Sangho Lee 0001

dblp:17/5702-1 · DBLP profile ↗
← Back
37ranked-venue papers
13as first author
10since 2021 · last 2025
0000-0002-0412-7768ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 25 · 6 first-author · 7 since 2021Systems, architecture and hardware · 5 · 1 first-author · 3 since 2021Computer networks · 3 · 3 first-authorSoftware engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 IOValve: Leakage-Free I/O Sandbox for Large-Scale Untrusted Data Processing
abstract
The widespread adoption of Large Language Models (LLMs) is driving the rapidly growing demand for large-scale computations like training and fine-tuning models. In many areas, the confidentiality of the underlying data is of critical importance to their corporate or government owners. However, securing data in large-scale computations is challenging. First, its demand for enormous hardware resources typically requires outsourcing (e.g., to the public cloud). Second, the large and rapidly evolving software stack used in LLM training in conjunction with a growing incidence of supply chain attacks and software vulnerabilities makes it all but impossible for data owners to establish trust in the code that processes their highly sensitive data. Confidential computing and sandboxing are promising techniques for solving these problems. However, existing sandboxes do not address covert channels which limits their ability to protect confidential data.
Sangho Lee 0001, Jules Drean, Marcus Peinado
CCS1
2025 Subverting the Secure VM by Exploiting PCIe Devices
Cheolwoo Myung, Sangho Lee 0001, Byoungyoung Lee
USENIX Security Symposium2
2023 Hacksaw: Hardware-Centric Kernel Debloating via Device Inventory and Dependency Analysis
abstract
Kernel debloating is a practical mechanism to mitigate the security problems of the operating system kernel by reducing its attack surface. Existing kernel debloating mechanisms focus on specializing a kernel to run a target application based on its dynamic traces collected in the past - they remove functions from the kernel which are not used by the application according to the traces. However, since the dynamic traces do not ensure full coverage, false removals of required functions are unavoidable. This paper proposes Hacksaw, a novel mechanism to debloat a kernel for a target machine based on its hardware device inventory. Hacksaw accurately debloats a kernel without false removals because figuring out which hardware components are attached to the machine as well as which device drivers manage them is comprehensive and deterministic. Hacksaw removes not only inoperative device drivers that do not control any attached hardware components but also other kernel modules and functions which are associated with the inoperative drivers according to three dependency analysis approaches: call-graph, driver-model, and compilation-unit analyses. Our evaluation shows that Hacksaw effectively removes inoperative kernel modules and functions (i.e., their respective reduction ratios are 45% and 30% on average) while ensuring validity and compatibility.
Zhenghao Hu, Sangho Lee 0001, Marcus Peinado
CCS2
2023 APRON: Authenticated and Progressive System Image Renovation
Sangho Lee 0001
USENIX ATC1
2023 Rethinking System Audit Architectures for High Event Coverage and Synchronous Log Availability
Varun Gandhi, Sarbartha Banerjee, Aniket Agrawal, Adil Ahmad, Sangho Lee 0001, Marcus Peinado
USENIX Security Symposium5
2022 Spacelord: Private and Secure Smart Space Sharing
abstract
Space sharing services like vacation rentals are being equipped with smart devices. However, sharing of such devices has privacy and security problems due to no or unclear control transfer between owners and users. In this paper, we propose Spacelord, a system to time-share smart devices contained in a shared space privately and securely while allowing users to configure them. When a user stays at a space, Spacelord ensures that the smart devices contained in it run code and configurations the user trusts while removing pre-installed code and configurations. When the user leaves the space, Spacelord reverts any changes the user has introduced to the smart devices to delete remaining private data and let the owner take back control over the devices. We evaluate Spacelord for two realistic space-sharing cases—smart home and coworking meeting room—and observe reasonable provisioning delay and runtime overhead.
Yechan Bae, Sarbartha Banerjee, Sangho Lee 0001, Marcus Peinado
ACSAC3
2022 DeView: Confining Progressive Web Applications by Debloating Web APIs
abstract
A progressive web application (PWA) becomes an attractive option for building universal applications based on feature-rich web Application Programming Interfaces (APIs). While flexible, such vast APIs inevitably bring a significant increase in an API attack surface, which commonly corresponds to a functionality that is neither needed nor wanted by the application. A promising approach to reduce the API attack surface is software debloating, a technique wherein an unused functionality is programmatically removed from an application. Unfortunately, debloating PWAs is challenging, given the monolithic design and non-deterministic execution of a modern web browser. In this paper, we present DeView, a practical approach that reduces the attack surface of a PWA by blocking unnecessary but accessible web APIs. DeView tackles the challenges of PWA debloating by i) record-and-replay web API profiling that identifies needed web APIs on an app-by-app basis by replaying (recorded) browser interactions and ii) compiler-assisted browser debloating that eliminates the entry functions of corresponding web APIs from the mapping between web API and its entry point in a binary. Our evaluation shows the effectiveness and practicality of DeView. DeView successfully eliminates 91.8% of accessible web APIs while i) maintaining original functionalities and ii) preventing 76.3% of known exploits on average.
