, David Mohaisen
SecureComm (1)3
2018 Two-Thumbs-Up: Physical protection for PIN entry secure against recording attacks
DaeHun Nyang, Hyoungshick Kim, Sung-bae Kang, Geumhwan Cho, Mun-Kyu Lee, David Mohaisen
Comput. Secur.1
2017 Rogue Access Point Detector Using Characteristics of Channel Overlapping in 802.11n
abstract
In this work, we introduce a powerful hardware-based rogue access point (PrAP), which can relay traffic between a legitimate AP and a wireless station back and forth, and act as a man-in-the-middle attacker. Our PrAP is built of two dedicated wireless routers interconnected physically, and can relay traffic rapidly between a station and a legitimate AP. Through extensive experiments, we demonstrate that the state-of-the-art time-based rogue AP (rAP) detectors cannot detect our PrAP, although effective against software-based rAP. To defend against PrAPs, we propose PrAP-Hunter based on intentional channel interference. PrAP-Hunter is highly accurate, even under heavy traffic scenarios. Using a high-performance (desktop) and low-performance (mobile) experimental setups of our PrAP-Hunter in various deployment scenarios, we demonstrate close to 100% of detection rate, compared to 60% detection rate by the state-of-the-art. We show that PrAP-Hunter is fast (takes 5-10 sec), does not require any prior knowledge, and can be deployed in the wild by real world experiments at 10 coffee shops.
RhongHo Jang, Jeonil Kang, David Mohaisen, DaeHun Nyang
ICDCS4
2017 RFlow+: An SDN-based WLAN monitoring and management framework
abstract
In this work, we propose an SDN-based WLAN monitoring and management framework called RFlow+to address WiFi service dissatisfaction caused by the limited view (lack of scalability) of network traffic monitoring and absence of intelligent and timely network treatments. Existing solutions (e.g., OpenFlow and sFlow) have limited view, no generic flow description, and poor trade-off between measurement accuracy and network overhead depending on the selection of the sampling rate. To resolve these issues, we devise a two-level counting mechanism, namely a distributed local counter (on-site and real-time) and central collector (a summation of local counters). With this, we proposed a highly scalable monitoring and management framework to handle immediate actions based on short-term (e.g., 50 ms) monitoring and eventual actions based on long-term (e.g., 1 month) monitoring. The former uses the local view of each access point (AP), and the latter uses the global view of the collector. Experimental results verify that RFlow+can achieve high accuracy (less than 5% standard error for short-term and less than 1% for long-term) and fast detection of flows of interest (within 23 ms) with manageable network overhead. We prove the practicality of RFlow+by showing the effectiveness of a MAC flooding attacker quarantine in a real-world testbed.
RhongHo Jang, DongGyu Cho, Youngtae Noh, DaeHun Nyang
INFOCOM4
2017 Two-level network monitoring and management in WLAN using software-defined networking: poster
abstract
In this work, we propose an SDN-based WLAN monitoring and management framework called RFlow+ and devise a two-level counting mechanism, namely a distributed local counter (on-site and real-time) and a central collector (a summation of local counters). Building on that, we proposed a highly scalable monitoring and management framework to handle immediate actions based on short-term (e.g., 50 ms) monitoring and eventual actions based on long-term (e.g., 1 month) monitoring. The former uses the local view of each access point (AP), and the latter uses the global view of the collector.
RhongHo Jang, DongGyu Cho, David Mohaisen, Youngtae Noh, DaeHun Nyang
WISEC5
2017 Highly-accurate rogue access point detection using intentional channel interference: poster
abstract
In this work, we introduce a powerful hardware-based rogue access point (PrAP), which can relay traffic between a legitimate AP and a wireless station, and act as a man-in-the-middle attacker. To defend against PrAPs, we propose PrAP-Hunter based on intentional channel interference. We demonstrate close to 100% of detection rate, compared to 60% detection rate by the state-of-the-art.
RhongHo Jang, Jeonil Kang, David Mohaisen, DaeHun Nyang
WISEC4
2017 A Privacy-Preserving Mobile Payment System for Mass Transit
abstract
In the near future, mobile payment systems based on smartphones are expected to be widely applied in various environments, including transit services. When passengers use mass transit, their private information, such as their identity and route, may be made available to some related organizations, such as transit agencies, financial institutions, mobile carriers, and providers of smart cards, among others, even when the passengers may not want their information to be revealed. To protect passenger privacy, this paper proposes a privacy-preserving transit payment system based on traceable signatures, identity-based signatures, and anonymous signatures. In addition to passenger privacy, the proposed system facilitates the proactive blocking of misbehaving passengers, free-transfer services (or transfer discount), and postpaid programs. We demonstrate that the performance of this system is good enough for immediate deployment based on various experiments.
