VLDB 2026 Research / reviewers in the wild / expert
Jeman Park 0001
dblp:163/7414
· DBLP profile ↗
19ranked-venue papers
7as first author
9since 2021 · last 2026
0000-0003-4387-8780ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 6 since 2021Computer networks · 6 · 3 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Achieving Zen: Combining Mathematical and Programmatic Deep Learning Model Representations for Attribution and Reuse
David Oygenblik, Dinko Dermendzhiev, Filippos Sofias, Mingxuan Yao, Haichuan Xu, Jeman Park 0001, Amit Kumar Sikder, Brendan Saltaformaggio |
NDSS | 7 |
| 2025 | Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered WebsitesabstractThe Android accessibility (a11y) service has been widely utilized by malware to abuse benign services.To prevent such abuse, developers need to secure a11y content access in both their apps and mobile websites.However, a misalignment of a11y protection mechanisms exists between them.Prior research has focused on attacking and defending a11y information embedded in native Android apps.However, our research found that a11y malware can retrieve app-protected a11y information in its mobile browser-rendered website counterpart, leaving mobile browser users more vulnerable to a11y attacks than app users.To help benign service developers vet this attack surface, we developed SOMBRA, an automated analysis pipeline to vet browser-side leakage of a11y information that is a11y-protected in apps.Using SOMBRA, we analyzed 294 benign services and found 29 of them deploy app-side a11y protection mechanisms to secure 256 views.SOMBRA discovered that 241, 402, 244, and 251 elements corresponding to their protected app-side views are a11y-exposed in their websites rendered by Chrome, Firefox, Brave, and Edge browsers, respectively.The leaked elements contain sensitive personal identifiable information.Finally, SOMBRA discovered that most developers do not adopt browser-side a11y protections because existing mechanisms either have ineffective protection or hinder the usability of their content. Haichuan Xu, Mingxuan Yao, David Oygenblik, Jeman Park 0001, Brendan Saltaformaggio |
CCS | 6 |
| 2025 | Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment Reuse
Mingxuan Yao, Haichuan Xu, Omar Alrawi, Jeman Park 0001, Brendan Saltaformaggio |
NDSS | 5 |
| 2024 | AI Psychiatry: Forensic Investigation of Deep Learning Networks in Memory Images
David Oygenblik, Carter Yagemann, Joseph Zhang, Arianna Mastali, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 5 |
| 2024 | DVa: Extracting Victims and Abuse Vectors from Android Accessibility Malware
Haichuan Xu, Mingxuan Yao, Mohamed Moustafa Dawoud, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 5 |
| 2022 | Mistrust Plugins You Must: A Large-Scale Study Of Malicious Plugins In WordPress Marketplaces
Ranjita Pai Kasturi, Jonathan Fuller 0001, Yiting Sun, Omar Chabklo, Andres Rodriguez 0005, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 6 |
| 2022 | A Large-Scale Behavioral Analysis of the Open DNS Resolvers on the InternetabstractOpen DNS resolvers are resolvers that perform recursive resolution on behalf of any user. They can be exploited by adversaries because they are open to the public and require no authorization to use. Therefore, it is important to understand the state of open resolvers to gauge their potentially negative impact on the security and stability of the Internet. In this study, we conducted a comprehensive probing over the entire IPv4 address space and found that more than 3 million IP addresses of open resolvers still exist in the wild. Moreover, we found that many of them work in a way that deviates from the standard. More importantly, we found that many open resolvers answer queries with incorrect, even malicious, responses. Contrasting to results obtained in 2013, we found that while the number of open resolvers has decreased significantly, the number of resolvers providing incorrect responses is almost the same, while the number of open resolvers providing malicious responses has increased, highlighting the prevalence of their threat. Through an extended analysis, we also empirically show that the use of forwarders in the open resolver ecosystem and the possibility that incorrect or malicious responses can be manipulated by these forwarders. Jeman Park 0001, RhongHo Jang, Manar Mohaisen, David Mohaisen |
IEEE/ACM Trans. Netw. | 1 |
| 2021 | Domain name system security and privacy: A contemporary survey
Aminollah Khormali, Jeman Park 0001, Hisham Alasmary, Afsah Anwar, Muhammad Saad 0001, David Mohaisen |
Comput. Networks | 2 |
| 2021 | Corrigendum to "Domain name system security and privacy: A contemporary survey" Computer Networks Volume 185 (2020) 107699
