Hoon Wei Lim

dblp:l/HWLim · DBLP profile ↗
← Back
29ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-7830-3007ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Computer networks · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2026 ARuleCon: Agentic Security Rule Conversion
abstract
The real-time demand for web security makes Security Information and Event Management (SIEM) platforms and their applied security rule an integral part of the intrusion detection life-cycle. However, the heterogeneity of vendor-specific rules (e.g., Splunk SPL, Microsoft KQL, IBM AQL, Google YARA-L, and RSA ESA) makes cross-platform rule reuse extremely difficult, requiring deep domain knowledge for reliable conversion. As a result, an autonomous and accurate rule conversion framework can significantly lead to effort savings, preserving the value of existing rules. In this paper, we propose ARuleCon, an agentic SIEM-rule conversion approach. Using ARuleCon, the security professionals do not need to distill the source rules' logic and re-map it to target vendors, instead, they provide the source rules, the documentation of the target rules and ARuleCon can purposely convert to the target vendors without more intervention. To achieve this, ARuleCon is equipped with intermediate representation (IR) that aligns core detection logic into vendor-neutral layer, agentic RAG pipeline that retrieves authoritative official vendor documentation to address the convension/schema mismatches, and Python-based consistency check that running both source and target rules in controlled test environments to mitigate subtle semantic drifts. We present a comprehensive evaluation of ARuleCon ranging from textual alignment between the source and target rules, and the execution success of target rules, showcasing ARuleCon can convert rules with higher fidelity, outperforming the baseline LLM models by 15% averagely. Finally, we perform a case study and interview with our industry collaborators 1, which showcases that ARuleCon can significantly save the expert's time on understanding the cross-SIEM's documentation and remapping the logic.
Ming Xu 0006, Hongtai Wang, Yanpei Guo, Zhengmin Yu, Weili Han, Hoon Wei Lim, Jin Song Dong 0001, Jiaheng Zhang
WWW6
2024 Poster: M2ASK: A Correlation-Based Multi-Step Attack Scenario Detection Framework Using MITRE ATT&CK Mapping
abstract
Traditional Network Intrusion Detection Systems (NIDS) often generate large volumes of alerts with redundancies and false positives, incapable of correlating detected attack actions. This adds difficulty for security analysts to construct a comprehensive understanding of multi-step attacks. To address these limitations, we present a novel MITRE-based Multi-step Attack Scenario Construction (M2ASK) algorithm that enhances cyber threat intelligence (CTI) by integrating MITRE ATT&CK tactic and technique mapping, facilitating the interpretation of multi-step attacks and informing response strategies. Our approach processes alert data from NIDSs, transforming it into a network communication graph. Graph-based correlation techniques are employed, combined with MITRE ATT&CK and Cyber Kill Chain stage profiling to construct comprehensive network attack scenarios. Our key contributions include: (1) the development of a Cyber Kill Chain based model for constructing attack scenarios; (2) the alert correlation approach based on MITRE ATT&CK tagging of attack actions.
Qiaoran Meng, Nay Oo, Yuning Jiang 0003, Hoon Wei Lim, Biplab Sikdar 0001
CCS4
2024 KnowPhish: Large Language Models Meet Multimodal Knowledge Graphs for Enhancing Reference-Based Phishing Detection
Yuexin Li, Chengyu Huang 0003, Shumin Deng, Mei Lin Lock, Tri Cao, Nay Oo, Hoon Wei Lim, Bryan Hooi
USENIX Security Symposium7
2024 RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems
abstract
Automotive Keyless Entry (RKE) systems provide car owners with a degree of convenience, allowing them to lock and unlock their car without using a mechanical key. Today’s RKE systems implement disposable rolling codes, making every key fob button press unique, effectively preventing simple replay attacks. However, a prior attack called RollJam was proven to break all rolling code–based systems in general. By a careful sequence of signal jamming, capturing, and replaying, an attacker can become aware of the subsequent valid unlock signal that has not been used yet. RollJam, however, requires continuous deployment indefinitely until it is exploited. Otherwise, the captured signals become invalid if the key fob is used again without RollJam in place. We introduce RollBack, a new replay-and-resynchronize attack against most of today’s RKE systems. In particular, we show that even though the one-time code becomes invalid in rolling code systems, replaying a few previously captured signals consecutively can trigger a rollback-like mechanism in the RKE system. Put differently, the rolling codes become resynchronized back to a previous code used in the past from where all subsequent yet already used signals work again. Moreover, the victim can still use the key fob without noticing any difference before and after the attack. Unlike RollJam, RollBack does not necessitate jamming at all. In fact, it requires signal capturing only once and can be exploited at any time in the future as many times as desired. This time-agnostic property is particularly attractive to attackers, especially in car-sharing/renting scenarios in which accessing the key fob is straightforward. However, while RollJam defeats virtually any rolling code–based system, vehicles might have additional anti-theft measures against malfunctioning key fobs, hence against RollBack. Our ongoing analysis (with crowd-sourced data) against different vehicle makes and models has revealed that ∼ 50% of the examined vehicles in the Asian region are vulnerable to RollBack, whereas the impact tends to be smaller in other regions, such as Europe and North America.