Jeonil Kang, DaeHun Nyang
IEEE Trans. Intell. Transp. Syst.2
2016 A simple proof of optimality for the MIN cache replacement policy
Mun-Kyu Lee, Pierre Michaud, Jeong Seop Sim, DaeHun Nyang
Inf. Process. Lett.4
2016 Recyclable Counter With Confinement for Real-Time Per-Flow Measurement
abstract
With the amount of Internet traffic increasing substantially, measuring per-flow traffic accurately is an important task. Because of the nature of high-speed routers, a measurement algorithm should be fast enough to process every packet going through them, and should be executable with only a limited amount of memory, as well. In this paper, we use two techniques to solve memory/speed constraints: (1) recycling a memory block by resetting it (for memory constraint), and (2) confinement of virtual vectors to one word (for speed constraint). These techniques allow our measurement algorithm, called a recyclable counter with confinement (RCC), to accurately measure all individual flow sizes with a small amount of memory. In terms of encoding speed, it uses about one memory access and one hash computation. Unlike other previously proposed schemes, RCC decodes very quickly, demanding about three memory accesses and two hash calculations. This fast decoding enables real-time detection of a high uploader/downloader. Finally, RCC's data structure includes flow labels for large flows, so it is possible to quickly retrieve a list of large-flow names and sizes.
DaeHun Nyang, DongOh Shin
IEEE/ACM Trans. Netw.1
2015 Transaction authentication using complementary colors
YoungJae Maeng, David Mohaisen, Mun-Kyu Lee, DaeHun Nyang
Comput. Secur.4
2015 UOIT Keyboard: A Constructive Keyboard for Small Touchscreen Devices
abstract
Many techniques have been proposed for reducing errors during text input on touchscreens. However, the majority of these techniques suffer from the same limitation, i.e., the keyboard keys are overcrowded on a small screen, resulting in high error rates and slow text inputs. To address this situation and resolve the problems associated with overcrowdedness, we introduce a new text-entry method called the “UOIT keyboard.” The idea behind the UOIT keyboard is to compose letters using “drawing-like typing” on the UOIT keyboard, which has 13 large keys that replace the 26 small keys that exist in the QWERTY keyboard. We describe the design, keys, and mechanism of the UOIT keyboard. A 24-participant user study was conducted to evaluate the speed and accuracy of the proposed entry method as compared with the QWERTY and multitap entry methods. As part of the evaluation, a questionnaire was used to collect participants' preferences. The UOIT keyboard has a mean entry speed of 11.3 words/min. The UOIT keyboard significantly reduces the typing errors with 3.8% total error rate comparing with 11.2% and 16.3% for QWERTY and multitap entry methods, respectively.
Tamer Abuhmed, KyungHee Lee, DaeHun Nyang
IEEE Trans. Hum. Mach. Syst.3
2015 Short Dynamic Group Signature Scheme Supporting Controllable Linkability
abstract
The controllable linkability of group signatures introduced by Hwanget al.enables an entity who has a linking key to find whether or not two group signatures were generated by the same signer, while preserving the anonymity. This functionality is very useful in many applications that require the linkability but still need the anonymity, such as sybil attack detection in a vehicular ad hoc network and privacy-preserving data mining. In this paper, we present a new group signature scheme supporting the controllable linkability. The major advantage of this scheme is that the signature length is very short, even shorter than this in the best-known group signature scheme without supporting the linkability. We have implemented our scheme in both a Linux machine with an Intel Core2 Quad and an iPhone4. We compare the results with a number of existing group signature schemes. We also prove security features of our scheme, such as anonymity, traceability, nonframeability, and linkability, under a random oracle model.
Jung Yeon Hwang, Liqun Chen 0002, Hyun Sook Cho, DaeHun Nyang
IEEE Trans. Inf. Forensics Secur.4
2014 Two-factor face authentication using matrix permutation transformation and a user password
Jeonil Kang, DaeHun Nyang, KyungHee Lee
Inf. Sci.2
2014 Keylogging-Resistant Visual Authentication Protocols
abstract
The design of secure authentication protocols is quite challenging, considering that various kinds of root kits reside in Personal Computers (PCs) to observe user's behavior and to make PCs untrusted devices. Involving human in authentication protocols, while promising, is not easy because of their limited capability of computation and memorization. Therefore, relying on users to enhance security necessarily degrades the usability. On the other hand, relaxing assumptions and rigorous security design to improve the user experience can lead to security breaches that can harm the users' trust. In this paper, we demonstrate how careful visualization design can enhance not only the security but also the usability of authentication. To that end, we propose two visual authentication protocols: one is a one-time-password protocol, and the other is a password-based authentication protocol. Through rigorous analysis, we verify that our protocols are immune to many of the challenging authentication attacks applicable in the literature. Furthermore, using an extensive case study on a prototype of our protocols, we highlight the potential of our approach for real-world deployment: we were able to achieve a high level of usability while satisfying stringent security requirements.
