VLDB 2026 Research / reviewers in the wild / expert
Shinjo Park
dblp:131/6138
· DBLP profile ↗
8ranked-venue papers
0as first author
2since 2021 · last 2022
0000-0002-8569-1327ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 since 2021Computer networks · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware
Grant Hernandez, Marius Muench, Dominik Christian Maier, Alyssa Milburn, Shinjo Park, Tobias Scharnowski, Tyler Tucker, Patrick Traynor, Kevin R. B. Butler |
NDSS | 5 |
| 2022 | A Post-Quantum Secure Subscription Concealed Identifier for 6Gabstract5G saw the introduction of an encrypted user identifier, the Subscriber Concealed Identifier (SUCI), to provide confidentiality of the subscriber's whereabouts and identities. The SUCI protects the new generation of cellular networks against tracking devices, so-called IMSI-catchers, which have undermined users' confidentiality ever since the inception of cellular networks. However, the potential advent of large-scale quantum computers in the near future threatens to compromise the confidentiality provided by the SUCI yet again. The security of the public-key cryptography that underpins the SUCI relies on the hardness of the discrete logarithm problem. Using Shor's algorithm, a quantum adversary could break the SUCI's cryptography and once more gain the capability to track and identify users. Advancements in quantum computing are unpredictable, and a breakthrough might be only a decade away. Given the slow nature of standards and their implementation, it is thus necessary to already integrate now quantum-resistant cryptography into the current and also next-generation (6G) cellular networks. To contribute to this development, we propose a post-quantum secure scheme for the SUCI calculation, \textttKEMSUCI. To this end, we first analyze the weak points in the current SUCI calculation scheme when considering quantum attacks. We then describe an alternative SUCI calculation scheme based on post-quantum secure key-encapsulation mechanisms (KEMs). Our proposed scheme can use any of the KEMs submitted to the NIST call for standardization of post-quantum secure cryptography (PQC) schemes. For the usage in \textttKEMSUCI, the KEM should provide efficient execution on a SIM card and induce little network communication overhead. We evaluate all of the NIST PQC finalists under these aspects and identify Kyber and Saber as the best fit. Instantiated with these KEMs, \textttKEMSUCI can be integrated into 5G and 6G. Compared to the existing SUPI protection schemes, \textttKEMSUCI exhibits faster execution speed and only little communication overhead. Vincent Ulitzsch, Shinjo Park, Soundes Marzougui, Jean-Pierre Seifert |
WISEC | 2 |
| 2020 | BaseSAFE: baseband sanitized fuzzing through emulationabstractRogue base stations are an effective attack vector. Cellular basebands represent a critical part of the smartphone's security: they parse large amounts of data even before authentication. They can, therefore, grant an attacker a very stealthy way to gather information about calls placed and even to escalate to the main operating system, over-the-air. In this paper, we discuss a novel cellular fuzzing framework that aims to help security researchers find critical bugs in cellular basebands and similar embedded systems. BaseSAFE allows partial rehosting of cellular basebands for fast instrumented fuzzing off-device, even for closed-source firmware blobs. BaseSAFE's sanitizing drop-in allocator, enables spotting heap-based buffer-overflows quickly. Using our proof-of-concept harness, we fuzzed various parsers of the Nucleus RTOS-based MediaTek cellular baseband that are accessible from rogue base stations. The emulator instrumentation is highly optimized, reaching hundreds of executions per second on each core for our complex test case, around 15k test-cases per second in total. Furthermore, we discuss attack vectors for baseband modems. To the best of our knowledge, this is the first use of emulation-based fuzzing for security testing of commercial cellular basebands. Most of the tooling and approaches of BaseSAFE are also applicable for other low-level kernels and firmware. Using BaseSAFE, we were able to find memory corruptions including heap out-of-bounds writes using our proof-of-concept fuzzing harness in the MediaTek cellular baseband. BaseSAFE, the harness, and a large collection of LTE signaling message test cases will be released open-source upon publication of this paper. Dominik Christian Maier, Lukas Seidel, Shinjo Park |
WISEC | 3 |
| 2019 | New vulnerabilities in 4G and 5G cellular access network protocols: exposing device capabilitiesabstractCellular devices support various technical features and services for 2G, 3G, 4G and upcoming 5G networks. For example, these technical features contain physical layer throughput categories, radio protocol information, security algorithm, carrier aggregation bands and type of services such as GSM-R, Voice over LTE etc. In the cellular security standardisation context, these technical features and network services termed as device capabilities and exchanged with the network during the device registration phase. In this paper, we study device capabilities information specified for 4G and 5G devices and their role in establishing security association between the device and network. Our research results reveal that device capabilities are exchanged with the network before the authentication stage without any protection and not verified by the network. Consequently, we present three novel classes of attacks exploiting unprotected device capabilities information in 4G and upcoming 5G networks - identification attacks, bidding down attacks, and battery drain attacks against cellular devices. We implement proof-of-concept attacks using low-cost hardware and software setup to evaluate their impact against commercially available 4G devices and networks. We reported identified vulnerabilities to the relevant standardisation bodies and provide countermeasure to mitigate device capabilities attacks in 4G and upcoming 5G networks. Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, Jean-Pierre Seifert |
