Jonghyun Kim 0005

dblp:92/5951-5 · also Jong Hyun Kim 0005, Jong hyun Kim 0005, Jong-Hyun Kim 0005 · DBLP profile ↗
← Back
13ranked-venue papers
0as first author
10since 2021 · last 2024
0000-0002-5532-2117ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 4 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Fake Base Station Detection and Blacklisting
abstract
A fake base station is a well-known security issue in mobile networking. The fake base station exploits the vulnerability in the broadcasting message announcing the base station’s presence, which is called SIB1 in telecommunications protocols such as 4G LTE and 5G NR, to get the user equipment to connect to itself. Once connected, the fake base station can deprive the user of connectivity and access to the Internet/cloud. We discover that a fake base station (which engages the user equipment until parts of the connectivity setup and then discontinues with the protocol) can disable the victim user equipment’s connectivity for an indefinitely long time, which we validate using our threat prototype against current 4G/5G practice. We design and build a detection and blacklisting identification of the fake base station so that the user equipment can avoid the base station and move on to connecting to a legitimate base station for the connectivity availability. Our detection and blacklisting scheme builds on the standardized 5G protocol and requires the implementation only on the user equipment (no further protocol changes), facilitating practicality. Our scheme uses the real-time information of both the time duration and the number of request transmissions, which features are directly impacted by the fake base station’s threat and have not been studied in the previous research. We implement both the base station and the user defense on software-defined radio using open-source 5G software (srsRAN and Open5GS) for validations. We vary the base station implementation to simulate legitimate vs. faulty-but-legitimate vs. fake-and-malicious base stations, where the faulty base station notifies the connectivity disruption and releases the session while the fake base station continues to hold the session. We empirically analyze the detection and identification thresholds, which vary with the fake base station’s power and the channel condition. By strategically selecting the threshold parameters, our scheme provides zero errors, including zero false positives to avoid blacklisting the temporarily faulty base stations which can not provide the connectivity at the time.
Sourav Purification, Simeon Wuthier, Jinoh Kim, Jonghyun Kim 0005, Sang-Yoon Chang
ICCCN4
2024 Intelligent Trajectory-based Approach to UAV Location Integrity Checks
abstract
While unmanned aerial vehicles (UAVs) are increasingly utilized in many domains, there is a growing concern about location integrity for securely deploying and managing the vehicles. A body of studies tackled this problem, e.g., using hardware sensors, cryptographic mechanisms, and machine learning (ML) approaches, but they concentrate primarily on GPS-related information (e.g., jamming and noise). In this study, we take a different approach that performs the checks by analyzing actual movement information. This new approach keeps track of location updates across the flight path (‘trajectory’) rather than relying only on point-wise GPS-specific features to test the validity of the location information. To this end, we develop a deep sequence method that takes a sequence of flight data samples with a minimal set of attributes capturing location movement over time. Our extensive experimental results support the feasibility of our approach, showing up to 98.9% accuracy for ensuring location consistency (even without referring to any of the GPS-specific features).
Sang-Yoon Chang, Jonghyun Kim 0005, Kyungmin Park, Jinoh Kim
ICCCN3
2024 Experimental Approach to Internal Security Threats for 5G-Advanced Core Networks
abstract
As we embrace the dawn of the 5G era, the fusion of Software Defined Network (SDN) and Network Function Virtualization (NFV) technologies has heralded a new epoch in network architecture. This provides indispensable capabilities and virtualized infrastructure to meet the burgeoning demands of modern networks. Yet, with each stride forward in mobile communication technology, security threats loom larger, casting a shadow over the very fabric of our networks. In this context, identifying and addressing these threats is crucial as it plays a key role in enhancing the security of a 5G-Advanced and a next 6G mobile communication technologies. Therefore, this paper undertakes an investigative journey to explore security threats introduced by SDN/NFV technologies in the 5G-Advanced core networks. Through our simulations, we unveil a need for fortified security technologies within the 5G-Advanced core networks, illuminating a path towards the creation of bespoke datasets tailored for the trends of 5G-Advanced security research.
