VLDB 2026 Research / reviewers in the wild / expert
Jonghoon Kwon
dblp:46/4109
· DBLP profile ↗
22ranked-venue papers
8as first author
15since 2021 · last 2026
0000-0002-3853-242XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 7 since 2021Computer networks · 8 · 4 first-author · 5 since 2021Systems, architecture and hardware · 5 · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Signet: Scalable Network-Driven Proof of Notification for Blockchain Systems
Elham Ehsani Moghadam, Marc Wyss, Jonghoon Kwon, Marc Frei, Yih-Chun Hu, Adrian Perrig, Alberto Sonnino |
ICDCS | 3 |
| 2025 | Path-Aware Access Control: Granting Access with Transit Network Attributes
Jonghoon Kwon, Julian Modanese, Jordi Subirà Nieto, Adrian Perrig |
ICC | 1 |
| 2025 | Scaling SCIERA: A Journey Through the Deployment of a Next-generation NetworkabstractThe SCION Next-Generation Network (NGN) architecture has expanded steadily since 2017, with today 20+ ISPs offering SCION connectivity. In production, IP-to-SCION-to-IP translation by SCION-IP-Gateways (SIGs) is used, such that applications are unaware of the NGN communication. To accelerate innovation and deployments, our aim is to increase the number of native SCION use cases, where the application is fully SCION-aware and optimizes communication across all path choices offered by the network. We set out to achieve two core objectives: (1) facilitating simple native connectivity for applications, and (2) enhancing the scalability of SCION deployment at academic sites. François Wirz, Marten Gartner, Jelte van Bommel, Elham Ehsani Moghadam, Grace H. Cimaszewski, Anxiao He, Yizhe Zhang 0006, Henry Birge-Lee, Felix Kottmann, Cyrill Krähenbühl, Jonghoon Kwon, Kyveli Mavromati, Liang Wang 0054, Daniel Bertolo, Marco Canini, Buseung Cho, Ronaldo A. Ferreira, Simon Peter Green, David Hausheer, Junbeom Hur, Xiaohua Jia, Heejo Lee, Prateek Mittal, Omo Oaiya, Chanjin Park, Adrian Perrig, Jerry Sobieski, Yixin Sun 0004, Cong Wang 0001, Klaas Wierenga |
SIGCOMM | 11 |
| 2025 | Low-Cost and Robust Global Time SynchronizationabstractNumerous vital applications depend on accurately synchronized time, and disruptions can yield severe consequences in terms of safety and security. Yet, establishing cost-efficient and robust synchronization across geographically distributed devices is challenging. Many solutions for global time synchronization require placing trust in a single entity or system, for example in Global Navigation Satellite Systems (G NSSes) or leased infrastructure providers, constituting a single point of failure and often incurring high costs. An alternative, cost-effective solution is to run time synchronization over the Internet. However, this approach faces challenges in achieving (i) precise time synchronization, (ii) robustness to failing, misconfigured, or compromised nodes, and (iii) robustness to congestion-related issues such as volumetric DDoS attacks. Existing proposals mostly attempt to solve challenges (i) and (ii), but none provide robustness against congestion and volumetric DDoS. We address the challenges identified in previous work with Everdeen. Everdeen minimizes costs by running on existing Internet infrastructure and avoids relying on any single en-tity by enabling nodes to mutually synchronize time. The core innovation of Everdeen is its weighted neighbor-based (WNB) synchronization mode, where participants synchronize exclusively with their direct neighbors. Our evaluation shows that Everdeen provides better time synchronization quality at lower communication overhead compared to prior work. It is also considerably more robust against failing, misconfigured, or compromised hosts. Most importantly, we experimentally demonstrate that time synchronization traffic protected with Everdeen is unaffected by network congestion, including vol-umetric DDoS attacks. Marc Wyss, Marc Frei, Jonghoon Kwon, Adrian Perrig |
SP | 3 |
