VLDB 2026 Research / reviewers in the wild / expert
Huy Kang Kim
dblp:82/7427
· DBLP profile ↗
57ranked-venue papers
1as first author
26since 2021 · last 2026
0000-0002-0760-8807ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 15 since 2021Artificial intelligence and machine learning · 8 · 1 first-author · 4 since 2021Computer networks · 8 · 3 since 2021Software engineering, systems software and programming languages · 6 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Databases, data management, data science and information retrieval · 4Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LUMI: Lightweight UAVCAN Message Window-Based Intrusion Detection System
Yuchan Song, Huy Kang Kim |
IV | 2 |
| 2026 | Vehicle-RNA: Reverse Engineering With Dynamic Time Warping for Automotive ProtocolabstractAs modern vehicles evolve and offer advanced functions managed by numerous ECUs, the potential for security threats increases due to the presence of expanded threat surfaces. Although research into Intrusion Detection Systems (IDS) and automotive fuzzing has progressed, such systems often rely on publicly available CAN data because proprietary CAN DBCs limit access to essential information. This hampers the ability to counter sophisticated attacks, highlighting the need for precise mapping of CAN IDs and payloads. CAN reverse engineering is crucial but is challenged by time-consuming manual analysis and incomplete PID information. To overcome these limitations, we propose theVehicle-RNA framework, which employs machine learning and dynamic time warping to automate the identification of CAN ID functions. TheVehicle-RNA framework is particularly effective in scenarios with limited data, achieving an F1-score of 0.9388 and accurately identifying 10 CAN IDs previously unanalyzed byOpenDBC, which represents a significant advancement in automotive cybersecurity. Huy Kang Kim, Sanghoon Jeon 0004 |
IEEE Internet Things J. | 2 |
| 2026 | J1939DB-IDS: SAE J1939 Dual-Branch Intrusion Detection System Against Novel Attacks
Hwejae Lee, Seonghoon Jeong 0001, Huy Kang Kim |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Threat Hunting and Security Analysis for Maritime VesselsabstractThe growing reliance on digital technologies onboard vessels has significantly increased their attack surface. As a result, both IT and OT systems are now vulnerable to a range of cyberattacks. However, existing methods used to assess vulnerability and threats often rely on outdated threat or vulnerability information, limiting their effectiveness. Consequently, a more proactive approach to assessing the security of vessel systems is needed. Threat hunting offers a proactive way of gathering the latest threat and vulnerability data from operational maritime vessels, which can be used for comprehensive security assessments. However, there is a lack of systems specifically designed to perform both threat-hunting and security assessment operations. In this paper, we propose a threat-hunting and security assessment framework that collects and processes real-time data from vessels and conducts security analysis using a graphical security model designed for vessel systems. Our approach demonstrates how the collected information can be used to evaluate a ship’s security posture by simulating potential attack scenarios and understanding how an adversary might attempt to compromise the vessel’s network. It also provides a foundation for more informed, data-driven cybersecurity strategies for the unique systems found onboard maritime vessels. Simon Yusuf Enoch, Hyunjae Kang 0001, Huy Kang Kim, Dong Seong Kim 0001 |
LCN | 3 |
| 2025 | Automated Timeline-Based Forensic Report Generation with Anomaly Detection and LLM-Based CTI MappingabstractDiverse vehicle forensics and in-vehicle intrusion detections researches are effectively adopted to the vehicle domain. However, known vehicle forensic researches rarely comprise outputs that are directly usable for investigators; outputs can ideally be auditable, mapped with Cyber Threat Intelligence (CTI), and presented as a timeline-driven incident report. This gap between research outputs and practical requirements creates tangible difficulties in real-world investigations. When forensic analysis fails to yield usable results, investigators must revert to manual spreadsheets and makeshift documents, increasing time and operational costs. Furthermore, even when connections between evidence are established, improper structuring of the attack, such as failing to build a coherent timeline, compromises traceability. To address these challenges of manual analysis and inadequate traceability, we propose a DataBase CAN (DBC)-independent vehicle forensics framework. First, the framework processes raw data by reconciling clocks, normalizing multi-source evidence, and segmenting attacks into episodes using Isolation Forest and change-point detection. Finally, it utilizes a small LLM integrated with the Threat Report ATT&CK Mapper (TRAM) and Automotive Information Sharing and Analysis Center (Auto- ISAC) Automotive Threat Matrix (ATM) to automatically generate CTI-mapped, evidence-linked timeline reports. To demonstrate the robustness and versatility of our framework, we validated it against three diverse public datasets: the VeReMi dataset, the HCRL Car-Hacking dataset, and the OTIDS dataset. Our evaluation focused on three key metrics: timeline fidelity, detection and segmentation quality, and CTI mapping accuracy. The results confirmed that the framework successfully generates systematic reports, organizing observed attacks into evidence-linked timelines with CTI mappings. This approach enhances auditability and traceability, reduces the time to report, and ultimately makes the findings directly actionable for investigators. Yongsik Kim, Saehee Jun, Junho Jang, Huy Kang Kim |
PRDC | 4 |
| 2025 | GALAXY: Generalized Attention-Based LSTM Architecture with External Query for Intrusion Detection in UAV CommunicationabstractUnmanned Aerial Vehicles (UAVs) rely on wireless communication with a Ground Control Station (GCS) for flight control, primarily using the Micro Air Vehicle Link (MAVLink) protocol. However, MAVLink lacks essential security mecha-nisms, making UAVs vulnerable to attacks. We introduce a stealthy relay-based Man-in-the-Middle (MITM) attack called Shadow-GCS, in which an unauthorized node relays MAVLink messages to maintain normal communication while injecting commands. The Shadow-GCS attack enables an adversary to monitor and control UAV s without triggering alerts at the GCS. To assess the attack's detectability, we collected a dataset from four realistic UAV-GCS scenarios. We then evaluated two existing MAVLink intrusion detection systems (IDSs), revealing their limitations in identifying attacks that do not significantly alter normal communication flow. To overcome these limitations and develop a more generalized intrusion detection capability, we propose GALAXY, an attention-based LSTM model with a single LSTM layer, where the attention weights are jointly derived from the hidden state and local statistical features. Experimental results show that GALAXY achieves detection performance comparable to a stacked LSTM baseline while offering improved interpretability. Jae Yeon Lee, Huy Kang Kim |
PRDC | 2 |