Aminollah Khormali, Jeman Park 0001, Hisham Alasmary, Afsah Anwar, Muhammad Saad 0001, David Mohaisen |
Comput. Networks | 2 |
| 2020 | Statically Dissecting Internet of Things Malware: Analysis, Characterization, and Detection
Afsah Anwar, Hisham Alasmary, Jeman Park 0001, An Wang 0002, Songqing Chen, David Mohaisen |
ICICS | 3 |
| 2020 | Assessing the effectiveness of pulsing denial of service attacks under realistic network synchronization assumptions
Jeman Park 0001, Manar Mohaisen, DaeHun Nyang, David Mohaisen |
Comput. Networks | 1 |
| 2019 | Where Are You Taking Me? Behavioral Analysis of Open DNS ResolversabstractOpen DNS resolvers are resolvers that perform recursive resolution on behalf of any user. They can be exploited by adversaries because they are open to the public and require no authorization to use. Therefore, it is important to understand the state of open resolvers to gauge their potentially negative impact on the security and stability of the Internet. In this study, we conducted a comprehensive probing over the entire IPv4 address space and found that more than 3 million open resolvers still exist in the wild. Moreover, we found that many of them work in a way that deviates from the standard. More importantly, we found that many open resolvers answer queries with the incorrect, even malicious, responses. Contrasting to results obtained in 2013, we found that while the number of open resolvers has decreased significantly, the number of resolvers providing incorrect responses is almost the same, while the number of open resolvers providing malicious responses has increased, highlighting the prevalence of their threat. Jeman Park 0001, Aminollah Khormali, Manar Mohaisen, David Mohaisen |
DSN | 1 |
| 2019 | Adversarial Learning Attacks on Graph-based IoT Malware Detection SystemsabstractIoT malware detection using control flow graph (CFG)-based features and deep learning networks are widely explored. The main goal of this study is to investigate the robustness of such models against adversarial learning. We designed two approaches to craft adversarial IoT software: off-the-shelf methods and Graph Embedding and Augmentation (GEA) method. In the off-the-shelf adversarial learning attack methods, we examine eight different adversarial learning methods to force the model to misclassification. The GEA approach aims to preserve the functionality and practicality of the generated adversarial sample through a careful embedding of a benign sample to a malicious one. Intensive experiments are conducted to evaluate the performance of the proposed method, showing that off-the-shelf adversarial attack methods are able to achieve a misclassification rate of 100%. In addition, we observed that the GEA approach is able to misclassify all IoT malware samples as benign. The findings of this work highlight the essential need for more robust detection tools against adversarial learning, including features that are not easy to manipulate, unlike CFG-based features. The implications of the study are quite broad, since the approach challenged in this work is widely used for other applications using graphs. Ahmed Abusnaina, Aminollah Khormali, Hisham Alasmary, Jeman Park 0001, Afsah Anwar, David Mohaisen |
ICDCS | 4 |
| 2019 | Breaking graph-based IoT malware detection systems using adversarial examples: posterabstractThe main goal of this study is to investigate the robustness of graph-based Deep Learning (DL) models used for Internet of Things (IoT) malware classification against Adversarial Learning (AL). We designed two approaches to craft adversarial IoT software, including Off-the-Shelf Adversarial Attack (OSAA) methods, using six different AL attack approaches, and Graph Embedding and Augmentation (GEA). The GEA approach aims to preserve the functionality and practicality of the generated adversarial sample through a careful embedding of a benign sample to a malicious one. Our evaluations demonstrate that OSAAs are able to achieve a misclassification rate (MR) of 100%. Moreover, we observed that the GEA approach is able to misclassify all IoT malware samples as benign. Ahmed Abusnaina, Aminollah Khormali, Hisham Alasmary, Jeman Park 0001, Afsah Anwar, Ulku Meteriz, David Mohaisen |
WiSec | 4 |
