VLDB 2026 Research / reviewers in the wild / expert
Kyu-Seok Shim
dblp:156/3851
· DBLP profile ↗
17ranked-venue papers
7as first author
3since 2021 · last 2024
0000-0002-3317-7000ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 3 first-authorSoftware engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Security and privacy · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Research on Quantum Key, Distribution Key and Post-quantum Cryptography Key Applied Protocols for Data Science and Web SecurityabstractCurrently, data security is one of the most concerning research topics. The traditional RSA encryption system has become vulnerable to quantum algorithms such as Grover and Shor, leading to the development of new security systems for the quantum. As a result, quantum cryptography is gaining importance as a key element of future communication security. This study focuses on quantum key distribution protocols for data quantum encryption, aiming to achieve quantum robustness in all stages of quantum cryptography communication processes. Quantum cryptography communication requires robust quantum encryption not only between end-nodes but also between all components. Therefore, this study demonstrates the process of end-to-end data quantum encryption and proves the overall quantum robustness in this process. Kyu-Seok Shim, Boseon Kim, Wonhyuk Lee |
J. Web Eng. | 1 |
| 2022 | Design and Validation of Quantum Key Management System for Construction of KREONET Quantum Cryptography CommunicationabstractAs it has been recently proven that the public key-based RSA algorithms that are currently used in encryption can be unlocked by Shor’s algorithm of quantum computers in a short time, conventional security systems are facing new threats, and accordingly, studies have been actively conducted on new security systems. They are classified into two typical methods: Post Quantum Cryptography (PQC) and Quantum Key Distribution (QKD). PQC aims to design conventional cryptography systems in a more robust way so that they will not be decrypted by a quantum computer in a short time whereas QKD aims to make data tapping and interception physically impossible by using quantum mechanical characteristics. In this paper, we design a quantum key management system, which is most crucial for constructing a QKD network and analyze the design requirements to apply them to Korea Research Environment Open NETwork (KREONET). The quantum key management system not only manages the lifecycle, such as storage, management, derivation, allocation, and deletion of the symmetric key generated in QKD but also enables many-to-many communication in QKD communication based on the key relay function and P2P communication to overcome the limitation of distance, which is a disadvantage of QKD. We have validated the designed quantum key management system through simulations to supplement the parts that were not considered during the initial design. Kyu-Seok Shim, Il Kwon Sohn, Eunjoo Lee, Kwang-il Bae, Wonhyuk Lee |
J. Web Eng. | 1 |
| 2021 | Enhance the ICS Network Security Using the Whitelist-based Network Monitoring Through Protocol AnalysisabstractIn our present technological age, most manual and semi-automated tasks are being automated for efficient productivity or convenience. In particular, industrial sites are rapidly being automated to increase productivity and improve work efficiency. However, while networks are increasingly deployed as an integral part of the automation of industrial processes, there are also many resultant dangers such as security threats, malfunctions, and interruption of industrial processes. In particular, while the security of business networks is reinforced and their information is not easily accessible, intruders are now targeting industrial networks whose security is relatively poor, wherein attacks could directly lead to physical damage. Therefore, numerous studies have been conducted to counter security threats through network traffic monitoring, and to minimize physical loss through the detection of malfunctions. In the case of industrial processes, such as in nuclear facilities and petroleum facilities, thorough monitoring is required as security issues can lead to significant danger to humans and damage to property. Most network traffic in industrial facilities uses proprietary protocols for efficient data transmission, and these protocols are kept confidential because of intellectual property and security reasons. Protocol reverse engineering is a preparatory step to monitor network traffic and achieve more accurate traffic analysis. The field extraction method proposed in this study is a method for identifying the structure of proprietary protocols used in industrial sites. From the extracted fields, the structure of commands and protocols used in the industrial environment can be derived. To evaluate the feasibility of the proposed concept, an experiment was conducted using the Modbus/TCP protocol and Ethernet/IP protocol used in actual industrial sites, and an additional experiment was conducted to examine the results of the analysis of conventional protocols using the file transfer protocol. Kyu-Seok Shim, Il Kwon Sohn, Eunjoo Lee, Woojin Seok, Wonhyuk Lee |
J. Web Eng. | 1 |