| 2025 | An Approach to Creating the Optimal Attack Path Based on Reinforcement LearningabstractBotnet attacks pose persistent security threats in IoT networks by sequentially infecting devices to create zombie networks for DDoS attacks. Analyzing botnet propagation requires approaches that consider entire system traversal rather than isolated targets. We propose a reinforcement learning-based model that identifies optimal attack paths from an attacker's perspective. Our approach employs Graph Attention Networks (GAT) to analyze network structure and trains using policy gradient techniques to select high-vulnerability nodes during exploration. We implemented a depth-first search algorithm with branch tracking that reflects realistic attacker behavior, evaluating neighbors based on Common Vulnerability Scoring System (CVSS) scores and maximizing cumulative vulnerability scores as rewards. Experimental validation on the UNSW IoT traffic dataset demonstrates effective identification of vulnerability-based attack paths. The model successfully reconstructed network topologies by eliminating non-essential edges while retaining critical paths, providing actionable intelligence for defensive resource allocation. Results show our approach effectively discovers high-risk paths by jointly considering node connectivity and vulnerability scores in realistic IoT environments. Hyo Sun Lee, Min Geun Song, Huy Kang Kim |
PRDC | 3 |
| 2025 | Robustness Evaluation Under RGB-Camera Attacks in CARLA: A Systematic Evaluation of Color Modes and Attack TypesabstractThe robustness of YOLOv5-based camera perception for autonomous driving was systematically evaluated under diverse visual perturbations and spectral configurations using the CARLA simulation environment. An agent-camera framework decoupled perception from vehicle control, enabling consistent testing across 20 configurations and 200 trials (104,231 frames) covering four color modes (RGB, red, green, blue) and five perturbation types (salt-and-pepper noise, Gaussian noise, blur, contrast enhancement, baseline). Results revealed counterintuitive robustness patterns: contrast enhancement and green-channel filtering each improved detection by 37%, while salt-and-pepper noise caused an 83% degradation. The optimal combination-red filtering with contrast enhancement-yielded a 42% gain, demonstrating synergistic effects between spectral and photometric factors. However, confidence scores remained nearly constant (0.55-0.65 range) despite large accuracy fluctuations, indicating that confidence-based monitoring fails to reflect true perception reliability. These findings highlight that lightweight spectral filtering and contrast optimization can enhance perception robustness, while safe deployment requires complementary reliability modeling and sensor redundancy to ensure dependable autonomous vision. Yufeng Lin, Hyunjae Kang 0001, Huy Kang Kim, Dong Seong Kim 0001 |
PRDC | 4 |
| 2025 | Toward Dependability Simulation for Intelligent Transportation Systems in Connected Vehicle EnvironmentsabstractThe Intelligent Transportation System for Connected Vehicles (ITS for CV) integrates diverse assets such as vehicles, unmanned aerial vehicles (UAVs), roadside units (RSUs), and central servers to improve traffic efficiency and public safety via real-time communication and coordination. However, increased interconnectivity introduces potential vulnerabilities across communication, control, and sensing layers, making it challenging to assess system-level mission impacts against cyber-physical attacks. This paper presents a simulation-based framework to evaluate dynamic attack-defense interactions. The proposed framework integrates threat database construction, scenario modeling, simulation environment development, and impact-based evaluation to enable quantitative assessment of mission degradation. Current progress includes the development of a simulator-integrated testbed, and mapping of attack and defense techniques to standardized frameworks. Future work will focus on autonomous attacker and defender agent training using deep reinforcement learning and hardware-in-the-loop (HIL) validation for real-world applicability. Saehoon Oh, Gang Min Kim, Huy Kang Kim |
PRDC | 4 |
| 2025 | MeNU: Memorizing normality for UAV anomaly detection with a few sensor values
Jeong Do Yoo, Gang Min Kim, Min Geun Song, Huy Kang Kim |
Comput. Secur. | 4 |
| 2024 | Benzene: A Practical Root Cause Analysis System with an Under-Constrained State MutationabstractFuzzing has demonstrated great success in bug discovery, and plays a crucial role in software testing today. Despite the increasing popularity of fuzzing, automated root cause analysis (RCA) has drawn less attention. One of the recent advances in RCA is crash-based statistical debugging, which leverages the behavioral differences in program execution between crash-triggered and non-crashing inputs. Hence, obtaining non-crashing behaviors close to the original crash is crucial but challenging with previous approaches (e.g., fuzzing). In this paper, we present Benzene, a practical end-to-end RCA system that facilitates an automated crash diagnosis. To this end, we introduce a novel technique, called under-constrained state mutation, that generates both crashing and non-crashing behaviors for effective and efficient RCA. We design and implement the Benzene prototype, and evaluate it with 60 vulnerabilities in the wild. Our empirical results demonstrate that Benzene not only surpasses in performance (i.e., root cause ranking), but also achieves superior results in both speed (4.6 times faster) and memory footprint (31.4 times less) on average than prior approaches. Younggi Park, Hwiwon Lee, Hyungjoon Koo, Huy Kang Kim |
SP | 5 |
| 2024 | GUIDE: GAN-based UAV IDS Enhancement
Jeong Do Yoo, Haerin Kim, Huy Kang Kim |
Comput. Secur. | 3 |
| 2024 | AERO: Automotive Ethernet Real-Time Observer for Anomaly Detection in In-Vehicle NetworksabstractAutomotive Ethernet enables high-bandwidth in-vehicle networking, facilitating the transmission of sensor data among electronic control units. However, the increasing connectivity and potential vulnerability inheritance in connected and autonomous vehicles expose them to security risks. To address this challenge, an intrusion detection system (IDS) capable of analyzing automotive Ethernet traffic and detecting anomalies is essential. In thisarticle, we propose automotive Ethernet real-time observer (AERO), an unsupervised network IDS designed to protect in-vehicle networks. AERO consists of three components: a feature extractor that constructs three multimodal features, a neural network for processing the extracted features, and an online anomaly detector that calculates outlier scores in real time. We evaluate the performance of AERO using the TOW-IDS automotive Ethernet intrusion dataset. The experimental results demonstrate that AERO achieves high detection performance across five different attack types and is highly applicable to automotive-grade devices for real-time anomaly detection. Seonghoon Jeong 0001, Huy Kang Kim, Mee Lan Han, Byung Il Kwak |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | Infotainment System Matters: Understanding the Impact and Implications of In-Vehicle Infotainment System Hacking with Automotive Grade LinuxabstractAn in-vehicle infotainment (IVI) system is connected to heterogeneous networks such as Controller Area Network bus, Bluetooth, Wi-Fi, cellular, and other vehicle-to-everything communications. An