| 2024 | Debuglet: Programmable and Verifiable Inter-Domain Network TelemetryabstractOn today's Internet, end-user debugging is largely limited to simple tools such as ping and traceroute, supplemented by purpose-built services such as bandwidth measurement, and website uptime monitors. Unfortunately, these tools do not provide sufficient data to isolate specific network faults, nor do they give the user results that can be validated by external entities. Furthermore, since networks disparately treat measurement packets, as our empirical results confirm, measurement packets need to be indistinguishable from data packets. In this paper, we argue for a distributed network debugging infrastructure and describe Debuglet, a deployable and incentivized architecture that allows inter-domain network debugging using real data packets and user-defined code, which facilitates accurate and flexible measurements of the network performance experienced by data packets. We implement the Debuglet system, and demonstrate its feasibility by deploying it on a network testbed, evaluating its measurement accuracy, and analyzing its deployment costs. Seyedali Tabaeiaghdaei, Filippo Costa, Jonghoon Kwon, Patrick Bamert, Yih-Chun Hu, Adrian Perrig |
ICDCS | 3 |
| 2023 | Qualitative Intention-aware Attribute-based Access Control Policy RefinementabstractDesigning access control policies is often expensive and tedious due to the heterogeneous systems, services, and diverse user demands. Although ABAC policy and decision engine creation methods based on machine learning have been proposed, they cannot make good access decisions for applications and situations not envisioned by the decision-makers who provide training examples. It results in over-and under-permissiveness. In this paper, we propose a framework that refines pre-developed policies. It creates a decision engine that makes better decisions than those policies. Inspired by multiple criteria decision theory, our method uses the policy manager's qualitative intentions behind their judgments to guide access decisions so that more benefits are expected. In the evaluation, we prepare a coarse and relatively elaborate policy. We refine the coarse policy to obtain a decision engine that is compared for the similarity in access decisions with the elaborate policy using AUC as a measure. The results show that our method improves the coarse policy by a difference of 12-26% in AUC and outperforms the conventional machine learning methods by a difference of 3-11% in AUC. Shohei Mitani, Jonghoon Kwon, Nakul Ghate, Taniya Singh, Hirofumi Ueda, Adrian Perrig |
SACMAT | 2 |
| 2023 | Did the Shark Eat the Watchdog in the NTP Pool? Deceiving the NTP Pool's Monitoring System
Jonghoon Kwon, Jeonggyu Song, Junbeom Hur, Adrian Perrig |
USENIX Security Symposium | 1 |
| 2022 | BLAP: Bluetooth Link Key Extraction and Page Blocking AttacksabstractSecure Simple Pairing (SSP) and Link Manager Protocol (LMP) authentication are two main authentication mechanisms in Bluetooth specification. In this paper, we present two novel attacks, called link key extraction and page blocking attacks, breaking LMP authentication and SSP authentication, respectively. Link key extraction attack allows attackers to extract link keys of Bluetooth devices generated during the SSP procedure by exploiting Bluetooth HCI dump. Page blocking attacks by man-in-the-middle (MITM) attackers enforce Blue-tooth connections, enabling subsequent SSP downgrade attacks to bypass the SSP authentication challenge. In order to demonstrate the efficacy, we implement our attacks on various real-world devices and show that (1) a target link key is dumped into a log and extracted efficiently, possibly leading to the subsequent impersonation attack, and (2) malicious MITM connections can be established with 100% success rate, enabling subsequent SSP downgrade attack. We investigate the root causes for the vulnerabilities and present mitigations. Changseok Koh, Jonghoon Kwon, Junbeom Hur |
DSN | 2 |
| 2022 | Consent Routing: Towards Bilaterally Trusted Communication PathsabstractIn today’s Internet, the security of data transfers largely depends on the forwarding path: on-path adversaries can launch powerful attacks against the confidentiality, integrity, and availability of Internet communication. Moreover, current routing protocols give little path control to end hosts; at best, a multi-homed host can choose the first hop of the forwarding path. In short, communicating hosts are facing the problem that they need to trust the entities which forward their packets but can barely choose the forwarding path. Recent research in networking has shown that path-aware network architectures can give the sender control over the path selection while increasing the overall efficiency and security of the network. Still, only half of the trust problem is solved: in these architectures, path selection is up to the sender’s judgment, even though the sender and the receiver have the same vital interest in choosing the forwarding path for their communication. In this paper, we introduce consent routing, a new routing paradigm in which the consent of both the sender and the receiver is required prior to using a forwarding path. The novelty of consent routing is to make path selection a cooperative process between the distributed communicating parties, enabling new opportunities for security and trust, e.g., mitigation of surveillance, censorship, and traffic analysis. Our implementation shows that consent routing is feasible in practice and can be incrementally deployed without changes to the underlying network architecture. Mathias Blarer, Jonghoon Kwon, Vincent Graf, Adrian Perrig |
