Myung-Sup Kim

dblp:23/3701 · DBLP profile ↗
← Back
57ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0002-3809-2057ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 48 · 3 first-author · 5 since 2021Security and privacy · 1
YearPublicationVenuePosition
2024 Lightweight Multi-Input Shape CNN-based Application Traffic Classification
abstract
This research focuses on the input shape of CNN-based application traffic. The previously proposed multi-input model CNN classification method classified applications through various shapes of features derived from fixed-length packets, achieving a higher classification accuracy compared to traditional CNNs. However, it had limitations such as vulnerability to overfitting despite its high classification accuracy and slow inference speed. To overcome these challenges, we introduce a lightweight version of the previously proposed MISCNN, called MISCNN+. MISCNN+ demonstrated approximately 2.9 times faster inference speed and a 3.6% improvement in classification accuracy compared to the previous version.
Ui-Jun Baek, Min-Seong Lee, Jee-Tae Park, Chang-Yui Shin, Ju-Sung Kim, Yoon-Seong Jang, Myung-Sup Kim
NOMS8
2023 Preprocessing and Analysis of an Open Dataset in Application Traffic Classification
Ui-Jun Baek, Min-Seong Lee, Jee-Tae Park, Chang-Yui Shin, Myung-Sup Kim
APNOMS6
2023 Lightweight-Heavyweight Hybrid Approach for Application Traffic Classification
Min-Seong Lee, Jee-Tae Park, Ui-Jun Baek, Chang-Yui Shin, Myung-Sup Kim
APNOMS6
2023 Network User Action Detection based on PSD Signature through Encrypted Traffic Analysis
Jee-Tae Park, Ui-Jun Baek, Chang-Yui Shin, Min-Seong Lee, Myung-Sup Kim
APNOMS6
2022 MISCNN: A Novel Learning Scheme for CNN-Based Network Traffic Classification
abstract
By the rapid development of the Internet and online applications, traffic classification has changed to an important topic in the field of network management. Although many studies have been conducted in recent years, designing a robust classification model remains a major challenge. Even though previous researches have focused on changing the layer structure within the deep learning model, they do not consider the input shape that best represents the traffic. To this end, a new traffic classification method is presented in this paper that aims to utilize various input shape that can be derived from fixed-length packet bytes. The proposed method utilized MISCNN (Multi Input Shape Convolution Neural Network) to generate robust traffic classification model that can be used in many domains. Various experiments were carried out to verify superiority of proposed method for the tasks of traffic classification and application identification. According to the obtained results, MISCNN achieved higher score compared to previous researches that utilized only 2D square input shape and 1D linear input shape on the ISCX VPN-nonVPN dataset.
Ui-Jun Baek, Boseon Kim, Jee-Tae Park, Myung-Sup Kim
APNOMS5
2022 Rule-based User Behavior Detection System for SaaS Application
abstract
SaaS is a cloud-based application service that allows users to use applications that work in a cloud environment. SaaS is a subscription type, and the service expenditure varies depending on the license, the number of users, and duration of use. For efficient network management, security and cost management, accurate detection of user behavior for SaaS applications is required. In this paper, we propose a rule-based traffic analysis method for the user behavior detection. We conduct comparative experiments with signature-based method by using the real SaaS application and demonstrate the validity of the proposed method.
Jee-Tae Park, Ui-Jun Baek, Myung-Sup Kim, Min-Seong Lee, Chang-Yui Shin
APNOMS3
2020 Comparison of Distance Measurement in Time Series Clustering for Predicting Bitcoin Prices
abstract
Since the development of Bitcoin, the first blockchain-based cryptocurrency, many cryptocurrencies have formed and have traded in markets. The integrity and anonymity of cryptocurrency was enough to raise its value and its price gained worldwide attention. Therefore, many studies are being carried out to predict the price of cryptocurrency for make a profit. We cluster time series through K-Medoids algorithm and train and evaluate each cluster with predictive models. We also examine the predictive performance in Bitcoin price according to the various distance measurement of clustering.
Ui-Jun Baek, Mu-Gon Shin, Min-Seong Lee, Boseon Kim, Jee-Tae Park, Myung-Sup Kim
APNOMS6
2020 An Automatic Protocol Reverse Engineering Approach from the Viewpoint of the TCP/IP Reference Model
abstract
Protocol reverse engineering represents a very powerful and important tool for network management and security. To cope with the emergence and evolution of rapidly increasing numbers of unknown protocols, automation is of great importance. Many methods for supporting the automation of the various steps for protocol reverse engineering have been investigated; however, there has been no method to automate the analysis of the target network environment. Most methods are designed only for application layer protocols, and all others are designed for specific environments. Given any unknown communication, we must be able to infer the structure of the protocol. However, there has been no research on automatic reverse engineering of protocols when both the protocol and the target network environment are entirely unknown. Here, we propose an automatic protocol reverse engineering approach that is designed to be generally applicable, regardless of the specific network environment. We demonstrate the feasibility of the proposed approach by applying it to several protocols in various layers of the TCP/ IP reference model.
