VLDB 2026 Research / reviewers in the wild / expert
Myoungsung You
dblp:330/7789
· DBLP profile ↗
14ranked-venue papers
6as first author
14since 2021 · last 2026
0000-0001-5822-5243ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 3 first-author · 7 since 2021Systems, architecture and hardware · 5 · 3 first-author · 5 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RDNet: An RDMA-aware Container Network Interface for Cloud Environments
Myoungsung You, Minjae Seo, Seungwon Shin 0001, Jaehyun Nam |
INFOCOM | 1 |
| 2026 | HybridMesh: A Hardware-software Hybrid Approach for Accelerating Service Mesh Ingress
Myoungsung You, Jaehyun Nam, Minjae Seo, Taejune Park, Seungwon Shin 0001 |
NSDI | 1 |
| 2026 | Comprehensive performance analysis of security applications on the BlueField-3 SmartNIC
Suhyeon Lee 0007, Myoungsung You, Taejune Park |
Comput. Networks | 2 |
| 2026 | BeaCon: Automatic container policy generation using environment-aware dynamic analysis
Haney Kang, Eduard Marin, Myoungsung You, Diego Perino, Seungwon Shin 0001, Jinwoo Kim 0006 |
Comput. Secur. | 3 |
| 2026 | AccelFaaS: Accelerating FaaS via Pre-Warmed Memory and Control Channel Offloading
Seong-Joong Kim, Seungwon Shin 0001, Myoungsung You |
IEEE Trans. Cloud Comput. | 3 |
| 2025 | MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and SplittingabstractTor, a widely utilized privacy network, enables anonymous communication but is vulnerable to flow correlation attacks that deanonymize users by correlating traffic patterns from Tor's ingress and egress segments. Various defenses have been developed to mitigate these attacks; however, they have two critical limitations: (i) significant network overhead during obfuscation and (ii) a lack of dynamic obfuscation for egress segments, exposing traffic patterns to adversaries. In response, we introduce MUFFLER, a novel connection-level traffic obfuscation system designed to secure Tor egress traffic. It dynamically maps real connections to a distinct set of virtual connections between the final Tor nodes and targeted services, either public or hidden. This approach creates egress traffic patterns fundamentally different from those at ingress segments without adding intentional padding bytes or timing delays. The mapping of real and virtual connections is adjusted in real-time based on ongoing network conditions, thwarting adversaries' efforts to detect egress traffic patterns. Extensive evaluations show that MUFFLER mitigates powerful correlation attacks with a TPR of 1% at an FPR of 10−2while imposing only a 2.17% bandwidth overhead. Moreover, it achieves up to 27x lower latency overhead than existing solutions and seamlessly integrates with the current Tor architecture. Minjae Seo, Myoungsung You, Jaehan Kim, Taejune Park, Seungwon Shin 0001, Jinwoo Kim 0006 |
INFOCOM | 2 |
| 2025 | HardMesh: Enabling High-performance Service Mesh Ingress Processing with SmartNICsabstractService meshes have become essential for enabling microservices in cloud environments; however, they also introduce substantial network overhead. In particular, the ingress gateway, which serves as the primary entry point for external traffic, has emerged as a major performance bottleneck due to CPU-intensive traffic analysis and prolonged forwarding paths through multiple network stack layers. Our analysis indicates that these inefficiencies can result in a 4-fold reduction in network throughput and increased CPU resource consumption. In response, we propose HardMesh, a hardware-software hybrid ingress gateway that leverages a Smart-NIC for high-performance traffic analysis and efficient traffic routing. This process is augmented by a lightweight CPU-based proxy for traffic management. Evaluations show that HardMesh outperforms existing ingress gateways, achieving up to 4.4× higher throughput while providing the same range of traffic management services. Myoungsung You, Jaehyun Nam, Minjae Seo, Taejune Park, Seungwon Shin 0001 |
SIGCOMM | 1 |
