I Luk Kim

dblp:174/2864 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
2since 2021 · last 2023
0000-0002-6905-5021ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorSystems, architecture and hardware · 1
YearPublicationVenuePosition
2023 BFTDETECTOR: Automatic Detection of Business Flow Tampering for Digital Content Service
abstract
Digital content services provide users with a wide range of content, such as news, articles, or movies, while monetizing their content through various business models and promotional methods. Unfortunately, poorly designed or unpro-tected business logic can be circumvented by malicious users, which is known as business flow tampering. Such flaws can severely harm the businesses of digital content service providers. In this paper, we propose an automated approach that discov-ers business flow tampering flaws. Our technique automatically runs a web service to cover different business flows (e.g., a news website with vs. without a subscription paywall) to collect execution traces. We perform differential analysis on the execution traces to identify divergence points that determine how the business flow begins to differ, and then we test to see if the divergence points can be tampered with. We assess our approach against 352 real-world digital content service providers and discover 315 flaws from 204 websites, including TIME, Fortune, and Forbes. Our evaluation result shows that our technique successfully identifies these flaws with low false-positive and false-negative rates of 0.49% and 1.44%, respectively.
I Luk Kim, Weihang Wang 0001, Yonghwi Kwon 0001, Xiangyu Zhang 0001
ICSE1
2022 Benefits and Limitations of Jupyter-based Scientific Web Applications
abstract
Scientists are increasingly interested in creating standalone web-applications as computational and data analysis tools. The authors have worked with several such research groups to design, develop, and deploy such web applications that are increasingly based on Jupyter notebooks. One of the primary reasons among many to use Jupyter notebooks is the fact that research groups inheriting these applications are capable of maintaining and extending them. In this paper, we walk through the design process for one such application and discuss development environments that are best suited to Jupyter notebook development. We then explore several other applications where we employ similar design patterns. In doing so, we expound upon the benefits, limitations, and challenges of Notebook-based applications to provide a guide for other facilitators in similar situations.
Nicole Brewer, Rajesh Kalyanam, I Luk Kim, Carol X. Song, Lan Zhao 0003
e-Science4
2020 Finding client-side business flow tampering vulnerabilities
abstract
The sheer complexity of web applications leaves open a large attack surface of business logic. Particularly, in some scenarios, developers have to expose a portion of the logic to the client-side in order to coordinate multiple parties (e.g. merchants, client users, and third-party payment services) involved in a business process. However, such client-side code can be tampered with on the fly, leading to business logic perturbations and financial loss. Although developers become familiar with concepts that the client should never be trusted, given the size and the complexity of the client-side code that may be even incorporated from third parties, it is extremely challenging to understand and pinpoint the vulnerability. To this end, we investigate client-side business flow tampering vulnerabilities and develop a dynamic analysis based approach to automatically identifying such vulnerabilities. We evaluate our technique on 200 popular real-world websites. With negligible overhead, we have successfully identified 27 unique vulnerabilities on 23 websites, such as New York Times, HBO, and YouTube, where an adversary can interrupt business logic to bypass paywalls, disable adblocker detection, earn reward points illicitly, etc.
I Luk Kim, Yunhui Zheng, Hogun Park, Weihang Wang 0001, Wei You 0001, Yousra Aafer, Xiangyu Zhang 0001
ICSE1
2019 Adjust: runtime mitigation of resource abusing third-party online ads
abstract
Online advertising is the most critical revenue stream for many Internet companies. However, showing ads on websites comes with a price tag. Since website contents and third-party ads are blended together, third-party ads may compete with the publisher contents, delaying or even breaking the rendering of first-party contents. In addition, dynamically including scripts from ad networks all over the world may introduce buggy scripts that slow down page loads and even freeze the browser. The resulting poor usability problems lead to bad user experience and lower profits. The problems caused by such resource abusing ads are originated from two root causes: First, content publishers have no control over third-party ads. Second, publishers cannot differentiate resource consumed by ads from that consumed by their own contents. To address these challenges, we propose an effective technique, AdJust, that allows publishers to specify constraints on events associated with third-party ads (e.g., URL requests, HTML element creations, and timers), so that they can mitigate user experience degradations and enforce consistent ads experience to all users. We report on a series of experiments over the Alexa top 200 news websites. The results point to the efficacy of our proposed techniques: AdJust effectively mitigated degradations that freeze web browsers (on 36 websites), reduced the load time of publisher contents (on 61 websites), prioritized publisher contents (on 166 websites) and ensured consistent rendering orders among top ads (on 68 websites).
Weihang Wang 0001, I Luk Kim, Yunhui Zheng
ICSE2
2019 MyGeoHub - A sustainable and evolving geospatial science gateway
Rajesh Kalyanam, Lan Zhao 0003, Carol X. Song, Larry L. Biehl, Derrick Kearney, I Luk Kim, Jaewoo Shin 0001, Nelson B. Villoria, Venkatesh Merwade
Future Gener. Comput. Syst.6
2018 AdBudgetKiller: Online Advertising Budget Draining Attack
abstract
In this paper, we present a new ad budget draining attack. By repeatedly pulling ads from targeted advertisers using crafted browsing profiles, we are able to reduce the chance of showing their ads to real-human visitors and trash the ad budget. From the advertiser profiles collected by an automated crawler, we infer advertising strategies, train satisfying browsing profiles and launch large-scale attacks. We evaluate our methods on 291 public advertisers selected from Alexa Top 500, where we successfully reveal the targeting strategies used by 87% of the advertisers we considered. We also executed a series of attacks against a controlled advertiser and 3 real-world advertisers within the ethical and legal boundary. The results show that we are able to fetch 40,958 ads and drain up to $155.89 from the targeted advertisers within an hour.