ChangSeok Oh, Sangho Lee 0001, Chenxiong Qian, Hyungjoon Koo, Wenke Lee
ACSAC2
2022 HARDLOG: Practical Tamper-Proof System Auditing Using a Novel Audit Device
abstract
Audit systems maintain detailed logs of security-related events on enterprise machines to forensically analyze potential incidents. In principle, these logs should be safely stored in a secure location (e.g., network storage) as soon as they are produced, but this incurs prohibitive slowdown to a monitored machine. Hence, existing audit systems protect batched logs asynchronously (e.g., after tens of seconds), but this allows attackers to tamper with unprotected logs.This paper presents HARDLOG, a practical and effective system that employs a novel audit device to provide fine-grained log protection with minimal performance slowdown. HARDLOG implements criticality-aware log protection: it ensures that logs are synchronously protected in the audit device before an infrequent security-critical event is allowed to execute, but logs are asynchronously protected on frequent non-critical events to minimize performance overhead. Importantly, even on non-critical events, HARDLOG ensures bounded-asynchronous protection: it sends log entries to the audit device within a tiny, bounded delay from their creation using well-known real-time techniques. To demonstrate HARDLOG’S effectiveness, we prototyped an audit device using commodity components and implemented a reference audit system for Linux. Our prototype achieves a bounded protection delay of 15 milliseconds at non-critical events alongside undelayed protection at critical events. We also show that, for diverse real-world programs, HARDLOG incurs a geometric mean performance slowdown of only 6.3%, hence it is suitable for many real-world deployment scenarios.
Adil Ahmad, Sangho Lee 0001, Marcus Peinado
SP2
2022 PRIDWEN: Universally Hardening SGX Programs via Load-Time Synthesis
Fan Sang, Ming-Wei Shih, Sangho Lee 0001, Xiaokuan Zhang, Michael Steiner 0001, Mona Vij, Taesoo Kim
USENIX ATC3
2021 Kard: lightweight data race detection with per-thread memory protection
abstract
Finding data race bugs in multi-threaded programs has proven challenging. A promising direction is to use dynamic detectors that monitor the program’s execution for data races. However, despite extensive work on dynamic data race detection, most proposed systems for commodity hardware incur prohibitive overheads due to expensive compiler instrumentation of memory accesses; hence, they are not efficient enough to be used in all development and testing settings.
Adil Ahmad, Sangho Lee 0001, Pedro Fonseca 0001, Byoungyoung Lee
ASPLOS2
2019 Dominance as a New Trusted Computing Primitive for the Internet of Things
abstract
The Internet of Things (IoT) is rapidly emerging as one of the dominant computing paradigms of this decade. Applications range from in-home entertainment to large-scale industrial deployments such as controlling assembly lines and monitoring traffic. While IoT devices are in many respects similar to traditional computers, user expectations and deployment scenarios as well as cost and hardware constraints are sufficiently different to create new security challenges as well as new opportunities. This is especially true for large-scale IoT deployments in which a central entity deploys and controls a large number of IoT devices with minimal human interaction. Like traditional computers, IoT devices are subject to attack and compromise. Large IoT deployments consisting of many nearly identical devices are especially attractive targets. At the same time, recovery from root compromise by conventional means becomes costly and slow, even more so if the devices are dispersed over a large geographical area. In the worst case, technicians have to travel to all devices and manually recover them. Data center solutions such as the Intelligent Platform Management Interface (IPMI) which rely on separate service processors and network connections are not only not supported by existing IoT hardware, but are unlikely to be in the foreseeable future due to the cost constraints of mainstream IoT devices. This paper presents Cider, a system that can recover IoT devices within a short amount of time, even if attackers have taken root control of every device in a large deployment. The recovery requires minimal manual intervention. After the administrator has identified the compromise and produced an updated firmware image, he/she can instruct Cider to force the devices to reset and to install the patched firmware on the devices. We demonstrate the universality and practicality of Cider by implementing it on three popular IoT platforms (HummingBoard Edge, Raspberry Pi Compute Module 3 and Nucleo-L476RG) spanning the range from high to low end. Our evaluation shows that the performance overhead of Cider is generally negligible.