IVI system has control of a connected vehicle and deals with privacy-sensitive information like current geolocation and destination, phonebook, SMS, and driver's voice. Several offensive studies have been conducted on IVI systems of commercialized vehicles to show the feasibility of car hacking. However, to date, there has been no comprehensive analysis of the impact and implications of IVI system exploitations. To understand security and privacy concerns, we provide our experience hosting an IVI system hacking competition, Cyber Security Challenge 2021 (CSC2021). We use a feature-flavored infotainment operating system, Automotive Grade Linux (AGL). The participants gathered and submitted 33 reproducible and verified proofs-of-concept exploit codes targeting 11 components of the AGL-based IVI testbed. The participants exploited four vulnerabilities to steal various data, manipulate the IVI system, and cause a denial of service. The data leakage includes privacy, personally identifiable information, and cabin voice. The participants proved lateral movement to electronic control units and smartphones. We conclude with lessons learned with three mitigation strategies to enhance the security of the IVI system. Seonghoon Jeong 0001, Minsoo Ryu, Hyunjae Kang 0001, Huy Kang Kim |
CODASPY | 4 |
| 2023 | TOW-IDS: Intrusion Detection System Based on Three Overlapped Wavelets for Automotive EthernetabstractDevices that ensure vehicle and driver safety or provide services to drivers generate a substantial amount of network traffic. The traffic is transmitted to the In-Vehicle Network (IVN) depending on the defined function. Consequently, to quickly process a lot of traffic transmitted to the IVN, an advanced network protocol such as Automotive Ethernet is necessary. However, owing to the connectivity reinforcement between devices inside a vehicle and external networks, attack vectors and vulnerabilities can be easily inherited from an established Ethernet to Automotive Ethernet. The present study proposes a method for detecting and identifying abnormalities in Automotive Ethernet based on wavelet transform and deep convolutional neural network. First, we define attack scenarios and extract normal and abnormal data corresponding to these scenarios. Second, we conduct several preprocesses, such as fixing the packet size and normalizing the network image data. Finally, we conduct extensive evaluations of the proposed method’s performance, considering the size of network image data and multi-resolution levels. The results demonstrate that the proposed method can effectively detect an abnormality. Furthermore, the results suggest that the our method is more effective in terms of time-cost compared to default ResNet and EfficientNet methods. Mee Lan Han, Byung Il Kwak, Huy Kang Kim |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Unsupervised malicious domain detection with less labeling effort
Kyung Ho Park, Hyun Min Song, Jeong Do Yoo, Su-Youn Hong, Byoungmo Cho, Huy Kang Kim |
Comput. Secur. | 7 |
| 2022 | Action2Score: An Embedding Approach to Score Player ActionabstractMultiplayer Online Battle Arena (MOBA) is one of the most successful game genres. MOBA games such as League of Legends have competitive environments where players race for their rank. In most MOBA games, a player's rank is determined by the match result (win or lose). It seems natural because of the nature of team play, but in some sense, it is unfair because the players who put a lot of effort lose their rank just in case of loss and some players even get free-ride on teammates' efforts in case of a win. To reduce the side-effects of the team-based ranking system and evaluate a player's performance impartially, we propose a novel embedding model that converts a player's actions into quantitative scores based on the actions' respective contribution to the team's victory. Our model is built using a sequence-based deep learning model with a novel loss function working on the team match. We showed that our model can evaluate a player's individual performance fairly and analyze the contributions of the player's respective actions. Junho Jang, Huy Kang Kim |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | Trading Behind-the-Scene: Analysis of Online Gold Farming Network in the Auction House SystemabstractOwing to the widespread use of smartphones, various online games based on mobile platforms are being launched. Although mobile games have the advantage of better accessibility compared to PC games, there is a limitation in that it is difficult to input specific actions. To overcome this limitation, game companies apply autoplay systems to support users. Autoplay (with macro or game bot programs) without human interaction was previously regarded as a cheating play. To provide a more comfortable and easy gaming experience to users, most mobile games currently provide autoplay functionality. Such introduction means that along with gold farming groups (GFGs), all users can use a game bot. Therefore, game companies prevent profit-producing activities of GFGs by introducing an in-game economic system in which a real money trading (RMT) is impossible. However, GFGs still operate by abusing an auction house. Our study uses the three-month transaction logs of a mobile game that introduces an auction house as an in-game economic system. We observe the abuse that makes RMTs possible through the auction house and propose a method of identifying abuse solely through a transaction log. We analyzed the GFGs using the identified abuse and confirmed that the GFG consists of a single role. Yuseung Noh, Seonghoon Jeong 0001, Huy Kang Kim |
IEEE Trans. Games | 3 |
| 2021 | Understand Watchdogs: Discover How Game Bot Get DiscoveredabstractThe game industry has long been troubled by malicious activities utilizing game bots. The game bots disturb other game players and destroy the environmental system of the games. For these reasons, the game industry put their best efforts to detect the game bots among players' characters using the learning-based detections. However, one problem with the detection methodologies is that they do not provide rational explanations about their decisions. To resolve this problem, in this work, we investigate the explainabilities of the game bot detection. We develop the XAI model using a dataset from the Korean MMORPG, AION, which includes game logs of human players and game bots. More than one classification model has been applied to the dataset to be analyzed by applying interpretable models. This provides us explanations about the game bots' behavior, and the truthfulness of the explanations has been evaluated. Besides, interpretability contributes to minimizing false detection, which imposes unfair restrictions on human players. Eunji Park, Kyung Ho Park, Huy Kang Kim |
ICAART (2) | 3 |