Jaehyoung Park, Jihye Kim 0006, Seungchan Woo, Kyungmin Park, Jonghyun Kim 0005, Jong-Hyouk Lee
PIMRC5
2024 Base station gateway to secure user channel access at the first hop edge
Sang-Yoon Chang, Arijet Sarker, Simeon Wuthier, Jinoh Kim, Jonghyun Kim 0005, Xiaobo Zhou 0002
Comput. Networks5
2023 Version++: Cryptocurrency Blockchain Handshaking With Software Assurance
abstract
Cryptocurrency software implements the cryptocurrency operations, including the distributed consensus protocol and the peer-to-peer networking. We design a software assurance scheme for cryptocurrency and advance the cryptocurrency handshaking protocol. Since we focus on Bitcoin (the most popular cryptocurrency) for implementation and integration, we call our scheme Version++, built on and advancing the current Bitcoin handshaking protocol based on the Version message. Our Version++ protocol providing software assurance is distinguishable from the previous research because it is permissionless, distributed, and lightweight to fit its cryptocurrency application. Our scheme is permissionless since it does not require a centralized trusted authority (unlike the remote software attestation techniques from trusted computing); it is distributed since the peer checks the software assurances of its own peer connections; and it is designed for efficiency/lightweight due to the dynamic nature of the peer connections and the large-scale broadcasting in cryptocurrency networking. Utilizing Merkle Tree for the efficiency of the proof verification, we implement and test Version++ on Bitcoin software and conduct experiments in an active Bitcoin node prototype connected to the Bitcoin Mainnet. Our prototype-based performance analyses demonstrate the lightweight design of Version++. The peer-specific verification grows logarithmically with the number of software files in processing time and in storage. In addition, the Version++ verification overhead is small compared to the overall handshaking process; our measured overhead of 2.22% with minimal networking latency between the virtual machines provides an upper bound in the real-world networking with greater handshaking duration, i.e., the relative Version++ overhead in the real world with physically separate machines will be smaller.
Arijet Sarker, Simeon Wuthier, Jinoh Kim, Jonghyun Kim 0005, Sang-Yoon Chang
CCNC4
2023 Version++ Protocol Demonstration for Cryptocurrency Blockchain Handshaking with Software Assurance
abstract
Cryptocurrency software implements the cryptocurrency operations. We design a software assurance scheme for cryptocurrency and advance the cryptocurrency handshaking protocol. More specifically, we focus on Bitcoin for implementation and integration and advance its Version-message based hand-shaking and thus call our scheme Version++, The Version++ protocol provides software assurance, which is distinguishable from the previous research because it is permissionless, distributed, and lightweight to fit its cryptocurrency application. Utilizing Merkle Tree for the verification efficiency, we implement and test Version++ on Bitcoin software and conduct experiments in an active Bitcoin node prototype connected to the Bitcoin Mainnet. This paper for the conference demonstration supplements our technical paper at CCNC 2023 for synergy but highlights the prototyping and demonstration components of our research.
Arijet Sarker, Simeon Wuthier, Jinoh Kim, Jonghyun Kim 0005, Sang-Yoon Chang
CCNC4
2023 An Empirical Evaluation of Autoencoding-Based Location Spoofing Detection
abstract
Location integrity is highly crucial in mobile communications. In this regard, the attack attempting to falsify the position of mobile agents (known as location spoofing) is critical, and thus, detecting such spoofing attacks should be a vital function in the mobile communication setting. With its importance, previous studies explored location spoofing attacks. Still, they mainly used classification techniques based on supervised learning, confining the detector's capability to detect known attack patterns. This study evaluates the feasibility of the autoencoder-based scheme that constructs a profile for legitimate data instances to be resilient to intelligent, previously unseen types of attacks (e.g., evading attacks). We examine three types of autoencoder models designed based on different structures and conduct extensive experiments to measure the performance of the autoencoder models with both standard and variation attacks, with a comparison study with conventional supervised learning-based classification techniques. Our experimental results show that the autoencoder models produce comparable or even better performance than supervised learners, which may be limited only to detecting known patterns.
Chiho Kim, Sang-Yoon Chang, Jonghyun Kim 0005, Jinoh Kim
ICMLA3
2023 Automated, Reliable Zero-Day Malware Detection Based on Autoencoding Architecture
abstract
While a body of studies has been carried out for malware detection with its significance, they are often limited to known malware patterns due to the reliance on signature-based or supervised learning approaches. The semi-supervised learning approach would be an option for identifying previously unseen patterns (i.e., zero-day detection); however, our preliminary study reveals critical limitations from existing methods, including (i) the profiling-based approach using an autoencoder can provide better detection but is sensitive to the threshold setting, and (ii) one-class (OC) classification does not require a manual threshold discovery but may be limited with low detection rates. In this paper, we present a new detection method incorporating the concept of autoencoding and OC classification, designed to benefit from strong abstraction by neural networks (using an autoencoder) and the removal of the complex threshold selection (using an OC classifier). For this combined architecture, a challenge is concurrent training of the autoencoder and the OC classifier, which may cause an ill-suited learner due to no reference to malware instances. To this end, we introduce a new model selection method that discovers well-optimized models from a variety of combinations. The experimental results performed with public malware datasets (Meraz’18 and Drebin) show the effectiveness of our presented methods with up to 97.1% accuracy, comparable to the supervised learning-based detection. We also examine the impact of evading attacks using adversarial attack tools, the result of which shows resilience to malware variants with over 99% detection rates.
