VLDB 2026 Research / reviewers in the wild / expert
Jinwoo Kim 0006
dblp:85/1809-6
· DBLP profile ↗
19ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0003-1303-8668ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 5 first-author · 11 since 2021Computer networks · 5 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BeaCon: Automatic container policy generation using environment-aware dynamic analysis
Haney Kang, Eduard Marin, Myoungsung You, Diego Perino, Seungwon Shin 0001, Jinwoo Kim 0006 |
Comput. Secur. | 6 |
| 2026 | SecTracer: A framework for uncovering the root causes of network intrusions via security provenance
Hyunmin Seo, Hwanjo Heo, Anduo Wang, Seungwon Shin 0001, Jinwoo Kim 0006 |
Comput. Secur. | 6 |
| 2026 | PassREfinder-FL: Privacy-preserving credential stuffing risk prediction via graph-based federated learning for representing password reuse between websites
Jaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin, Seungwon Shin 0001, Jinwoo Kim 0006 |
Expert Syst. Appl. | 6 |
| 2025 | CryptoGuard: Lightweight Hybrid Detection and Response to Host-based Cryptojackers in Linux Cloud EnvironmentsabstractHost-based cryptomining malware, commonly known as cryptojackers, have gained notoriety for their stealth and the significant financial losses they cause in Linux-based cloud environments. Existing solutions often struggle with scalability due to high monitoring overhead, low detection accuracy against obfuscated behavior, and lack of integrated remediation. We present CryptoGuard, a lightweight hybrid solution that combines detection and remediation strategies to counter cryptojackers. To ensure scalability, CryptoGuard uses sketch- and sliding window-based syscall monitoring to collect behavior patterns with minimal overhead. It decomposes the classification task into a two-phase process, leveraging deep learning models to identify suspicious activity with high precision. To counter evasion techniques such as entry point poisoning and PID manipulation, CryptoGuard integrates targeted remediation mechanisms based on eBPF, a modern Linux kernel feature deployable on any compatible host. Evaluated on 123 real-world cryptojacker samples, it achieves average F1-scores of 96.12% and 92.26% across the two phases, and outperforms state-of-the-art baselines in terms of true and false positive rates, while incurring only 0.06% CPU overhead per host. Gyeonghoon Park, Jaehan Kim, Jinu Choi, Jinwoo Kim 0006 |
AsiaCCS | 4 |
| 2025 | The Hidden Dangers of Public Serverless Repositories: An Empirical Security Assessment
Eduard Marin, Jinwoo Kim 0006, Alessio Pavoni, Mauro Conti, Roberto Di Pietro |
ESORICS (3) | 2 |
| 2025 | MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and SplittingabstractTor, a widely utilized privacy network, enables anonymous communication but is vulnerable to flow correlation attacks that deanonymize users by correlating traffic patterns from Tor's ingress and egress segments. Various defenses have been developed to mitigate these attacks; however, they have two critical limitations: (i) significant network overhead during obfuscation and (ii) a lack of dynamic obfuscation for egress segments, exposing traffic patterns to adversaries. In response, we introduce MUFFLER, a novel connection-level traffic obfuscation system designed to secure Tor egress traffic. It dynamically maps real connections to a distinct set of virtual connections between the final Tor nodes and targeted services, either public or hidden. This approach creates egress traffic patterns fundamentally different from those at ingress segments without adding intentional padding bytes or timing delays. The mapping of real and virtual connections is adjusted in real-time based on ongoing network conditions, thwarting adversaries' efforts to detect egress traffic patterns. Extensive evaluations show that MUFFLER mitigates powerful correlation attacks with a TPR of 1% at an FPR of 10−2while imposing only a 2.17% bandwidth overhead. Moreover, it achieves up to 27x lower latency overhead than existing solutions and seamlessly integrates with the current Tor architecture. Minjae Seo, Myoungsung You, Jaehan Kim, Taejune Park, Seungwon Shin 0001, Jinwoo Kim 0006 |
INFOCOM | 6 |
| 2024 | Enhancing security in SDN: Systematizing attacks and defenses from a penetration perspective
Jinwoo Kim 0006, Minjae Seo, Seungsoo Lee 0001, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu, Seungwon Shin 0001 |
Comput. Networks | 1 |
| 2024 | Fatriot: Fault-tolerant MEC architecture for mission-critical systems using a SmartNIC
Taejune Park, Myoungsung You, Jinwoo Kim 0006, Seungsoo Lee 0001 |
J. Netw. Comput. Appl. | 3 |