Young-Hoon Goo, Kyu-Seok Shim, Ui-Jun Baek, Jee-Tae Park, Mu-Gon Shin, Myung-Sup Kim
APNOMS6
2019 DDoS Attack Detection on Bitcoin Ecosystem using Deep-Learning
abstract
Since Bitcoin, the first cryptocurrency that applied blockchain technology was developed by Satoshi Nakamoto, the cryptocurrency market has grown rapidly. Along with this growth, many vulnerabilities and attacks are threatening the Bitcoin ecosystem, which is not only at the bitcoin network-level but also at the service level that applied it, according to the survey. We intend to analyze and detect DDoS attacks on the premise that bitcoin's network-level data and service-level DDoS attacks with bitcoin are associated. We evaluate the results of the experiment according to the proposed metrics, resulting in an association between network-level data and service-level DDoS attacks of bitcoin. In conclusion, we suggest the possibility that the proposed method could be applied to other blockchain systems.
Ui-Jun Baek, Se-Hyun Ji, Jee-Tae Park, Min-Seob Lee, Jun-Sang Park, Myung-Sup Kim
APNOMS6
2019 Best Feature Selection using Correlation Analysis for Prediction of Bitcoin Transaction Count
abstract
Cryptocurrency made on the basis of block-chain technology Bitcoin is drawing the attention of individuals, corporations, governments and financial institutions today. As the number of Bitcoin transactions increases over the past years, the scale of the Bitcoin market has been increasing day by day. Predicting the number of transactions contained in a Bitcoin block is important in a Bitcoin network. The aim of this paper is to propose a learning feature selection method for designing a machine learning model that predicts the number of transactions contained in the Bitcoin block by applying the machine learning algorithm. Selecting the appropriate feature to design a machine learning model is crucial things to the performance of the model. We apply correlation analysis to select the appropriate learning feature of the transaction count prediction model in the Bitcoin block and verify the validity of the proposed method through experiments.
Se-Hyun Ji, Ui-Jun Baek, Mu-Gon Shin, Young-Hoon Goo, Jun-Sang Park, Myung-Sup Kim
APNOMS6
2019 A Method for Extracting Static Fields in Private Protocol Using Entropy and Statistical Analysis
abstract
Modern society is turning into the environment in which high-capacity network traffic generated by the development of high-speed internet. As a result, new applications and malicious behaviors are increasing exponentially. Most protocols that occur in these network environments are private protocols. Because private protocols do not have any specifications open, it is very important to analyze the structures of the private protocol for efficient network management and security. Various protocol reverse engineering methodologies have been studied so far, but there is not standardized methodology to extract the protocol's field. Therefore, this paper proposes a methodology for clearly extracting fields of the smallest unit of protocol's structure, and conducts experiments and validates performance on the protocols that are actually being used.
Min-Seob Lee, Young-Hoon Goo, Kyu-Seok Shim, Sung-Ho Yoon, Se-Hyun Ji, Myung-Sup Kim
APNOMS6
2019 Block Analysis in Bitcoin System Using Clustering with Dimension Reduction
abstract
The online cryptocurrency bitcoin, created based in blockchain technology, is attracting the attention of individuals, businesses and the government as well. As interest in blockchain technology and cryptocurrency has steadily increased over the past few years, trading volume and market size of cryptocurrency have increased at an astonishing speed. As a result, analysis and monitoring measures for blockchain networks, blocks, and transactions have become an important issue. In this paper, the method of clustering applied dimension reduction as a method of bitcoin network analysis is proposed. The proposed method applies the analysis way using K-means algorithm with PCA to block data in bitcoin collected by this research team.
Mu-Gon Shin, Ui-Jun Baek, Kyu-Seok Shim, Jee-Tae Park, Sung-Ho Yoon, Myung-Sup Kim
APNOMS6
2018 Framework for precise protocol reverse engineering based on network traces
abstract
Emergence of high-speed Internet and ubiquitous environment is generating massive traffic, and it has led to a rapid increase of applications and malicious behaviors with various functions. Many of the complex and diverse protocols that occur under these situations, are unknown or proprietary protocols that are at least documented. For efficient network management and network security, protocol reverse engineering that extract the specification of the protocols is very important. While various protocol reverse engineering methods have been studied, there is no single standardized method to extract protocol specification completely yet, and each of methods has some limitations. In this paper, we propose the framework for precise protocol reverse engineering based on network traces. The proposed framework can extract highly elaborative and intuitive message formats, flow formats, and protocol state machine of the unknown protocol. We demonstrate the validity of our framework through an example of HTTP protocol.