Meng Xu 0001, Manuel Huber 0001, Zhichuang Sun, Paul England, Marcus Peinado, Sangho Lee 0001, Andrey Marochko, Dennis Mattoon, Rob Spiger, Stefan Thom
IEEE Symposium on Security and Privacy6
2019 libmpk: Software Abstraction for Intel Memory Protection Keys (Intel MPK)
Sangho Lee 0001, Wen Xu 0002, Hyungon Moon, Taesoo Kim
USENIX ATC2
2019 All Your Clicks Belong to Me: Investigating Click Interception on the Web
Mingxue Zhang 0001, Wei Meng 0001, Sangho Lee 0001, Byoungyoung Lee, Xinyu Xing 0001
USENIX Security Symposium3
2018 Enabling Refinable Cross-Host Attack Investigation with Efficient Data Flow Tagging and Tracking
Yang Ji 0002, Sangho Lee 0001, Mattia Fazzini, Joey Allen, Evan Downing, Taesoo Kim, Alessandro Orso, Wenke Lee
USENIX Security Symposium2
2018 QSYM : A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing
Insu Yun, Sangho Lee 0001, Meng Xu 0001, Yeongjin Jang, Taesoo Kim
USENIX Security Symposium2
2017 RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow Tracking
abstract
As modern attacks become more stealthy and persistent, detecting or preventing them at their early stages becomes virtually impossible. Instead, an attack investigation or provenance system aims to continuously monitor and log interesting system events with minimal overhead. Later, if the system observes any anomalous behavior, it analyzes the log to identify who initiated the attack and which resources were affected by the attack and then assess and recover from any damage incurred. However, because of a fundamental tradeoff between log granularity and system performance, existing systems typically record system-call events without detailed program-level activities (e.g., memory operation) required for accurately reconstructing attack causality or demand that every monitored program be instrumented to provide program-level information.
Yang Ji 0002, Sangho Lee 0001, Evan Downing, Weiren Wang, Mattia Fazzini, Taesoo Kim, Alessandro Orso, Wenke Lee
CCS2
2017 T-SGX: Eradicating Controlled-Channel Attacks Against Enclave Programs
Ming-Wei Shih, Sangho Lee 0001, Taesoo Kim, Marcus Peinado
NDSS2
2017 FACT: Functionality-centric Access Control System for IoT Programming Frameworks
abstract
Improvement in the security and availability is important for the success of the Internet of Things (IoT). Given that recent IoT devices are likely to have multiple functionalities and support third-party applications, this goal becomes challenging to achieve. Through an in-depth investigation of existing IoT frameworks, we focused on two inherent security flaws in their design caused by their device-centric approaches: (1) coarse-grained access control and (2) lack of resource isolation. Because of the coarse-grained access control, IoT devices suffer from over-privileged applications. Furthermore, the lack of resource isolation allows the possibility of Denial-of-Service attacks.
Sanghak Lee, Jihun Kim 0002, Beumjin Cho, Sangho Lee 0001, Hanjun Kim 0001, Jong Kim 0001
SACMAT5
2017 CAB-Fuzz: Practical Concolic Testing Techniques for COTS Operating Systems
Su Yong Kim, Sangho Lee 0001, Insu Yun, Wen Xu 0002, Byoungyoung Lee, Youngtae Yun, Taesoo Kim
USENIX ATC2
2017 Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch Shadowing
Sangho Lee 0001, Ming-Wei Shih, Prasun Gera, Taesoo Kim, Hyesoon Kim, Marcus Peinado
USENIX Security Symposium1
2016 Inferring browser activity and status through remote monitoring of storage usage
Hyungsub Kim, Sangho Lee 0001, Jong Kim 0001
ACSAC2
2016 Breaking Kernel Address Space Layout Randomization with Intel TSX
abstract
Kernel hardening has been an important topic since many applications and security mechanisms often consider the kernel as part of their Trusted Computing Base (TCB). Among various hardening techniques, Kernel Address Space Layout Randomization (KASLR) is the most effective and widely adopted defense mechanism that can practically mitigate various memory corruption vulnerabilities, such as buffer overflow and use-after-free. In principle, KASLR is secure as long as no memory leak vulnerability exists and high entropy is ensured.
