Ikkyun Kim

dblp:23/6710 · also Ik-Kyun Kim · DBLP profile ↗
← Back
17ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0001-8915-3270ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-author · 4 since 2021Systems, architecture and hardware · 4Security and privacy · 4Applied, interdisciplinary, general and emerging computing · 2
YearPublicationVenuePosition
2025 Base Station Certificate and Authentication for 5G Radio Control Security
abstract
Current cellular networking remains vulnerable to fake base stations due to the lack of base station authentication mechanism or even a key to enable authentication. We design and build a base station certificate (certifying the base station’s public key and location) and a multi-factor authentication (making use of the certificate and the information transmitted in the online radio control communications) to provide authenticity of the source base station and its radio resource control communications. We advance beyond the state-of-the-art research by introducing greater authentication factors and by using blockchain to deliver the base station digital certificate offline, enabling greater key length/security strength and computational/networking efficiency. The multi-factor authentication at the user equipment involves multiple factors verified through the ledger database, the location sensing, and the cryptographic digital signature verification of the cellular radio control communication (SIB1 broadcasting). We analyze our scheme’s security, performance, and the fit to the existing standardized networking protocols. Our work involves the implementation building on X.509 certificate (adapted), smart contract-based blockchain, 5G-standardized radio resource control communications, and software-defined radios. Our analyses show that our scheme effectively defends against more security threats and can enable stronger security, i.e., ECDSA with greater key lengths. Furthermore, our scheme achieves over threefold improvement in computing and energy efficiency on the mobile user equipment compared to previous research.
Sourav Purification, Simeon Wuthier, Jinoh Kim, Ikkyun Kim, Sang-Yoon Chang
MASS4
2023 Practical Covert Wireless Unidirectional Communication in IEEE 802.11 Environment
abstract
Covert communications, or covert channels, are commonly exploited to establish a data exfiltration channel from an insider on a trusted network to a malicious receiver outside the network without using normal communication of the network. It is because the malicious receiver is an unauthorized user of the communication network and so he cannot communicate with any entity in the network. In this study, we construct a new covert wireless unidirectional communication mechanism in an IEEE 802.11 environment. Our covert communication is based on a covert timing channel exploiting the beacon interval of a given commercial-like AP. Because the wireless covert channel we proposed can be implemented only with firmware modification to the WLAN MAC protocol, it is very suitable for application in a real public AP environment. In order to dramatically reduce the chance of covert signals being detected by others, a new and simple covert data encoding scheme, called ping-pong covert timing channel (PPCTC), is proposed, and we show that the covertness of the PPCTC is excellent compared to the previous timing-based covert channels. Although this wireless covert communication is unidirectional communication, since PPCTC has recovery characteristics against consecutive 2-bit errors, stable communication is guaranteed. Furthermore, a covert frame structure is presented for providing the confidentiality and integrity of the information transmitted via our covert channel. To the best of our knowledge, this is the first attempt.
Hayoung Seong, Ikkyun Kim, Yongsung Jeon, Mi-Kyung Oh, Sangjae Lee, Dooho Choi
IEEE Internet Things J.2
2022 A Machine Learning Approach to Anomaly Detection Based on Traffic Monitoring for Secure Blockchain Networking
abstract
While blockchain technology provides strong cryptographic protection on the ledger and the system operations, the underlying blockchain networking remains vulnerable due to potential threats such as denial of service (DoS), Eclipse, spoofing, and Sybil attacks. Effectively detecting such malicious events should thus be an essential task for securing blockchain networks and services. Due to its importance, several studies investigated anomaly detection in Bitcoin and blockchain networks, but their analyses mainly focused on the blockchain ledger in the application context (e.g., transactions) and targets specific types of attacks (e.g., double-spending, deanonymization, etc). In this study, we present a security mechanism based on the analysis of blockchain network traffic statistics (rather than ledger data) to detect malicious events, through the functions of data collection and anomaly detection. The data collection engine senses the underlying blockchain traffic and generates multi-dimensional data streams in a periodic, real-time manner. The anomaly detection engine then detects anomalies from the created data instances based on semi-supervised learning, which is capable of detecting previously unseen patterns, and we introduce our profiling-based detection engine implemented on top of AutoEncoder (AE). Our experimental results evaluated with real and simulated traffic data support the effectiveness of our security mechanism and design choices based on the AE structure, with the approximate detection performance to the supervised learning methods only through the profiling of normal instances. The measured time complexity is sufficiently cheap to perform real-time analysis, with less than 1.4 msec for per-instance testing on a single core setting.
Jinoh Kim, Makiya Nakashima, Wenjun Fan, Simeon Wuthier, Xiaobo Zhou 0002, Ikkyun Kim, Sang-Yoon Chang
IEEE Trans. Netw. Serv. Manag.6
2021 A Machine Learning Approach to Peer Connectivity Estimation for Reliable Blockchain Networking
abstract
Peer connectivity plays a significant role in a blockchain network since any poor connectivity may result in the nodes operating on outdated data (e.g., cryptocurrency transactions). Although connectivity information is maintained by individual nodes, such identifier-based information might be unreliable due to the possibility of bogus identifiers. This paper tackles the problem of peer connectivity estimation through data-driven analytics of blockchain traffic for reliable blockchain networking. We define a set of variables to represent traffic characteristics and estimate peer connectivity from the collected data using a machine learning methodology. We also investigate the feasibility of feature prioritization to minimize estimation complexities. Our experimental results show that the presented estimation mechanism makes accurate predictions, with less than 0.1 difference between the measurement and estimation for over 99.7% of predictions. The time complexity measured on a commodity machine shows a microsecond scale for completing a single prediction task, enabling real-time operations.
