VLDB 2026 Research / reviewers in the wild / expert
Heejo Lee
dblp:75/4485
· DBLP profile ↗
83ranked-venue papers
5as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 1 first-author · 15 since 2021Computer networks · 16 · 1 first-author · 1 since 2021Systems, architecture and hardware · 11 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Q3Fuzz: Multi-Layered Stateful Fuzzing for the QUIC-HTTP/3 Protocol Stack
Isa Jafarov, Choongin Lee, Heejo Lee, Sven Dietrich |
DSN | 3 |
| 2025 | ZCover: Uncovering Z-Wave Controller Vulnerabilities Through Systematic Security Analysis of Application Layer ImplementationabstractThe increasing use of smart home technologies has raised concerns about security vulnerabilities, particularly in Z-Wave systems. Existing approaches hold the promise of assessing Z-Wave security in slave devices but fall short of being effectively applied to discover vulnerabilities in Z-Wave controllers, which are central to Z-Wave systems. We present ZCover, a framework for systematically analyzing the application layer of Z-Wave controllers to uncover security vulnerabilities. By extracting the known and unknown properties of the Z-Wave controller and utilizing mutation that considers the correlations of the Z-Wave packet frame fields, ZCover can effectively discover unknown vulnerabilities in the target Z-Wave controller. Evaluation on nine real-world Z-Wave devices showed that ZCover outperformed existing Z-Wave security research, by discovering 15 previously unknown critical vulnerabilities with 12 new CVE IDs assigned. ZCover can be utilized as a resource for ensuring the security of Z-Wave controllers in building a secure Z-Wave smart home. Carlos Nkuba Kayembe, Jimin Kang, Seunghoon Woo, Heejo Lee |
DSN | 4 |
| 2025 | IMUFuzzer: Resilience-based Discovery of Signal Injection Attacks on Robotic Aerial VehiclesabstractRobotic aerial vehicles (RAVs), particularly drones, are crucial in civil and military sectors. However, researchers have found that adversaries can inject noise into sensor measurements and cause physical impacts on the RAVs like crashes. Although identifying such signal injection attacks is essential to evaluate and improve the robustness of an RAV, it is challenging to discover them since their impact depends on the RAV’s physical states and the search space of noise signals and physical states is vast due to its dynamic nature.This paper proposes IMUFUZZER, a feedback-driven fuzzing framework, to automatically test an RAVs system and discover signal injection attacks. IMUFUZZER generates realistic noise signals for various inertial measurement unit (IMU) sensors, and monitors their impact on RAV control to detect mission failures, leveraging a high-fidelity RAV simulator. To find the physical states that attacks depend on, IMUFUZZER generates various mission paths that the RAV will fly through. We develop a novel feedback mechanism to quantify the resilience of the RAV against attacks and efficiently guide the fuzzing process to find signal injection attacks. Using IMUFUZZER, we have discovered 23 successful signal injection attacks on popular RAV control software (ArduPilot). We evaluate the correctness and effectiveness of our feedback-based sensor fuzzing and demonstrate the feasibility of the discovered attacks through physical experiments. Sudharssan Mohan, Kyeongseok Yang, Zelun Kong, Yonghwi Kwon 0001, Junghwan Rhee, Tyler Summers, Hongjun Choi, Heejo Lee |
ASE | 8 |
| 2025 | Scaling SCIERA: A Journey Through the Deployment of a Next-generation NetworkabstractThe SCION Next-Generation Network (NGN) architecture has expanded steadily since 2017, with today 20+ ISPs offering SCION connectivity. In production, IP-to-SCION-to-IP translation by SCION-IP-Gateways (SIGs) is used, such that applications are unaware of the NGN communication. To accelerate innovation and deployments, our aim is to increase the number of native SCION use cases, where the application is fully SCION-aware and optimizes communication across all path choices offered by the network. We set out to achieve two core objectives: (1) facilitating simple native connectivity for applications, and (2) enhancing the scalability of SCION deployment at academic sites. François Wirz, Marten Gartner, Jelte van Bommel, Elham Ehsani Moghadam, Grace H. Cimaszewski, Anxiao He, Yizhe Zhang 0006, Henry Birge-Lee, Felix Kottmann, Cyrill Krähenbühl, Jonghoon Kwon, Kyveli Mavromati, Liang Wang 0054, Daniel Bertolo, Marco Canini, Buseung Cho, Ronaldo A. Ferreira, Simon Peter Green, David Hausheer, Junbeom Hur, Xiaohua Jia, Heejo Lee, Prateek Mittal, Omo Oaiya, Chanjin Park, Adrian Perrig, Jerry Sobieski, Yixin Sun 0004, Cong Wang 0001, Klaas Wierenga |
SIGCOMM | 22 |
| 2025 | A large-scale analysis of the effectiveness of publicly reported security patches
Seunghoon Woo, Eunjin Choi, Heejo Lee |
Comput. Secur. | 3 |
| 2024 | BloomFuzz: Unveiling Bluetooth L2CAP Vulnerabilities via State Cluster Fuzzing with Target-Oriented State Machines
Pyeongju Ahn, Yeonseok Jang, Seunghoon Woo, Heejo Lee |
ESORICS (3) | 4 |
| 2024 | PRETT2: Discovering HTTP/2 DoS Vulnerabilities via Protocol Reverse Engineering
Choongin Lee, Isa Jafarov, Sven Dietrich, Heejo Lee |
ESORICS (2) | 4 |
| 2024 | CNEPS: A Precise Approach for Examining Dependencies among Third-Party C/C++ Open-Source ComponentsabstractThe rise in open-source software (OSS) reuse has led to intricate dependencies among third-party components, increasing the demand for precise dependency analysis. However, owing to the presence of reused files that are difficult to identify the originating components (i.e., indistinguishable files) and duplicated components, precisely identifying component dependencies is becoming challenging. Yoonjong Na, Seunghoon Woo, Joomyeong Lee, Heejo Lee |
ICSE | 4 |
| 2023 | AutoMetric: Towards Measuring Open-Source Software Quality Metrics AutomaticallyabstractIn modern software development, open-source software (OSS) plays a crucial role. Although some methods exist to verify the safety of OSS, the current automation technologies fall short. To address this problem, we propose AutoMetric, an automatic technique for measuring security metrics for OSS in repository level. Using AutoMetric which only collects repository addresses of the projects, it is possible to inspect many projects simultaneously regardless of its size and scope. AutoMetric contains five metrics: Mean Time to Update (MU), Mean Time to Commit (MC), Number of Contributors (NC), Inactive Period (IP), and Branch Protection (BP). These metrics can be calculated quickly even if the source code changes. By comparing metrics in AutoMetric with 2,675 reported vulnerabilities in GitHub Advisory Database (GAD), the result shows that the more frequent updates and commits and the shorter the inactivity period, the more vulnerabilities were found. Taejun Lee, Heewon Park, Heejo Lee |
AST | 3 |
| 2023 | V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification Techniques
Seunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo Oh |
USENIX Security Symposium | 3 |
| 2022 | Poster: Automated Discovery of Sensor Spoofing Attacks on Robotic VehiclesabstractRobotic vehicles are playing an increasingly important role in our daily life. Unfortunately, attackers have demonstrated various sensor spoofing attacks that interfere with robotic vehicle operations, imposing serious threats. Thus, it is crucial to discover such attacks earlier than attackers so that developers can secure the vehicles. In this paper, we propose a new sensor fuzzing framework SensorFuzz that can systematically discover potential sensor spoofing attacks on robotic vehicles. It generates malicious sensor inputs by formally modeling the existing sensor attacks and leveraging high-fidelity vehicle simulation, and then analyzes the impact of the inputs on the vehicle with a resilience-based feedback mechanism. Kyeongseok Yang, Sudharssan Mohan, Yonghwi Kwon 0001, Heejo Lee |