| 2019 | Analyzing and Detecting Emerging Internet of Things Malware: A Graph-Based ApproachabstractThe steady growth in the number of deployed Internet of Things (IoT) devices has been paralleled with an equal growth in the number of malicious software (malware) targeting those devices. In this paper, we build a detection mechanism of IoT malware utilizing control flow graphs (CFGs). To motivate for our detection mechanism, we contrast the underlying characteristics of IoT malware to other types of malware—Android malware, which are also Linux-based—across multiple features. The preliminary analyses reveal that the Android malware have high density, strong closeness and betweenness, and a larger number of nodes. We show that IoT malware samples have a large number of edges despite a smaller number of nodes, which demonstrate a richer flow structure and higher complexity. We utilize those various characterizing features as a modality to build a highly effective deep learning-based detection model to detect IoT malware. To test our model, we use CFGs of about 6000 malware and benign IoT disassembled samples, and show a detection accuracy of $\approx 99.66$ %. Hisham Alasmary, Aminollah Khormali, Afsah Anwar, Jeman Park 0001, Jinchun Choi, Ahmed Abusnaina, Amro Awad, DaeHun Nyang, David Mohaisen |
IEEE Internet Things J. | 4 |
| 2019 | Transparency in the New gTLD Era: Evaluating the DNS Centralized Zone Data ServiceabstractThe centralized zone data service (CZDS) was introduced by the Internet Corporation for Assigned Names and Numbers (ICANN) to facilitate sharing and access to zone data of the new generic Top-Level Domains (gTLDs). CZDS aims to improve the security and transparency of the naming system of the Internet. In this paper, we investigate CZDS's transparency by measurement and evaluation. By requesting access to zone data of all gTLDs listed in the CZDS portal, we analyze various aspects of CZDS, including access status, responsiveness and provided reasons for granting access or denial. Among other findings, we find that while a large percent of the gTLD admins respond within a reasonable time, more than 10% of them have a long request-to-decision waiting time, and sometimes requests go unanswered even after six months of a request. Furthermore, we find that denial cases were for unjustified reasons, where administrators who denied the requests have asked for information that was already provided in the request form. We discuss implications, and how to enforce better outcomes of CZDS using insight from our measurement and evaluation. Jeman Park 0001, Jinchun Choi, DaeHun Nyang, David Mohaisen |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2018 | QOI: Assessing Participation in Threat Information SharingabstractWe introduce the notion of Quality of Indicator (QoI) to assess the level of contribution by participants in threat intelligence sharing. We exemplify QoI by metrics of the correctness, relevance, utility, and uniqueness of indicators. We build a system that extrapolates the metrics using a machine learning process over a reference set of indicators. We compared these results against a model that only considers the volume of information as a metric for contribution, and unveiled various observations, including the ability to spot low-quality contributions that are synonymous to free-riding. Jeman Park 0001, Hisham Alasmary, Omar Al-Ibrahim, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla, David Mohaisen |
ICASSP | 1 |
| 2018 | Timing is Almost Everything: Realistic Evaluation of the Very Short Intermittent DDoS AttacksabstractDistributed Denial-of-Service (DDoS) is a big threat to the security and stability of Internet-based services today. Among the recent advanced application-layer DDoS attacks, the Very Short Intermittent DDoS (VSI-DDoS) is the attack, which can bypass existing detection systems and significantly degrade the QoS experienced by users of web services. However, in order for the VSI-DDoS attack to work effectively, bots participating in the attack should be tightly synchronized, an assumption that is difficult to be met in reality. In this paper, we conducted a quantitative analysis to understand how a minimal deviation from perfect synchronization in botnets affects the performance and effectiveness of the VSI-DDoS attack. We found that VSI-DDoS became substantially less effective. That is, it lost 85.7% in terms of effectiveness under about 90ms synchronization inaccuracy, which is a very small inaccuracy under normal network conditions. Jeman Park 0001, DaeHun Nyang, David Mohaisen |
PST | 1 |
| 2015 | Exploring Smartphones as WAVE DevicesabstractIn this paper, we explore the possibility of using smartphones as WAVE devices. When it is expected to take more than a decade from now to deploy the WAVE technology in full scale, smartphones running the WAVE protocol stack can bring the benefit of the technology earlier. In particular, we design and implement the lower layers of the WAVE stack in software defined radio (SDR) on smartphone platform and test its vehicle-to-vehicle (V2V) performance in the real driving scenarios. We also investigate the performance in the vehicle-to-pedestrian (V2P) communication context. Jeman Park 0001, Seungho Kuk, Yongtae Park |
VTC Fall | 1 |