| 2020 | An Automatic Protocol Reverse Engineering Approach from the Viewpoint of the TCP/IP Reference ModelabstractProtocol reverse engineering represents a very powerful and important tool for network management and security. To cope with the emergence and evolution of rapidly increasing numbers of unknown protocols, automation is of great importance. Many methods for supporting the automation of the various steps for protocol reverse engineering have been investigated; however, there has been no method to automate the analysis of the target network environment. Most methods are designed only for application layer protocols, and all others are designed for specific environments. Given any unknown communication, we must be able to infer the structure of the protocol. However, there has been no research on automatic reverse engineering of protocols when both the protocol and the target network environment are entirely unknown. Here, we propose an automatic protocol reverse engineering approach that is designed to be generally applicable, regardless of the specific network environment. We demonstrate the feasibility of the proposed approach by applying it to several protocols in various layers of the TCP/ IP reference model. Young-Hoon Goo, Kyu-Seok Shim, Ui-Jun Baek, Jee-Tae Park, Mu-Gon Shin, Myung-Sup Kim |
APNOMS | 2 |
| 2019 | A Method for Extracting Static Fields in Private Protocol Using Entropy and Statistical AnalysisabstractModern society is turning into the environment in which high-capacity network traffic generated by the development of high-speed internet. As a result, new applications and malicious behaviors are increasing exponentially. Most protocols that occur in these network environments are private protocols. Because private protocols do not have any specifications open, it is very important to analyze the structures of the private protocol for efficient network management and security. Various protocol reverse engineering methodologies have been studied so far, but there is not standardized methodology to extract the protocol's field. Therefore, this paper proposes a methodology for clearly extracting fields of the smallest unit of protocol's structure, and conducts experiments and validates performance on the protocols that are actually being used. Min-Seob Lee, Young-Hoon Goo, Kyu-Seok Shim, Sung-Ho Yoon, Se-Hyun Ji, Myung-Sup Kim |
APNOMS | 3 |
| 2019 | Block Analysis in Bitcoin System Using Clustering with Dimension ReductionabstractThe online cryptocurrency bitcoin, created based in blockchain technology, is attracting the attention of individuals, businesses and the government as well. As interest in blockchain technology and cryptocurrency has steadily increased over the past few years, trading volume and market size of cryptocurrency have increased at an astonishing speed. As a result, analysis and monitoring measures for blockchain networks, blocks, and transactions have become an important issue. In this paper, the method of clustering applied dimension reduction as a method of bitcoin network analysis is proposed. The proposed method applies the analysis way using K-means algorithm with PCA to block data in bitcoin collected by this research team. Mu-Gon Shin, Ui-Jun Baek, Kyu-Seok Shim, Jee-Tae Park, Sung-Ho Yoon, Myung-Sup Kim |
APNOMS | 3 |
| 2018 | Framework for precise protocol reverse engineering based on network tracesabstractEmergence of high-speed Internet and ubiquitous environment is generating massive traffic, and it has led to a rapid increase of applications and malicious behaviors with various functions. Many of the complex and diverse protocols that occur under these situations, are unknown or proprietary protocols that are at least documented. For efficient network management and network security, protocol reverse engineering that extract the specification of the protocols is very important. While various protocol reverse engineering methods have been studied, there is no single standardized method to extract protocol specification completely yet, and each of methods has some limitations. In this paper, we propose the framework for precise protocol reverse engineering based on network traces. The proposed framework can extract highly elaborative and intuitive message formats, flow formats, and protocol state machine of the unknown protocol. We demonstrate the validity of our framework through an example of HTTP protocol. Young-Hoon Goo, Kyu-Seok Shim, Byeong-Min Chae, Myung-Sup Kim |
NOMS | 2 |
| 2018 | Inference of network unknown protocol structure using CSP(Contiguous Sequence Pattern) algorithm based on tree structureabstractAs Internet traffic generation grows and new applications and malicious acts continue to emerge, traffic to be analyzed is growing rapidly. Most network security threat traffic is communicated using unknown protocol. Thus, protocol reverse engineering is very important to address network security issues. While various protocol reverse engineering methods have been studied, there is no single standardized method to extract protocol specification completely yet, and each of methods has some limitations. This paper proposes to extract the static fields of the protocol. The method uses CSP algorithm based on Apriori to extract the common strings. However, we propose the method of extraction of a protocol static field using the CSP algorithm based on the tree structure because it is not possible to extract all static fields with only CSP algorithm. This method allows extraction of all static fields that are infrequent but possible, not just frequently occurring. This method has been validated by experiments with HTTP protocol. Kyu-Seok Shim, Young-Hoon Goo, Min-Seob Lee, Huru Hasanova, Myung-Sup Kim |