CCS | 4 |
| 2022 | L2Fuzz: Discovering Bluetooth L2CAP Vulnerabilities Using Stateful Fuzz TestingabstractBluetooth Basic Rate/Enhanced Data Rate (BR/EDR) is a wireless technology used in billions of devices. Recently, several Bluetooth fuzzing studies have been conducted to detect vulnerabilities in Bluetooth devices, but they fall short of effectively generating malformed packets. In this paper, we propose L2FUZZ, a stateful fuzzer to detect vulnerabilities in Bluetooth BR/EDR Logical Link Control and Adaptation Protocol (L2CAP) layer. By selecting valid commands for each state and mutating only the core fields of packets, L2FUZZ can generate valid malformed packets that are less likely to be rejected by the target device. Our experimental results confirmed that: (1) L2FUZZ generates up to 46 times more malformed packets with a much less packet rejection ratio compared to the existing techniques, and (2) L2FUZZ detected five zero-day vulnerabilities from eight real-world Bluetooth devices. Haram Park, Carlos Nkuba Kayembe, Seunghoon Woo, Heejo Lee |
DSN | 4 |
| 2022 | MOVERY: A Precise Approach for Modified Vulnerable Code Clone Discovery from Modified Open-Source Software Components
Seunghoon Woo, Hyunji Hong, Eunjin Choi, Heejo Lee |
USENIX Security Symposium | 4 |
| 2022 | Improving SSH detection model using IPA time and WGAN-GP
Junwon Lee, Heejo Lee |
Comput. Secur. | 2 |
| 2021 | Dicos: Discovering Insecure Code Snippets from Stack Overflow Posts by Leveraging User DiscussionsabstractOnline Q&A fora such as Stack Overflow assist developers to solve their faced coding problems. Despite the advantages, Stack Overflow has the potential to provide insecure code snippets that, if reused, can compromise the security of the entire software. Hyunji Hong, Seunghoon Woo, Heejo Lee |
ACSAC | 3 |
| 2021 | OCTOPOCS: Automatic Verification of Propagated Vulnerable Code Using Reformed Proofs of ConceptabstractAddressing vulnerability propagation has become a major issue in software ecosystems. Existing approaches hold the promise of detecting widespread vulnerabilities but cannot be applied to verify effectively whether propagated vulnerable code still poses threats. We present OCTOPOCS, which uses a reformed Proof-of-Concept (PoC), to verify whether a vulnerability is propagated. Using context-aware taint analysis, OCTOPOCS extracts crash primitives (the parts used in the shared code area between the original vulnerable software and propagated software) from the original PoC. OCTOPOCS then utilizes directed symbolic execution to generate guiding inputs that direct the execution of the propagated software from the entry point to the shared code area. Thereafter, OCTOPOCS creates a new PoC by combining crash primitives and guiding inputs. It finally verifies the propagated vulnerability using the created PoC. We evaluated OCTOPOCS with 15 real-world C and C++ vulnerable software pairs, with results showing that OCTOPOCS successfully verified 14 propagated vulnerabilities. Seongkyeong Kwon, Seunghoon Woo, Gangmo Seong, Heejo Lee |
DSN | 4 |
| 2021 | Centris: A Precise and Scalable Approach for Identifying Modified Open-Source Software ReuseabstractOpen-source software (OSS) is widely reused as it provides convenience and efficiency in software development. Despite evident benefits, unmanaged OSS components can introduce threats, such as vulnerability propagation and license violation. Unfortunately, however, identifying reused OSS components is a challenge as the reused OSS is predominantly modified and nested. In this paper, we propose CENTRIS, a precise and scalable approach for identifying modified OSS reuse. By segmenting an OSS code base and detecting the reuse of a unique part of the OSS only, CENTRIS is capable of precisely identifying modified OSS reuse in the presence of nested OSS components. For scalability, CENTRIS eliminates redundant code comparisons and accelerates the search using hash functions. When we applied CENTRIS on 10,241 widely-employed GitHub projects, comprising 229,326 versions and 80 billion lines of code, we observed that modified OSS reuse is a norm in software development, occurring 20 times more frequently than exact reuse. Nonetheless, CENTRIS identified reused OSS components with 91% precision and 94% recall in less than a minute per application on average, whereas a recent clone detection technique, which does not take into account modified and nested OSS reuse, hardly reached 10% precision and 40% recall. Seunghoon Woo, Sunghan Park, Seulbae Kim, Heejo Lee, Hakjoo Oh |
ICSE | 4 |
| 2021 | QuickBCC: Quick and Scalable Binary Vulnerable Code Clone Detection
Hajin Jang, Kyeongseok Yang, Geonwoo Lee, Yoonjong Na, Jeremy D. Seideman, Shoufu Luo, Heejo Lee, Sven Dietrich |
SEC | 7 |
| 2021 | Secure and Scalable IoT: An IoT Network Platform Based on Network Overlay and MAC Security
Junwon Lee, Heejo Lee |
SEC | 2 |
| 2021 | V0Finder: Discovering the Correct Origin of Publicly Reported Software Vulnerabilities
Seunghoon Woo, Sunghan Park, Heejo Lee, Sven Dietrich |
USENIX Security Symposium | 4 |
| 2020 | Enhancing the Reliability of IoT Data Marketplaces through Security Validation of IoT DevicesabstractIoT data marketplaces are being developed to help cities and communities create large scale IoT applications. Such data marketplaces let the IoT device owners sell their data to the application developers. Following this application development model, the application developers need not deploy their own IoT devices when developing IoT applications; instead, they can buy data from a data marketplace. In a marketplace-based IoT application, the application developers are making critical business and operation decisions using the data produced by seller's IoT devices. Under these circumstances, it is crucial to verify and validate the security of IoT devices.In this paper, we assess the security of IoT data marketplaces. In particular, we discuss what kind of vulnerabilities exist in IoT data marketplaces using the well-known STRIDE model, and present a security assessment and certification framework for IoT data marketplaces to help the device owners to examine the security vulnerabilities of their devices. Most importantly, our solution certifies the IoT devices when they connect to the data marketplace, which helps the application developers to make an informed decision when buying and consuming data from a data marketplace. To demonstrate the effectiveness of the proposed approach, we have developed a proof-of-concept using I3 (Intelligent IoT Integrator), which is an open-source IoT data marketplace developed at the University of Southern California, and IoTcube, which is a vulnerability detection toolkit developed by researchers at Korea University. Through this work, we show that it is possible to increase the reliability of a IoT data marketplace while not damaging the convenience of the users. Yoonjong Na, Yejin Joo, Heejo Lee, Xiangchen Zhao, Kurian Karyakulam Sajan, Gowri Sankar Ramachandran, Bhaskar Krishnamachari |
DCOSS | 3 |