Young-Hoon Goo, Kyu-Seok Shim, Byeong-Min Chae, Myung-Sup Kim
NOMS4
2018 Network attack traffic detection using seed based sequential grouping model
abstract
Along with the development of high-speed Internet and smart devices, various attack methods were emerged, and attack traffic has also changed into various and complex forms. In order to provide reliable services and efficient management of network resources, it is essential to detect and analyze the attack traffic. While various application and attack traffic detection or classification methods have been studied, but signature-based methods are still mainstream of the most. In this paper, we propose the seed based sequential grouping model for attack traffic detection. Model consists of two main indices, which are similarity and connectivity index. In addition to model, we define the set of optimal thresholds of each index by using our balancing algorithm and define it as Guideline. By applying the proposed model to the actual attack traffic, we demonstrate that the model has high detection accuracy and completeness.
Jee-Tae Park, Sung-Ho Lee, Young-Hoon Goo, Ui-Jun Baek, Myung-Sup Kim
NOMS5
2018 Inference of network unknown protocol structure using CSP(Contiguous Sequence Pattern) algorithm based on tree structure
abstract
As Internet traffic generation grows and new applications and malicious acts continue to emerge, traffic to be analyzed is growing rapidly. Most network security threat traffic is communicated using unknown protocol. Thus, protocol reverse engineering is very important to address network security issues. While various protocol reverse engineering methods have been studied, there is no single standardized method to extract protocol specification completely yet, and each of methods has some limitations. This paper proposes to extract the static fields of the protocol. The method uses CSP algorithm based on Apriori to extract the common strings. However, we propose the method of extraction of a protocol static field using the CSP algorithm based on the tree structure because it is not possible to extract all static fields with only CSP algorithm. This method allows extraction of all static fields that are infrequent but possible, not just frequently occurring. This method has been validated by experiments with HTTP protocol.
Kyu-Seok Shim, Young-Hoon Goo, Min-Seob Lee, Huru Hasanova, Myung-Sup Kim
NOMS5
2018 A Survey of Automatic Protocol Reverse Engineering Approaches, Methods, and Tools on the Inputs and Outputs View
abstract
A network protocol defines rules that control communications between two or more machines on the Internet, whereas Automatic Protocol Reverse Engineering (APRE) defines the way of extracting the structure of a network protocol without accessing its specifications. Enough knowledge on undocumented protocols is essential for security purposes, network policy implementation, and management of network resources. This paper reviews and analyzes a total of 39 approaches, methods, and tools towards Protocol Reverse Engineering (PRE) and classifies them into four divisions, approaches that reverse engineer protocol finite state machines, protocol formats, and both protocol finite state machines and protocol formats to approaches that focus directly on neither reverse engineering protocol formats nor protocol finite state machines. The efficiency of all approaches’ outputs based on their selected inputs is analyzed in general along with appropriate reverse engineering inputs format. Additionally, we present discussion and extended classification in terms of automated to manual approaches, known and novel categories of reverse engineered protocols, and a literature of reverse engineered protocols in relation to the seven layers’ OSI (Open Systems Interconnection) model.
Baraka D. Sija, Young-Hoon Goo, Kyu-Seok Shim, Huru Hasanova, Myung-Sup Kim
Secur. Commun. Networks5
2017 A traffic grouping method using the correlation model of network flow
abstract
Emergence of high-speed Internet and ubiquitous environment has led to a rapid increase of applications on the Internet and network traffic complexity. In order to provide reliable services and efficient management of network resources, it is essential to classify traffic with specific units. While various traffic classification methods are being studied, there is no single method to classify traffic completely yet. In this paper, we define the correlation model of network flow and propose a traffic grouping method based on it. The proposed correlation model of network flow for traffic grouping consists of the Similarity model and the Connectivity model. We define the Similarity model guideline and the Connectivity model guideline for the purpose of applying the proposed method effectively. By applying the proposed method to the actual application traffic classification, we demonstrate that the method has high accuracy and completeness.
Young-Hoon Goo, Sung-Ho Lee, Seongyun Choi, Mi-Jung Choi, Myung-Sup Kim
APNOMS5
2017 Structured whitelist generation in SCADA network using PrefixSpan algorithm
abstract
SCADA system works in repeated or periodic used of only limited communication devices. Because of this feature, whitelist based security techniques are widely used and access restriction method using whitelist based static ACL is most commonly applied in security field. Static ACL have advantages in security, but their expressiveness is too simple to express communication using dynamic allocated port. In addition, it does not reflect all the communication characteristics of the control device, and the generated static ACL should always be open regardless of the frequent use. We propose a structured ACL that extends the fixed generation sequence information between the communication and communication-specific periodicity to reflect the mechanical and repetitive communication characteristics of the SCADA system in the static ACL. We demonstrate the feasibility of the proposed Structured ACL model in this paper by applying the real SCADA network traffic.
