VLDB 2026 Research / reviewers in the wild / expert
Sungmin Park
dblp:34/2725
· DBLP profile ↗
9ranked-venue papers
4as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-authorSecurity and privacy · 2Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Debun: Detecting Bundled JavaScript Libraries on Web using Property-Order GraphsabstractDetecting front-end JavaScript libraries in web applications is essential for website profiling, vulnerability detection, and dependency management. However, bundlers like Webpack transpile code in various ways, altering the original directory and code structure, which complicates library detection. While state-of-the-art techniques utilize property pattern-based library detection at runtime, they face two key limitations: (1) they cannot detect libraries inaccessible from the global object, and (2) they have limitations in granular version detection. To address these challenges, we present Debun, a scalable technique for detecting JavaScript libraries and their versions using function-level fingerprints. Our key insight is that bundlers preserve the property names and execution order of property operations, even after transpilation. To leverage this, we introduce the property-order graph (POG), which represents the execution order of property operations within a function body. We evaluate Debun on 68 high-traffic websites with 78 front-end JavaScript libraries. Our approach outperforms existing tools, achieving a 91.76% F1-score in library detection (1.39x higher) and an 79.81% F1-score in version identification with inclusion match (1.36x higher). Sungmin Park, Jihyeok Park |
ASE | 2 |
| 2025 | Verification and Classification of Exploits for Node.js VulnerabilitiesabstractVulnerabilities in the Node.js ecosystem pose serious security threats. Generating exploits for such vulnerabilities is a critical and essential step for fixing the vulnerabilities and understanding attack vectors. To address this need, prior work has proposed a range of methods, including static analysis approaches, dynamic analysis approaches, and LLM-based techniques. However, most studies verify only at the end of execution whether the expected effect of each vulnerability has occurred. This approach does not confirm whether the exploit actually reaches the target vulnerable sinks. As a result, it may fail to exercise the intended vulnerability or inadvertently trigger a different sink.In this study, we propose a method for validating and classifying exploits related to Node.js vulnerabilities. Our method instruments sink APIs and related objects prior to execution to capture sink APIs calls and their arguments when a sink is triggered at runtime. This lets us verify that an exploit reaches the intended sink and classify exploits by the point at which the sink is triggered. Sungmin Park |
ASE | 1 |
| 2014 | Performance Evaluation of the SSD-Based Swap System for Big Data ProcessingabstractSolid State Drives (SSDs) are quickly replacing HDDs not only in laptops but also in servers. Since SSD uses semiconductor, i.e., NAND flash memory, as its storage medium, it locates itself between memory and storage: it is faster but more expensive than HDD, and slower but cheaper than DRAM. Meanwhile, big data processing systems require both faster storage and larger memory. While lots of works have been conducted on evaluating the performance enhancement in big data processing systems by replacing HDD with SSD, the effect of SSD as a simple memory extension, i.e., Swap device, has not been studied, sufficiently. In this paper, we investigate the feasibility of using SSD as a swap device for big data processing systems through extensive experiments. Experimental results show that 1) incredibly large amount of IO's are issued to swap device when the physical memory cannot accommodate all data for processing, 2) SSD processes IO's to a swap device significantly faster than HDD, 3) using SSD as a storage device is a far better choice than using it as a swap device, and 4) enterprise SSD is not cost effective when it is used as a swap device. Sungmin Park, Minsoo Ryu, Sooyong Kang |
TrustCom | 2 |
| 2014 | Integrated write buffer management for solid state drives
Sungmin Park, Jaehyuk Cha, Sooyong Kang |
J. Syst. Archit. | 1 |
| 2011 | Parity Cloud Service: A Privacy-Protected Personal Data Recovery ServiceabstractAs more and more data are generated in an electronic format, the necessity of data recovery service became larger and the development of more efficient data backup and recovery technology has been an important issue during the past decade. While lots of effective backup and recovery technologies, including data dedeplication and incremental backup, have been developed for enterprise level data backup service, few works have been done for efficient personal data recovery service. Since the privacy protection is a crucial issue for providing a personal data recovery service, a plain data backup-based recovery service is not adequate for public service. Users are not expected to upload their critical data to the internet backup server until they can fully trust the service provider in terms of the privacy protection. In this paper, we propose a novel data recovery service framework on cloud infrastructure, a Parity Cloud Service (PCS) that provides a privacy-protected personal data recovery service. The proposed framework does not require any user data to be uploaded to the server for data recovery. Also the necessary server-side resources for providing the service are within a reasonable bound. Chi-won Song, Sungmin Park, Sooyong Kang |
TrustCom | 2 |
| 2009 | Performance Trade-Offs in Using NVRAM Write Buffer for Flash Memory-Based Storage DevicesabstractWhile NAND flash memory is used in a variety of end-user devices, it has a few disadvantages, such as asymmetric speed of read and write operations, inability to in-place updates, among others. To overcome these problems, various flash-aware strategies have been suggested in terms of buffer cache, file system, FTL, and others. Also, the recent development of next-generation nonvolatile memory types such as MRAM, FeRAM, and PRAM provide higher commercial value to non-volatile RAM (NVRAM). At today's prices, however, they are not yet cost-effective. In this paper, we suggest the utilization of small-sized, next-generation NVRAM as a write buffer to improve the .overall performance of NAND flash memory-based storage systems. We propose various block-based NVRAM write buffer management policies and evaluate the performance improvement of NAND flash memory-based storage systems under each policy. Also, we propose a novel write buffer-aware flash translation layer algorithm, optimistic FTL, which is designed to harmonize well with NVRAM write buffers. Simulation results show that the proposed buffer management policies outperform the traditional page-based LRU algorithm and the proposed optimistic FTL outperforms previous log block-based FTL algorithms, such as BAST and FAST. Sooyong Kang, Sungmin Park, Hoyoung Jung, Hyoki Shim, Jaehyuk Cha |
IEEE Trans. Computers | 2 |
| 2008 | Using Non-Volatile RAM as a Write Buffer for NAND Flash Memory-based Storage Devices
Sungmin Park, Hoyoung Jung, Hyoki Shim, Sooyong Kang, Jaehyuk Cha |
MASCOTS | 1 |
| 2008 | Write-Buffer-Aware Address Mapping for NAND Flash Memory Devices
Sungmin Park, Hoyoung Jung, Hyoki Shim, Sooyong Kang, Jaehyuk Cha |
MASCOTS | 1 |
| 2007 | LIRS-WSR: Integration of LIRS and Writes Sequence Reordering for Flash Memory
Hoyoung Jung, Kyunghoon Yoon, Hyoki Shim, Sungmin Park, Sooyong Kang, Jaehyuk Cha |
ICCSA (1) | 4 |