| 2020 | VERISMART: A Highly Precise Safety Verifier for Ethereum Smart ContractsabstractWe present VERISMART, a highly precise verifier for ensuring arithmetic safety of Ethereum smart contracts. Writing safe smart contracts without unintended behavior is critically important because smart contracts are immutable and even a single flaw can cause huge financial damage. In particular, ensuring that arithmetic operations are safe is one of the most important and common security concerns of Ethereum smart contracts nowadays. In response, several safety analyzers have been proposed over the past few years, but state-of-the-art is still unsatisfactory; no existing tools achieve high precision and recall at the same time, inherently limited to producing annoying false alarms or missing critical bugs. By contrast, VERISMART aims for an uncompromising analyzer that performs exhaustive verification without compromising precision or scalability, thereby greatly reducing the burden of manually checking undiscovered or incorrectly-reported issues. To achieve this goal, we present a new domain-specific algorithm for verifying smart contracts, which is able to automatically discover and leverage transaction invariants that are essential for precisely analyzing smart contracts. Evaluation with real-world smart contracts shows that VERISMART can detect all arithmetic bugs with a negligible number of false alarms, far outperforming existing analyzers. Sunbeom So, Myungho Lee, Heejo Lee, Hakjoo Oh |
SP | 4 |
| 2018 | Obfuscated VBA Macro Detection Using Machine LearningabstractMalware using document files as an attack vector has continued to increase and now constitutes a large portion of phishing attacks. To avoid anti-virus detection, malware writers usually implement obfuscation techniques in their source code. Although obfuscation is related to malicious code detection, little research has been conducted on obfuscation with regards to Visual Basic for Applications (VBA) macros. In this paper, we summarize the obfuscation techniques and propose an obfuscated macro code detection method using five machine learning classifiers. To train these classifiers, our proposed method uses 15 discriminant static features, taking into account the characteristics of the VBA macros. We evaluated our approach using a real-world dataset of obfuscated and non-obfuscated VBA macros extracted from Microsoft Office document files. The experimental results demonstrate that our detection approach achieved a F2 score improvement of greater than 23% compared to those of related studies. Sangwoo Kim, Seokmyung Hong, Jaesang Oh, Heejo Lee |
DSN | 4 |
| 2018 | PRETT: Protocol Reverse Engineering Using Binary Tokens and Network Traces
Choong In Lee, Jeonghan Bae, Heejo Lee |
SEC | 3 |
| 2018 | Software systems at risk: An empirical study of cloned vulnerabilities in practice
Seulbae Kim, Heejo Lee |
Comput. Secur. | 2 |
| 2017 | VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoveryabstractThe ecosystem of open source software (OSS) has been growing considerably in size. In addition, code clones - code fragments that are copied and pasted within or between software systems - are also proliferating. Although code cloning may expedite the process of software development, it often critically affects the security of software because vulnerabilities and bugs can easily be propagated through code clones. These vulnerable code clones are increasing in conjunction with the growth of OSS, potentially contaminating many systems. Although researchers have attempted to detect code clones for decades, most of these attempts fail to scale to the size of the ever-growing OSS code base. The lack of scalability prevents software developers from readily managing code clones and associated vulnerabilities. Moreover, most existing clone detection techniques focus overly on merely detecting clones and this impairs their ability to accurately find "vulnerable" clones. In this paper, we propose VUDDY, an approach for the scalable detection of vulnerable code clones, which is capable of detecting security vulnerabilities in large software programs efficiently and accurately. Its extreme scalability is achieved by leveraging function-level granularity and a length-filtering technique that reduces the number of signature comparisons. This efficient design enables VUDDY to preprocess a billion lines of code in 14 hour and 17 minutes, after which it requires a few seconds to identify code clones. In addition, we designed a security-aware abstraction technique that renders VUDDY resilient to common modifications in cloned code, while preserving the vulnerable conditions even after the abstraction is applied. This extends the scope of VUDDY to identifying variants of known vulnerabilities, with high accuracy. In this study, we describe its principles and evaluate its efficacy and effectiveness by comparing it with existing mechanisms and presenting the vulnerabilities it detected. VUDDY outperformed four state-of-the-art code clone detection techniques in terms of both scalability and accuracy, and proved its effectiveness by detecting zero-day vulnerabilities in widely used software systems, such as Apache HTTPD and Ubuntu OS Distribution. Seulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo Oh |
IEEE Symposium on Security and Privacy | 3 |
| 2016 | Automated Source Code Instrumentation for Verifying Potential Vulnerabilities
Hongzhe Li, Jaesang Oh, Hakjoo Oh, Heejo Lee |
SEC | 4 |
| 2016 | PsyBoG: A scalable botnet detection method for large-scale DNS traffic
Jonghoon Kwon, Jehyun Lee, Heejo Lee, Adrian Perrig |
Comput. Networks | 3 |
| 2016 | CLORIFI: software vulnerability discovery using code clone verificationabstractSummary Software vulnerability has long been considered an important threat to the system safety. A vulnerability is often reproduced because of the frequent code reuse by programmers. Security patches are usually not propagated to all code clones; however, they could be leveraged to discover unknown vulnerabilities. Static code auditing approaches are frequently proposed to scan source codes for security flaws; unfortunately, these approaches generate too many false positives. While dynamic execution analysis methods can precisely report vulnerabilities, they are ineffective in path exploration, which limits them to scale to large programs. With the purpose of detecting vulnerability in a scalable way with more preciseness, in this paper, we propose a novel mechanism, called software vulnerability discovery using Code Clone Verification (CLORIFI), that scalably discovers vulnerabilities in real world programs using code clone verification. In the beginning, we use a fast and scalable syntax‐based way to find code clones in program source codes based on released security patches. Subsequently, code clones are being verified using concolic testing to dramatically decrease the false positives. In addition, we mitigate the path explosion problem by backward sensitive data tracing in concolic execution. Experiments have been conducted with real‐world open‐source projects (recent Linux OS distributions and program packages). As a result, we found 7 real vulnerabilities out of 63 code clones from Ubuntu 14.04 LTS (Canonical, London, UK) and 10 vulnerabilities out of 40 code clones from CentOS 7.0 (The CentOS Project(community contributed)). Furthermore, we confirmed more code clone vulnerabilities in various versions of programs including Rsyslog (Open Source(Original author: Rainer Gerhards)), Apache (Apache Software Foundation, Forest Hill, Maryland, USA) and Firefox (Mozilla Corporation, Mountain View, California, USA). In order to evaluate the effectiveness of vulnerability verification in a systematic way, we also utilized Juliet Test Suite as measurement objects. The results show that CLORIFI achieves 98% accuracy with 0 false positives. Copyright © 2015 John Wiley & Sons, Ltd. Hongzhe Li, Hyuckmin Kwon, Jonghoon Kwon, Heejo Lee |
Concurr. Comput. Pract. Exp. | 4 |
| 2015 | An incrementally deployable anti-spoofing mechanism for software-defined networks
Jonghoon Kwon, Dongwon Seo, Minjin Kwon, Heejo Lee, Adrian Perrig |
Comput. Commun. | 4 |
| 2015 | Screening smartphone applications using malware family signatures
Jehyun Lee, Suyeon Lee, Heejo Lee |
Comput. Secur. | 3 |
| 2015 | A jamming approach to enhance enterprise Wi-Fi secrecy through spatial access control
Yu Seung Kim, Patrick Tague, Heejo Lee |