I Luk Kim, Weihang Wang 0001, Yonghwi Kwon 0001, Yunhui Zheng, Yousra Aafer, Weijie Meng, Xiangyu Zhang 0001
WWW1
2017 PAD: programming third-party web advertisement censorship
abstract
In the current online advertisement delivery, an ad slot on a publisher's website may go through multiple layers of bidding and reselling until the final ad content is delivered. The publishers have little control on the ads being displayed on their web pages. As a result, website visitors may suffer from unwanted ads such as malvertising, intrusive ads, and information disclosure ads. Unfortunately, the visitors often blame the publisher for their unpleasant experience and switch to competitor websites. In this paper, we propose a novel programming support system for ad delivery, called PAD, for publisher programmers, who specify their policies on regulating third-party ads shown on their websites. PAD features an expressive specification language and a novel persistent policy enforcement runtime that can self-install and self-protect throughout the entire ad delegation chain. It also provides an ad-specific memory protection scheme that prevents malvertising by corrupting malicious payloads. Our experiments show that PAD has negligible runtime overhead. It effectively suppresses a set of malvertising cases and unwanted ad behaviors reported in the real world, without affecting normal functionalities and regular ads.
Weihang Wang 0001, Yonghwi Kwon 0001, Yunhui Zheng, Yousra Aafer, I Luk Kim, Wen-Chuan Lee, Yingqi Liu, Weijie Meng, Xiangyu Zhang 0001, Patrick Eugster
ASE5
2017 Self Destructing Exploit Executions via Input Perturbation
Yonghwi Kwon 0001, Brendan Saltaformaggio, I Luk Kim, Kyu Hyung Lee, Xiangyu Zhang 0001, Dongyan Xu
NDSS3
2017 J-Force: Forced Execution on JavaScript
abstract
Web-based malware equipped with stealthy cloaking and obfuscation techniques is becoming more sophisticated nowadays. In this paper, we propose J-FORCE, a crash-free forced JavaScript execution engine to systematically explore possible execution paths and reveal malicious behaviors in such malware. In particular, J-FORCE records branch outcomes and mutates them for further explorations. J-FORCE inspects function parameter values that may reveal malicious intentions and expose suspicious DOM injections. We addressed a number of technical challenges encountered. For instance, we keep track of missing objects and DOM elements, and create them on demand. To verify the efficacy of our techniques, we apply J-FORCE to detect Exploit Kit (EK) attacks and malicious Chrome extensions. We observe that J-FORCE is more effective compared to the existing tools.
Kyungtae Kim, I Luk Kim, Yonghwi Kwon 0001, Yunhui Zheng, Xiangyu Zhang 0001, Dongyan Xu
WWW2
2016 Apex: automatic programming assignment error explanation
abstract
This paper presents Apex, a system that can automatically generate explanations for programming assignment bugs, regarding where the bugs are and how the root causes led to the runtime failures. It works by comparing the passing execution of a correct implementation (provided by the instructor) and the failing execution of the buggy implementation (submitted by the student). The technique overcomes a number of technical challenges caused by syntactic and semantic differences of the two implementations. It collects the symbolic traces of the executions and matches assignment statements in the two execution traces by reasoning about symbolic equivalence. It then matches predicates by aligning the control dependences of the matched assignment statements, avoiding direct matching of path conditions which are usually quite different. Our evaluation shows that Apex is every effective for 205 buggy real world student submissions of 4 programming assignments, and a set of 15 programming assignment type of buggy programs collected from stackoverflow.com, precisely pinpointing the root causes and capturing the causality for 94.5% of them. The evaluation on a standard benchmark set with over 700 student bugs shows similar results. A user study in the classroom shows that Apex has substantially improved student productivity.
Dohyeong Kim, Yonghwi Kwon 0001, Peng Liu 0010, I Luk Kim, David Mitchel Perry, Xiangyu Zhang 0001, Gustavo Rodriguez-Rivera
OOPSLA4
2014 A novel approach to detection of mobile rogue access points
abstract
ABSTRACT Rogue access points (APs) have been used in several attacks such as packet sniffing and man‐in‐the‐middle attacks. It is becoming a serious security threat to users in public and enterprise networks. Moreover, it is easy to install malicious APs using mobile devices and networks, and existing solutions do not effectively detect these rogue APs. In this paper, we propose a method to detect rogue APs over mobile networks using round‐trip time measurements, without relying on information from authorized lists of APs or users. Through experiments, we proved that our proposed method could detect rogue APs successfully. Copyright © 2013 John Wiley & Sons, Ltd.
I Luk Kim, Jung Taek Seo, Taeshik Shon, Jongsub Moon
Secur. Commun. Networks1