| 2024 | HardWhale: A Hardware-Isolated Network Security Enforcement System for Cloud EnvironmentsabstractWith the increasing popularity of containers for deploying microservices, ensuring the security of container networks has become a vital concern. However, current security solutions rely on a host's operating system (OS) to enforce network policies for container traffic. This design incurs severe overhead and cannot guarantee container network security when attackers gain access to the host's OS. Therefore, we propose HardWhale, a hardware-isolated network security enforcement system for containers that delivers high-performance and robust network security without depending on the host's OS. HardWhale leverages a smartNIC, physically isolating the entire container traffic inspection stack from the host and accelerating inspection tasks. Inspection policies securely reside within the smartNIC and are updated in runtime without involving the host, due to our isolated policy management mechanism. This design ensures robust network security for containers, even if the host is exposed to attackers. Evaluations show that HardWhale protects containers against various network attacks in compromised environments and improves HTTP throughput threefold and HTTP latency 2.3-fold compared to state-of-the-art solutions. Myoungsung You, Jaehyun Nam, Hyunmin Seo, Minjae Seo, Jaehan Kim, Dongmin Choi, Seungwon Shin 0001 |
ICDCS | 1 |
| 2024 | Fatriot: Fault-tolerant MEC architecture for mission-critical systems using a SmartNIC
Taejune Park, Myoungsung You, Jinwoo Kim 0006, Seungsoo Lee 0001 |
J. Netw. Comput. Appl. | 2 |
| 2024 | Hyperion: Hardware-Based High-Performance and Secure System for Container NetworksabstractContainers have become the predominant virtualization technique for deploying microservices in cloud environments. However, container networking, critical for microservice functionality, often introduces significant overhead and resource consumption, potentially degrading the performance of microservices. This challenge arises from the complexity of the software-based network data plane, responsible for network virtualization and access control within container traffic. To tackle this challenge, we proposeHyperion, a novel hardware-based container networking system that prioritizes high performance and security. Leveraging smartNICs, commonly found in cloud environments,Hyperionimplements a fully-functional container network data plane, encompassing network virtualization and access control. It also has the capability to dynamically optimize its data plane for agile responses to frequent changes in container environments, ensuring up-to-date data plane operation. This hardware-based design empowersHyperionto significantly improve the overall container networking performance without relying on the host system resources. Notably,Hyperionseamlessly integrates with existing containerized applications without necessitating modifications. Our evaluation shows that compared to state-of-the-art solutions,Hyperionachieves significant improvements in HTTP container communication latency and throughput by up to 2.25x and 4.3x, respectively. Furthermore, it reduces CPU utilization associated with container networking by up to 4x. Myoungsung You, Minjae Seo, Jaehan Kim, Seungwon Shin 0001, Jaehyun Nam |
IEEE Trans. Cloud Comput. | 1 |
| 2023 | Cryonics: Trustworthy Function-as-a-Service using Snapshot-based EnclavesabstractRecent research has proposed the use of trusted execution environments (TEEs), such as SGX, in serverless computing to safeguard against threats from insecure system software, malicious co-located tenants, or suspicious cloud operators. However, integrating SGX, one of the most mature TEE, with serverless computing results in significant performance degradation due to the function startup latency caused by enclave creation. This performance degradation arises because SGX is not designed with serverless function startup procedures in mind, where numerous application codes, libraries, and data are re-initialized upon each function invocation. The inherent limitations of SGX contribute to significant performance degradation, whether through the addition of every page into the enclave, or the restriction of page permissions, which ultimately cause TLB flushes, context switches, and re-entering the enclave. In this paper, we first take key observations resident in the intrinsic features of the server-less function and propose Cryonics, a method of serving snapshot-based enclave that accelerates the startup time of the function instance by creating a future-proof working set of that. We consider the page locality and obsolete pages of the enclaved function instance to create a lightweight working set used for serving requests. Our evaluation shows that Cryonics achieves up to 100x outperformed startup time compared to existing cold-start-based methods and reveals the stability of the startup time. Seong-Joong Kim, Myoungsung You, Byung Joon Kim, Seungwon Shin 0001 |