ICDCS | 2 |
| 2022 | Analysis of NTP pool monitoring system based on multiple monitoring stationsabstractThe Network Time Protocol (NTP) is a server-client-based time synchronization protocol that transmits time information over a network, and is used in various applications on the Internet. Especially, the NTP Pool Project is designed to connect NTP servers that provide accurate time to millions of clients, and balance the load on the NTP servers using the NTP pool. The NTP pool operates the NTP pool monitor system to evaluate the time accuracy and availability of the NTP servers registered with the NTP pool. There are currently two operating environments for monitoring systems in practice: one is a single monitoring system, which is officially operating, and the other is a multiple-monitoring system, which is now under beta testing. In this study, we investigate the NTP pool monitoring system based on multiple monitoring stations, which is expected to be deployed soon in the real world. We then discuss possible threats and their security implications when the current single monitoring system extends to the multiple-monitoring system. Jeonggyu Song, Jonghoon Kwon, Junbeom Hur |
MobiHoc | 2 |
| 2022 | G-SINC: Global Synchronization Infrastructure for Network ClocksabstractMany critical computing applications rely on secure and dependable time which is reliably synchronized across large distributed systems. Today's time synchronization architectures are commonly based on global navigation satellite systems at the considerable risk of being exposed to outages, malfunction, or attacks against availability and accuracy. This paper describes a practical instantiation of a new global, Byzantine fault-tolerant clock synchronization approach that does not place trust in any single entity and is able to tolerate a fraction of faulty entities while still maintaining synchronization on a global scale among otherwise sovereign network topologies. Leveraging strong resilience and security properties provided by the path-aware SCION networking architecture, the presented design can be implemented as a backward compatible active standby solution for existing time synchronization deployments. Through extensive evaluation, we demonstrate that over 94 % of time servers reliably minimize the offset of their local clocks to real-time in the presence of up to 20 % malicious nodes, and all time servers remain synchronized with a skew of only 2 ms even after one year of reference clock outage. Marc Frei, Jonghoon Kwon, Seyedali Tabaeiaghdaei, Marc Wyss, Christoph Lenzen 0001, Adrian Perrig |
SRDS | 2 |
| 2022 | Creating a Secure Underlay for the Internet
Henry Birge-Lee, Joel Wanner, Grace H. Cimaszewski, Jonghoon Kwon, Liang Wang 0054, François Wirz, Prateek Mittal, Adrian Perrig, Yixin Sun 0004 |
USENIX Security Symposium | 4 |
| 2021 | Deployment and scalability of an inter-domain multi-path routing infrastructureabstractPath aware networking (PAN) is a promising approach that enables endpoints to participate in end-to-end path selection. PAN unlocks numerous benefits, such as fast failover after link failures, application-based path selection and optimization, and native interdomain multi-path. The utility of PAN hinges on the availability of a large number of high-quality path options. In an inter-domain context, two core questions arise. Can we deploy such an architecture natively in today's Internet infrastructure without creating an overlay relying on BGP? Can we build a scalable multi-path routing system that provides a large number of high-quality paths? Cyrill Krähenbühl, Seyedali Tabaeiaghdaei, Christelle Gloor, Jonghoon Kwon, Adrian Perrig, David Hausheer, Dominik Roos |
CoNEXT | 4 |
| 2021 | SpeedCam: Towards Efficient Flow Monitoring for Multipath Communication
Kilian Gärtner, Jonghoon Kwon, David Hausheer |