Wirel. Networks | 3 |
| 2014 | Lightweight Resource Management for DDoS Traffic Isolation in a Cloud Environment
Ibnu Mubarok, Kiryong Lee, Sihyung Lee, Heejo Lee |
SEC | 4 |
| 2014 | GMAD: Graph-based Malware Activity Detection by DNS traffic analysis
Jehyun Lee, Heejo Lee |
Comput. Commun. | 2 |
| 2014 | Cylindrical Coordinates Security Visualization for multiple domain command and control botnet detection
Ilju Seo, Heejo Lee, Seung Chul Han |
Comput. Secur. | 2 |
| 2013 | Software Vulnerability Detection Using Backward Trace Analysis and Symbolic ExecutionabstractSoftware vulnerability has long been considered an important threat to the safety of software systems. When source code is accessible, we can get much help from the information of source code to detect vulnerabilities. Static analysis has been used frequently to scan code for errors that cause security problems when source code is available. However, they often generate many false positives. Symbolic execution has also been proposed to detect vulnerabilities and has shown good performance in some researches. However, they are either ineffective in path exploration or could not scale well to large programs. During practical use, since most of paths are actually not related to security problems and software vulnerabilities are usually caused by the improper use of security-sensitive functions, the number of paths could be reduced by tracing sensitive data backwardly from security-sensitive functions so as to consider paths related to vulnerabilities only. What's more, in order to leave ourselves free from generating bug triggering test input, formal reasoning could be used by solving certain program conditions. In this research, we propose backward trace analysis and symbolic execution to detect vulnerabilities from source code. We first find out all the hot spot in source code file. Based on each hot spot, we construct a data flow tree so that we can get the possible execution traces. Afterwards, we do symbolic execution to generate program constraint(PC) and get security constraint(SC) from our predefined security requirements along each execution trace. A program constraint is a constraint imposed by program logic on program variables. A security constraint(SC) is a constraint on program variables that must be satisfied to ensure system security. Finally, this hot spot will be reported as a vulnerability if there is an assignment of values to program inputs which could satisfy PC but violates SC, in other words, satisfy PC Λ S̅C̅. We have implemented our approach and conducted experiments on test cases which we randomly choose from Juliet Test Suites provided by US National Security Agency(NSA). The results show that our approach achieves Precision value of 83.33%, Recall value of 90.90% and F1 Value of 86.95% which gains the best performance among competing tools. Moreover, our approach can efficiently mitigate path explosion problem in traditional symbolic execution. Hongzhe Li, Taebeom Kim, Munkhbayar Bat-Erdene, Heejo Lee |
ARES | 4 |
| 2013 | A Digital Forensic Framework for Automated User Activity Reconstruction
Jungin Kang, Heejo Lee |
ISPEC | 3 |
| 2013 | UAS: Universal anti-spoofing by incorporating existing mechanismsabstractIP spoofing is attractive to amplify network attacks and to provide anonymity. Many approaches have to prevent IP spoofing attacks; however, they do not address a significant deployment issue: filtering inefficiency caused by lack of incentives for early adopters. Practically, no mechanism has been widely deployed and none successfully blocks IP spoofing attacks. We propose a universal anti-spoofing (UAS) mechanism that incorporates existing mechanisms to thwart IP spoofing attacks. In the proposed mechanism, intermediate routers utilize any existing anti-spoofing mechanism that ascertains whether a packet is spoofed or not, and inscribes this information in the packet header. The edge routers at a victim network can estimate the forgery of a packet based on the information sent by the upstream routers. The results of experiments conducted with Internet topologies indicate that UAS reduces false alarms up to 84.5% compared to cases where each mechanism operates separately. Our evaluation shows that incorporating multiple anti-spoofing mechanisms reduces false alarms significantly. Hyok An, Heejo Lee, Adrian Perrig |
LCN | 2 |
| 2013 | Screening Smartphone Applications Using Behavioral Signatures
Suyeon Lee, Jehyun Lee, Heejo Lee |
SEC | 3 |
| 2013 | SIPAD: SIP-VoIP Anomaly Detection using a Stateful Rule Tree
Dongwon Seo, Heejo Lee, Ejovi Nuwere |
Comput. Commun. | 2 |
| 2013 | APFS: Adaptive Probabilistic Filter Scheduling against distributed denial-of-service attacks
Dongwon Seo, Heejo Lee, Adrian Perrig |
Comput. Secur. | 2 |
| 2012 | Carving secure wi-fi zones with defensive jammingabstractWith rampant deployment of wireless technologies such as WLAN, information leakage is increasingly becoming a threat for its serious adopters such as enterprises. Research on antidotes has been mainly focused on logical measures such as authentication protocols and secure channels, but an inside collaborator can readily circumvent such defenses and wirelessly divert the classified information to a conniver outside. In this paper, we propose a novel approach to the problem that forges a walled wireless coverage, a secure Wi-Fi zone in particular. Inspired by the fact that jamming as an attack is inherently difficult to defeat, we turn the table and use it as a defensive weapon to fend off the covert illegal access from outside. To validate the proposed approach, we conduct extensive outdoor experiments with the IEEE 802.11g Wi-Fi adapters. The measurements show that the forged secure zones match well with the model prediction and that the defensive jamming approach can indeed be used to protect wireless networks against information leakage. Lastly, we propose the algorithms to configure defensive jammers in arbitrary geometry. Yu Seung Kim, Patrick Tague, Heejo Lee |
AsiaCCS | 3 |
| 2012 | Detection of cache pollution attacks using randomness checksabstractThe Internet plays an increasing role in content dissemination as user-generated contents have exploded recently. Cache servers have been deployed to bypass bottlenecks in the network so that contents can be delivered to end users more efficiently. With caches becoming more embedded in the networks, emerging threats follow naturally. A cache pollution attack is one of the most serious threats on caching networks including the current Internet and emerging caching networks such as Content Centric Networking (CCN). In this paper, we propose a detection approach against cache pollution attacks using randomness checks of a matrix. We apply an effective filtering approach and a statistical sequential analysis for detecting low-rate attacks. The results of our experiments show that our approach can detect a cache pollution attack with attack rate of only a few percent of the overall rate. Hyundo Park, Indra Widjaja, Heejo Lee |
ICC | 3 |
| 2012 | Cyber Weather Forecasting: Forecasting Unknown Internet Worms Using Randomness Analysis
Hyundo Park, Sung-Oh David Jung, Heejo Lee, Hoh Peter In |
SEC | 3 |
