Jehyun Lee

dblp:69/4779 · DBLP profile ↗
← Back
10ranked-venue papers
6as first author
3since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 3 since 2021Computer networks · 2 · 1 first-author
YearPublicationVenuePosition
2023 Attacking Logo-Based Phishing Website Detectors with Adversarial Perturbations
Jehyun Lee, Zhe Xin, Melanie Ng Pei See, Kanav Sabharwal, Giovanni Apruzzese, Dinil Mon Divakaran
ESORICS (3)1
2022 SIERRA: Ranking Anomalous Activities in Enterprise Networks
abstract
An enterprise today deploys multiple security middleboxes such as firewalls, IDS, IPS, etc. in its network to collect different kinds of events related to threats and attacks. These events are streamed into a SIEM (Security Information and Event Management) system for analysts to investigate and respond quickly with appropriate actions. However, the number of events collected for a single enterprise can easily run into hundreds of thousands per day, much more than what analysts can investigate under a given budget constraint (time). In this work, we look into the problem of prioritizing suspicious events or anomalies to analysts for further investigation. We develop SIERRA, a system that processes event logs from multiple and diverse middleboxes to detect and rank anomalous activities. SIERRA takes an unsupervised approach and therefore has no dependence on ground truth data. Different from other works, SIERRA defines contexts, that help it to provide visual explanations of highly-ranked anomalous points to analysts, despite employing unsupervised models. We evaluate SIERRA using months of logs from multiple security middleboxes of an enterprise network. The evaluations demonstrate the capability of SIERRA to detect top anomalies in a network while outperforming naive application of existing anomaly detection algorithms as well as a state-of-the-art SIEM-based anomaly detection solution.
Jehyun Lee, Farren Tang, Phyo May Thet, Desmond Yeoh, Mitch Rybczynski, Dinil Mon Divakaran
EuroS&P1
2021 D-Fence: A Flexible, Efficient, and Comprehensive Phishing Email Detection System
abstract
Phishing continues to be a major security concern for organizations around the globe. Past works proposed classifiers to detect phishing emails; however many of them are based on rules, whereas others are typically standalone models focusing on one specific component of emails (say, URL strings). In this work, we take a different approach and propose a multi-modular and comprehensive phishing email detection system, called D-Fence. The different modules of D-Fence — structure module, text module, and URL module — detect phishing attempts in different components of an email. This allows D-Fence to cover larger attack surfaces while also offering flexible (model) configurations with reduced computational overhead. We carry out experiments on a large-scale real-world email dataset comprising mails from multiple enterprises. Our evaluations demonstrate the effectiveness of D-Fence in detecting phishing emails that do not have malicious intentions manifesting in all email components; D-Fence achieves a high recall of 0.99 at a low false-positive rate of 1 in 10K. Furthermore, we perform systematic evaluations to find and evaluate cost-efficient model configurations for D-Fence; the results reveal that D-Fence maintains high detection capability while bringing significant savings in computational time.
Jehyun Lee, Farren Tang, Pingxiao Ye, Fahim Abbasi, Phil Hay, Dinil Mon Divakaran
EuroS&P1
2019 SplitSecond: Flexible Privilege Separation of Android Apps
abstract
Android applications have been attractive targets to attackers due to the large number of users and the sensitive information they possess. After the success of the first step of an attack exploiting a software vulnerability, the consequential damage is primarily determined by the criticality and the amount of Android permissions that a victim application has. As a countermeasure, process separation techniques that isolate potentially vulnerable components - usually native libraries - from the critical data and permissions, have been proposed. However, existing techniques offer little flexibility in the separation, e.g., with all native code being placed into one process without considering its dependency with other (Java) components and the non-empty set of permissions needed. In this paper, we propose a flexible privilege separation system, named SplitSecond, that enables selective permission separation at the granularity of Java components and native methods. SplitSecond provides safety against the attacks by restricting permissions on a user selectable isolation unit. According to our case study and experimental evaluation on a real handset with SplitSecond adopted Android OS and 100 top-ranked Android applications, 59.59% of activities, 66.8% of native methods, and 47.49% of permissions on average are flexibly splittable by SplitSecond with moderate overhead.
Jehyun Lee, Akshaya Venkateswara Raja, Debin Gao
PST1
2017 On Return Oriented Programming Threats in Android Runtime
abstract
Android has taken a large share of operating systems for smart devices including smartphones, and has been an attractive target to the attackers. The arms race between attackers and defenders typically occurs on two front lines - the latest attacking technology and the latest updates to the operating system (including defense mechanisms deployed). In terms of attacking technology, Return-Oriented Programming (ROP) is one of the most sophisticated attack methods on Android devices. In terms of the operating system updates, Android Runtime (ART) was the latest and biggest change to the Android family. In this paper, we investigate the extent to which Android Runtime (ART) makes Return-Oriented Programming (ROP) attacks easier or more difficulty. In particular, we show that by updating system libraries and adopting Ahead-of-Time compiling instead of Justin- Time compiling in the ART architecture, a larger number and more diverse gadgets are disclosed to ROP attackers, which serve as direct ingredients to ROP attacks. We show that between three and six times more gadgets are found on the ART adopted versions of Android due to the new ART runtime. Moreover, in constrained situations where an attacker requires specific instructions and target registers, Android running ART provides up to 30% more conditional coverage than pre-ART Android does. We additionally demonstrate a sample ROP attack on post- ART Android that would not have been possible on pre-ART Android.
Akshaya Venkateswara Raja, Jehyun Lee, Debin Gao
PST2
2016 PsyBoG: A scalable botnet detection method for large-scale DNS traffic
Jonghoon Kwon, Jehyun Lee, Heejo Lee, Adrian Perrig
Comput. Networks2
2015 Screening smartphone applications using malware family signatures
Jehyun Lee, Suyeon Lee, Heejo Lee
Comput. Secur.1
2014 GMAD: Graph-based Malware Activity Detection by DNS traffic analysis
Jehyun Lee, Heejo Lee
Comput. Commun.1
2013 Screening Smartphone Applications Using Behavioral Signatures
Suyeon Lee, Jehyun Lee, Heejo Lee
SEC2
2011 Hidden Bot Detection by Tracing Non-human Generated Traffic at the Zombie Host
Jonghoon Kwon, Jehyun Lee, Heejo Lee
ISPEC2