Jinoh Kim, Makiya Nakashima, Wenjun Fan, Simeon Wuthier, Xiaobo Zhou 0002, Ikkyun Kim, Sang-Yoon Chang
LCN6
2019 A semantic approach to improving machine readability of a large-scale attack graph
Jooyoung Lee 0005, Daesung Moon, Ikkyun Kim, Youngseok Lee 0002
J. Supercomput.3
2017 Unsupervised Labeling for Supervised Anomaly Detection in Enterprise and Cloud Networks
abstract
Identifying anomalous events in the network is one of the vital functions in enterprises, ISPs, and datacenters to protect the internal resources. With its importance, there has been a substantial body of work for network anomaly detection using supervised and unsupervised machine learning techniques with their own strengths and weaknesses. In this work, we take advantage of the both worlds of unsupervised and supervised learning methods. The basic process model we present in this paper includes (i) clustering the training data set to create referential labels, (ii) building a supervised learning model with the automatically produced labels, and (iii) testing individual data points in question using the established learning model. By doing so, it is possible to construct a supervised learning model without the provision of the associated labels, which are often not available in practice. To attain this process, we set up a new property defining anomalies in the context of clustering, based on our observations from anomalous events in network, by which the referential labels can be obtained. Through our extensive experiments with a public data set (NSL-KDD), we will show that the presented method perform very well, yielding fairly comparable performance to the traditional method running with the original labels provided in the data set, with respect to the accuracy for anomaly detection.
Sunhee Baek, Donghwoon Kwon, Jinoh Kim, Sang C. Suh, Hyunjoo Kim, Ikkyun Kim
CSCloud6
2017 DTB-IDS: an intrusion detection system based on decision tree using behavior analysis for preventing APT attacks
Daesung Moon, Hyungjin Im, Ikkyun Kim, Jong Hyuk Park 0001
J. Supercomput.3
2016 Host-based intrusion detection system for secure human-centric computing
Daesung Moon, Sung Bum Pan, Ikkyun Kim
J. Supercomput.3
2014 An enhanced integrity of web contents through mobile cloud environments
Ikkyun Kim, Jong Hyuk Park 0001
J. Supercomput.2
2012 Endpoint Mitigation of DDoS Attacks Based on Dynamic Thresholding
Byoung-Koo Kim, Ikkyun Kim, Jeong-Nyeo Kim, Hyunsook Cho
ICICS3
2012 Network-based Executable File Extraction and Analysis for Malware Detection
Byoung-Koo Kim, Ikkyun Kim, Tai-Myung Chung
SECRYPT2
2012 Defense Against TCP Flooding Attack
Seungyong Yoon, Jintae Oh, Ikkyun Kim, Jongsoo Jang
SECRYPT3
2009 Baseline Traffic Modeling for Anomalous Traffic Detection on Network Transit Points
Yoohee Cho, Koohong Kang, Ikkyun Kim, Kitae Jeong
APNOMS3
2009 Lightweight Static Analysis to Detect Polymorphic Exploit Code with Static Analysis Resistant Technique
abstract
The general method in which attackers obtain the control authority of the remote host is through the exploit code. As network security systems have mounted the desired signatures about exploits, they have reduced damage due to the spreading and reoccurrence of the exploits. However, to avoid signature-based detection techniques, exploits employing techniques such as polymorphism and metamorphism have become more prevalent. Especially in the case of polymorphism, because there are many automation engines even if there is no special knowledge in order to make various exploits easily, the polymorphism researches need to be more actively studied. We present a new static analysis method for detecting the decryption routine of polymorphic exploit code. Most of decryption routines store the program counter value of remote host on a stack and use the value as the address for accessing the memory that the encrypted original code is positioned. The proposed method traces the processing steps of decryption routine as using the static analysis method. In the results of experiment, the proposed method can detect polymorphic exploit codes that the static analysis resistant techniques are used, and shows more efficient than the emulation-based method in the processing performance.
Ikkyun Kim, Jintae Oh, Hyunsook Cho
ICC2
2007 A Practical Approach for Detecting Executable Codes in Network Traffic
Ikkyun Kim, Koohong Kang, Yangseo Choi, Jintae Oh, Ki Jun Han
APNOMS1
2004 Implementation and Performance Evaluation of High-Performance Intrusion Detection and Response System
Hyeong-Ju Kim, Byoung-Koo Kim, Ikkyun Kim
ICCSA (1)3
2004 Design and Implementation of High-Performance Intrusion Detection System
Byoung-Koo Kim, Ikkyun Kim, Ki-Young Kim, Jongsoo Jang
ICCSA (4)2