Chiho Kim, Sang-Yoon Chang, Jonghyun Kim 0005, Dongeun Lee 0001, Jinoh Kim
IEEE Trans. Netw. Serv. Manag.3
2022 Lightweight Code Assurance Proof for Wireless Software
abstract
Software-defined radio (SDR) and the softwarization of the wireless and mobile systems enable intelligent processing and control in wireless networking. We design and build a lightweight code assurance proof scheme for wireless system software implementations. More specifically, our scheme assures that a wireless user/prover holds the correct software codes, e.g., the correct version, for its wireless networking implementations. In contrast to the previous research for code attestation in trusted computing, our scheme forgoes hardware-based security and real-time networking, thus substantially increasing the application feasibility. We further design our scheme to be efficient in computing by using a Merkle tree for the efficiency of the verification of the assurance proof. We implement our scheme for proof-of-concept on srsRAN (a popular open-source software for cellular technology) and conduct preliminary measurements to demonstrate the lightweight design. We envision our scheme to be orthogonal and supplementary to the previous trustworthy code attestation because it provides different properties (assurance vs. attestation) and because the lightweight aspect yields greater applicability and lower overheads in hardware and networking. Our scheme will therefore be appropriate for the wireless/mobile environment which uses broadcasting (where receiving/verifications occur more frequently than transmitting/generations) and whose devices are resource-constrained.
Theo Gamboni-Diehl, Simeon Wuthier, Jinoh Kim, Jonghyun Kim 0005, Sang-Yoon Chang
WISEC4
2021 Zero-day Malware Detection using Threshold-free Autoencoding Architecture
abstract
The impact of malware attacks has been getting more significant, targeting critical infrastructures as well as commodity computing devices. A body of studies has been carried out for detecting malware with its devastating impacts, but they are often limited to known malware attacks due to the nature of the signature-based and supervised machine learning approaches. The semi-supervised learning approach would be an option for identifying previously unseen types of malware attacks (i.e., zero-day detection); however, our preliminary studies suggest two limitations in this avenue: (1) one class (OC) classifiers can be limited with relatively low detection rates, and (2) the profiling-based approach (using an autoencoder) may yield better detection performance but under the assumption of the "ideal" threshold setting. In this paper, we tackle these challenges and present a new detection method, which combines the concepts of autoencoding and OC classification, to benefit from strong abstractions by neural networks (using an autoencoder) but to remove the necessity of the complex threshold selection (using an OC classifier). Our extensive experimental results with a recent malware dataset (Meras’18) show the effectiveness of our method with up to 96% accuracy for zero-day malware detection, which is comparable to the supervised learning-based detection (limited to known types of malware). The proposed method also shows the resilience to adversarial attacks, yielding better performance for identifying synthetic samples generated to evade the detection process than supervised learning algorithms.
Chiho Kim, Sang-Yoon Chang, Jonghyun Kim 0005, Dongeun Lee 0001, Jinoh Kim
IEEE BigData3
2020 A Learning-based Data Augmentation for Network Anomaly Detection
abstract
While machine learning technologies have been remarkably advanced over the past several years, one of the fundamental requirements for the success of learning-based approaches would be the availability of high-quality data that thoroughly represent individual classes in a problem space. Unfortunately, it is not uncommon to observe a significant degree of class imbalance with only a few instances for minority classes in many datasets, including network traffic traces highly skewed toward a large number of normal connections while very small in quantity for attack instances. A well-known approach to addressing the class imbalance problem is data augmentation that generates synthetic instances belonging to minority classes. However, traditional statistical techniques may be limited since the extended data through statistical sampling should have the same density as original data instances with a minor degree of variation. This paper takes a learning-based approach to data augmentation to enable effective network anomaly detection. One of the critical challenges for the learning-based approach is the mode collapse problem resulting in a limited diversity of samples, which was also observed from our preliminary experimental result. To this end, we present a novel "Divide-Augment-Combine" (DAC) strategy, which groups the instances based on their characteristics and augments data on a group basis to represent a subset independently using a generative adversarial model. Our experimental results conducted with two recently collected public network datasets (UNSW-NB15 and IDS-2017) show that the proposed technique enhances performances up to 21.5% for identifying network anomalies.
Mohammad Al Olaimat, Dongeun Lee 0001, Youngsoo Kim 0002, Jonghyun Kim 0005, Jinoh Kim
ICCCN4
2018 An Encoding Technique for CNN-based Network Anomaly Detection
abstract
An important challenge in the cyber-space is the effective identification of network anomalies, often caused by malicious activities. With the remarkable advances, machine learning algorithms have widely been studied for network intrusion and anomaly detection. In particular, deep learning based on neural network structures has recently been given a greater attention to deal with the growing complexity of data with higher dimensions and non-linearity. Convolutional Neural Networks (CNNs) is one of the widely employed deep learning methods. In this work, we introduce a new encoding technique that enhances the performance for the identification of anomalous events using a CNN structure. To evaluate, we utilize three different datasets for the extensive analysis. The experimental results show that our method consistently outperforms the gray-scale encoding technique previously proposed over the datasets employed in the evaluation.
Taejoon Kim, Sang C. Suh, Hyunjoo Kim, Jonghyun Kim 0005, Jinoh Kim
IEEE BigData4
2007 PKG-MIB: Private-Mib for Package-Based Linux Systems in a Large Scale Management Domain
Jong-Hyouk Lee, Young-Ju Han, Jonghyun Kim 0005, Jung-Chan Na, Tai-Myung Chung
KES-AMSTA3