Levente Csikor, Hoon Wei Lim, Jun Wen Wong, Soundarya Ramesh, Rohini Poolat Parameswarath, Mun Choon Chan
ACM Trans. Cyber Phys. Syst.2
2023 POSTER: Security Logs Graph Analytics for Industry Network System
abstract
As Information Technology (IT) infrastructures have become increasingly complex to secure against accelerating cyber threats, current threat detection approaches have been largely silos in nature; security analysts in the environment are typically bombarded with large volume of security alerts that often cause severe fatigues and the possibility of judgement errors. This problem is further exacerbated by the number of false-positives that analysts may waste valuable time and resources pursuing. In this paper, we present how intuitive graph-based machine learning can be used to address the problem of alert fatigue and prioritize risky alerts to assist security analysts. The rationale and workflow of the proposed Graph Analysis (GA) algorithm is discussed in detail, with its effectiveness demonstrated by simulated experiments.
Qiaoran Meng, Nay Oo, Hoon Wei Lim, Biplab Sikdar 0001
AsiaCCS3
2022 PSI-Stats: Private Set Intersection Protocols Supporting Secure Statistical Functions
Jason H. M. Ying, Shuwei Cao 0002, Geong Sen Poh, Jia Xu 0006, Hoon Wei Lim
ACNS5
2022 Machine-Learning-Based Attestation for the Internet of Things Using Memory Traces
abstract
The advent of 4G and 5G mobile networks has made the Internet of Things (IoT) devices an essential part of smart nation drives. Firmware integrity is crucial to the security of IoT systems. Most of the existing techniques for firmware attestation require a legitimate copy of an IoT device’s firmware. However, firmware is considered an intellectual property (IP) of the manufacturer and may not be available. To solve this issue, this article proposes a software-based attestation technique where remote verifiers use machine learning (ML) classifiers on an IoT device’s memory dump to verify the integrity of an IoT device’s internal state. The experimental results from an actual prototype show that the proposed technique not only successfully detects attacks with high accuracy but also results in about 96% lower latency as compared to existing techniques. All this is achieved with high availability, low computational complexity, and without requiring a legitimate copy of the device’s original firmware.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Jun Wen Wong, Jia Xu 0006, Hoon Wei Lim, Biplab Sikdar 0001
IEEE Internet Things J.5
2020 HAtt: Hybrid Remote Attestation for the Internet of Things With High Availability
abstract
The critical and sensitive nature of data that the Internet-of-Things (IoT) devices produce makes them an attractive target for cyber attacks. Among the various types of attacks, malware is becoming a major concern for the IoT device. This article proposes a remote attestation protocol, hybrid remote attestation, which ensures the high availability of IoT devices during the software attestation process. The proposed attestation technique uses a randomized approach to attest different parts of an IoT device's memory. We use physical unclonable functions (PUFs) to protect the secrets of an IoT device from physical attacks. The security analysis shows that the proposed attestation technique can effectively detect roving malware. Implementation of the proposed protocol on Raspberry Pi and AVR/ARM-based ATMEL microcontrollers and comparison with existing techniques shows that the proposed protocol results in significantly higher availability and lower energy consumption.
Muhammad Naveed Aman, Mohamed Haroon Basheer, Siddhant Dash, Jun Wen Wong, Jia Xu 0006, Hoon Wei Lim, Biplab Sikdar 0001
IEEE Internet Things J.6
2020 Data Integrity Threats and Countermeasures in Railway Spot Transmission Systems
abstract
Modern trains rely on balises (communication beacons) located on the track to provide location information as they traverse a rail network. Balises, such as those conforming to the Eurobalise standard, were not designed with security in mind and are thus vulnerable to cyber attacks targeting data availability, integrity, or authenticity. In this work, we discuss data integrity threats to balise transmission modules and use high-fidelity simulation to study the risks posed by data integrity attacks. To mitigate such risk, we propose a practical two-layer solution: At the device level, we design a lightweight and low-cost cryptographic solution to protect the integrity of the location information; at the system layer, we devise a secure hybrid train speed controller to mitigate the impact under various attacks. Our simulation results demonstrate the effectiveness of our proposed solutions.