| 2012 | Online Detection of Fake Access Points Using Received Signal StrengthsabstractWireless access points (APs) are widely used for the convenience and productivity of smartphone users. The growing popularity of wireless local area networks (WLANs) increases the risk of wireless security attacks. A fake AP can be set in any public space in order to impersonate legitimate APs for monetization. Existing fake AP detection methods analyze wireless traffic by using extra devices, and the traffic is collected by servers. However, using these server-side methods is costly and only provide secure communication, in limited places, of clients' devices. Recently, several fake AP detection methods have been designed in order to overcome the server-side problems in a client-side. However, there are two limitations to the client-side methods: cumbersome processes and limited resources. When the methods attempt to collect data, calculating interval time incurs time-consuming processes to detect fake characteristics in the client-side. Moreover, the operating systems in smartphones provide limited resources that can hardly be adopted in the client-side. In this paper, we propose a novel fake AP detection method to solve the aforementioned problems in the client-side. The method leverages received signal strengths (RSSs) and online detection algorithm. Our method collects RSSs from nearby APs and normalizes them for accurate measurement. We measure the similarity of normalized RSSs. If the similarity between normalized RSSs is less than the fixed threshold value, we determine that the RSSs are generated from a fake device. We can measure the optimal threshold value derived from the sequential hypothesis testing. In our experiment, when the fixed threshold value was 2, the true positive was over than 99% and the false positive was less than 0.1% in three observations. Taebeom Kim, Haemin Park, Hyunchul Jung, Heejo Lee |
VTC Spring | 4 |
| 2012 | Identifying botnets by capturing group activities in DNS traffic
Hyunsang Choi, Heejo Lee |
Comput. Networks | 2 |
| 2012 | Cyber-Physical Security of a Smart Grid InfrastructureabstractIt is often appealing to assume that existing solutions can be directly applied to emerging engineering domains. Unfortunately, careful investigation of the unique challenges presented by new domains exposes its idiosyncrasies, thus often requiring new approaches and solutions. In this paper, we argue that the “smart” grid, replacing its incredibly successful and reliable predecessor, poses a series of new security challenges, among others, that require novel approaches to the field of cyber security. We will call this new field cyber-physical security. The tight coupling between information and communication technologies and physical systems introduces new security concerns, requiring a rethinking of the commonly used objectives and methods. Existing security approaches are either inapplicable, not viable, insufficiently scalable, incompatible, or simply inadequate to address the challenges posed by highly complex environments such as the smart grid. A concerted effort by the entire industry, the research community, and the policy makers is required to achieve the vision of a secure smart grid infrastructure. Yilin Mo, Tiffany Hyun-Jin Kim, Kenneth Brancik, Dona Dickinson, Heejo Lee, Adrian Perrig, Bruno Sinopoli |
Proc. IEEE | 5 |
| 2011 | Hidden Bot Detection by Tracing Non-human Generated Traffic at the Zombie Host
Jonghoon Kwon, Jehyun Lee, Heejo Lee |
ISPEC | 3 |
| 2011 | PFS: Probabilistic filter scheduling against distributed denial-of-service attacksabstractDistributed denial-of-service (DDoS) attacks continue to pose an important challenge to current networks. DDoS attacks can cause victim resource consumption and link congestion. A filter-based DDoS defense is considered as an effective approach, since it can defend against both attacks: victim resource consumption and link congestion. However, existing filter-based approaches do not address necessary properties for viable DDoS solutions: how to practically identify attack paths, how to propagate filters to the best locations (filter routers), and how to manage many filters to maximize the defense effectiveness. We propose a novel mechanism, termed PFS (Probabilistic Filter Scheduling), to efficiently defeat DDoS attacks and to satisfy the necessary properties. In PFS, filter routers identify attack paths using probabilistic packet marking, and maintain filters using a scheduling policy to maximize the defense effectiveness. Our experiments show that PFS achieves 44% higher effectiveness than other filter-based approaches. Furthermore, we vary PFS parameters in terms of the marking probability and deployment ratio, and find that 30% marking probability and 30% deployment rate maximize the attack blocking rate of PFS. Dongwon Seo, Heejo Lee, Adrian Perrig |
LCN | 2 |
| 2010 | Activity-oriented access control to ubiquitous hospital information and services
Le Xuan Hung, Sungyoung Lee 0001, Young-Koo Lee, Heejo Lee, Murad Khalid, Ravi Sankar |
Inf. Sci. | 4 |
| 2009 | Activity-Oriented Access Control for Ubiquitous EnvironmentsabstractRecent research on ubiquitous computing has introduced a new concept of activity-based computing as a way of thinking about supporting human activities in ubiquitous computing environment. Existing access control approaches such as RBAC, became inappropriate to support this concept because they do not consider human activities. In this paper, we propose Activity-Oriented Access Control (AOAC) model, aiming to support user's activity in ubiquitous environments. We have designed and implemented our initial AOAC system. We also built up a simple scenario in order to illustrate how it supports user activities. The results have shown that AOAC meets our objectives. Also, AOAC it takes approximately 0.26 second to give a response which proves that AOAC is suitable to work in real-time environments. Le Xuan Hung, Riaz Ahmed Shaikh 0001, Hassan Jameel, Syed Muhammad Khaliq-ur-Rahman Raazi, Weiwei Yuan, Ngo Trong Canh, Phan Tran Ho Truc, Sungyoung Lee 0001, Heejo Lee, Yuseung Son, Miguel Fernandes |
CCNC | 9 |
| 2009 | Fast detection and visualization of network attacks on parallel coordinates
Hyunsang Choi, Heejo Lee |
Comput. Secur. | 2 |
| 2009 | Maximum-Utility Scheduling of Operation Modes With Probabilistic Task Execution Times Under Energy ConstraintsabstractWe propose a novel scheduling scheme that determines the instant operation modes of multiple tasks. The tasks have probabilistic execution times and are executed on discrete operation modes providing different utilities with different energy consumptions. We first design an optimal offline scheduling scheme that stochastically maximizes the cumulative utility of the tasks under energy constraints, at the cost of heavy computational overhead. Next, the optimal offline scheme is modified to an approximate online scheduling scheme. The online scheme has little runtime overhead and yields almost the maximum utility, with an energy budget that is given at runtime. The difference between the maximum utility and the output utility of the online scheme is bounded by a controllable input value. Extensive evaluation shows that the output utility of the online scheme approaches the maximum utility in most cases, and is much higher than that of existing methods by up to 50% of the largest utility difference among available operation modes. Wan Yeon Lee, Heejo Lee |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2009 | Group-Based Trust Management Scheme for Clustered Wireless Sensor NetworksabstractTraditional trust management schemes developed for wired and wireless ad hoc networks are not well suited for sensor networks due to their higher consumption of resources such as memory and power. In this work, we propose a new lightweight group-based trust management scheme (GTMS) for wireless sensor networks, which employs clustering. Our approach reduces the cost of trust evaluation. Also, theoretical as well as simulation results show that our scheme demands less memory, energy, and communication overheads as compared to the current state-of-the-art trust management schemes and it is more suitable for large-scale sensor networks. Furthermore, GTMS also enables us to detect and prevent malicious, selfish, and faulty nodes. Riaz Ahmed Shaikh 0001, Hassan Jameel, Brian J. d'Auriol, Heejo Lee, Sungyoung Lee 0001, Young Jae Song |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2008 | Network Level Privacy for Wireless Sensor NetworksabstractFull network level privacy spectrum comprises of identity, route, location and data privacy. Existing privacy schemes of wireless sensor networks only provide partial network level privacy. Providing full network level privacy is a critical and challenging problem due to the constraints imposed by the sensor nodes, sensor networks and QoS issues. In this paper, we propose full network level privacy solution that addresses this problem. This solution comprises of Identity, Route and Location (IRL) privacy algorithm and data privacy mechanism, that collectively provides protection against privacy disclosure attacks such as eavesdropping and hop-by-hop trace back attacks. Riaz Ahmed Shaikh 0001, Hassan Jameel, Brian J. d'Auriol, Sungyoung Lee 0001, Young Jae Song, Heejo Lee |