Yeongjin Jang, Sangho Lee 0001, Taesoo Kim
CCS2
2016 Inference Attack on Browsing History of Twitter Users Using Public Click Analytics and Twitter Metadata
abstract
Twitter is a popular online social network service for sharing short messages (tweets) among friends. Its users frequently use URL shortening services that provide (i) a short alias of a long URL for sharing it via tweets and (ii) public click analytics of shortened URLs. The public click analytics is provided in an aggregated form to preserve the privacy of individual users. In this paper, we propose practical attack techniques inferring who clicks which shortened URLs on Twitter using the combination of public information: Twitter metadata and public click analytics. Unlike the conventional browser history stealing attacks, our attacks only demand publicly available information provided by Twitter and URL shortening services. Evaluation results show that our attack can compromise Twitter users' privacy with high accuracy.
Jonghyuk Song, Sangho Lee 0001, Jong Kim 0001
IEEE Trans. Dependable Secur. Comput.2
2015 CrowdTarget: Target-based Detection of Crowdturfing in Online Social Networks
abstract
Malicious crowdsourcing, also known as crowdturfing, has become an important security problem. However, detecting accounts performing crowdturfing tasks is challenging because human workers manage the crowdturfing accounts such that their characteristics are similar with the characteristics of normal accounts. In this paper, we propose a novel crowdturfing detection method, called CrowdTarget, that aims to detect target objects of crowdturfing tasks (e.g., post, page, and URL) not accounts performing the tasks. We identify that the manipulation patterns of target objects by crowdturfing workers are unique features to distinguish them from normal objects. We apply CrowdTarget to detect collusion-based crowdturfing services to manipulate account popularity on Twitter with artificial retweets. Evaluation results show that CrowdTarget can accurately distinguish tweets receiving crowdturfing retweets from normal tweets. When we fix the false-positive rate at 0.01, the best true-positive rate is up to 0.98.
Jonghyuk Song, Sangho Lee 0001, Jong Kim 0001
CCS2
2015 Identifying Cross-origin Resource Status Using Application Cache
Sangho Lee 0001, Hyungsub Kim, Jong Kim 0001
NDSS1
2014 Exploring and mitigating privacy threats of HTML5 geolocation API
abstract
The HTML5 Geolocation API realizes location-based services via theWeb by granting web sites the geographical location information of user devices. However, the Geolocation API can violate a user's location privacy due to its coarse-grained permission and location models. The API provides either exact location or nothing to web sites even when they only require approximate location. In this paper, we first conduct case studies on numerous web browsers and web sites to explore how they implement and utilize the Geolocation API. We detect 14 vulnerable web browsers and 603 overprivileged web sites that can violate a user's location privacy. To mitigate the privacy threats of the Geolocation API, we propose a novel scheme that (1) supports fine-grained permission and location models, and (2) recommends appropriate privacy settings to each user by inspecting the location sensitivity of each web page. Our scheme can accurately estimate each web page's necessary geolocation degree (estimation accuracy: ~93.5%). We further provide suggestions to improve the Geolocation API.
Hyungsub Kim, Sangho Lee 0001, Jong Kim 0001
ACSAC2
2014 Stealing Webpages Rendered on Your Browser by Exploiting GPU Vulnerabilities
abstract
Graphics processing units (GPUs) are important components of modern computing devices for not only graphics rendering, but also efficient parallel computations. However, their security problems are ignored despite their importance and popularity. In this paper, we first perform an in-depth security analysis on GPUs to detect security vulnerabilities. We observe that contemporary, widely-used GPUs, both NVIDIA's and AMD's, do not initialize newly allocated GPU memory pages which may contain sensitive user data. By exploiting such vulnerabilities, we propose attack methods for revealing a victim program's data kept in GPU memory both during its execution and right after its termination. We further show the high applicability of the proposed attacks by applying them to the Chromium and Firefox web browsers which use GPUs for accelerating webpage rendering. We detect that both browsers leave rendered webpage textures in GPU memory, so that we can infer which web pages a victim user has visited by analyzing the remaining textures. The accuracy of our advanced inference attack that uses both pixel sequence matching and RGB histogram matching is up to 95.4%.
Sangho Lee 0001, Youngsok Kim, Jangwoo Kim, Jong Kim 0001
IEEE Symposium on Security and Privacy1
2014 Early filtering of ephemeral malicious accounts on Twitter
Sangho Lee 0001, Jong Kim 0001
Comput. Commun.1
2013 I know the shortened URLs you clicked on Twitter: inference attack using public click analytics and Twitter metadata
abstract
Twitter is a popular social network service for sharing messages among friends. Because Twitter restricts the length of messages, many Twitter users use URL shortening services, such as bit.ly and goo.gl, to share long URLs with friends. Some URL shortening services also provide click analytics of the shortened URLs, including the number of clicks, countries, platforms, browsers and referrers. To protect visitors' privacy, they do not reveal identifying information about individual visitors. In this paper, we propose a practical attack technique that can infer who clicks what shortened URLs on Twitter. Unlike the conventional browser history stealing attacks, our attack methods only need publicly available information provided by URL shortening services and Twitter. Evaluation results show that our attack technique can compromise Twitter users' privacy with high accuracy.