Woo-Suk Jung, Jeong-Han Yun, Sin-Kyu Kim, Kyu-Seok Shim, Myung-Sup Kim
APNOMS5
2017 Sky-Scope : Skype application traffic identification system
abstract
Today, as the network environment increases, various types of traffic patterns generated for each application and service are generated, and traffic analysis methods that can classify traffic applications and services are being studied. In particular, Skype is a VoIP service that is serviced by Microsoft and is currently the most widely used internationally. For this reason, the importance of Skype traffic detection is growing in terms of network management. In order to overcome the limitations of signature and machine learning based detection methods and to more accurately analyze and detect the current Skype traffic pattern, this paper presents a comprehensive Skype traffic detection system that combines pattern, list and signature based application detection methods. The proposed system is applied to various Skype traffic collected through campus network to verify accuracy and detection rate.
Sung-Ho Lee, Young-Hoon Goo, Jee-Tae Park, Se-Hyun Ji, Myung-Sup Kim
APNOMS5
2017 Classification of application traffic using tensorflow machine learning
abstract
Applications are becoming more complicated and diverse as the network environment grows day by day. So, it is important to classify application traffic accurately. Although there are many ways to classify applications traffic, machine learning based approaches are becoming more efficient in nowadays. This is because machine learning methods are more appropriate than existing methods for accurate and efficient applications traffic classification. Payload signature methods have limitations to deal with various patterns and increasing application traffic complexity. In this paper, we propose a method for extracting flow features and a system for classifying applications traffic based on Machine Learning.
Jee-Tae Park, Kyu-Seok Shim, Sung-Ho Lee, Myung-Sup Kim
APNOMS4
2017 SigManager: Automatic payload signature management system for the classification of dynamically changing internet applications
abstract
Today's network environment is becoming very complicated. Accordingly, traffic classification for network management becomes difficult. For the study of traffic classification, the development of automatic payload signature generation system was carried out very actively. However, the existing automatic payload signature generation system has problems such as semi-automatic system, disposable signature generation, false-positive signature generation and not up-to-date signature. Therefore, we propose the SigManager. SigManager performs all process such as traffic collection, signature generation, signature management and signature verification. The traffic collection stage automatically collects ground-truth traffic through TMA and TMS. The signature management stage removes unnecessary signatures and the signature generation stage generates the new signatures. Finally, the signature verification stage removes the false-positive signatures. We solved the problem of existing automatic signature generation system through this system. As a result of applying this system to campus network, we could maintain high completeness and low false-positive rate for 4 applications.
Kyu-Seok Shim, Young-Hoon Goo, Sungyun Kim, Mi-Jung Choi, Myung-Sup Kim
APNOMS5
2017 Survey on network protocol reverse engineering approaches, methods and tools
abstract
A network protocol defines rules that control communications between two or more hosts on the Internet, whereas Protocol Reverse Engineering (PRE) defines the process of extracting the structure, attributes and data from a network protocol. Enough knowledge on protocol specifications is essential for security purposes, network policy implementation and management of network resources. Protocol Reverse Engineering is a complex process intended to uncover specifications of unknown protocols. The complexity of PRE, in terms of time consumption, tediousness and error-prone, has led to short and diverse outcomes of Protocols Reverse Engineering approaches. This paper, surveys outputs of 9 PRE approaches in three divisions with methodology analysis and its possible applications. Moreover, in the introductory part we provide a general PRE literature in great depth.
Baraka D. Sija, Young-Hoon Goo, Kyu-Seok Shim, Sungyun Kim, Mi-Jung Choi, Myung-Sup Kim
APNOMS6
2016 Payload signature structure for accurate application traffic classification
abstract
Emergence of high-speed Internet and various smart devices has led to a rapid increase of applications on the Internet. In order to provide reliable services and efficient management of network resources, accurate traffic classification of various applications is essential. Through various methods of extraction when payload signatures are extracted, most of these payload signature formats are just strings or hex values which appear frequently within payloads. Thus, it is difficult to extract unique signatures for a specific application, because redundant signatures extraction is in most cases unavoidable. In this paper, we propose a more elaborative payload signature structure for accurate classification of each specific application. The formats of this signature structure is composed of three level signatures. These are Content signature which is single contiguous substring in payloads, Packet signature which is the sequence of Content signatures that appear in the same packet, and the Flow signature which is a sequence of Packet signatures that appear in the same flow. By applying and comparing the existing signature format and proposed signature format to the actual application traffic classification, we demonstrate the effectiveness of the proposed signature structure.
Young-Hoon Goo, Kyu-Seok Shim, Su-Kang Lee, Myung-Sup Kim
APNOMS4
2016 Whitelist representation for FTP service in SCADA system by using structured ACL model
abstract
Due to recent integration of SCADA systems with business systems, SCADA systems became open(unprotected), leading to not only security vulnerabilities increase but also sophisticated and intelligent cyber-attacks specifically targeting SCADA systems. A whitelist based security control technique that has attracted a lot of attention, is an emerging systems control, currently can be applied to solve security problems of the SCADA system. Most of the current security techniques for systems control based on whitelist, use static ACL model. But the static ACL model has limitations in use of ANY-ANY rule which is the only way to express communications using dynamic server port and express ranges of communication features in a control device. In this paper, we propose an structured ACL model to represent an FTP service to overcome the problem of dynamice server port in passive FTP. We demonstrate the feasibility of the proposed model in this paper by applying the FTP features extraction algorithm to FTP traffic.
