VLDB 2026 Research / reviewers in the wild / expert
Seungsoo Lee 0001
dblp:75/3639-1
· DBLP profile ↗
15ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-6883-1869ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 2 first-author · 6 since 2021Security and privacy · 4 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ALPS: Automated Least-Privilege Enforcement for Securing Serverless Functions
Changhee Shin, Bom Kim, Seungsoo Lee 0001 |
INFOCOM | 3 |
| 2025 | KUBETEUS: An Intelligent Network Policy Generation Framework for Containers
Bom Kim, Seungsoo Lee 0001 |
INFOCOM | 3 |
| 2024 | Enhancing security in SDN: Systematizing attacks and defenses from a penetration perspective
Jinwoo Kim 0006, Minjae Seo, Seungsoo Lee 0001, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu, Seungwon Shin 0001 |
Comput. Networks | 3 |
| 2024 | Fatriot: Fault-tolerant MEC architecture for mission-critical systems using a SmartNIC
Taejune Park, Myoungsung You, Jinwoo Kim 0006, Seungsoo Lee 0001 |
J. Netw. Comput. Appl. | 4 |
| 2024 | Ambusher: Exploring the Security of Distributed SDN Controllers Through Protocol State FuzzingabstractDistributed SDN (Software-Defined Networking) controllers have rapidly become an integral element ofWide Area Networks (WAN), particularly within SD-WAN, providing scalability and fault-tolerance for expansive network infrastructures. However, the architecture of these controllers introduces new potential attack surfaces that have thus far received inadequate attention. In response to these concerns, we introduceAmbusher, a testing tool designed to discover vulnerabilities within protocols used in distributed SDN controllers.Ambusherachieves this by leveragingprotocol state fuzzing, which systematically finds attack scenarios based on an inferred state machine. Since learning states from a cluster is complicated,Ambusherproposes a novel methodology that extracts a single and relatively simple state machine, achieving efficient state-based fuzzing. Our evaluation ofAmbusher, conducted on a real SD-WAN deployment spanning two campus networks and one enterprise network, illustrates its ability to uncover 6 potential vulnerabilities in the widely used distributed controller platform. Jinwoo Kim 0006, Minjae Seo, Eduard Marin, Seungsoo Lee 0001, Jaehyun Nam, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Secure Inter-Container Communications Using XDP/eBPFabstractWhile the use of containerization technologies for virtual application deployment has grown at an astonishing rate, the question of the robustness of container networking has not been well scrutinized from a security perspective, even though inter-container networking is indispensable for microservices. Thus, this paper first analyzes container networks from a security perspective, discussing the implications based on their architectural limitations. Then, it presents Bastion+, a secure inter-container communication bridge. Bastion+ introduces ($i$) a network security enforcement stack that provides fine-grained control per container application and securely isolates inter- container traffic in a point-to-point manner. Bastion+ also supports ($ii$) selective security function chaining, enabling various security functions to be chained between containers for further security inspections (e.g., deep packet inspection) according to the container’s network context. Bastion+ incorporates ($iii$) a security policy assistant that helps an administrator discover inter-container networking dependencies correctly. Our evaluation demonstrates how Bastion+ can effectively mitigate several adversarial attacks in container networks while improving the overall performance up to 25.4% within single-host containers and 17.7% for cross-host container communications. Jaehyun Nam, Seungsoo Lee 0001, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2022 | Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control TrafficabstractSoftware-defined wide area network (SD-WAN) has emerged as a new paradigm for steering a large-scale network flexibly by adopting distributed software-defined network (SDN) controllers. The key to building a logically centralized but physically distributed control-plane is running diverse cluster management protocols to achieve consistency through an exchange of control traffic. Meanwhile, we observe that the control traffic exposes unique time-series patterns and directional relationships due to the operational structure even though the traffic is encrypted, and this pattern can disclose confidential information such as control-plane topology and protocol dependencies, which can be exploited for severe attacks. With this insight, we propose a new SD-WAN fingerprinting system, called Heimdallr. It analyzes periodical and operational patterns of SD-WAN cluster management protocols and the context of flow directions from the collected control traffic utilizing a deep learning-based approach, so that it can classify the cluster management protocols automatically from miscellaneous control traffic datasets. Our evaluation, which is performed in a realistic SD-WAN environment consisting of geographically distant three campus networks and one enterprise network shows that Heimdallr can classify SD-WAN control traffic with ≥ 93%, identify individual protocols with ≥ 80% macro F-1 scores, and finally can infer control-plane topology with ≥ 70% similarity. Minjae Seo, Jaehan Kim, Eduard Marin, Myoungsung You, Taejune Park, Seungsoo Lee 0001, Seungwon Shin 0001, Jinwoo Kim 0006 |
ACSAC | 6 |