NOMS | 1 |
| 2018 | A Survey of Automatic Protocol Reverse Engineering Approaches, Methods, and Tools on the Inputs and Outputs ViewabstractA network protocol defines rules that control communications between two or more machines on the Internet, whereas Automatic Protocol Reverse Engineering (APRE) defines the way of extracting the structure of a network protocol without accessing its specifications. Enough knowledge on undocumented protocols is essential for security purposes, network policy implementation, and management of network resources. This paper reviews and analyzes a total of 39 approaches, methods, and tools towards Protocol Reverse Engineering (PRE) and classifies them into four divisions, approaches that reverse engineer protocol finite state machines, protocol formats, and both protocol finite state machines and protocol formats to approaches that focus directly on neither reverse engineering protocol formats nor protocol finite state machines. The efficiency of all approaches’ outputs based on their selected inputs is analyzed in general along with appropriate reverse engineering inputs format. Additionally, we present discussion and extended classification in terms of automated to manual approaches, known and novel categories of reverse engineered protocols, and a literature of reverse engineered protocols in relation to the seven layers’ OSI (Open Systems Interconnection) model. Baraka D. Sija, Young-Hoon Goo, Kyu-Seok Shim, Huru Hasanova, Myung-Sup Kim |
Secur. Commun. Networks | 3 |
| 2017 | Structured whitelist generation in SCADA network using PrefixSpan algorithmabstractSCADA system works in repeated or periodic used of only limited communication devices. Because of this feature, whitelist based security techniques are widely used and access restriction method using whitelist based static ACL is most commonly applied in security field. Static ACL have advantages in security, but their expressiveness is too simple to express communication using dynamic allocated port. In addition, it does not reflect all the communication characteristics of the control device, and the generated static ACL should always be open regardless of the frequent use. We propose a structured ACL that extends the fixed generation sequence information between the communication and communication-specific periodicity to reflect the mechanical and repetitive communication characteristics of the SCADA system in the static ACL. We demonstrate the feasibility of the proposed Structured ACL model in this paper by applying the real SCADA network traffic. Woo-Suk Jung, Jeong-Han Yun, Sin-Kyu Kim, Kyu-Seok Shim, Myung-Sup Kim |
APNOMS | 4 |
| 2017 | Classification of application traffic using tensorflow machine learningabstractApplications are becoming more complicated and diverse as the network environment grows day by day. So, it is important to classify application traffic accurately. Although there are many ways to classify applications traffic, machine learning based approaches are becoming more efficient in nowadays. This is because machine learning methods are more appropriate than existing methods for accurate and efficient applications traffic classification. Payload signature methods have limitations to deal with various patterns and increasing application traffic complexity. In this paper, we propose a method for extracting flow features and a system for classifying applications traffic based on Machine Learning. Jee-Tae Park, Kyu-Seok Shim, Sung-Ho Lee, Myung-Sup Kim |
APNOMS | 2 |
| 2017 | SigManager: Automatic payload signature management system for the classification of dynamically changing internet applicationsabstractToday's network environment is becoming very complicated. Accordingly, traffic classification for network management becomes difficult. For the study of traffic classification, the development of automatic payload signature generation system was carried out very actively. However, the existing automatic payload signature generation system has problems such as semi-automatic system, disposable signature generation, false-positive signature generation and not up-to-date signature. Therefore, we propose the SigManager. SigManager performs all process such as traffic collection, signature generation, signature management and signature verification. The traffic collection stage automatically collects ground-truth traffic through TMA and TMS. The signature management stage removes unnecessary signatures and the signature generation stage generates the new signatures. Finally, the signature verification stage removes the false-positive signatures. We solved the problem of existing automatic signature generation system through this system. As a result of applying this system to campus network, we could maintain high completeness and low false-positive rate for 4 applications. Kyu-Seok Shim, Young-Hoon Goo, Sungyun Kim, Mi-Jung Choi, Myung-Sup Kim |
APNOMS | 1 |