Woo-Suk Jung, Sung-Min Kim, Young-Hoon Goo, Myung-Sup Kim
APNOMS4
2016 Finding the highly efficient application signature through payload signature quality evaluation
abstract
Internet traffic identification is an essential preliminary step for stable service provision and efficient network management. The payload signature-based-classification is considered as a reliable method for Internet traffic identification. But its performance is highly dependent on the number and the structure of signatures. If the numbers and structural complexity of signatures are not proper, the performance of payload signature-based-classification easily deteriorates. Therefore, in order to improve the performance of the identification system, it is necessary to regulate the numbers of the signature. In this paper, we propose a novel signature quality evaluation method to decide which signature is highly efficient for Internet traffic identification. We newly define the signature quality evaluation criteria and find the highly efficient signature through the method. Quality evaluation is performed in three different perspectives and the weight of each signature is computed through those perspectives values. And we construct the signature map(S-MAP) to find the highly efficient signature. The proposed method achieved an approximately fourfold increased efficiency in application traffic identification.
Sung-Ho Lee, Young-Hoon Goo, Baraka D. Sija, Myung-Sup Kim
APNOMS4
2015 Efficient payload signature structure for performance improvement of traffic identification
abstract
The traffic identification is a preliminary and essential step for stable network service provision and efficient network resource management. While a number of identification methods have been introduced in literature, the payload signature-based identification method shows the highest performance in terms of accuracy, completeness, and practicality. However, the payload signature-based method's processing speed is much slower than other identification method such as header-based and statistical methods. In this paper, we first classifies signatures by matching type based on range, order, and direction of packet in a flow when each signature matches to payload. By using this classification, we suggest a novel method to improve processing speed of payload signature-based identification by reducing searching space.
Woo-Suk Jung, Jun-Sang Park, Myung-Sup Kim, Jae-Hyun Ham
APNOMS3
2015 A method for service identification of SSL/TLS encrypted traffic with the relation of session ID and Server IP
abstract
The SSL/TLS, one of the most popular encryption protocol, was developed as a solution of various network security problem while the network traffic has become complex and diverse. But the SSL/TLS traffic has been identified as its protocol name, not its used services, which is required for the effective network traffic management. This paper proposes a new method to generate service signatures automatically from SSL/TLS payload data and to classify network traffic in accordance with their application services. We utilize the certificate publication information field in the certificate exchanging record of SSL/TLS traffic for the service signatures, which occurs when SSL/TLS performs Handshaking before encrypt transmission. We proved the performance and feasibility of the proposed method by experimental result that classify about 95% SSL/TLS traffic with about 90% accuracy for every SSL/TLS services.
Sung-Min Kim, Young-Hoon Goo, Myung-Sup Kim, Soo-Gil Choi, Mi-Jung Choi
APNOMS3
2015 Network and system management object modeling for smart grid infrastructure
abstract
Smart grid is an electricity network to monitor and control all its physical environments of electricity infrastructure in a fully automated way. As the importance of reliable energy utility infrastructure is growing, various security countermeasures to protect power system from security threats have been suggested, whereas there were less consideration on security by design, from the bottom system modeling level. Thus, this paper first highlights the international security standard on network and system management (NSM) requirements suggested from International Electronical Committee (IEC). Then this paper proposes significance of security by design, especially the security object modeling as the most important factor in smart grid environment. In our approach, we propose a common NSM objects for IEC-61850 protocol based substation automation environment. Finally, we present the setup procedures to implement and test NSM objects for IEC 61850-based digital substation in Korean environment.
YooJin Kwon, Myung-Sup Kim, Yong Hun Lim, Jongin Lim 0001
APNOMS2
2015 High performance payload signature-based Internet traffic classification system
abstract
Internet traffic classification is an essential step for stable service provision and efficient network management. The payload signature-based-classifier is considered as a reliable method for Internet traffic classification, but is prohibitively and computationally expensive for real-time handling of large amounts of traffic on high-speed network. To solve this problem, most studies focused on the pattern matching algorithm or hardware-based approaches such as FPGA and network processor. However, in order to improve the performance of the classification system, It is also necessary to consider the classification criteria and signature model in accordance with the characteristics of various application protocols. In this paper, we newly define the classification criteria and signature model, and propose an optimized classification architecture in perspective of input data minimization and complexity of pattern matching algorithm to improve the processing speed of classification system. Each of them can be applied individually, or in any combination. The proposed method achieved an approximately 5-fold increase in processing speed over existing baseline classification system.