| 2021 | Traffic Accident Recognition in First-Person Videos by Learning a Spatio-Temporal Visual PatternabstractA camera-based perception of dangerous road situations such as traffic accidents is a significant task in modern autonomous driving and ADAS. The previous approaches have scrutinized a spatio-temporal characteristics of the traffic accident in a sequence of images. However, we figured out the limit of past works that the aforementioned spatio-temporal pattern is only considered in 2D manner, which loses a contextual knowledge of the road situation in 3D space where the accident actually happens. In this study, we propose a novel approach to learn a spatio-temporal pattern of traffic accidents in a sequence of traffic scene images. First, we designed a spatial feature extractor that illustrates the distance among traffic objects in a 3D manner, which contextually describes the road situation better by considering traffic objects’ location with their depth information. Second, we proposed an accident detection model and examined the model identified traffic accidents with 0.8560 accuracy and a 0.9080 F1 score. Lastly, we suggested an accident anticipation model, and it outperformed the previously-proposed benchmark anticipation model in a challenging task. We expect further improvement of our approach can contribute to the safe vehicular technology for autonomous driving and ADAS development. Kyung Ho Park, Dong Hyun Ahn, Huy Kang Kim |
VTC Spring | 3 |
| 2021 | AutoVAS: An automated vulnerability analysis system with a deep learning approach
Sanghoon Jeon 0004, Huy Kang Kim |
Comput. Secur. | 2 |
| 2021 | TZMon: Improving mobile game security with ARM trustzone
Sanghoon Jeon 0004, Huy Kang Kim |
Comput. Secur. | 2 |
| 2021 | Cybersecurity for autonomous vehicles: Review of attacks and defense
Kyounggon Kim, Jun Seok Kim, Seonghoon Jeong 0001, Jo-Hee Park, Huy Kang Kim |
Comput. Secur. | 5 |
| 2021 | Cosine similarity based anomaly detection methodology for the CAN bus
Byung Il Kwak, Mee Lan Han, Huy Kang Kim |
Expert Syst. Appl. | 3 |
| 2021 | Event-Triggered Interval-Based Anomaly Detection and Attack Identification Methods for an In-Vehicle NetworkabstractVehicle communication technology has been steadily progressing alongside the convergence of the in-vehicle network (IVN) and wireless communication technology. The communication with various external networks further reinforces the connectivity between the inside and outside of a vehicle. However, this bears risks of malicious packet attacks on computer-assisted mechanical mechanisms that are capable of hijacking the vehicle's functions. The present study proposes a method to detect and identify abnormalities in vehicular networks based on the periodic event-triggered interval of the controller area network (CAN) messages. To this end, we first define four attack scenarios and then extract normal and abnormal driving data corresponding to these scenarios. Next, we analyze the CAN ID's event-triggered interval and measure statistical moments depending on the defined time-window. Finally, we conduct extensive evaluations of the proposed methods' performance by considering different attack scenarios and three types of machine learning models. The results demonstrate that the proposed method can effectively detect an abnormality in the IVN, with up to 99% accuracy. Our results suggest that when tree-based machine learning models are used as the classifier, the proposed method of attack identification can achieve more than 94% accuracy. Mee Lan Han, Byung Il Kwak, Huy Kang Kim |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Driver Identification Based on Wavelet Transform Using Driving PatternsabstractThe modern automotive system, based on the convergence of information and communication technologies, is equipped with various functions to ensure vehicle safety and convenience of the driver. A driver-identification technology is an effective method to perform vehicle-theft detection. It can also provide customized driver-personalization services, such as healthcare or insurance. In this article, we propose and evaluate a driver-identification method based on wavelet transform by performing driving-pattern analysis for each driver. We compare the performances of three different machine-learning algorithms, namely Support Vector Machine (SVM), Random Forest, and XGBoost for performing driver identification. The proposed method is applicable to both binary and multiclass classifications for the driving data of five drivers. In the case of motorway, the XGBoost classifier identifies each driver and delivers an accuracy of up to 96.18% in binary classification and an accuracy of 91.6% in multiclass classification. Moreover, in the case of an urban road, the SVM classifier achieves an accuracy of up to 95.07% in binary classification and accuracy of 89.06% in multiclass classification. The proposed method provides a context for a better understanding of the association between driver behavior, which is an in-vehicle event, and mechanical reactions. Our results shall help researchers to broaden the understanding of driver identification using in-vehicle data. Byung Il Kwak, Mee Lan Han, Huy Kang Kim |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | De-Wipimization: Detection of data wiping traces for investigating NTFS file system
Dong Bin Oh, Kyung Ho Park, Huy Kang Kim |
Comput. Secur. | 3 |
| 2020 | CAN-ADF: The controller area network attack detection framework
Shahroz Tariq, Sangyup Lee, Huy Kang Kim, Simon S. Woo |
Comput. Secur. | 3 |
| 2020 | What's your protocol: Vulnerabilities and security threats related to Z-Wave protocol
Kyounggon Kim, Kiyoon Cho, Jihwan Lim, Young Ho Jung, Min Seok Sung, Seong Beom Kim, Huy Kang Kim |
Pervasive Mob. Comput. | 7 |
| 2020 | Beyond PS-LTE: Security Model Design Framework for PPDR Operational EnvironmentabstractNational disasters can threaten national security and require several organizations to integrate the functionalities to correspond to the event. Many countries are constructing a nationwide mobile communication network infrastructure to share information and promptly communicate with corresponding organizations. Public Safety Long-Term Evolution (PS-LTE) is a communication mechanism adopted in many countries to achieve such a purpose. Organizations can increase the efficiency of public protection and disaster relief (PPDR) operations by securely connecting the services run on their legacy networks to the PS-LTE infrastructure. This environment allows the organizations to continue facilitating the information and system functionalities provided by the legacy network. The vulnerabilities in the environment, which differ from commercial LTE, need to be resolved to connect the network securely. In this study, we propose a security model design framework to derive the system architecture and the security requirements targeting the restricted environment applied by certain technologies for a particular purpose. After analyzing the PPDR operation environment’s characteristics under the PS-LTE infrastructure, we applied the framework to derive the security model for organizations using PPDR services operated in their legacy networks through this infrastructure. Although the proposed security model design framework is applied to the specific circumstance in this research, it can be generally adopted for the application environment. Daegeon Kim, Do Hyung Gu, Huy Kang Kim |
Secur. Commun. Networks | 3 |