| 2017 | Survey on network protocol reverse engineering approaches, methods and toolsabstractA network protocol defines rules that control communications between two or more hosts on the Internet, whereas Protocol Reverse Engineering (PRE) defines the process of extracting the structure, attributes and data from a network protocol. Enough knowledge on protocol specifications is essential for security purposes, network policy implementation and management of network resources. Protocol Reverse Engineering is a complex process intended to uncover specifications of unknown protocols. The complexity of PRE, in terms of time consumption, tediousness and error-prone, has led to short and diverse outcomes of Protocols Reverse Engineering approaches. This paper, surveys outputs of 9 PRE approaches in three divisions with methodology analysis and its possible applications. Moreover, in the introductory part we provide a general PRE literature in great depth. Baraka D. Sija, Young-Hoon Goo, Kyu-Seok Shim, Sungyun Kim, Mi-Jung Choi, Myung-Sup Kim |
APNOMS | 3 |
| 2016 | Payload signature structure for accurate application traffic classificationabstractEmergence of high-speed Internet and various smart devices has led to a rapid increase of applications on the Internet. In order to provide reliable services and efficient management of network resources, accurate traffic classification of various applications is essential. Through various methods of extraction when payload signatures are extracted, most of these payload signature formats are just strings or hex values which appear frequently within payloads. Thus, it is difficult to extract unique signatures for a specific application, because redundant signatures extraction is in most cases unavoidable. In this paper, we propose a more elaborative payload signature structure for accurate classification of each specific application. The formats of this signature structure is composed of three level signatures. These are Content signature which is single contiguous substring in payloads, Packet signature which is the sequence of Content signatures that appear in the same packet, and the Flow signature which is a sequence of Packet signatures that appear in the same flow. By applying and comparing the existing signature format and proposed signature format to the actual application traffic classification, we demonstrate the effectiveness of the proposed signature structure. Young-Hoon Goo, Kyu-Seok Shim, Su-Kang Lee, Myung-Sup Kim |
APNOMS | 2 |
| 2015 | Signature management system to cope with traffic changes in application and serviceabstractToday, the number of applications using network service has been increasing. Also, many applications have changed their traffic pattern frequently due to various reasons. Nevertheless, network managers tend to stay with old signatures. But they should update with new signatures to detect the modified application traffic. The extraction of signature is work to demand a lot of time. And it is difficult to continuously and timely extract the new signature for all applications. In this paper, we propose a noble signature management system which automatically extract new signatures detecting the modified traffic and delete old signatures no longer used. The proposed system analyzes traffic with existing signatures and extracts new signature automatically for updated traffic. For automatic generation of new signatures, we uses a sequence pattern algorithm. Also, the proposed system analyze usage of the old signatures to remove them when they are not used any more. We proved the feasibility and applicability of the proposed system by showing that that detection rate of all application was increased. Kyu-Seok Shim, Sung-Ho Yoon, Mi-Jung Choi, Myung-Sup Kim |
APNOMS | 1 |
| 2015 | Framework for multi-level application traffic identificationabstractWith the acceleration of the Internet speed and the vigorous emergence of new applications, the amount of Internet traffic has increased. In order to provide stable Internet service, efficient network management based on accurate traffic identification is critical. Although various methods for traffic identification have been proposed, not a single method identifies all types of Internet traffic. In this paper, we propose a framework for multi-level application traffic identification by combining several single methods. Sung-Ho Yoon, Kyu-Seok Shim, Su-Kang Lee, Myung-Sup Kim |
APNOMS | 2 |
| 2014 | Application traffic classification in Hadoop distributed computing environmentabstractToday, network traffic has increased because of the appearance of various applications and services. However, methods for network traffic analysis are not developed to catch up the trend of increasing usage of the network. Most methods for network traffic analysis are operated on a single server environment, which results in the limits about memory, processing speed, storage capacity. When considering the increment of network traffic, we need a method of network traffic to handle the Bigdata traffic. Hadoop system can be effectively used for analyzing Bigdata traffic. In this paper, we propose a method of application traffic classification in Hadoop distributed computing system and compare the processing time of the proposed system with a single server system to show the advantages of Hadoop. Kyu-Seok Shim, Su-Kang Lee, Myung-Sup Kim |
APNOMS | 1 |