SoCC | 2 |
| 2023 | HELIOS: Hardware-assisted High-performance Security Extension for Cloud NetworkingabstractWith the increasing adoption of containerization in cloud services, container networking has become a critical concern, as it enables the agile deployment of microservices but also introduces new vulnerabilities susceptible to network attacks, posing a threat to container environments. While several security solutions have been introduced to address this concern, they unfortunately exhibit significant shortcomings, including security vulnerabilities and limited performance. We thus propose Helios, a novel hardware-based network security extension that addresses the security and performance limitations in existing solutions. Leveraging a smartNIC, Helios enhances both the security and performance facets of container networking through two key mechanisms: (i) the establishment of physically isolated container communication channels and (ii) the network security engines fully offloaded to the smartNIC. Our evaluation shows that Helios mitigates various network threats initiated from both container- and host-side while performing up to 3x faster than the existing solutions in container communication. Myoungsung You, Jaehyun Nam, Minjae Seo, Seungwon Shin 0001 |
SoCC | 1 |
| 2022 | Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control TrafficabstractSoftware-defined wide area network (SD-WAN) has emerged as a new paradigm for steering a large-scale network flexibly by adopting distributed software-defined network (SDN) controllers. The key to building a logically centralized but physically distributed control-plane is running diverse cluster management protocols to achieve consistency through an exchange of control traffic. Meanwhile, we observe that the control traffic exposes unique time-series patterns and directional relationships due to the operational structure even though the traffic is encrypted, and this pattern can disclose confidential information such as control-plane topology and protocol dependencies, which can be exploited for severe attacks. With this insight, we propose a new SD-WAN fingerprinting system, called Heimdallr. It analyzes periodical and operational patterns of SD-WAN cluster management protocols and the context of flow directions from the collected control traffic utilizing a deep learning-based approach, so that it can classify the cluster management protocols automatically from miscellaneous control traffic datasets. Our evaluation, which is performed in a realistic SD-WAN environment consisting of geographically distant three campus networks and one enterprise network shows that Heimdallr can classify SD-WAN control traffic with ≥ 93%, identify individual protocols with ≥ 80% macro F-1 scores, and finally can infer control-plane topology with ≥ 70% similarity. Minjae Seo, Jaehan Kim, Eduard Marin, Myoungsung You, Taejune Park, Seungsoo Lee 0001, Seungwon Shin 0001, Jinwoo Kim 0006 |
ACSAC | 4 |
| 2022 | MECaNIC: SmartNIC to Assist URLLC Processing in Multi-Access Edge Computing PlatformsabstractMulti-access edge computing (MEC) providing server capabilities at near end-users is introduced to enable Ultra Reliable Low Latency Communication (URLLC) for mission-critical and time-sensitive networked services. However, the current MEC simply shortens the physical travel distance of traffic but does not include any architectural approach for supporting URLLC. As a result, MEC implicates resource contention issues, and important packets can be easily delayed or lost, resulting in critical flaws for those services. To address these problems, we introduce MECaNIC, which extends the data plane of MEC to SmartNIC and assists URLLC of MEC. It provides i) precise packet scheduling that handles traffic priorities into two dimensions of reliability and latency, and ii) task offloading that accelerates MEC applications, including payload matching and response caching. The prototype implemented using NetFPGA shows that MECaNIC reduces the average latency of the high-priority traffic from$2,883\ \mu s$to$397\ \mu s$while ensuring packet delivery, even when the traffic competes with other lower priority traffic. Also, task offloading improves a MEC's payload processing 4-fold and reduces file downloading time and video random access time by 44% and 17%, respectively. Taejune Park, Myoungsung You, Youngjin Jin, Kilho Lee, Seungwon Shin 0001 |
ICNP | 2 |