IM | 2 |
| 2021 | Mondrian: Comprehensive Inter-domain Network Zoning Architecture
Jonghoon Kwon, Claude Hähni, Patrick Bamert, Adrian Perrig |
NDSS | 1 |
| 2020 | SCIONLAB: A Next-Generation Internet TestbedabstractNetwork testbeds have empowered networking re-search and facilitated scientific progress. However, current testbeds focus mainly on experiments involving the current Inter-net. In this paper, we propose SCIONLAB, a novel global network testbed that enables exciting research opportunities and experimentation with the SCION next-generation Internet architecture. New users can join SCIONLAB as a full-fledged autonomous system with minimal effort and administrative overhead, and directly gain unfettered access to its inter-domain routing system. Based on a well-connected network topology consisting of globally distributed nodes, SCIONLAB enables new experiments, such as inter-domain multipath communication, path-aware networking, exploration of novel routing policies, and new approaches for DDoS defense. SCIONLAB has been operational since 2016 and has supported diverse research projects. We describe the design and implementation of SCIONLAB, and present use cases that illustrate exciting research opportunities. Jonghoon Kwon, Juan A. García-Pardo, Markus Legner, François Wirz, Matthias Frei, David Hausheer, Adrian Perrig |
ICNP | 1 |
| 2020 | SVLAN: Secure & Scalable Network Virtualization
Jonghoon Kwon, Taeho Lee 0003, Claude Hähni, Adrian Perrig |
NDSS | 1 |
| 2016 | PsyBoG: A scalable botnet detection method for large-scale DNS traffic
Jonghoon Kwon, Jehyun Lee, Heejo Lee, Adrian Perrig |
Comput. Networks | 1 |
| 2016 | CLORIFI: software vulnerability discovery using code clone verificationabstractSummary Software vulnerability has long been considered an important threat to the system safety. A vulnerability is often reproduced because of the frequent code reuse by programmers. Security patches are usually not propagated to all code clones; however, they could be leveraged to discover unknown vulnerabilities. Static code auditing approaches are frequently proposed to scan source codes for security flaws; unfortunately, these approaches generate too many false positives. While dynamic execution analysis methods can precisely report vulnerabilities, they are ineffective in path exploration, which limits them to scale to large programs. With the purpose of detecting vulnerability in a scalable way with more preciseness, in this paper, we propose a novel mechanism, called software vulnerability discovery using Code Clone Verification (CLORIFI), that scalably discovers vulnerabilities in real world programs using code clone verification. In the beginning, we use a fast and scalable syntax‐based way to find code clones in program source codes based on released security patches. Subsequently, code clones are being verified using concolic testing to dramatically decrease the false positives. In addition, we mitigate the path explosion problem by backward sensitive data tracing in concolic execution. Experiments have been conducted with real‐world open‐source projects (recent Linux OS distributions and program packages). As a result, we found 7 real vulnerabilities out of 63 code clones from Ubuntu 14.04 LTS (Canonical, London, UK) and 10 vulnerabilities out of 40 code clones from CentOS 7.0 (The CentOS Project(community contributed)). Furthermore, we confirmed more code clone vulnerabilities in various versions of programs including Rsyslog (Open Source(Original author: Rainer Gerhards)), Apache (Apache Software Foundation, Forest Hill, Maryland, USA) and Firefox (Mozilla Corporation, Mountain View, California, USA). In order to evaluate the effectiveness of vulnerability verification in a systematic way, we also utilized Juliet Test Suite as measurement objects. The results show that CLORIFI achieves 98% accuracy with 0 false positives. Copyright © 2015 John Wiley & Sons, Ltd. Hongzhe Li, Hyuckmin Kwon, Jonghoon Kwon, Heejo Lee |
Concurr. Comput. Pract. Exp. | 3 |
| 2015 | An incrementally deployable anti-spoofing mechanism for software-defined networks
Jonghoon Kwon, Dongwon Seo, Minjin Kwon, Heejo Lee, Adrian Perrig |
Comput. Commun. | 1 |
| 2011 | Hidden Bot Detection by Tracing Non-human Generated Traffic at the Zombie Host
Jonghoon Kwon, Jehyun Lee, Heejo Lee |
ISPEC | 1 |
| 2008 | HoneyID : Unveiling Hidden Spywares by Generating Bogus Events
Jeheon Han, Jonghoon Kwon, Heejo Lee |
SEC | 2 |