IAS | 6 |
| 2008 | Reducing Payload Scans for Attack Signature Matching Using Rule Classification
Heejo Lee |
ACISP | 2 |
| 2008 | Activity-based Security Scheme for Ubiquitous EnvironmentsabstractBardram introduced a new concept of activity-based computing as a way of thinking about supporting human activities in ubiquitous environments. In such environments where users are using a multitude of heterogeneous computing devices, the need for supporting users at the activity level becomes essential. However, without considering basic security issues, it could be rife with vulnerabilities. Security services, like authentication and access control, have to not only guarantee security, privacy, and confidentiality for ubiquitous computing resources, but also support user activities equipped with various devices. In this paper, we present an activity-based security scheme. The proposed scheme aims to enhance security services on mobile devices and facilitate user activities. We also integrate off-the-shell security services like MD5, TEA, Diffie-Hellman key agreement protocol so that it makes the scheme more robust and practically usable. The implementation and sample scenario have shown the requirement satisfactory of the scheme. Le Xuan Hung, Hassan Jameel, Riaz Ahmed Shaikh 0001, Syed Muhammad Khaliq-ur-Rahman Raazi, Weiwei Yuan, Ngo Trong Canh, Phan Tran Ho Truc, Sungyoung Lee 0001, Heejo Lee, Yuseung Son, Miguel Fernandes, Miso Kim, Yonil Zhung |
IPCCC | 9 |
| 2008 | PROBE: A Process Behavior-Based Host Intrusion Prevention System
Minjin Kwon, Kyoochang Jeong, Heejo Lee |
ISPEC | 3 |
| 2008 | Unified Rate Limiting in Broadband Access Networks for Defeating Internet Worms and DDoS Attacks
Keun Park, Dongwon Seo, Jaewon Yoo, Heejo Lee |
ISPEC | 4 |
| 2008 | Distinguishing between FE and DDoS Using Randomness Check
Hyundo Park, Peng Li 0059, Debin Gao, Heejo Lee, Robert H. Deng |
ISC | 4 |
| 2008 | HoneyID : Unveiling Hidden Spywares by Generating Bogus Events
Jeheon Han, Jonghoon Kwon, Heejo Lee |
SEC | 3 |
| 2008 | Detecting More SIP Attacks on VoIP Services by Combining Rule Matching and State Transition Models
Dongwon Seo, Heejo Lee, Ejovi Nuwere |
SEC | 2 |
| 2007 | Cyber Threat Trend Analysis Model Using HMMabstractPrevention is normally recognized as one of the best defense strategy against malicious hackers or attackers. The desire of deploying better prevention mechanisms has motivated many security researchers and practitioners, who are studies threat trend analysis models. However, threat trend is not directly revealed from the time-series data because the trend is implicit in its nature. Besides, traditional time-series analysis, which predicts the future trend pattern by relying exclusively on the past trend pattern, is not appropriate for predicting a trend pattern in dynamic network environments (e.g., the Internet). Thus, supplemental environmental information is required to uncover a trend pattern from the implicit (or hidden) raw data. In this paper, we propose cyber threat trend analysis model using hidden Markov model (HMM) by incorporating the supplemental environmental information into the trend analysis. Do-Hoon Kim, Taek Lee, Sung-Oh David Jung, Hoh Peter In, Heejo Lee |
IAS | 5 |
| 2007 | Transmission Time-Based Mechanism to Detect Wormhole AttacksabstractImportant applications of Wireless Ad Hoc Networks make them very attractive to attackers, therefore more research is required to guarantee the security for Wireless Ad Hoc Networks. In this paper, we proposed a transmission time based mechanism (TTM) to detect wormhole attacks - one of the most popular & serious attacks in Wireless Ad Hoc Networks. TTM detects wormhole attacks during route setup procedure by computing transmission time between every two successive nodes along the established path. Wormhole is identified base on the fact that transmission time between two fake neighbors created by wormhole is considerably higher than that between two real neighbors which are within radio range of each other. TTM has good performance, little overhead and no special hardware is required. Tran Van Phuong, Ngo Trong Canh, Young-Koo Lee, Sungyoung Lee 0001, Heejo Lee |
APSCC | 5 |
| 2007 | TTM: An Efficient Mechanism to Detect Wormhole Attacks in Wireless Ad-hoc NetworksabstractNetworks make them very attractive to attackers, therefore more research is required to guarantee the security for Wireless Ad Hoc Networks. In this paper, we proposed a transmission time based mechanism (TTM) to detect wormhole attacks – one of the most popular & serious attacks in Wireless Ad Hoc Networks. TTM detects wormhole attacks during route setup procedure by computing transmission time between every two successive nodes along the established path. Wormhole is identified base on the fact that transmission time between two fake neighbors created by wormhole is considerably higher than that between two real neighbors which are within radio range of each other. TTM has good performance, little overhead and no special hardware required. TTM is designed specifically for Ad Hoc On-Demand Vector Routing Protocol (AODV) but it can be extended to work with other routing protocols. Tran Van Phuong, Le Xuan Hung, Young-Koo Lee, Sungyoung Lee 0001, Heejo Lee |
CCNC | 5 |
| 2007 | BASE: an incrementally deployable mechanism for viable IP spoofing preventionabstractDoS attacks use IP spoofing to forge the source IP address of packets, and thereby hide the identity of the source. This makes it hard to defend against DoS attacks, so IP spoofing will still be used as an aggressive attack mechanism even under distributed attack environment. While many IP spoofing prevention techniques have been proposed, none have achieved widespread real-world use. One main reason is the lack of properties favoring incremental deployment, an essential component for the adoption of new technologies. A viable solution needs to be not only technically sound but also economically acceptable. An incrementally deploy-able protocol should have three properties: initial benefits for early adopters, incremental benefits for subsequent adopters, and effectiveness under partial deployment. Since no previous anti-spoofing solution satisfies all three of these properties, we propose a new mechanism called "BGP Anti-Spoofing Extension" (BASE). The BASE mechanism is an anti-spoofing protocol designed to fulfill the incremental deployment properties necessary for adoption in current Internet environments. Based on simulations we ran using a model of Internet AS connectivity, BASE shows desirable IP spoofing prevention capabilities under partial deployment. We find that just 30% deployment can drop about 97% of attack packets. Therefore, BASE not only provides adopters' benefit but also outperforms previous anti-spoofing mechanisms. Heejo Lee, Minjin Kwon, Geoffrey Hasker, Adrian Perrig |
