VLDB 2026 Research / reviewers in the wild / expert
Hyo Jin Jo
dblp:147/6656
· DBLP profile ↗
12ranked-venue papers
3as first author
6since 2021 · last 2024
0000-0002-3496-7899ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 3 since 2021Security and privacy · 4 · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Securing Passive Keyless Entry and Start System in Modern Vehicles Based on LF-Band Signal AnalysisabstractThe low-frequency-band (LF-band) communication in the passive keyless entry and start (PKES) system is basically designed to enable short-range communication (1 to 2 m) through which a key fob determines whether it is in the vicinity of its paired vehicle. However, this short-range communication is vulnerable because it is unable to precisely verify the distance, as the LF-band signals can be easily relayed or amplified. In this article, we present a novel method (named low-frequency fingerprinting,LOFI) to detect LF-band signals generated by an attacker.LOFIis designed as a subauthentication method that supports existing authentication systems for PKES systems. Through a series of experiments, we demonstrate thatLOFIeffectively detects attacks on the PKES system, achieving an average false positive rate (FPR) of 0.92% and an average false negative rate (FNR) of 0.01% under Non-Line-of-Sight (NLoS) conditions. Moreover, using a physics-based ray-tracing simulation, we analyze detection boundaries against feature impersonation attackers. Kyungho Joo, Hyo Jin Jo, Wonsuk Choi 0001 |
IEEE Internet Things J. | 2 |
| 2024 | In-Vehicle Network Intrusion Detection System Using CAN Frame-Aware FeaturesabstractWith the advancement of connected and automated vehicles (CAVs), drivers now have access to convenient features such as lane-keeping, cruise control, and more. The electronic control units (ECUs) equipped within vehicles communicate with each other through the controller area network (CAN). However, since the CAN does not possess any security mechanisms, it becomes a target for adversaries to attack. In light of this, a significant amount of research regarding intrusion detection systems (IDSs) has focused on detecting such maliciously injected CAN packets. Nevertheless, most existing machine learning-based IDSs neither calculate the exact time intervals of the CAN packets nor utilize the counter information. Precise timing intervals are a crucial feature for detecting spoofing, fuzzing, and replay attacks, and counter information is also a significant feature that can detect fuzzing and replay attacks. Therefore, in this paper, we propose a methodology for extracting two detection features that are aware of CAN frame characteristics: the interframe space (IFS) between two consecutive CAN packets, and the counter information of a CAN data payload (i.e., data field). Using these features, we introduce decision tree-based IDS. We evaluate the proposed features with popular decision tree-based models such as random forest and extreme gradient boosting (XGBoost). The results show that our proposed IDS can detect maliciously injected CAN packets with an F1 score of 99.54% in binary classification and 97.99% in multi-class classification, which are higher scores than what existing machine/deep learning-based IDSs achieve. Additionally, we measure the detection time of our proposed IDS in both online and offline testing environments. Yeonseon Jeong, Hyunghoon Kim, Seyoung Lee 0003, Wonsuk Choi 0001, Dong Hoon Lee 0001, Hyo Jin Jo |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | RIDAS: Real-time identification of attack sources on controller area networks
Jiwoo Shin, Hyunghoon Kim, Seyoung Lee 0003, Wonsuk Choi 0001, Dong Hoon Lee 0001, Hyo Jin Jo |
USENIX Security Symposium | 6 |
| 2023 | Flooding attack mitigator for in-vehicle CAN using fault confinement in CAN protocol
Sung Bum Park, Hyo Jin Jo, Dong Hoon Lee 0001 |
Comput. Secur. | 2 |
| 2023 | ErrIDS: An Enhanced Cumulative Timing Error-Based Automotive Intrusion Detection SystemabstractContemporary vehicles have undergone numerous transformations to become fully computerized machines. This computerizing process is intended to provide safety and convenience for drivers; however, there have been many studies demonstrating how to remotely maneuver a vehicle by compromising its in-vehicle electronic control units (ECU). As a countermeasure, automotive intrusion detection systems (IDSs) have also been extensively explored as potential remedies. The clock-based IDS was one of the most promising methods for an automotive IDS, but researchers have recently determined it to be insufficient, as adversaries can emulate the clock skew. In this paper, we propose a novel automotive IDS that leverages the residuals—which have traditionally been considered an error that should be removed from analysis—of average and actual timestamp intervals of two consecutive controller area network (CAN) messages. Thus, we present a rationale as to why large residuals occur in a real in-vehicle CAN network. Our method analyzes transmission