WiSec | 3 |
| 2019 | New Privacy Threat on 3G, 4G, and Upcoming 5G AKA ProtocolsabstractAbstract Mobile communications are used by more than two-thirds of the world population who expect security and privacy guarantees. The 3rd Generation Partnership Project (3GPP) responsible for the worldwide standardization of mobile communication has designed and mandated the use of the AKA protocol to protect the subscribers’ mobile services. Even though privacy was a requirement, numerous subscriber location attacks have been demonstrated against AKA, some of which have been fixed or mitigated in the enhanced AKA protocol designed for 5G. In this paper, we reveal a new privacy attack against all variants of the AKA protocol, including 5G AKA, that breaches subscriber privacy more severely than known location privacy attacks do. Our attack exploits a new logical vulnerability we uncovered that would require dedicated fixes. We demonstrate the practical feasibility of our attack using low cost and widely available setups. Finally we conduct a security analysis of the vulnerability and discuss countermeasures to remedy our attack. Ravishankar Borgaonkar, Lucca Hirschi, Shinjo Park, Altaf Shaik |
Proc. Priv. Enhancing Technol. | 3 |
| 2018 | On the Impact of Rogue Base Stations in 4G/LTE Self Organizing NetworksabstractMobile network operators choose Self Organizing Network (SON) concept as a cost-effective method to deploy LTE/4G networks and meet user expectations for high quality of service and bandwidth. The main objective of SON is to introduce automation into network management activities and reduce human intervention. SON enabled LTE networks heavily rely on the information acquired from mobile phones to provide self-configuration, self-optimization, and self-healing features. However, mobile phones can be attacked over-the-air using rogue base stations. In this paper, we carefully study SON related LTE/4G security specifications and reveal several vulnerabilities. Our key idea is to introduce a rogue eNodeB that uses legitimate mobile devices as a covert channel to launch attacks against SON enabled LTE networks. Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, Jean-Pierre Seifert |
WISEC | 3 |
| 2018 | Peeking Over the Cellular Walled Gardens - A Method for Closed Network Diagnosis -abstractA cellular network is a closed system, and each network operator has built a unique “walled garden” for their network by combining different operation policies, network configurations, and implementation optimizations. Unfortunately, some of these combinations can induce performance degradation due to misconfiguration or unnecessary procedures. To detect such degradation, a thorough understanding of even the minor details of the standards and operator-specific implementations is important. However, it is difficult to detect such problems, as the control plane is complicated by numerous procedures. This paper introduces a simple yet powerful method that diagnoses these problems by exploiting the operator-specific implementations of cellular networks. We develop a signaling collection and analysis tool that collects control plane messages from operators and finds problems through comparative analysis. The analysis process consists of three different control plane comparison procedures that can find such problems effectively. These individual procedures use a time threshold, control flow sequence, and signaling failure as the basis for comparison. To this end, we collect approximately 3.1 million control-plane messages from 13 major cellular operators worldwide. As a case study, we analyze the circuit-switched fallback technology that triggers generation crossover between third generation and long-term evolution technologies. Byeongdo Hong, Shinjo Park, Dongkwan Kim 0001, Hyunwook Hong, Hyunwoo Choi, Jean-Pierre Seifert, Sung-Ju Lee 0001, Yongdae Kim |
IEEE Trans. Mob. Comput. | 2 |
| 2013 | Comparison of caching strategies in modern cellular backhaul networksabstractRecent popularity of smartphones drives rapid growth in the demand for cellular network bandwidth. Unfortunately, due to the centralized architecture of cellular networks, increasing the physical backhaul bandwidth is challenging. While content caching in the cellular network could be beneficial, relatively few characteristics of the cellular traffic is known to come up with a highly-effetive caching strategy. In this work, we provide insight into flow and content-level characteristics of modern 3G traffic at a large cellular ISP in South Korea. We first develop a scalable deep flow inspection (DFI) system that can manage hundreds of thousands of concurrent TCP flows on a commodity multicore server. Our DFI system collects various HTTP/TCP-level statistics and produces logs for analyzing the effectiveness of conventional Web caching, prefix-based Web caching, and TCP-level redundancy elimination (RE) without a single packet drop at a 10~Gbps link. Our week-long measurements of over 370 TBs of the 3G traffic reveal that standard Web caching can reduce download bandwidth consumption up to 27.1% while simple TCP-level RE can save the bandwidth consumption up to 42.0% with a cache of 512~GB of RAM. We also find that applying TCP-level RE on the largest 9.4% flows eliminates 68.4% of the total redundancy. Most of the redundancy (52.1%~58.9%) comes from serving the same HTTP objects while the contribution by aliased URLs is up to 38.9%. Shinae Woo, Eunyoung Jeong, Shinjo Park, Jong Min Lee 0001, Sunghwan Ihm, KyoungSoo Park |
MobiSys | 3 |