| 2024 | Ambusher: Exploring the Security of Distributed SDN Controllers Through Protocol State FuzzingabstractDistributed SDN (Software-Defined Networking) controllers have rapidly become an integral element ofWide Area Networks (WAN), particularly within SD-WAN, providing scalability and fault-tolerance for expansive network infrastructures. However, the architecture of these controllers introduces new potential attack surfaces that have thus far received inadequate attention. In response to these concerns, we introduceAmbusher, a testing tool designed to discover vulnerabilities within protocols used in distributed SDN controllers.Ambusherachieves this by leveragingprotocol state fuzzing, which systematically finds attack scenarios based on an inferred state machine. Since learning states from a cluster is complicated,Ambusherproposes a novel methodology that extracts a single and relatively simple state machine, achieving efficient state-based fuzzing. Our evaluation ofAmbusher, conducted on a real SD-WAN deployment spanning two campus networks and one enterprise network, illustrates its ability to uncover 6 potential vulnerabilities in the widely used distributed controller platform. Jinwoo Kim 0006, Minjae Seo, Eduard Marin, Seungsoo Lee 0001, Jaehyun Nam, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Extended data plane architecture for in-network security services in software-defined networks
Jinwoo Kim 0006, Yeonkeun Kim, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001, Taejune Park |
Comput. Secur. | 1 |
| 2022 | Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control TrafficabstractSoftware-defined wide area network (SD-WAN) has emerged as a new paradigm for steering a large-scale network flexibly by adopting distributed software-defined network (SDN) controllers. The key to building a logically centralized but physically distributed control-plane is running diverse cluster management protocols to achieve consistency through an exchange of control traffic. Meanwhile, we observe that the control traffic exposes unique time-series patterns and directional relationships due to the operational structure even though the traffic is encrypted, and this pattern can disclose confidential information such as control-plane topology and protocol dependencies, which can be exploited for severe attacks. With this insight, we propose a new SD-WAN fingerprinting system, called Heimdallr. It analyzes periodical and operational patterns of SD-WAN cluster management protocols and the context of flow directions from the collected control traffic utilizing a deep learning-based approach, so that it can classify the cluster management protocols automatically from miscellaneous control traffic datasets. Our evaluation, which is performed in a realistic SD-WAN environment consisting of geographically distant three campus networks and one enterprise network shows that Heimdallr can classify SD-WAN control traffic with ≥ 93%, identify individual protocols with ≥ 80% macro F-1 scores, and finally can infer control-plane topology with ≥ 70% similarity. Minjae Seo, Jaehan Kim, Eduard Marin, Myoungsung You, Taejune Park, Seungsoo Lee 0001, Seungwon Shin 0001, Jinwoo Kim 0006 |
ACSAC | 8 |
| 2022 | EqualNet: A Secure and Practical Defense for Long-term Network Topology Obfuscation
Jinwoo Kim 0006, Eduard Marin, Mauro Conti, Seungwon Shin 0001 |
NDSS | 1 |
| 2022 | Towards Building Secure and Reconfigurable Virtual Networks on Multi-Tenant Data CentersabstractNetwork virtualization (NV) has been widely used today in data centers to meet the multi-tenancy requirement-a key to achieving Infrastructure as a Service (IaaS) in a modern cloud environment. However, even though NV is a popular solution employed by network operators, we argue that most solutions still have challenges in terms of (i) configuration, (ii) management, and (iii) security; all of which hinder the deployment of secure and practical virtual networks that tenants wish to construct. To bridge the gaps, we propose LinkWire, a new NV system that produces secure and reconfigurable virtual networks. For this, LinkWire leverages extended Berkeley Packet Filter (eBPF), the recently-adopted in-kernel programmable networking technology. We also illustrate several use cases to show how our system brings benefits. Jinwoo Kim 0006, Jaehyun Nam |
PRDC | 1 |
| 2022 | A Framework for Policy Inconsistency Detection in Software-Defined NetworksabstractSoftware-Defined Networking (SDN) has aggressively grown in data center networks, telecommunication providers, and enterprises by virtue of its programmable and extensible control plane. Also, there have been many kinds of research on the security of SDN components along with the growth of SDN. Some of them have inspected network policy inconsistency problems that can severely cause network reliability and security issues in SDN. However, they do not consider whether a single network policy itself is corrupted during processing inside and between SDN components. In this paper, we thus focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among those components. We then present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise inOpenFlownetworks, the most prevalent SDN protocol. To prove its feasibility, we applied AudiSDN to two widely used SDN controllers, Floodlight and ONOS, and uncovered three separate CVEs (Common Vulnerabilities and Exposures) that cause the network policy inconsistencies among SDN components. Furthermore, we investigate the design flaws that cause the inconsistencies in modern SDN components, suggesting specific validations to address such a serious but understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2021 | GapFinder: Finding Inconsistency of Security Information From Unstructured TextabstractTextual data mining of open source intelligence on the Web has become an increasingly important topic across a wide range of domains such as business, law enforcement, military, and cybersecurity. Text mining efforts utilize natural language processing to transform