Jonghyuk Song, Sangho Lee 0001, Jong Kim 0001
WWW2
2013 Fluxing botnet command and control channels with URL shortening services
Sangho Lee 0001, Jong Kim 0001
Comput. Commun.1
2013 WarningBird: A Near Real-Time Detection System for Suspicious URLs in Twitter Stream
abstract
Twitter is prone to malicious tweets containing URLs for spar, phishing, and malware distribution. Conventional Twitter spar detection schemes utilize account features such as the ratio of tweets containing URLs and the account creation date, or relation features in the Twitter graph. These detection schemes are ineffective against feature fabrications or consume much time and resources. Conventional suspicious URL detection schemes utilize several features including lexical features of URLs, URL redirection, HTIUIL content, and dynamic behavior. However, evading techniques such as time-based evasion and crawler evasion exist. in this paper, we propose WARNINGBIRD, a suspicious URL detection system for Twitter. Our system investigates correlations of URL redirect chains extracted from several tweets. Because attackers have limited resources and usually reuse them, their URL redirect chains frequently share the same URLs. We develop methods to discover correlated URL redirect chains using the frequently shared URLs and to determine their suspiciousness. We collect numerous tweets from the Twitter public timeline and build a statistical classifier using them. Evaluation results show that our classifier accurately and efficiently detects suspicious URLs. We also present WARNINGBIRD as a near real-time system for classifying suspicious URLs in the Twitter stream.
Sangho Lee 0001, Jong Kim 0001
IEEE Trans. Dependable Secur. Comput.1
2012 WarningBird: Detecting Suspicious URLs in Twitter Stream
Sangho Lee 0001, Jong Kim 0001
NDSS1
2012 DRMFS: A file system layer for transparent access semantics of DRM-protected contents
Sangho Lee 0001, Hay-Rim Lee, Seungkwang Lee, Jong Kim 0001
J. Syst. Softw.1
2011 A batch rekeying time decision algorithm for IPTV systems
abstract
This paper proposes an algorithm to decide on the batch rekeying time for group key management schemes for Internet protocol television (IPTV) systems. Batch rekeying schemes can reduce the effect of membership changes in group key management schemes by collecting and processing several join and leave events at once. Because membership of IPTV systems frequently changes due to the frequent changes of TV channels viewed by subscribers, batch rekeying schemes are suitable to IPTV systems. Our algorithm considers one more factor; programs broadcasted on IPTV channels can have various values. By computing the expected loss from the value of programs, and the number and time of join and leave events, our algorithm decides on the next rekeying time where the expected loss becomes larger than the predefined loss value given by the service provider.
Sangho Lee 0001, Jong Kim 0001
CCNC1
2011 Spam Filtering in Twitter Using Sender-Receiver Relationship
Jonghyuk Song, Sangho Lee 0001, Jong Kim 0001
RAID2
2010 A secure and mutual-profitable DRM interoperability scheme
abstract
In most cases, the use of digital contents on several devices is blocked by digital rights management (DRM) technology to protect the rights of digital content owners, which is called as the DRM's walled garden strategy. This strategy has raised many legal, economical, and ethical problems. DRM interoperability can complement this strategy. However, there is no agreeable systematic interoperability scheme between various DRM systems. This problem cannot be solved without the cooperation and participation of both DRM technology providers and content providers. Some previous attempts to solve the DRM interoperability problem have suggested that both providers need to open parts of their security properties, without the assurance of a beneficial outcome. They were therefore reticent about participating. In this paper, we propose a secure mutual-profitable DRM interoperability scheme which minimizes disclosure of the security properties of DRM technology providers and content providers while preserving their profits. We use a designated proxy re-encryption scheme to allow the providers to designate a proxy which re-encrypts their digital contents and a neutral format scheme to enable format-independent translations. Moreover, we allow the providers to manage and trace their digital contents, and to request additional fees for interoperability services. We describe detailed protocols and analyze the scheme. We also introduce a prototype implementation.
Sangho Lee 0001, Heejin Park, Jong Kim 0001
ISCC1
2009 Security weakness of Tseng's fault-tolerant conference-key agreement protocol
Sangho Lee 0001, Jong Kim 0001, Sung Je Hong
J. Syst. Softw.1