VLDB 2026 Research / reviewers in the wild / expert
Woonghee Lee 0004
dblp:24/1519-4
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0002-9984-6879ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SPCA: Stream Parser Confusion Attack for Web Application Firewall Evasion in HTTP/2abstractWeb Application Firewalls (WAFs) are widely deployed as a primary defense mechanism against injection-based web attacks by inspecting HTTP traffic for malicious patterns. However, structural inconsistencies in HTTP/2 stream parsing introduce a protocol-level attack surface that remains insufficiently examined. We propose the Stream Parser Confusion Attack (SPCA), a novel evasion technique that exploits discrepancies between WAFs and backend HTTP/2 servers in processing stream dependencies and priorities. SPCA operates without altering payload content, relying solely on RFC-compliant manipulation of stream priority weights and dependency trees to deliver unmodified malicious inputs past WAF inspection. To evaluate the feasibility and generality of SPCA, we design three well-defined stream topologies—skewed, k-ary, and unbalanced—each capturing unique structural traits observed in real-world HTTP/2 scheduling patterns. Each topology's dataset consists of 500 structurally distinct requests, derived by embedding 100 malicious test cases across five distinct priority levels. We transmit these requests against 13 commercial and open-source WAFs and 20 backend web frameworks in a black-box setting. Each topology individually achieves a bypass success rate of 49.66% for the skewed tree, 44.62% for the k-ary tree, and 46.38% for the unbalanced tree. Under the concurrent attack with three topologies, the overall success rate exceeds 89% on average against the open-source and commercial WAFs. These findings demonstrate that structure-only protocol-compliant manipulation is sufficient to systematically bypass modern WAFs, revealing critical blind spots in HTTP/2-aware traffic inspection. We responsibly disclosed the identified issues to all affected vendors and received acknowledgments of the disclosures. Kyungrok Choi, Woonghee Lee 0004, Junbeom Hur |
WWW | 2 |
| 2025 | Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate ValidationabstractWhile providing a seamless user experience by enabling web access within the app, in-app browsers raise security concerns, particularly in certificate validation, which can leave users vulnerable to Man-In-The-Middle (MITM) or phishing attacks unless appropriately implemented.In this paper, we systematically evaluated the certificate validation mechanisms of in-app browsers, also known as WebView, focusing on how effectively they comply with X.509 certificate standards and support advanced certificate extensions related to revocation and Certificate Transparency (CT). To ensure reproducibility and enable platform-specific trust anchor control which is particularly challenging on Android 14 and later, we developed a unified framework called FAITH using physical devices for iOS and Android emulators. Using FAITH and 115 crafted certificate chains—including 87 non-compliant chains and 28 designed to test advanced certificate extensions—we tested 20 popular Android and iOS apps, as well as desktop and mobile browsers. Android WebView apps accepted 77.0% of non-compliant chains and all non-compliant intermediate CA certificate tests, significantly higher than mainstream browsers and iOS apps. We identified the root cause in Android WebView's reliance on the system-level certificate validation handler, which performs minimal checks and lacks support for extensions such as OCSP Must-Staple and Precertificate. Additionally, we found that cached intermediate CA certificates are reused during validation in Android WebView, which exposes the process to unintended bypass of certificate checks. To demonstrate its real-world impact, we constructed a detailed CA caching attack scenario, and disclosed it to responsible vendors including Google. The reported bug was subsequently acknowledged as a valid security vulnerability. Finally, we conclude by providing recommendations to improve WebView's certificate validation behavior. Woonghee Lee 0004, Junbeom Hur, Hyunsoo Kwon |
CCS | 1 |
| 2024 | Beneath the Phishing Scripts: A Script-Level Analysis of Phishing Kits and Their Impact on Real-World Phishing WebsitesabstractPhishing kits have become increasingly popular among cybercriminals because they offer an easy-to-use and efficient way for phishing attackers to build phishing websites. Prior work on phishing kits has focused on analyzing specific behavioral features (e.g., evasion techniques), and measuring their effectiveness on the anti-phishing mechanisms. Unfortunately, such prior studies provide a limited perspective, either targeting specific phishing kits or not fully addressing the server-side strategies at the script level that offer insights into the phishing attacker's view. Woonghee Lee 0004, Junbeom Hur, Doowon Kim |
AsiaCCS | 1 |
| 2024 | PhishinWebView: Analysis of Anti-Phishing Entities in Mobile Apps with WebView Targeted PhishingabstractDespite the relentless efforts on developing anti-phishing techniques, phishing attacks continue to proliferate, often incorporating evasion techniques to bypass detection. While recent studies have continuously enhanced our understanding of their evasion techniques in desktop environments, few studies have been conducted to explore how the phishing attack is being handled in mobile environments, specifically WebView. Yoonjung Choi, Woonghee Lee 0004, Junbeom Hur |
WWW | 2 |
| 2023 | A Honey postMessage, but a Heart of Gall: Exploiting Push Service in Service Workers Via postMessageabstractProgressive web app (PWA) is a kind of web apps, which is designed to enhance users’ browsing experience by combining the advantages of a web app’s reachability and a native app’s diverse functionalities. PWA sites have a special JavaScript file, service worker, which is executed in a different thread from the browser’s main page. It thus can support unique functionalities such as offline usage and push service even after the browser is closed. Because of these features, the service worker has been a main target of many web attacks such as a DDOS attack, or abused to generate illegal sites such as darknet sites. However, previous attacks exploiting the push service have limitations in that they need the pre-installation of a malicious service worker or only can passively utilize the existing push notification from the legitimate site (e.g., hijacking the push notification to track users’ location). Yeomin Jeong, Woonghee Lee 0004, Junbeom Hur |
AsiaCCS | 2 |