unstructured web content into structured forms that can drive various machine learning applications and data indexing services. For example, applications for text mining in cybersecurity have produced a range of threat intelligence services that serve the IT industry. However, a less studied problem is that of automating the identification of semantic inconsistencies among various text input sources. In this paper, we introduce GapFinder, a new inconsistency checking system for identifying semantic inconsistencies within the cybersecurity domain. Specifically, we examine the problem of identifying technical inconsistencies that arise in the functional descriptions of open source malware threat reporting information. Our evaluation, using tens of thousands of relations derived from web-based malware threat reports, demonstrates the ability of GapFinder to identify the presence of inconsistencies. Hyeonseong Jo, Jinwoo Kim 0006, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | BottleNet: Hiding Network Bottlenecks Using SDN-Based Topology DeceptionabstractThe robustness of a network’s connectivity to other networks is often highly dependent on a few critical nodes and links that tie the network to the larger topology. The failure or degradation to such network bottlenecks can result in outages that may propagate throughout the network. Unfortunately, the presence of the bottlenecks also offers opportunities for targetedlink flooding attacks (LFAs). Researchers have proposed a new and promising defense to counter LFAs, referred to astopology deception. This strategy centers on hindering the discovery of bottlenecks by presenting false trace responses to adversaries as they perform topological probing of the target network. Even though the goal of topology deception centers on obscuring critical links, node dependencies can be exploited by an adversary. However, current approaches do not consider a wide range of metrics that may reveal important and diverse aspects of network bottlenecks. Furthermore, existing approaches create a simple form of virtual topology, which is subject to relatively easy detection by the adversary, reducing its effectiveness. In this paper, we propose a comprehensive topology deception framework, which we refer to as BottleNet. Our suggested approach can analyze various network topology features both with respect to static and dynamic metrics and then use this information to identify bottlenecks, finally producing complex virtual topologies that are resilient to adversarial detection. Jinwoo Kim 0006, Jaehyun Nam, Suyeol Lee, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksabstractAt the foundation of every network security architecture lies the premise that formulated network flow policies are reliably deployed and enforced by the network infrastructure. However, software-defined networks (SDNs) add a particular challenge to satisfying this premise, as for SDNs the flow pol-icy implementation spans multiple applications and abstraction layers across the SDN stack. In this paper, we focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among these components. This question is rather essential, as when such inconsistencies arise the implications to the security and reliability of the network are devastating. We present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise in OpenFlow networks, the most prevalent SDN protocol used today. We also present results from applying AudiSDN to two widely used SDN controllers, Floodlight and ONOS. In fact, our test results have led to the filing of 3 separate CVE reports. We believe that the approach presented in this paper is applicable to the breadth of OpenFlow platforms used today, and that its broader usage will help to address a serious but yet understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
INFOCOM | 3 |
| 2020 | A comprehensive security assessment framework for software-defined networks
Seungsoo Lee 0001, Jinwoo Kim 0006, Seungwon Woo, Changhoon Yoon, Sandra Scott-Hayward, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
Comput. Secur. | 2 |
| 2017 | Athena: A Framework for Scalable Anomaly Detection in Software-Defined NetworksabstractNetwork-based anomaly detection is a well-mined area of research, with many projects that have produced algorithms to detect suspicious and anomalous activities at strategic points in a network. In this paper, we examine how to integrate an anomaly detection development framework into existing software-defined network (SDN) infrastructures to support sophisticated anomaly detection services across the entire network data plane, not just at network egress boundaries. We present Athena as a new SDN-based software solution that exports a well-structured development interface and provides general purpose functions for rapidly synthesizing a wide range of anomaly detection services and network monitoring functions with minimal programming effort. Athena is a fully distributed application hosting architecture, enabling a unique degree of scalability from prior SDN security monitoring and analysis projects. We discuss example use-case scenarios with Athena's development libraries, and evaluate system performance with respect to usability, scalability, and overhead in real world environments. Jinwoo Kim 0006, Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran |
DSN | 2 |