Hoon Wei Lim, William G. Temple, Bao Anh N. Tran, Binbin Chen 0001, Zbigniew T. Kalbarczyk, Jianying Zhou 0001
ACM Trans. Cyber Phys. Syst.1
2020 PrivateLink: Privacy-Preserving Integration and Sharing of Datasets
abstract
In privacy-enhancing technology, it has been inevitably challenging to strike a reasonable balance between privacy, efficiency, and usability (utility). To this, we propose a highly practical solution for the privacy-preserving integration and sharing of datasets among a group of participants. At the heart of our solution is a new interactive protocol, PrivateLink. Through PrivateLink, each participant is able to randomize his/her dataset via an independent and untrusted third party, such that the resulting dataset can be merged with other randomized datasets contributed by other participants in a privacy-preserving manner. Our approach does not require key sharing among participants in order to integrate different datasets. This, in turn, leads to a user-friendly and scalable solution. Moreover, the correctness of a randomized dataset returned by the third party can be securely verified by the participant. We further demonstrate PrivateLink's general utilities: using it to construct a structure-preserving data integration protocol. This is particularly useful for private, fine-grained integration of network traffic data. We state the security of our protocols under the well-established real-ideal simulation paradigm and demonstrate practicality by a prototype implementation on: 1) healthcare datasets and 2) DNS and NetFlow datasets.
Hoon Wei Lim, Geong Sen Poh, Jia Xu 0006, Varsha Chittawar
IEEE Trans. Inf. Forensics Secur.1
2016 Authenticated Key Exchange Protocols for Parallel Network File Systems
abstract
We study the problem of key establishment for secure many-to-many communications. The problem is inspired by the proliferation of large-scale distributed file systems supporting parallel access to multiple storage devices. Our work focuses on the current Internet standard for such file systems, i.e., parallel Network File System (pNFS), which makes use of Kerberos to establish parallel session keys between clients and storage devices. Our review of the existing Kerberos-based protocol shows that it has a number of limitations: (i) a metadata server facilitating key exchange between the clients and the storage devices has heavy workload that restricts the scalability of the protocol; (ii) the protocol does not provide forward secrecy; (iii) the metadata server generates itself all the session keys that are used between the clients and storage devices, and this inherently leads to key escrow. In this paper, we propose a variety of authenticated key exchange protocols that are designed to address the above issues. We show that our protocols are capable of reducing up to approximately 54 percent of the workload of the metadata server and concurrently supporting forward secrecy and escrow-freeness. All this requires only a small fraction of increased computation overhead at the client.
Hoon Wei Lim, Guomin Yang
IEEE Trans. Parallel Distributed Syst.1
2015 Privacy-Preserving Observation in Public Spaces
Florian Kerschbaum, Hoon Wei Lim
ESORICS (2)2
2014 Distributed Searchable Symmetric Encryption
abstract
Searchable Symmetric Encryption (SSE) allows a client to store encrypted data on a storage provider in such a way, that the client is able to search and retrieve the data selectively without the storage provider learning the contents of the data or the words being searched for. Practical SSE schemes usually leak (sensitive) information during or after a query (e.g., the search pattern). Secure schemes on the other hand are not practical, namely they are neither efficient in the computational search complexity, nor scalable with large data sets. To achieve efficiency and security at the same time, we introduce the concept of distributed SSE (DSSE), which uses a query proxy in addition to the storage provider. We give a construction that combines an inverted index approach (for efficiency) with scrambling functions used in private information retrieval (PIR) (for security). The proposed scheme, which is entirely based on XOR operations and pseudo-random functions, is efficient and does not leak the search pattern. For instance, a secure search in an index over one million documents and 500 keywords is executed in less than 1 second.
Christoph Bösch 0001, Andreas Peter 0001, Bram Leenders, Hoon Wei Lim, Qiang Tang 0001, Huaxiong Wang, Pieter H. Hartel, Willem Jonker
PST4
2014 Spatial encryption supporting non-monotone access structure
Jie Chen 0021, Hoon Wei Lim, San Ling, Le Su, Huaxiong Wang
Des. Codes Cryptogr.2
2014 The relation and transformation between hierarchical inner product encryption and spatial encryption
Jie Chen 0021, Hoon Wei Lim, San Ling, Huaxiong Wang
Des. Codes Cryptogr.2
2014 Shorter identity-based encryption via asymmetric pairings
Jie Chen 0021, Hoon Wei Lim, San Ling, Huaxiong Wang, Hoeteck Wee
Des. Codes Cryptogr.2
2014 Cross-Domain Password-Based Authenticated Key Exchange Revisited
abstract
We revisit the problem of secure cross-domain communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this article, we propose a generic framework for designing four-party password-based authenticated key exchange (4PAKE) protocols. Our framework takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords, which they share with their respective domain authentication servers. On the other hand, the authentication servers, assumed to be part of a standard PKI, act as ephemeral CAs that certify some key materials that the users can subsequently use to exchange and agree on as a session key. Moreover, we adopt a compositional approach. That is, by treating any secure two-party password-based key exchange (2PAKE) protocol and two-party asymmetric-key/symmetric-key-based key exchange (2A/SAKE) protocol as black boxes, we combine them to obtain generic and provably secure 4PAKE protocols.