| 2020 | Profit Optimizing Churn Prediction for Long-Term Loyal Customers in Online GamesabstractTo successfully operate online games, gaming companies are introducing the systematic customer relationship management model. Particularly, churn analysis is one of the most important issues, because preventing a customer from churning is often more cost-efficient than acquiring a new customer. Churn prediction models should, thus, consider maximizing not only accuracy but also the expected profit derived from the churn prevention. We, thus, propose a churn prediction method for optimizing profit consisting of two main steps: first, selecting prediction target, second, tuning threshold of the model. In online games, the distribution of a user's customer lifetime value is very biased that a few users contribute to most of the sales, and most of the churners are no-paying users. Consequently, it is cost-effective to focus on churn prediction to loyal customers who have sufficient benefits. Furthermore, it is more profitable to adjust the threshold of the prediction model so that the expected profit is maximized rather than maximizing the accuracy. We applied the proposed method to real-world online game service, Aion, one of the most popular online games in South Korea, and then show that our method has more cost-effectiveness than the prediction model for total users when the campaign cost and the conversion rate are considered. Eunjo Lee, Boram Kim, Sungwook Kang 0001, Byung-Soo Kang, Yoonjae Jang, Huy Kang Kim |
IEEE Trans. Games | 6 |
| 2019 | FuzzBuilder: automated building greybox fuzzing environment for C/C++ libraryabstractFuzzing is an effective method to find bugs in software. Many security communities are interested in fuzzing as an automated approach to verify software security because most of the bugs discovered by fuzzing are related to security vulnerabilities. However, not all software can be tested by fuzzing because fuzzing requires a running environment, especially an executable. Notably, in the case of libraries, most of the libraries do not have a relevant executable in practice. Thus, state-of-the-art fuzzers have a limitation to test an arbitrary library. To overcome this problem, we propose FuzzBuilder to provide an automated fuzzing environment for libraries. FuzzBuilder generates an executable that calls library API functions to enable library fuzzing. Moreover, any executable generated by FuzzBuilder is compatible with existing fuzzers such as AFL. We evaluate the overall performance of FuzzBuilder by testing open source libraries. Consequently, we discovered unknown bugs in libraries while achieving high code coverage. We believe that FuzzBuilder helps security researchers to save both setup cost and learning cost for library fuzzing. Joonun Jang, Huy Kang Kim |
ACSAC | 2 |
| 2019 | CBR-Based Decision Support Methodology for Cybercrime Investigation: Focused on the Data-Driven Website Defacement AnalysisabstractCriminal profiling is a useful technique to identify the most plausible suspects based on the evidence discovered at the crime scene. Similar to offline criminal profiling, in-depth profiling for cybercrime investigation is useful in analysing cyberattacks and for speculating on the identities of the criminals. Every cybercrime committed by the same hacker or hacking group has unique traits such as attack purpose, attack methods, and target. These unique traits are revealed in the evidence of cybercrime; in some cases, these unique traits are well hidden in the evidence such that it cannot be easily perceived. Therefore, a complete analysis of several factors concerning cybercrime can provide an investigator with concrete evidence to attribute the attacks and narrow down the scope of the criminal data and grasp the criminals in the end. We herein propose a decision support methodology based on the case-based reasoning (CBR) for cybercrime investigation. This study focuses on the massive data-driven analysis of website defacement. Our primary aim in this study is to demonstrate the practicality of the proposed methodology as a proof of concept. The assessment of website defacement was performed through the similarity measure and the clustering processing in the reasoning engine based on the CBR. Our results show that the proposed methodology that focuses on the investigation enables a better understanding and interpretation of website defacement and assists in inferring the hacker’s behavioural traits from the available evidence concerning website defacement. The results of the case studies demonstrate that our proposed methodology is beneficial for understanding the behaviour and motivation of the hacker and that our proposed data-driven analytic methodology can be utilized as a decision support system for cybercrime investigation. Mee Lan Han, Byung Il Kwak, Huy Kang Kim |
Secur. Commun. Networks | 3 |
| 2019 | Automated Dataset Generation System for Collaborative Research of Cyber Threat AnalysisabstractThe objectives of cyberattacks are becoming sophisticated, and attackers are concealing their identity by masquerading as other attackers. Cyber threat intelligence (CTI) is gaining attention as a way to collect meaningful knowledge to better understand the intention of an attacker and eventually predict future attacks. A systemic threat analysis based on data acquired from actual cyber incidents is a useful approach to generating intelligence for such an objective. Developing an analysis technique requires a high-volume and fine-quality data. However, researchers can become discouraged by inaccessibility to data because organizations rarely release their data to the research community. Owing to a data inaccessibility issue, academic research tends to be biased toward techniques that develop steps of the CTI process other than analysis and production. In this paper, we propose an automated dataset generation system called CTIMiner. The system collects threat data from publicly available security reports and malware repositories. The data are stored in a structured format. We released the source codes and dataset to the public, including approximately 640,000 records from 612 security reports published from January 2008 to June 2019. In addition, we present a statistical feature of the dataset and techniques that can be developed using it. Moreover, we demonstrate an application example of the dataset that analyzes the correlation and characteristics of an incident. We believe our dataset will promote collaborative research on threat analysis for the generation of CTI. Daegeon Kim, Huy Kang Kim |
Secur. Commun. Networks | 2 |
| 2018 | Andro-Simnet: Android Malware Family Classification using Social Network AnalysisabstractWhile the rapid adaptation of mobile devices changes our daily life more conveniently, the threat derived from malware is also increased. There are lots of research to detect malware to protect mobile devices, but most of them adopt only signature-based malware detection method that can be easily bypassed by polymorphic and metamorphic malware. To detect malware and its variants, it is essential to adopt behavior-based detection for efficient malware classification. This paper presents a system that classifies malware by using common behavioral characteristics along with malware families. We measure the similarity between malware families with carefully chosen features commonly appeared in the same family. With the proposed similarity measure, we can classify malware by malware's attack behavior pattern and tactical characteristics. Also, we apply community detection algorithm to increase the modularity within each malware family network aggregation. To maintain high classification accuracy, we propose a process to derive the optimal weights of the selected features in the proposed similarity measure. During this process, we find out which features are significant for representing the similarity between malware samples. Finally, we provide an intuitive graph visualization of malware samples which is helpful to understand the distribution and likeness of the malware networks. In the experiment, the proposed system achieved 97% accuracy for malware classification and 95% accuracy for prediction by K-fold cross-validation using the real malware dataset. Hye Min Kim, Hyun Min Song, Jae Woo Seo, Huy Kang Kim |