periodicity so closely that any minuscule change can be detected in the event of an intrusion. We show that our method detects a vehicle intrusion with a low false-alarm rate, and that it can detect a new sophisticated attack which emulates the clock skew of an original transmission. To the best of our knowledge, this is the first approach analyzing transmission time to detect the frequency masquerading attack with clock skew emulation. Finally, our method enables the sharing of parameters determined in a vehicle with other like models, which is meaningful for manufacturers in terms of scalability. Seyoung Lee 0003, Wonsuk Choi 0001, Hyo Jin Jo, Dong Hoon Lee 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | A Survey of Attacks on Controller Area Networks and Corresponding CountermeasuresabstractThe development of vehicle technologies such as connected and autonomous vehicle environments provide drivers with functions for convenience and safety that are highly capable of remote vehicle diagnosis or lane-keeping assistance. Unfortunately, despite impressive advantages for drivers, these functions also have various vulnerabilities that could lead to cyber-physical attacks on automotive Controller Area Networks (i.e., automotive CAN). To deal with these security issues, a multitude of issue-specific countermeasures have already been proposed. In this paper, we introduce existing research on automotive CAN attacks and evaluate several state-of-the-art countermeasures. Particularly, we provide a comprehensive adversary model for automotive CAN and classify existing countermeasures into four system categories: (1) preventative protection, (2) intrusion detection, (3) authentication, and (4) post-protection. From the extensive literature review, we attempt to summarize the security research regarding automotive CAN and identify open research directions for in-vehicle networks of autonomous vehicle. Hyo Jin Jo, Wonsuk Choi 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2019 | How to Securely Record Logs based on ARM TrustZoneabstractA number of logs are generated from IT devices. Since logs have important information regarding a system, they are used for finding the trace of an intrusion or obtaining important information through a big data analysis. Hence, the logs have become a major attack surface for attackers. To protect logs, IT devices require secure logging methods as a mandatory service. Secure logging can provide detection of malicious manipulation of logs and verification of their origin. In this paper, we propose a secure logging method satisfying forward and backward secrecy based on ARM TrustZone for embedded systems, which enables to efficiently generate secure logs through inter-process communication without modification of the existing system (Syslog). Also, we show that the proposed method does not require extra overhead compared with the existing logging method. Wonsuk Choi 0001, Hyo Jin Jo, Dong Hoon Lee 0001 |
AsiaCCS | 3 |
| 2018 | VoltageIDS: Low-Level Communication Characteristics for Automotive Intrusion Detection SystemabstractThe proliferation of computerized functions aimed at enhancing drivers' safety and convenience has increased the number of vehicular attack surfaces accordingly. The fundamental vulnerability is caused by the fact that the controller area network protocol, a de facto standard for in-vehicle networks, does not support message origin authentication. Several methods to resolve this problem have been suggested. However, most of them require modification of the CAN protocol and have their own vulnerabilities. In this paper, we focus on securing in-vehicle CAN networks, proposing a novel automotive intrusion detection system (so-called VoltageIDS). The system leverages the inimitable characteristics of an electrical CAN signal as a fingerprint of the electronic control units. The noteworthy contributions are that VoltageIDS does not require any modification of the current system and has been validated on actual vehicles while driving on the road. VoltageIDS is also the first automotive intrusion detection system capable of distinguishing between errors and the bus-off attack. Our experimental results on a CAN bus prototype and on real vehicles show that VoltageIDS detects intrusions in the in-vehicle CAN network. Moreover, we evaluate VoltageIDS while a vehicle is moving. Wonsuk Choi 0001, Kyungho Joo, Hyo Jin Jo, Moon Chan Park, Dong Hoon Lee 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Reliable Cooperative Authentication for Vehicular NetworksabstractVehicular ad-hoc networks (VANETs) have been researched with regard to enhance driver's safety and comfort. In VANETs, all vehicles share their status and road conditions with neighboring nodes by periodically generating safety messages. To provide reliable VANET services, message authentication is an important feature. In particular, anonymous message authentication has attracted considerable interest, because periodic broadcast messages from a vehicle can be used to