DaeHun Nyang, David Mohaisen, Jeonil Kang
IEEE Trans. Mob. Comput.1
2013 Group signatures with controllable linkability for dynamic membership
Jung Yeon Hwang, Byung-Ho Chung, Hyun Sook Cho, DaeHun Nyang
Inf. Sci.5
2009 Software-Based Remote Code Attestation in Wireless Sensor Network
abstract
Sensor nodes are usually vulnerable to be compromised due to their unattended deployment. The low cost requirement of the sensor node precludes using an expensive tamper resistant hardware for sensor physical protection. Thus, the adversary can reprogram the compromised sensors and deviates sensor network functionality. In this paper, we propose two simple software-based remote code attestation schemes for different WSN criterion. Our schemes use different independent memory noise filling techniques called pre-deployment and post-deployment noise filling, and also different communication protocols for attestation purpose. The protocols are well-suited for wireless sensor networks, where external factors , such as channel collision, result in network delay. Hence, the success of our schemes of attestation does not depend on the accurate measurement of the execution time, which is the main drawback of previously proposed wireless sensor network attestation schemes.
Tamer Abuhmed, Nandinbold Nyamaa, DaeHun Nyang
GLOBECOM3
2009 A-Kad: an anonymous P2P protocol based on Kad network
abstract
With the growth of decentralized network users, preserving privacy becomes a critical issue in this open community. Kad-based network, as a typical decentralized system, has been widely used nowadays. However, there is not enough research to achieve anonymity on it. In this paper, we propose an anonymous protocol based on Kad network, named Anonymous Kad (A-Kad), which achieves complete privacy and security for file providers and requesters. A-Kad has the desired property of anonymity and still keeps high efficiency in publishing and querying phases. To achieve anonymity, we establish two anonymous channels which help file providers to anonymously publish file information and securely transfer files. Through these two channels, the file requester can also efficiently query and retrieve files without worrying about exposing its behavior. Moreover, we propose an anonymity degree evaluation model (ADEM) according to three different attacking capabilities and anonymity degree.
YongQing Ni, DaeHun Nyang
MASS2
2008 Data Randomization for Lightweight Secure Data Aggregation in Sensor Network
David Mohaisen, Ik Rae Jeong, Dowon Hong, Nam-Su Jho, DaeHun Nyang
UIC5
2008 Protection Techniques of Secret Information in Non-tamper Proof Devices of Smart Home Network
David Mohaisen, YoungJae Maeng, Jeonil Kang, DaeHun Nyang, KyungHee Lee, Dowon Hong, Jong Wook Han
UIC4
2007 Proactive Code Verification Protocol in Wireless Sensor Network
Young-Geun Choi, Jeonil Kang, DaeHun Nyang
ICCSA (2)3
2007 Certificate Issuing Using Proxy and Threshold Signatures in Self-initialized Ad Hoc Network
Jeonil Kang, DaeHun Nyang, David Mohaisen, Young-Geun Choi, KoonSoon Kim
ICCSA (3)2
2007 Structures for Communication-Efficient Public Key Revocation in Ubiquitous Sensor Network
David Mohaisen, DaeHun Nyang, YoungJae Maeng, KyungHee Lee
MSN2
2007 Secret Key Revocation in Sensor Networks
YoungJae Maeng, David Mohaisen, DaeHun Nyang
UIC3
2007 Smart Proactive Caching Scheme for Fast Authenticated Handoff in Wireless LAN
Sinkyu Kim, DaeHun Nyang, GeneBeck Hahn, JooSeok Song
J. Comput. Sci. Technol.3
2006 Distributed Certificate Authority Under the GRID-Location Aided Routing Protocol
Jihyung Lim, DaeHun Nyang, Jeonil Kang, KyungHee Lee, Hyotaek Lim
ICCSA (4)2
2006 Cooperative Public Key Authentication Protocol in Wireless Sensor Network
DaeHun Nyang, David Mohaisen
UIC1
1999 A complete test sequence using cyclic sequence for conformance testing
DaeHun Nyang, S. Y. Lim, JooSeok Song
Comput. Commun.1