Sung-Ho Lee, Jun-Sang Park, Sung-Ho Yoon, Myung-Sup Kim
APNOMS4
2015 Research on automatic header-signature naming system for Internet service identification
abstract
With the rapid growth of the Internet speed and emergence of new applications, the amount of Internet traffic is continuously increasing. In order to provide stable Internet service, efficient network management based on accurate traffic identification is gaining much importance than ever. Header signature-based identification method for network management can be identified the network traffic quickly more than other methods. In this paper, we propose an automatic header-signature naming system and identification system using the named header-signature. The proposed system provides efficient management of header-signature of each service as well. To prove the feasibility of the proposed systems, we applied the system to the campus network environment. In experimental result, we could find the URI information of actual content providers, which cannot find through IP search such as “whois” or command such as “nslookup”. In addition, we can get the characteristics of a network in a short period of time by applying the proposed system.
Su-Kang Lee, Sung-Ho Yoon, Myung-Sup Kim
APNOMS3
2015 Signature management system to cope with traffic changes in application and service
abstract
Today, the number of applications using network service has been increasing. Also, many applications have changed their traffic pattern frequently due to various reasons. Nevertheless, network managers tend to stay with old signatures. But they should update with new signatures to detect the modified application traffic. The extraction of signature is work to demand a lot of time. And it is difficult to continuously and timely extract the new signature for all applications. In this paper, we propose a noble signature management system which automatically extract new signatures detecting the modified traffic and delete old signatures no longer used. The proposed system analyzes traffic with existing signatures and extracts new signature automatically for updated traffic. For automatic generation of new signatures, we uses a sequence pattern algorithm. Also, the proposed system analyze usage of the old signatures to remove them when they are not used any more. We proved the feasibility and applicability of the proposed system by showing that that detection rate of all application was increased.
Kyu-Seok Shim, Sung-Ho Yoon, Mi-Jung Choi, Myung-Sup Kim
APNOMS4
2015 Framework for multi-level application traffic identification
abstract
With the acceleration of the Internet speed and the vigorous emergence of new applications, the amount of Internet traffic has increased. In order to provide stable Internet service, efficient network management based on accurate traffic identification is critical. Although various methods for traffic identification have been proposed, not a single method identifies all types of Internet traffic. In this paper, we propose a framework for multi-level application traffic identification by combining several single methods.
Sung-Ho Yoon, Kyu-Seok Shim, Su-Kang Lee, Myung-Sup Kim
APNOMS4
2014 Packet out-of-order and retransmission in statistics-based traffic analysis
abstract
With the rapid growth of the Internet, the importance of application traffic analysis increases for efficient network management. The statistical information in traffic flows, can be efficiently utilized for application traffic identification. However, the packet out-of-order and retransmission generated at the traffic collection point reduce the performance of the statistics-based traffic analysis. In this paper, we propose a novel method to detect and resolve the packet out-of-order and retransmission problem in order to improve completeness and accuracy of the traffic identification. To prove the feasibility of the proposed method, we applied our method to a real traffic analysis system using statistical flow information, and compared the performance of the system with the selected 9 popular applications. The experiment showed maximum 4.9% of completeness growth in traffic bytes, which shows that the proposed method contributes to the analysis of heavy flow.
Su-Kang Lee, Hyun-Min Ahn, Myung-Sup Kim
APNOMS3
2014 Application traffic classification in Hadoop distributed computing environment
abstract
Today, network traffic has increased because of the appearance of various applications and services. However, methods for network traffic analysis are not developed to catch up the trend of increasing usage of the network. Most methods for network traffic analysis are operated on a single server environment, which results in the limits about memory, processing speed, storage capacity. When considering the increment of network traffic, we need a method of network traffic to handle the Bigdata traffic. Hadoop system can be effectively used for analyzing Bigdata traffic. In this paper, we propose a method of application traffic classification in Hadoop distributed computing system and compare the processing time of the proposed system with a single server system to show the advantages of Hadoop.
Kyu-Seok Shim, Su-Kang Lee, Myung-Sup Kim
APNOMS3
2013 Application traffic classification using statistic signature
Hyun-Min An, Myung-Sup Kim, Jae-Hyun Ham
APNOMS2
2013 Improved processing speed of traffic classification based on payload signature hierarchy
Ji-Hyeok Choi, Myung-Sup Kim
APNOMS2
2013 Performance improvement of payload signature-based traffic classification system using application traffic temporal locality
Jun-Sang Park, Sung-Ho Yoon, Myung-Sup Kim
APNOMS3
2013 An efficient method to maintain the header signatures for internet traffic identification
Sung-Ho Yoon, Myung-Sup Kim
APNOMS2
2012 Towards smart phone traffic classification
abstract
The appearance of smart phones and their continuing rapid uptake has large affects on our society in as much as they represent a paradigm shift in the traditional industrial structure. The Telecom market is changing day by day, networks with the complicated and varied traffic have almost reached capacity because of the rapid increase of user and the service releases on smart phones. Therefore, the necessity for smart phone traffic monitoring and analysis has increased. Traffic analysis is an essential element for efficient and reliable networks. In this paper, we propose a new smart phone traffic classification by application method. The proposed method is composed of several consecutive steps: grouping the HTTP User-Agent field, extracting common strings by the LCS algorithm and finally classifying the traffic. In addition, to classify unknown traffic from previous methods, we propose a process that extracts header signatures in grouped information to improve the classification completeness. We achieved about a 90% accuracy rate for the analysis by our proposed method in the target campus network.