track its location. Unfortunately, previously proposed anonymous message authentication protocols had serious practical shortcomings, including high communication, authentication, and revocation costs, as well as reliability issues. Thus, in this paper, we propose an anonymous authentication protocol based on a cooperative authentication method. The proposed method does not require mode synchronization between cooperative and non-cooperative authentication. In addition, we design a two-layer pseudo-identity generation method and construct a key update tree for efficient revocation. Simulations show that our protocol does not result in packet losses caused by authentication overheads, even when the vehicle density is 200/km2. Hyo Jin Jo, In Seok Kim, Dong Hoon Lee 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2016 | A Practical Security Architecture for In-Vehicle CAN-FDabstractThe controller area network with flexible data rate (CAN-FD) is attracting attention as the next generation of in-vehicle network technology. However, security issues have not been completely taken into account when designing CAN-FD, although every bit of information transmitted could be critical to driver safety. If we fail to solve the security vulnerabilities of CAN-FD, we cannot expect Vehicle-Information and Communications Technology (Vehicle-ICT) convergence to continue to develop. Fortunately, secure in-vehicle CAN-FD communication environments can be constructed using the larger data payload of CAN-FD. In this paper, we propose a security architecture for in-vehicle CAN-FD as a countermeasure (designed in accordance with CAN-FD specifications). We considered the characteristics of the International Organization for Standardization (ISO) 26262 Automotive Safety Integrity Level and the in-vehicle subnetwork to design a practical security architecture. We also evaluated the feasibility of the proposed security architecture using three kinds of microcontroller unit and the CANoe software. Our evaluation findings may be used as an indicator of the performance level of electronic control units for manufacturing next-generation vehicles. Samuel Woo, Hyo Jin Jo, In-Seok Kim, Dong Hoon Lee 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2015 | A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CANabstractVehicle-IT convergence technology is a rapidly rising paradigm of modern vehicles, in which an electronic control unit (ECU) is used to control the vehicle electrical systems, and the controller area network (CAN), an in-vehicle network, is commonly used to construct an efficient network of ECUs. Unfortunately, security issues have not been treated properly in CAN, although CAN control messages could be life-critical. With the appearance of the connected car environment, in-vehicle networks (e.g., CAN) are now connected to external networks (e.g., 3G/4G mobile networks), enabling an adversary to perform a long-range wireless attack using CAN vulnerabilities. In this paper we show that a long-range wireless attack is physically possible using a real vehicle and malicious smartphone application in a connected car environment. We also propose a security protocol for CAN as a countermeasure designed in accordance with current CAN specifications. We evaluate the feasibility of the proposed security protocol using CANoe software and a DSP-F28335 microcontroller. Our results show that the proposed security protocol is more efficient than existing security protocols with respect to authentication delay and communication load. Samuel Woo, Hyo Jin Jo, Dong Hoon Lee 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2014 | Efficient Privacy-Preserving Authentication in Wireless Mobile NetworksabstractSecure authentication in roaming services is being designed to allow legal users to get access to wireless network services when they are away from their home location. Recently, to protect the location privacy of users, there have been researches on anonymous authentication. In particular, anonymous authentication without the participation of home servers has attracted considerable interest owing to its influence on the communication efficiency. Unfortunately, the previously proposed anonymous authentication schemes have serious practical shortcomings, such as high communication and computation costs and huge revocation lists. In this paper, we propose a novel three-round anonymous roaming protocol that does not require the participation of home servers. The proposed protocol uses a pseudo-identity-based signcryption scheme to perform efficient revocation with a short revocation list and efficient authentication. The use of a signcryption algorithm minimizes the number of pseudo-identities stored in a Subscriber Identification Module (SIM) card with limited storage capacity. The authentication efficiency is also higher than that of existing protocols. The proposed protocol is formally proved in the Canetti-Krawczyk (CK) model. Hyo Jin Jo, Jungha Paik, Dong Hoon Lee 0001 |
IEEE Trans. Mob. Comput. | 1 |