PST | 4 |
| 2018 | GIDS: GAN based Intrusion Detection System for In-Vehicle NetworkabstractA Controller Area Network (CAN) bus in the vehicles is an efficient standard bus enabling communication between all Electronic Control Units (ECU). However, CAN bus is not enough to protect itself because of lack of security features. To detect suspicious network connections effectively, the intrusion detection system (IDS) is strongly required. Unlike the traditional IDS for Internet, there are small number of known attack signatures for vehicle networks. Also, IDS for vehicle requires high accuracy because any false-positive error can seriously affect the safety of the driver. To solve this problem, we propose a novel IDS model for in-vehicle networks, GIDS (GAN based Intrusion Detection System) using deep-learning model, Generative Adversarial Nets. GIDS can learn to detect unknown attacks using only normal data. As experiment result, GIDS shows high detection accuracy for four unknown attacks. Eunbi Seo, Hyun Min Song, Huy Kang Kim |
PST | 3 |
| 2018 | Automated Reverse Engineering and Attack for CAN Using OBD-IIabstractController area network (CAN) is one of the most popular in-vehicle networks. CAN allows electronic control units (ECUs) to communicate with each other. ECUs control various function of vehicle systems such as engine and transmission control. Therefore, CAN and ECUs are the high priority targets by hackers. If the CAN and the connected components are attacked, the vehicle may cause serious malfunction and fatal accidents. However, it is hard to find out the exact CAN messages to send and control the vehicle as intended by hackers. Likewise, vehicle security researchers have the same problem to find out the exact meaning of CAN messages to detect sophisticated attacks as well as attackers. It is relatively easy to detect the simple pattern of attacks such as denial of service (DoS) attack. However, CAN specification information is private information of car OEMs, to reveal the exact meaning of CAN messages, we need to analyze the messages by reverse engineering techniques, which is time-consuming and laborious tasks. To solve this problem, we developed the Automated CAN Analyzer (ACA). The ACA has automated reverse engineering functions which can help to analyze the relationship between the response data from a diagnostic query of on-board diagnostics II (OBD-II) and the related CAN traffic data. Furthermore, it supports the automated attack function that can inject fake messages into CAN bus based on pre-analyzed CAN message information. Researchers can easily confirm whether the reverse engineering results are correctly working or not through the provided automated attack function. As a result, the ACA could lower the barriers to entry to in-vehicle network research. To evaluate the ACA, we applied our approach to two real vehicles, Hyundai YF Sonata (2010 model) and KIA Soul (2014 model). In this paper, we can find out the meaning of CAN messages on both vehicles with the help of the ACA. Additionally, since modern vehicles are all equipped with OBD-II, our approach can be applied to most vehicle widely. Tae Un Kang, Hyun Min Song, Seonghoon Jeong 0001, Huy Kang Kim |
VTC Fall | 4 |
| 2018 | Unveiling a Socio-Economic System in a Virtual World: A Case Study of an MMORPGabstractUnderstanding socio-economic systems in MMORPGs can provide an important implication on how people participate in the economy and how people interact with each other. In this paper, we model the socio-economic system of an Aion, a popular MMORPG, as a multi-layer graph. Using the dataset consisting of 94,870 users and their activity records spanning three months, we examine how economic activities are associated with social interactions, and find that social interactions like participating in a party or exchanging messages are highly correlated with the trade activities. We also find that virtual economy in Aion is heavily inclined to a small number of upper-class userswho play a crucial role in virtual economy. Our analysis on the upper-class users reveals that a significant portion of them reach at the max-level and tend to either (i) have many social interactions with others or (ii) play extremely much time with no social activity. We also reveal that there are some low-level upper-class users who gain much money but hardly socialize with others. Lastly, we show how upper-class users who are at low-levels, play the game extremely much more than others, or rarely interact with other users, are associated with the Real Money Trade (RMT), which may be an illegal behavior that gathers in-game money for exchanging into real-world money. We reveal that more than half of total money exchanged through the trade are associated with the upper-class users who involve in the RMT. Selin Chun, Daejin Choi, Jinyoung Han, Huy Kang Kim, Ted Taekyoung Kwon |
WWW | 4 |
| 2018 | No Silk Road for Online Gamers!: Using Social Network Analysis to Unveil Black Markets in Online GamesabstractOnline game involves a very large number of users who are interconnected and interact with each other via the Internet. We studied the characteristics of exchanging virtual goods with real money through the processes called "real money trading (RMT)". This exchange might influence online game user behaviors and cause damage to the reputation of game companies. We examined in-game transactions to reveal RMT by constructing a social graph of virtual goods exchanges in an online game and identifying network communities of users. Eunjo Lee, Hyoungshick Kim, Huy Kang Kim |
WWW | 4 |
| 2017 | OTIDS: A Novel Intrusion Detection System for In-vehicle Network by Using Remote FrameabstractController Area Network (CAN) is a bus communication protocol which defines a standard for reliable and efficient transmission between in-vehicle nodes in real-time. Since CAN message is broadcast from a transmitter to the other nodes on a bus, it does not contain information about the source and destination address for validation. Therefore, an attacker can easily inject any message to lead system malfunctions. In this paper, we propose an intrusion detection method based on the analysis of the offset ratio and time interval between request and response messages in CAN. If a remote frame having a particular identifier is transmitted, a receiver node should respond to the remote frame immediately. In attack-free state, each node has a fixed response offset ratio and time interval while these values vary in attack state. Using this property, we can measure the response performance of the existing nodes based on the offset ratio and time interval between request and response messages. As a result, our methodology can detect intrusions by monitoring offset ratio and time interval, and it allows quick intrusion detection with high accuracy. Hyunsung Lee, Seonghoon Jeong 0001, Huy Kang Kim |
PST | 3 |
