Taejune Park

dblp:164/1709 · DBLP profile ↗
← Back
20ranked-venue papers
7as first author
13since 2021 · last 2026
0000-0003-1421-5996ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 5 first-author · 9 since 2021Security and privacy · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 RAGNAROS: Large-Scale Regex Processing Acceleration with Neural Networks for DPI
Sebin Jo, Taejune Park
ICDCS2
2026 HybridMesh: A Hardware-software Hybrid Approach for Accelerating Service Mesh Ingress
Myoungsung You, Jaehyun Nam, Minjae Seo, Taejune Park, Seungwon Shin 0001
NSDI4
2026 Comprehensive performance analysis of security applications on the BlueField-3 SmartNIC
Suhyeon Lee 0007, Myoungsung You, Taejune Park
Comput. Networks4
2025 MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and Splitting
abstract
Tor, a widely utilized privacy network, enables anonymous communication but is vulnerable to flow correlation attacks that deanonymize users by correlating traffic patterns from Tor's ingress and egress segments. Various defenses have been developed to mitigate these attacks; however, they have two critical limitations: (i) significant network overhead during obfuscation and (ii) a lack of dynamic obfuscation for egress segments, exposing traffic patterns to adversaries. In response, we introduce MUFFLER, a novel connection-level traffic obfuscation system designed to secure Tor egress traffic. It dynamically maps real connections to a distinct set of virtual connections between the final Tor nodes and targeted services, either public or hidden. This approach creates egress traffic patterns fundamentally different from those at ingress segments without adding intentional padding bytes or timing delays. The mapping of real and virtual connections is adjusted in real-time based on ongoing network conditions, thwarting adversaries' efforts to detect egress traffic patterns. Extensive evaluations show that MUFFLER mitigates powerful correlation attacks with a TPR of 1% at an FPR of 10−2while imposing only a 2.17% bandwidth overhead. Moreover, it achieves up to 27x lower latency overhead than existing solutions and seamlessly integrates with the current Tor architecture.
Minjae Seo, Myoungsung You, Jaehan Kim, Taejune Park, Seungwon Shin 0001, Jinwoo Kim 0006
INFOCOM4
2025 HardMesh: Enabling High-performance Service Mesh Ingress Processing with SmartNICs
abstract
Service meshes have become essential for enabling microservices in cloud environments; however, they also introduce substantial network overhead. In particular, the ingress gateway, which serves as the primary entry point for external traffic, has emerged as a major performance bottleneck due to CPU-intensive traffic analysis and prolonged forwarding paths through multiple network stack layers. Our analysis indicates that these inefficiencies can result in a 4-fold reduction in network throughput and increased CPU resource consumption. In response, we propose HardMesh, a hardware-software hybrid ingress gateway that leverages a Smart-NIC for high-performance traffic analysis and efficient traffic routing. This process is augmented by a lightweight CPU-based proxy for traffic management. Evaluations show that HardMesh outperforms existing ingress gateways, achieving up to 4.4× higher throughput while providing the same range of traffic management services.
Myoungsung You, Jaehyun Nam, Minjae Seo, Taejune Park, Seungwon Shin 0001
SIGCOMM4
2024 Fatriot: Fault-tolerant MEC architecture for mission-critical systems using a SmartNIC
Taejune Park, Myoungsung You, Jinwoo Kim 0006, Seungsoo Lee 0001
J. Netw. Comput. Appl.1
2023 Extended data plane architecture for in-network security services in software-defined networks
Jinwoo Kim 0006, Yeonkeun Kim, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001, Taejune Park
Comput. Secur.6
2022 Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control Traffic
abstract
Software-defined wide area network (SD-WAN) has emerged as a new paradigm for steering a large-scale network flexibly by adopting distributed software-defined network (SDN) controllers. The key to building a logically centralized but physically distributed control-plane is running diverse cluster management protocols to achieve consistency through an exchange of control traffic. Meanwhile, we observe that the control traffic exposes unique time-series patterns and directional relationships due to the operational structure even though the traffic is encrypted, and this pattern can disclose confidential information such as control-plane topology and protocol dependencies, which can be exploited for severe attacks. With this insight, we propose a new SD-WAN fingerprinting system, called Heimdallr. It analyzes periodical and operational patterns of SD-WAN cluster management protocols and the context of flow directions from the collected control traffic utilizing a deep learning-based approach, so that it can classify the cluster management protocols automatically from miscellaneous control traffic datasets. Our evaluation, which is performed in a realistic SD-WAN environment consisting of geographically distant three campus networks and one enterprise network shows that Heimdallr can classify SD-WAN control traffic with ≥ 93%, identify individual protocols with ≥ 80% macro F-1 scores, and finally can infer control-plane topology with ≥ 70% similarity.