| 2022 | A Framework for Policy Inconsistency Detection in Software-Defined NetworksabstractSoftware-Defined Networking (SDN) has aggressively grown in data center networks, telecommunication providers, and enterprises by virtue of its programmable and extensible control plane. Also, there have been many kinds of research on the security of SDN components along with the growth of SDN. Some of them have inspected network policy inconsistency problems that can severely cause network reliability and security issues in SDN. However, they do not consider whether a single network policy itself is corrupted during processing inside and between SDN components. In this paper, we thus focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among those components. We then present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise inOpenFlownetworks, the most prevalent SDN protocol. To prove its feasibility, we applied AudiSDN to two widely used SDN controllers, Floodlight and ONOS, and uncovered three separate CVEs (Common Vulnerabilities and Exposures) that cause the network policy inconsistencies among SDN components. Furthermore, we investigate the design flaws that cause the inconsistencies in modern SDN components, suggesting specific validations to address such a serious but understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2020 | AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksabstractAt the foundation of every network security architecture lies the premise that formulated network flow policies are reliably deployed and enforced by the network infrastructure. However, software-defined networks (SDNs) add a particular challenge to satisfying this premise, as for SDNs the flow pol-icy implementation spans multiple applications and abstraction layers across the SDN stack. In this paper, we focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among these components. This question is rather essential, as when such inconsistencies arise the implications to the security and reliability of the network are devastating. We present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise in OpenFlow networks, the most prevalent SDN protocol used today. We also present results from applying AudiSDN to two widely used SDN controllers, Floodlight and ONOS. In fact, our test results have led to the filing of 3 separate CVE reports. We believe that the approach presented in this paper is applicable to the breadth of OpenFlow platforms used today, and that its broader usage will help to address a serious but yet understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
INFOCOM | 1 |
| 2020 | BASTION: A Security Enforcement Network Stack for Container Networks
Jaehyun Nam, Seungsoo Lee 0001, Hyunmin Seo, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
USENIX ATC | 2 |
| 2020 | A comprehensive security assessment framework for software-defined networks
Seungsoo Lee 0001, Jinwoo Kim 0006, Seungwon Woo, Changhoon Yoon, Sandra Scott-Hayward, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
Comput. Secur. | 1 |
| 2017 | DELTA: A Security Assessment Framework for Software-Defined Networks
Seungsoo Lee 0001, Changhoon Yoon, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras |
NDSS | 1 |
| 2017 | Flow Wars: Systemizing the Attack Surface and Defenses in Software-Defined NetworksabstractEmerging software defined network (SDN) stacks have introduced an entirely new attack surface that is exploitable from a wide range of launch points. Through an analysis of the various attack strategies reported in prior work, and through our own efforts to enumerate new and variant attack strategies, we have gained two insights. First, we observe that different SDN controller implementations, developed independently by different groups, seem to manifest common sets of pitfalls and design weakness that enable the extensive set of attacks compiled in this paper. Second, through a principled exploration of the underlying design and implementation weaknesses that enables these attacks, we introduce a taxonomy to offer insight into the common pitfalls that enable SDN stacks to be broken or destabilized when fielded within hostile computing environments. This paper first captures our understanding of the SDN attack surface through a comprehensive survey of existing SDN attack studies, which we extend by enumerating 12 new vectors for SDN abuse. We then organize these vulnerabilities within the well-known confidentiality, integrity, and availability model, assess the severity of these attacks by replicating them in a physical SDN testbed, and evaluate them against three popular SDN controllers. We also evaluate the impact of these attacks against published SDN defense solutions. Finally, we abstract our findings to offer the research and development communities with a deeper understanding of the common design and implementation pitfalls that are enabling the abuse of SDN networks. Changhoon Yoon, Seungsoo Lee 0001, Heedo Kang, Taejune Park, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
IEEE/ACM Trans. Netw. | 2 |
| 2015 | SPIRIT: A Framework for Profiling SDNabstractSoftware-Defined Networking (SDN), which separates the control and data plane of network, is strongly considered as a promising future networking architecture. Compared with legacy networking architecture, it allows to enable a variety of innovative network functions at much less cost and effort. Accordingly, each component of SDN is also being rapidly realized, and one of the most noticeable SDN component implementations would be SDN controllers, such as ONOS or Floodlight. One advantage of these SDN controllers is capability of hosting various network applications to enable innovative network functions, however, it is crucial to analyze these applications before the actual deployment as they may directly affect the performance of the managed network. To be more specific, SDN applications may contain performance bugs that unnecessarily consume significant system resource or produce critical bottlenecks in the controller. In this paper, we introduce an automatic SDN application profiling framework, SPIRIT, which reduces the human effort in revealing any performance bugs that might exist in SDN applications. In order to show the effectiveness of our framework, we reveal new performance bugs exist in ONOS and Floodlight applications. Heedo Kang, Seungsoo Lee 0001, Changhoon Yoon, Seungwon Shin 0001 |
ICNP | 2 |
| 2015 | Enabling security functions with SDN: A feasibility study
Changhoon Yoon, Taejune Park, Seungsoo Lee 0001, Heedo Kang, Seungwon Shin 0001, Zonghua Zhang |
Comput. Networks | 3 |