Min Hur, Myung-Sup Kim
APNOMS2
2012 Study on traffic classification taxonomy for multilateral and hierarchical traffic classification
abstract
Internet traffic has rapidly increased due to the increasing use of wireless devices and the appearance of various applications and services. With the rapid increase of Internet traffic, the need for Internet traffic classification becomes important for the effective use of network resources. However, the traffic classification taxonomy has received little attention compared to the study of classification methods. In this paper, we propose novel traffic classification taxonomy for multilateral and hierarchical traffic identification. The proposed taxonomy can support multilateral identification based on the proposed four classification criteria: service, application, protocol, and function. In addition, the proposed taxonomy can support hierarchical structure supporting roll-up and drill-down operation to the classification result. We proved the applicability and advantages of the proposed taxonomy by applying it to real campus network traffic.
Ji-hye Kim, Sung-Ho Yoon, Myung-Sup Kim
APNOMS3
2012 Signature maintenance for Internet application traffic identification using header signatures
abstract
Application traffic identification is important for the effective management of network resources. The header-based identification method uses the header signatures: the 3-tuple {IP address, port number, transport layer protocol (TCP/UDP)} of packet header which representing a dedicated or temporal Internet application server to overcome the limitations of other methods, such as processing overhead, payload encryption, etc. The main problem of header-based identification method is the extremely large number of signatures. Thus, we need a maintenance method to keep essential and active signatures. In this paper, we represent a novel signature maintenance method using the properties of identified traffic and usage history of signatures. We prove the feasibility and applicability of our proposed method by an acceptable experimental result.
Sung-Ho Yoon, Jun-Sang Park, Myung-Sup Kim
NOMS3
2011 A study identifying the connection type of an end-host to the network using Round-Trip-Time
abstract
Use of a smart device has become popular. The number of smart devices has increased and the amount of wireless traffic has grown rapidly in a PC-centric business environment. Traffic bandwidth and IP band management of wireless in the enterprise network are crucial. The information that identifies the connection type of a terminal host in the network design is a big adv continuous management to identify a terminal host enables the network to be efficient. The change of connection type can identify the use of the NAT host. In this paper, we propose a methodology to identify the connection type of a terminal host using RTT (Round-Trip-Time). We prove the feasibility of our proposed method in a target campus network.
Min Hur, Hyun-Shin Lee, Myung-Sup Kim
APNOMS3
2011 Research on traffic taxonomy for Internet traffic classification
abstract
Various traffic analysis methods are suggested to use and handle the limited internet resource efficiently due to the rapid increase in the amount of Internet traffic. However, the analysis results cannot be used effectively, as there is no established system and standard for classification. This paper suggests taxonomy to utilize traffic analysis effectively. We define classification taxonomy of common network equipment and suggest multi-dimensional classification taxonomy.
Ji-hye Kim, Sung-Ho Yoon, Myung-Sup Kim
APNOMS3
2011 A study on Smart-phone traffic analysis
abstract
The increase in Smart-phone users and expansion of market value creates traffic complexity and causes network saturation. Network technology lags development compared to the growth of traditional internet applications and Smart-phone based applications. Thus, the need for interest in network traffic monitoring increase. Traffic monitoring becomes an important element in the management of stable, efficient network. This paper analyzes various results of Smart-phone traffic in the campus network. It compares the characteristics and differences among traditional internet traffic and Smart-phone traffic.
Jun-Sang Park, Hyun-Shin Lee, Myung-Sup Kim
APNOMS4
2011 Towards management of machine to machine networks
abstract
Machine to Machine (M2M) technology has the potential to increase the revenue, decrease the costs and improve the customer services of an organization. We have analyzed the management requirements of M2M systems, which are based on existing M2M network use cases and services. The most important characteristics including sleeping devices, low power lossy area networks, heterogeneous networks, device intelligence, mobility, two way communication, network dynamics, time sensitivity of data and data volume of M2M systems have been comprehensively investigated and reflected in management requirements discussed in this paper. The main management functionalities are fault, configuration, mobility, QoS and security management.