Minjae Seo, Jaehan Kim, Eduard Marin, Myoungsung You, Taejune Park, Seungsoo Lee 0001, Seungwon Shin 0001, Jinwoo Kim 0006
ACSAC5
2022 MECaNIC: SmartNIC to Assist URLLC Processing in Multi-Access Edge Computing Platforms
abstract
Multi-access edge computing (MEC) providing server capabilities at near end-users is introduced to enable Ultra Reliable Low Latency Communication (URLLC) for mission-critical and time-sensitive networked services. However, the current MEC simply shortens the physical travel distance of traffic but does not include any architectural approach for supporting URLLC. As a result, MEC implicates resource contention issues, and important packets can be easily delayed or lost, resulting in critical flaws for those services. To address these problems, we introduce MECaNIC, which extends the data plane of MEC to SmartNIC and assists URLLC of MEC. It provides i) precise packet scheduling that handles traffic priorities into two dimensions of reliability and latency, and ii) task offloading that accelerates MEC applications, including payload matching and response caching. The prototype implemented using NetFPGA shows that MECaNIC reduces the average latency of the high-priority traffic from$2,883\ \mu s$to$397\ \mu s$while ensuring packet delivery, even when the traffic competes with other lower priority traffic. Also, task offloading improves a MEC's payload processing 4-fold and reduces file downloading time and video random access time by 44% and 17%, respectively.
Taejune Park, Myoungsung You, Youngjin Jin, Kilho Lee, Seungwon Shin 0001
ICNP1
2022 Reconfigurable regular expression matching architecture for real-time pattern update and payload inspection
Jaehyun Nam, Seung Ho Na, Seungwon Shin 0001, Taejune Park
J. Netw. Comput. Appl.4
2022 Supporting ultra-low latency mixed-criticality communication using hardware-based data plane architecture
Taejune Park, Kilho Lee
J. Netw. Comput. Appl.1
2021 Reinhardt: Real-time Reconfigurable Hardware Architecture for Regular Expression Matching in DPI
abstract
Regular expression (regex) matching is an integral part of deep packet inspection (DPI) but a major bottleneck due to its low performance. For regex matching (REM) acceleration, FPGA-based studies have emerged and exploited parallelism by matching multiple regex patterns concurrently. However, even though guaranteeing high-performance, existing FPGA-based regex solutions do not still support dynamic updates in run time. Hence, it was inappropriate as a DPI function due to frequently altered malicious signatures. In this work, we introduce Reinhardt, a real-time reconfigurable hardware architecture for REM. Reinhardt represents regex patterns as a combination of reconfigurable cells in hardware and updates regex patterns in real-time while providing high performance. We implement the prototype using NetFPGA-SUME, and our evaluation demonstrates that Reinhardt updates hundreds of patterns within a second and achieves up to 10 Gbps throughput (max. hardware bandwidth). Our case studies show that Reinhardt can operate as NIDS/NIPS and as the REM accelerator for them.
Taejune Park, Jaehyun Nam, Seung Ho Na, Jaewoong Chung, Seungwon Shin 0001
ACSAC1
2021 Formullar: An FPGA-based network testing tool for flexible and precise measurement of ultra-low latency networking systems
Taejune Park, Seungwon Shin 0001, Insik Shin, Kilho Lee
Comput. Networks1
2019 DPX: Data-Plane eXtensions for SDN Security Service Instantiation
Taejune Park, Yeonkeun Kim, Vinod Yegneswaran, Phillip A. Porras, Zhaoyan Xu, KyoungSoo Park, Seungwon Shin 0001
DIMVA1
2019 SODA: A software-defined security framework for IoT environments
Yeonkeun Kim, Jaehyun Nam, Taejune Park, Sandra Scott-Hayward, Seungwon Shin 0001
Comput. Networks3
2019 MC-SDN: Supporting Mixed-Criticality Real-Time Communication Using Software-Defined Networking
abstract
Despite recent advances, there still remain many problems to design reliable cyber-physical systems. One of the typical problems is to achieve a seemingly conflicting goal, which is to support timely delivery of real-time flows while improving resource efficiency. Recently, the concept of mixed-criticality (MC) has been widely accepted as useful in addressing the goal for real-time resource management. However, it has not been yet studied well for real-time communication. In this paper, we present the first approach to support MC flow scheduling on switched Ethernet networks leveraging an emerging network architecture, software-defined networking (SDN). Though SDN provides flexible and programmatic ways to control packet forwarding and scheduling, it yet raises several challenges to enable real-time MC flow scheduling on SDN, including: 1) how to handle (i.e., drop or re-prioritize) out-of-mode packets in the middle of the network when the criticality mode changes and 2) how the mode change affects end-to-end transmission delays. Addressing such challenges, we develop MC-SDN that supports real-time MC flow scheduling by extending SDN-enabled switches and OpenFlow protocols. It manages and schedules MC packets in different ways depending on the system criticality mode. To this end, we carefully design the mode change protocol that provides analytic mode change delay bound, and then resolve implementation issues for system architecture. For evaluation, we implement a prototype of MC-SDN on top of Open vSwitch, and integrate it into a real world network testbed as well as a 1/10 autonomous vehicle. Our extensive evaluations with the network testbed and vehicle deployment show that MC-SDN supports MC flow scheduling with minimal delays on forwarding rule updates and it brings a significant improvement in safety in a real-world application scenario.