Liqun Chen 0002, Hoon Wei Lim, Guomin Yang
ACM Trans. Inf. Syst. Secur.2
2013 Fully Secure Attribute-Based Systems with Short Ciphertexts/Signatures and Threshold Access Structures
Jie Chen 0021, Hoon Wei Lim, Zhenfeng Zhang, Dengguo Feng, San Ling, Huaxiong Wang
CT-RSA3
2013 Cross-domain password-based authenticated key exchange revisited
abstract
We revisit the problem of cross-domain secure communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a four-party password-based authenticated key exchange (4PAKE) protocol that takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with their respective domain authentication servers. On the other hand, the authentication servers, assumed to be part of a standard PKI, act as ephemeral CAs that “certify” some key materials that the users can subsequently exchange and agree on a session key. Moreover, we adopt a compositional approach. That is, by treating any secure two-party password-based key exchange protocol and two-party asymmetric-key based key exchange protocol as black boxes, we combine them to obtain a generic and provably secure 4PAKE protocol.
Liqun Chen 0002, Hoon Wei Lim, Guomin Yang
INFOCOM2
2013 Revocable IBE Systems with Almost Constant-Size Key Update
Le Su, Hoon Wei Lim, San Ling, Huaxiong Wang
Pairing2
2012 Revocable Identity-Based Encryption from Lattices
Jie Chen 0021, Hoon Wei Lim, San Ling, Huaxiong Wang, Khoa Nguyen 0002
ACISP2
2012 Shorter IBE and Signatures via Asymmetric Pairings
Jie Chen 0021, Hoon Wei Lim, San Ling, Huaxiong Wang, Hoeteck Wee
Pairing2
2012 Combined Public-Key Schemes: The Case of ABE and ABS
Jie Chen 0021, Hoon Wei Lim, Zhenfeng Zhang, Dengguo Feng
ProvSec3
2012 Revisiting a Secret Sharing Approach to Network Codes
ZhaoHui Tang, Hoon Wei Lim, Huaxiong Wang
ProvSec2
2012 Workflow Signatures for Business Process Compliance
abstract
Interorganizational workflow systems play a fundamental role in business partnerships. We introduce and investigate the concept of workflow signatures. Not only can these signatures be used to ensure authenticity and protect integrity of workflow data, but also to prove the sequence and logical relationships, such as AND-join and AND-split, of a workflow. Hence, workflow signatures can be electronic evidence useful for auditing, that is proving compliance of business processes against some regulatory requirements. Furthermore, signing keys can be used to grant permissions to perform tasks. Since the signing keys are issued on-the-fly, authorization to execute a task within a workflow can be controlled and granted dynamically at runtime. In this paper, we propose a concrete workflow signature scheme, which is based on hierarchical identity-based cryptography, to meet security properties required by interorganizational workflows.
Hoon Wei Lim, Florian Kerschbaum, Huaxiong Wang
IEEE Trans. Dependable Secur. Comput.1
2011 An Efficient Cacheable Secure Scalar Product Protocol for Privacy-Preserving Data Mining
Duc H. Tran, Wee Keong Ng, Hoon Wei Lim
DaWaK3
2008 Role Signatures for Access Control in Open Distributed Systems
Jason Crampton, Hoon Wei Lim
SEC2
2007 Multi-key Hierarchical Identity-Based Signatures
Hoon Wei Lim, Kenneth G. Paterson
IMACC1
2005 Identity-Based Cryptography for Grid Security
abstract
The majority of current security architectures for grid systems use public key infrastructure (PKI) to authenticate identities of grid members and to secure resource allocation to these members. Identity-based cryptography (IBC) has some attractive properties which seem to align well with the demands of grid computing. This paper presents a comprehensive investigation of the use of identity-based techniques to provide an alternative grid security architecture. We propose a customised identity-based key agreement protocol which fits nicely with the grid security infrastructure (GSI) and provides a more lightweight secure job submission environment for grid users. Single sign-on and delegation services are also supported in a very natural way in our identity-based architecture.
Hoon Wei Lim, Kenneth G. Paterson
e-Science1