AsiaCCS | 1 |
| 2007 | Human Identification Through Image Evaluation Using Secret Predicates
Hassan Jameel, Riaz Ahmed Shaikh 0001, Heejo Lee, Sungyoung Lee 0001 |
CT-RSA | 3 |
| 2007 | A Privacy Preserving Access Control Scheme using Anonymous Identification for Ubiquitous EnvironmentsabstractCompared to all emerging issues, privacy is probably the most prominent concern when it comes to judging the effects of a wide spread deployment of ubiquitous computing. On one hand, service providers want to authenticate legitimate users and make sure they are accessing their authorized services in a legal way. On the other hand, users prefer not to expose any sensitive information to anybody. They want to have complete control on their personal data, without being tracked down for wherever they are, whenever and whatever they do. In this paper, we introduce an anonymous identification authentication and access control scheme to secure interactions between users and services in ubiquitous environments. The scheme uses anonymous user ID, sensitive data sharing method, and account management to provide a lightweight authentication while keeping users anonymously interacting with the services in a secure and flexible way. Nguyen Ngoc Diep, Sungyoung Lee 0001, Young-Koo Lee, Heejo Lee |
RTCSA | 4 |
| 2007 | Activity-based Access Control Model to Hospital InformationabstractHospital work is characterized by the need to manage multiple activities simultaneously, constant local mobility, frequently interruptions, and intense collaboration and communication. Hospital employees must handle a large amount of data that is often tied to specific work activities. This calls for a proper access control model. In this paper, we propose a novel approach, activity-based access control model (ACM). Unlike conventional approaches which exploit user identity/role information, ACM leverages user's activities to determine the access permissions for that user. In ACM, a user is assigned to perform a number of actions if s/he poses a set of satisfactory attributes. Access permissions to hospital information are granted according to user's actions. By doing this, ACM contributes a number of advantages over conventional models: (1) facilitates user's work; (2) reduces complexity and cost of access management. Though the design of ACM first aims to support clinical works in hospitals, it can be applied in other activity-centered environments. Le Xuan Hung, Sungyoung Lee 0001, Young-Koo Lee, Heejo Lee |
RTCSA | 4 |
| 2007 | A password stretching method using user specific saltsabstractIn this paper, we present a password stretching method using user specific salts. Our scheme takes similar time to stretch a password as recent password stretching algorithms, but the complexity of a pre-computation attack increases by 10^8 times and the storage required to store the pre-computation result increases by 10^8 times. ChangHee Lee, Heejo Lee |
WWW | 2 |
| 2007 | 100+ VoIP Calls on 802.11b: The Power of Combining Voice Frame Aggregation and Uplink-Downlink Bandwidth Control in Wireless LANsabstractThe bandwidth efficiency of voice over IP (VoIP) traffic on the IEEE 802.11 WLAN is notoriously low. VoIP over 802.11 incurs high bandwidth cost for voice frame packetization and MAC/PHY framing, which is aggravated by channel access overhead. For instance, 10 calls with the G.729 codec can barely be supported on 802.11b with acceptable QoS - less than 2% efficiency. As WLANs and VoIP services become increasingly widespread, this inefficiency must be overcome. This paper proposes a solution that boosts the efficiency high enough to support a significantly larger number of calls than existing schemes, with fair call quality. The solution comes in two parts: adaptive frame aggregation and uplink/downlink bandwidth equalization. The former reduces the absolute number of MAC frames according to the link congestion level, and the latter balances the bandwidth usage between the access point (AP) and wireless stations. When used in combination, they yield superior performance, for instance, supporting more than 100 VoIP calls over an IEEE 802.11b link. The authors demonstrate the performance of the proposed approach through extensive simulation, and validate the simulation through analysis. Sangki Yun, Heejo Lee, Inhye Kang |
IEEE J. Sel. Areas Commun. | 3 |
| 2006 | A Simple Congestion-Resilient Link Adaptation Algorithm for IEEE 802.11 WLANsabstractAlgorithmic approach to link adaptation for IEEE 802.11 networks such as Automatic Rate Fallback (ARF) is known to suffer from the inability to differentiate between collision and channel-induced error. In this paper, we propose a novel algorithm called COLA that overcomes the shortcoming and achieves near-optimal throughput over wide range of channel and load conditions. The result is significant since the throughput is achieved without any hardware support. Moreover, COLA does not require any optional or extra-protocol mechanisms support, either, such as RTS/CTS exchange, Clear Channel Assessment (CCS), and promiscuous channel monitoring. Finally, the COLA algorithm has a short critical path of just 10 instructions, and it is free of heuristic parameters, which will facilitate practical use. Sangki Yun, Heejo Lee, Inhye Kang, Kyu-Young Choi |
GLOBECOM | 3 |
| 2006 | On the Cross-Layer Impact of TCP ACK Thinning on IEEE 802.11 Wireless MAC DynamicsabstractACK thinning refers to the technique to discard or reduce TCP acknowledgements (ACKs) for the purpose of diverting scarce bandwidth to TCP data traffic. Delayed ACK and ACK filtering fall into the category. It has been shown that under some circumstances the technique is effective to boost the TCP throughput on wireless links, in particular the IEEE 802.11 wireless LAN (WLAN). In this paper, however, we show that ACK thinning backfires under congestion due to its cross-layer impact on the 802.11 MAC dynamics. With the ACK filtering example, we demonstrate the phenomenon and analyze the cause. Based on the analysis, we show how the IEEE 802.11 contention window size control solves the problem. Although only the ACK filtering and Delayed ACK are considered in this paper, any other techniques to save on TCP ACK bandwidth usage share the same fundamental issues. Heejo Lee, Sangmin Shin, Inhye Kang |
VTC Fall | 2 |
| 2006 | Improving VoIP Call Capacity of Multi-Hop Wireless Networks through Self-Controlled Frame AggregationabstractIn multi-hop wireless networks, the number of supportable VoIP calls can be surprisingly small due to the increased spatial interference. To mitigate the interference, voice frame aggregation can be used. In this paper, we depart from the traditional approaches that perform aggregation at the voice source, and propose a technique called the self-controlled frame aggregation (SCFA) that runs at wireless routers. The core idea of SCFA is to let the congestion itself control the degree of aggregation. Unlike existing frame aggregation approaches, SCFA does not incur fixed delay cost, since it is used only when and by exactly as much as it is needed. In this paper, we take the example of 802.11-based multi-hop network to show the impact of SCFA, since many emerging multi-hop networks are built on the 802.11 technology. The result shows that SCFA on 802.11-based multi-hop network can boost the number of calls approximately twofold, or extends the hop distance threefold for a given number of calls to carry. Sangki Yun, Heejo Lee, Inhye Kang |
VTC Fall | 3 |
| 2005 | PCAV: Internet Attack Visualization on Parallel Coordinates
Hyunsang Choi, Heejo Lee |
ICICS | 2 |
| 2005 | Defending a Web Browser Against Spying with Browser Helper Objects
Beomsoo Park, Sungjin Hong, Jaewook Oh, Heejo Lee |
ISI | 4 |