Suman Pandey, Mi-Jung Choi, Myung-Sup Kim, James Won-Ki Hong
APNOMS3
2009 Internet Application Traffic Classification Using Fixed IP-Port
Sung-Ho Yoon, Jin-Wan Park, Jun-Sang Park, Young-Seok Oh, Myung-Sup Kim
APNOMS5
2008 Design and Implementation of an SNMP-Based Traffic Flooding Attack Detection System
Jun-Sang Park, Myung-Sup Kim
APNOMS2
2008 Empirical Analysis of Application-Level Traffic Classification Using Supervised Machine Learning
Byungchul Park, Young J. Won, Mi-Jung Choi, Myung-Sup Kim, James Won-Ki Hong
APNOMS4
2008 Towards automated application signature generation for traffic identification
abstract
Traditionally, Internet applications have been identified by using predefined well-known ports with questionable accuracy. An alternative approach, application-layer signature mapping, involves the exhaustive search of reliable signatures but with more promising accuracy. With a prior protocol knowledge, the signature generation can guarantee a high accuracy. As more applications use proprietary protocols, it becomes increasingly difficult to obtain an accurate signature while avoiding time-consuming and manual signature generation process. This paper proposes an automated approach for generating application-level signature, the LASER algorithm, that does not need to be preceded by an analysis of application protocols. We show that our approach is as accurate and efficient as the approach that uses preceding application protocol analysis.
Byung-Chul Park, Young J. Won, Myung-Sup Kim, James Won-Ki Hong
NOMS3
2008 Traffic flooding attack detection with SNMP MIB using SVM
Jaehak Yu, Hansung Lee, Myung-Sup Kim, Daihee Park
Comput. Commun.3
2007 Autonomic Network Resource Management Using Virtual Network Concept
Myung-Sup Kim, Alberto Leon-Garcia
APNOMS1
2007 Measurement Analysis of IP-Based Process Control Networks
Young J. Won, Mi-Jung Choi, Myung-Sup Kim, Hong-Sun Noh, Jun Hyub Lee, Hwa Won Hwang, James Won-Ki Hong
APNOMS3
2006 A generic architecture for autonomic service and network management
Yu Cheng 0003, Ramy Farha, Myung-Sup Kim, Alberto Leon-Garcia, James Won-Ki Hong
Comput. Commun.3
2006 Characteristic analysis of internet traffic from the perspective of flows
Myung-Sup Kim, Young J. Won, James Won-Ki Hong
Comput. Commun.1
2005 Virtual network based autonomic network resource control and management system
abstract
Traditional telecommunications service providers are undergoing a transition to a shared infrastructure in which multiple services will be delivered by peer and server computers interconnected by IP networks. IP transport networks that can transfer packets according to differentiated levels of QoS, availability and price are a key element to generating revenue through a rich offering of services. Automated service and network management are essential to creating and maintaining a flexible and agile service delivery infrastructure that also has much lower operations expense than existing systems. In this paper we focus on the SLA-based IP packet transport service on a core network infrastructure and we argue that the above requirements can be met by a self-management system based on autonomic computing and virtual network concepts. We present a control and management system based on this approach.
Myung-Sup Kim, Ali Tizghadam, Alberto Leon-Garcia, James Won-Ki Hong
GLOBECOM1
2004 A flow-based method for abnormal network traffic detection
abstract
One recent trend in network security attacks is an increasing number of indirect attacks which influence network traffic negatively, instead of directly entering a system and damaging it. In future, damages from this type of attack are expected to become more serious. In addition, the bandwidth consumption by these attacks influences the entire network performance. This paper presents an abnormal network traffic detecting method and a system prototype. By aggregating packets that belong to the identical flow, we can reduce processing overhead in the system. We suggest a detecting algorithm using changes in traffic patterns that appear during attacks. This algorithm can detect even mutant attacks that use a new port number or changed payload, while signature-based systems are not capable of detecting these types of attacks. Furthermore, the proposed algorithm can identify attacks that cannot be detected by examining only single packet information.
Myung-Sup Kim, Hun-Jeong Kang, Seong-Cheol Hong, Seung-Hwa Chung, James Won-Ki Hong
NOMS (1)1
2002 Highly available and efficient load cluster management system using SNMP and Web
abstract
To cope with the explosive increase in the number of requests to Internet server systems, one popular solution is a load-balancing technique that uses a dispatcher in the front-end of a cluster farm. A cluster group is viewed as a single system image with very high performance and also gives a good scalability. But a failure in any single host in a cluster group can cause an overall system failure. The high availability in a cluster group is desperately needed for stable and fault-tolerant service to clients. So it is necessary to develop a cluster management system that integrates all these cluster functions and user-friendly management functions. We present the design and implementation of a load cluster management system (LCMS) based on SNMP and Web technology. Our LCMS implementation has been deployed on a commercial ultra dense server like an EnterFLEX. First we examine the requirements of LCMS to provide efficient and stable management operations and high availability. Our LCMS follows the client-server management paradigm of SNMP, and consists of three managers having different roles, which distribute management functionality to all hosts in a cluster group. By using SNMP we can reduce the network bandwidth required in management operations. This system also provides automatic cluster configuration and current status monitoring of each host in a cluster group through a Java and Web technologies.
Myung-Sup Kim, Mi-Jeong Choi, James Won-Ki Hong
NOMS1