Kilho Lee, Taejune Park, Hoon Sung Chwa, Jinkyu Lee 0001, Seungwon Shin 0001, Insik Shin
IEEE Internet Things J.3
2018 MC-SDN: Supporting Mixed-Criticality Scheduling on Switched-Ethernet Using Software-Defined Networking
abstract
In this paper, we present the first approach to support mixed-criticality (MC) flow scheduling on switched Ethernet networks leveraging an emerging network architecture, Software-Defined Networking (SDN). Though SDN provides flexible and programmatic ways to control packet forwarding and scheduling, it yet raises several challenges to enable real-time MC flow scheduling on SDN, including i) how to handle (i.e., drop or reprioritize) out-of-mode packets in the middle of the network when the criticality mode changes, and ii) how the mode change affects end-to-end transmission delays. Addressing such challenges, we develop MC-SDN that supports real-time MC flow scheduling by extending SDN-enabled switches and OpenFlow protocols. It manages and schedules MC packets in different ways depending on the system criticality mode. To this end, we carefully design the mode change protocol that provides analytic mode change delay bound, and then resolve implementation issues for system architecture. For evaluation, we implement a prototype of MC-SDN on top of Open vSwitch, and integrate it into a real world network testbed as well as a 1/10 autonomous vehicle. Our extensive evaluations with the network testbed and vehicle deployment show that MC-SDN supports MC flow scheduling with minimal delays on forwarding rule updates and it brings a significant improvement in safety in a real-world application scenario.
Kilho Lee, Taejune Park, Hoon Sung Chwa, Jinkyu Lee 0001, Seungwon Shin 0001, Insik Shin
RTSS2
2017 Flow Wars: Systemizing the Attack Surface and Defenses in Software-Defined Networks
abstract
Emerging software defined network (SDN) stacks have introduced an entirely new attack surface that is exploitable from a wide range of launch points. Through an analysis of the various attack strategies reported in prior work, and through our own efforts to enumerate new and variant attack strategies, we have gained two insights. First, we observe that different SDN controller implementations, developed independently by different groups, seem to manifest common sets of pitfalls and design weakness that enable the extensive set of attacks compiled in this paper. Second, through a principled exploration of the underlying design and implementation weaknesses that enables these attacks, we introduce a taxonomy to offer insight into the common pitfalls that enable SDN stacks to be broken or destabilized when fielded within hostile computing environments. This paper first captures our understanding of the SDN attack surface through a comprehensive survey of existing SDN attack studies, which we extend by enumerating 12 new vectors for SDN abuse. We then organize these vulnerabilities within the well-known confidentiality, integrity, and availability model, assess the severity of these attacks by replicating them in a physical SDN testbed, and evaluate them against three popular SDN controllers. We also evaluate the impact of these attacks against published SDN defense solutions. Finally, we abstract our findings to offer the research and development communities with a deeper understanding of the common design and implementation pitfalls that are enabling the abuse of SDN networks.
Changhoon Yoon, Seungsoo Lee 0001, Heedo Kang, Taejune Park, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu
IEEE/ACM Trans. Netw.4
2016 QoSE: Quality of security a network security framework with distributed NFV
abstract
An effort to deploy security devices by the network provider has been increasing as the network is being exposed to various types of network attacks. However, network providers are incapable of handling all types of attacks as each security device is designed for a certain purpose. If an attack breaks out, only one particular device becomes busy in terms of resource usage while others being idle. Moreover, it is hard to adjust a level of security service with respect to the importance of network flow. To address these issues, we propose a new security solution, QoSE, which provides adaptive security services based on Network Function Virtualization (NFV). QoSE provides a capability to manage resource usage that the network flow is not concentrated on a specific node. We design QoSE considering a distributed NFV environment to avoid a single point of failure and a bottleneck problem. Our proposed solution has also shown a quick recovery from fault situation. In addition, we provide a novel resource optimization algorithm to operate security services efficiently. We have implemented a prototype system to verify our ideas and have checked that QoSE shows reasonable performance compared with a common device.
Taejune Park, Yeonkeun Kim, Jaehyun Park 0002, Hyunmin Suh, Byeongdo Hong, Seungwon Shin 0001
ICC1
2015 Enabling security functions with SDN: A feasibility study
Changhoon Yoon, Taejune Park, Seungsoo Lee 0001, Heedo Kang, Seungwon Shin 0001, Zonghua Zhang
Comput. Networks2