| 2017 | Firewall ruleset visualization analysis tool based on segmentationabstractAlthough most companies operate a firewall to protect their information assets, they have difficulties in identifying the control conditions of firewalls. This study proposes an analysis tool to visualize segment-based firewall rules to facilitate verification of the current control conditions. The proposed visualization tool analyzes the current control conditions of packets automatically, thereby eliminating the need for manual inspection as before, and displays the conditions with a visualization model to allow them to be easily verified. This enables managers to perform fast and accurate verification to assess whether packets are allowed or denied. This present study involved implementing the proposed visualization tool, and simulations were conducted to verify that the proposed approach was achievable. The present study also included conducting interviews with firewall experts whose feedback was positive. A video of the proposed visualization tool can be found on the following web site: https://youtu.be/q4HMnBvXbk. Sukjun Ko, Dong Seong Kim 0001, Huy Kang Kim |
VizSEC | 4 |
| 2017 | Crime Scene Reconstruction: Online Gold Farming Network AnalysisabstractMany online games have their own ecosystems, where players can purchase in-game assets using game money. Players can obtain game money through active participation or “real money trading” through official channels: converting real money into game money. The unofficial market for real money trading gave rise to gold farming groups (GFGs), a phenomenon with serious impact in the cyber and real worlds. GFGs in massively multiplayer online role-playing games (MMORPGs) are some of the most interesting underground cyber economies because of the massive nature of the game. To detect GFGs, there have been various studies using behavioral traits. However, they can only detect gold farmers, not entire GFGs with internal hierarchies. Even worse, GFGs continuously develop techniques to hide, such as forming front organizations, concealing cyber-money, and changing trade patterns when online game service providers ban GFGs. In this paper, we analyze the characteristics of the ecosystem of a large-scale MMORPG, and devise a method for detecting GFGs. We build a graph that characterizes virtual economy transactions, and trace abnormal trades and activities. We derive features from the trading graph and physical networks used by GFGs to identify them in their entirety. Using their structure, we provide recommendations to defend effectively against GFGs while not affecting the existing virtual ecosystem. Hyukmin Kwon, David Mohaisen, Yongdae Kim, Eunjo Lee, Huy Kang Kim |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2016 | You are a Game Bot!: Uncovering Game Bots in MMORPGs via Self-similarity in the Wild
Eunjo Lee, Hyoungshick Kim, David Mohaisen, Huy Kang Kim |
NDSS | 5 |
| 2016 | Know your master: Driver profiling-based anti-theft methodabstractAlthough many anti-theft technologies are implemented, auto-theft is still increasing. Also, security vulnerabilities of cars can be used for auto-theft by neutralizing anti-theft system. This keyless auto-theft attack will be increased as cars adopt computerized electronic devices more. To detect auto-theft efficiently, we propose the driver verification method that analyzes driving patterns using measurements from the sensor in the vehicle. In our model, we add mechanical features of automotive parts that are excluded in previous works, but can be differentiated by drivers' driving behaviors. We design the model that uses significant features through feature selection to reduce the time cost of feature processing and improve the detection performance. Further, we enrich the feature set by deriving statistical features such as mean, median, and standard deviation. This minimizes the effect of fluctuation of feature values per driver and finally generates the reliable model. We also analyze the effect of the size of sliding window on performance to detect the time point when the detection becomes reliable and to inform owners the theft event as soon as possible. We apply our model with real driving and show the contribution of our work to the literature of driver identification. Byung Il Kwak, Huy Kang Kim |
PST | 3 |
| 2016 | A Longitudinal Analysis of .i2p Leakage in the Public DNS InfrastructureabstractThe Invisible Internet Project (I2P) is an overlay network that provides secure and anonymous communication channels. EepSites are the anonymous websites hosted in the I2P network. To access the eepSites, DNS requests of a domain name suffixed with the {\sf .i2p} pseudo top-level domain (TLD) are routed within the I2P network. However, not only that {\sf .i2p} queries are leaking in the public DNS infrastructure, but also such leakage has various plausible root causes and implications that are different from other related leakage. In this paper, we analyze the leaked {\sf .i2p} requests captured in the A and J root name servers of the public DNS, showing that a large number of queries are observed and outlining various potential directions of addressing such leakage. Seonghoon Jeong 0001, Ah Reum Kang, Joongheon Kim, Huy Kang Kim, David Mohaisen |
SIGCOMM | 4 |
| 2016 | Andro-Dumpsys: Anti-malware system based on the similarity of malware creator and malware centric information
Jae-wook Jang, Hyunjae Kang 0001, David Mohaisen, Huy Kang Kim |
Comput. Secur. | 5 |
| 2015 | Analysis of Game Bot's Behavioral Characteristics in Social Interaction Networks of MMORPGabstractMMORPG (Massively Multiplayer Online Role-Playing Game) is one of the best platforms to observe human's behaviors. In collaboration with a leading online game company, NCSoft, we can observe all behaviors in a large-scale of commercialized MMORPG. Especially, we analyzed the behavioral differences between game bots and human users. We categorized the five groups, Bot-Bot, Bot-All, Human-Human, Human-All and All-All, and we observe the characteristics of six social interaction networks for each group. As a result, we found that there are significant differences in social behaviors between game bots and human. Seonghoon Jeong 0001, Ah Reum Kang, Huy Kang Kim |
SIGCOMM | 3 |
| 2015 | Case study of the vulnerability of OTP implemented in internet banking systems of South Korea
Changsok Yoo, Byung-Tak Kang, Huy Kang Kim |
Multim. Tools Appl. | 3 |
| 2014 | Unveiling group characteristics in online social games: a socio-economic analysisabstractUnderstanding the group characteristics in MMORPGs is important in user behavior studies since people tend to gather together and form groups due to their inherent nature. In this paper, we analyze the group activities of users in Aion, one of the largest MMORPGs, based on the records of the activities of 94,497 users. In particular, we focus on (i) how social interactions within a group differ from the ones across groups, (ii) what makes a group rise, sustain, or fall, (iii) how group members join and leave a group, and (iv) what makes a group end. We first find that structural patterns of social interactions within a group are more likely to be close-knit and reciprocative than the ones across groups. We also observe that members in a rising group (i.e., the number of members increases) are more cohesive, and communicate with more evenly within the group than the ones in other groups. Our analysis further reveals that if a group is not cohesive, not actively communicating, or not evenly communicating among members, members of the group tend to leave. Taejoong Chung, Jinyoung Han, Daejin Choi, Ted Taekyoung Kwon, Huy Kang Kim, Yanghee Choi |