| 2004 | A connection management protocol for stateful inspection firewalls in multi-homed networksabstractTo provide network services consistently under various network failures, enterprise networks increasingly utilize path diversity through multi-homing. As a result, multi-homed non-transit autonomous systems (ASes) has surpassed the single-homed networks in number. In this paper, we address an inevitable problem that occurs when networks with multiple entry points deploy stateful inspection firewalls in their borders. In this paper, we formulate this phenomenon into a state-sharing problem among multiple firewalls under the asymmetric routing condition. To solve this problem, we propose a stateful inspection protocol that requires a very low processing and messaging overhead. Our protocol consists of the following two phases: 1) generation of a TCP SYN cookie marked with the firewall identification number upon a SYN packet arrival, and 2) state sharing triggered by a SYN/ACK packet arrival in the absence of the trail of its initial SYN packet. We demonstrate that our protocol is scalable, robust, and simple enough to be deployed for high speed networks. It also transparently works under any client-server configurations. Last but not the least, we present the experimental results through a prototype implementation. Saewoong Bahk, Heejo Lee |
ICC | 3 |
| 2004 | Attack Resiliency of Network Topologies
Heejo Lee, Jong Kim 0001 |
PDCAT | 1 |
| 2003 | Task scheduling using a block dependency DAG for block-oriented sparse Cholesky factorization
Heejo Lee, Jong Kim 0001, Sung Je Hong, Sunggu Lee |
Parallel Comput. | 1 |
| 2003 | Processor Allocation and Task Scheduling of Matrix Chain Products on Parallel SystemsabstractThe problem of finding an optimal product sequence for sequential multiplication of a chain of matrices (the matrix chain ordering problem, MCOP) is well-known. We consider the problem of finding an optimal product schedule for evaluating a chain of matrix products on a parallel computer (the matrix chain scheduling problem, MCSP). The difference between MCSP and MCOP is that MCOP pertains to a product sequence for single processor systems and MCSP pertains to a sequence of concurrent matrix products for parallel systems. The approach of parallelizing each matrix product after finding an optimal product sequence for single processor systems does not always guarantee minimum evaluation time on parallel systems since each parallelized matrix product may use processors inefficiently. We introduce a new processor scheduling algorithm for MCSP which reduces the evaluation time of a chain of matrix products on a parallel computer, even at the expense of a slight increase in the total number of operations. Given a chain of n matrices and a matrix product utilizing at most P/k processors in a P-processor system, the proposed algorithm approaches k(n-1)/(n+klog(k)-k) times the performance of parallel evaluation using the optimal sequence found for MCOP. Experiments performed on a Fujitsu AP1000 multicomputer also show that the proposed algorithm significantly decreases the time required to evaluate a chain of matrix products in parallel systems. Heejo Lee, Jong Kim 0001, Sung Je Hong, Sunggu Lee |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2001 | On the Effectiveness of Probabilistic Packet Marking for IP Traceback under Denial of Service AttackabstractEffective mitigation of denial of service (DoS) attack is a pressing problem on the Internet. In many instances, DoS attacks can be prevented if the spoofed source IP address is traced back to its origin which allows assigning penalties to the offending party or isolating the compromised hosts and domains from the rest of the network. IP traceback mechanisms based on probabilistic packet marking (PPM) have been proposed for achieving traceback of DoS attacks. We show that probabilistic packet marking-of interest due to its efficiency and implementability vis-a-vis deterministic packet marking and logging or messaging based schemes-suffers under spoofing of the marking field in the IP header by the attacker which can impede traceback by the victim. We show that there is a trade-off between the ability of the victim to localize the attacker and the severity of the DoS attack, which is represented as a function of the marking probability, path length, and traffic volume. The optimal decision problem-the victim can choose the marking probability whereas the attacker can choose the spoofed marking value, source address, and attack volume-can be expressed as a constrained minimax optimization problem, where the victim chooses the marking probability such that the number of forgeable attack paths is minimized. We show that the attacker's ability to hide his location is curtailed by increasing the marking probability, however, the latter is upper-bounded due to sampling constraints. In typical IP internets, the attacker's address can be localized to within 2-5 equally likely sites which renders PPM effective against single source attacks. Under distributed DoS attacks, the uncertainty achievable by the attacker can be amplified, which diminishes the effectiveness of PPM. Heejo Lee, Kihong Park |
INFOCOM | 1 |
| 2001 | On the effectiveness of route-based packet filtering for distributed DoS attack prevention in power-law internetsabstractDenial of service (DoS) attack on the Internet has become a pressing problem. In this paper, we describe and evaluate route-based distributed packet filtering (DPF), a novel approach to distributed DoS (DDoS) attack prevention. We show that DPF achieves proactiveness and scalability, and we show that there is an intimate relationship between the effectiveness of DPF at mitigating DDoS attack and power-law network topology.The salient features of this work are two-fold. First, we show that DPF is able to proactively filter out a significant fraction of spoofed packet flows and prevent attack packets from reaching their targets in the first place. The IP flows that cannot be proactively curtailed are extremely sparse so that their origin can be localized---i.e., IP traceback---to within a small, constant number of candidate sites. We show that the two proactive and reactive performance effects can be achieved by implementing route-based filtering on less than 20% of Internet autonomous system (AS) sites. Second, we show that the two complementary performance measures are dependent on the properties of the underlying AS graph. In particular, we show that the power-law structure of Internet AS topology leads to connectivity properties which are crucial in facilitating the observed performance effects. Kihong Park, Heejo Lee |
SIGCOMM | 2 |
| 1997 | Replicated Process Allocation for Load Distribution in Fault-Tolerant MulticomputersabstractIn this paper, we consider a load-balancing process allocation method for fault-tolerant multicomputer systems that balances the load before as well as after faults start to degrade the performance of the system. In order to be able to tolerate a single fault, each process (primary process) is duplicated (i.e., has a backup process). The backup process executes on a different processor from the primary, checkpointing the primary process and recovering the process in the primary process fails. In this paper, we formalize the problem of load-balancing process allocation and propose a new process allocation method and analyze the performance of the proposed method. Simulations are used to compare the proposed method with a process allocation method that does not take into account the different load characteristics of the primary and backup processes. While both methods perform well before the occurrence of a fault, only the proposed method maintains a balanced load after the occurrence of such a fault. Jong Kim 0001, Heejo Lee, Sunggu Lee |
IEEE Trans. Computers | 2 |