WWW | 5 |
| 2013 | The contagion of malicious behaviors in online gamesabstractThis article investigates whether individual users are more likely to display malicious behavior after receiving social reinforcement from friends in their online social networks. We analyze the dynamics of game bot diffusion on the basis of real data supplied by a major massively multiplayer online role-playing game company. We find that the social reinforcement, measured by the ratio of bot friends over total friends, affects the likelihood of game bot adoption and the commitment in terms of usage time. Ah Reum Kang, Huy Kang Kim |
SIGCOMM | 3 |
| 2012 | Detection of botnets before activation: an enhanced honeypot system for intentional infection and behavioral observation of malwareabstractABSTRACT As botnets have become the primary means for cyber attacks, how to detect botnets becomes an important issue for researchers and practitioners. In this study, we introduce a system that is designed to detect botnets prior to their activation. Pre‐detection of botnets becomes available with our enhanced honeypot system that allows us to intentionally infect virtual machines in honeynets. For empirical testing, we applied our system to a major Internet service provider in Korea. After running our proposed system for 12 months, it was found that nearly 40% of blacklisted botnets were pre‐detected by our system before their attacks begin. We expect that our system can be used to detect command‐and‐control servers and to screen them out during their propagation stage before they make harmful attacks. Copyright © 2012 John Wiley & Sons, Ltd. Young-Hoon Moon, Suh Mahn Hur, Huy Kang Kim |
Secur. Commun. Networks | 4 |
| 2011 | Self-similarity Based Lightweight Intrusion Detection Method for Cloud Computing
Hyukmin Kwon, Taesu Kim, Song Jin Yu, Huy Kang Kim |
ACIIDS (2) | 4 |
| 2011 | Multi-relational social networks in a large-scale MMORPGabstractWe analyze multi-relational social interaction networks in a large-scale commercial Massively Multiplayer Online Role-Playing Game(MMORPG). Our work is based on data from AION, currently the world's second most-played MMORPG with 3.4 million subscribers as of mid 2010, created and serviced by NCSoft, Inc. We construct and characterize six distinct interactivity networks (Friend, Private Messaging, Party invitation, Trade, Mail, and Shop), each representing diverse player interaction types. Seokshin Son, Ah Reum Kang, Hyunchul Kim, Ted Taekyoung Kwon, Juyong Park, Huy Kang Kim |
SIGCOMM | 6 |
| 2011 | What can free money tell us on the virtual black market?abstract"Real money trading" or "Gold farming" refers to a set of illicit practices for gathering and distributing virtual goods in online games for real money. Unlike previous work, we use network-wide economic interactions among in-game characters as a lens to monitor, detect and identify gold farming networks. Our work is based on a set of real in-game trade activity logs collected for one month in year 2010 from the world's second largest MMORPG called AION (with 3.4 million subscribers). This is the first work that empirically (i) shows that "free money network" is a promising measure/approximation for detecting and characterizing gold farming networks, and (ii) measures the size of the free money net and in-game virtual economy in a large-scale MMORPG in terms of the cash flow. Kyungmoon Woo, Hyukmin Kwon, Hyunchul Kim, Chong-Kwon Kim, Huy Kang Kim |
SIGCOMM | 5 |
| 2010 | DSS for computer security incident response applying CBR and collaborative response
Huy Kang Kim, Kwang Hyuk Im |
Expert Syst. Appl. | 1 |
| 2010 | Security Requirement Representation Method for Confidence of Systems and NetworksabstractSoftware vulnerability is a key determiner of confidence in computer systems and networks. Usually, software requirements are listed at the beginning of software design, whereas vulnerabilities appear only after development is complete and sometimes only after the system is operational. Therefore, the security requirements during the design stage should address software vulnerabilities. This paper presents a method of representing software vulnerabilities as atomic vulnerabilities (AVs): an AV is an undividable cause-unit of vulnerability, and a set of AVs and the relationships among them represent software vulnerabilities. The AV concept originates from system theory and modeling methodology. AVs and the relationships among them can be used to construct a behavioral model of systems and networks with a focus on vulnerability. The logical relationships among AVs are named vulnerability expressions (VXs). With all the accumulated VXs of the systems and networks, we can set security requirements that resolve or circumvent vulnerabilities effectively and reinforce confidence in system and network robustness. The contribution of this paper is to use the concepts of AV and VX to derive the security requirements considering software vulnerabilities for secure systems and networks. The requirement derived can be used to complement the vulnerable situation caused by software that is developed without cognizance of security consideration. Hyung-Jong Kim 0002, Huy Kang Kim, Hae Young Lee |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2000 | A hybrid approach of neural network and memory-based learning to data miningabstractWe propose a hybrid prediction system of neural network and memory-based learning. Neural network (NN) and memory-based reasoning (MBR) are frequently applied to data mining with various objectives. They have common advantages over other learning strategies. NN and MBR can be directly applied to classification and regression without additional transformation mechanisms. They also have strength in learning the dynamic behavior of the system over a period of time. Unfortunately, they have shortcomings when applied to data mining tasks. Though the neural network is considered as one of the most powerful and universal predictors, the knowledge representation of NN is unreadable to humans, and this "black box" property restricts the application of NN to data mining problems, which require proper explanations for the prediction. On the other hand, MBR suffers from the feature-weighting problem. When MBR measures the distance between cases, some input features should be treated as more important than other features. Feature weighting should be executed prior to prediction in order to provide the information on the feature importance. In our hybrid system of NN and MBR, the feature weight set, which is calculated from the trained neural network, plays the core role in connecting both learning strategies, and the explanation for prediction can be given by obtaining and presenting the most similar examples from the case base. Moreover, the proposed system has advantages in the typical data mining problems such as scalability to large datasets, high dimensions, and adaptability to dynamic situations. Experimental results show that the hybrid system has a high potential in solving data mining problems. Chung-Kwan Shin, Ui Tak Yun, Huy Kang Kim |
IEEE Trans. Neural Networks Learn. Syst. | 3 |