Hojoon Lee 0001

dblp:119/7678-1 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
12since 2021 · last 2025
0000-0001-5344-6266ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 5 first-author · 11 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 PIM-ORAM: Towards Oblivious RAM Primitives in Commodity Processing-In-Memory
abstract
Oblivious RAM (ORAM) is theoretically proven to render memory access patterns of a computation completely uniform, mitigating memory side-channel attacks. However, it is accompanied by orders of magnitude slower memory access latency and, thus, is often impractical in many circumstances. On the other hand, Processing-In-Memory (PIM) has been advancing as a solution to accelerate memory-intensive work-loads and mitigate the memory wall problem. In this paper, we explore the new direction of in-DRAM oblivious RAM with a design named PIM-ORAM. We retrofit the currently available commodity PIM hardware to provide future direction for secure computation on PIM, and design PIM-ORAM. Our design proposes split-data ORAM, a parallelizable in-memory ORAM scheme that takes full advantage of the parallel computing power of the PIM while retaining the original security guarantee of ORAM and dealing with the constraints existing in the commodity PIM. We evaluate PIM-ORAM using the PIM -enabled testbed cloud to provide more realistic numerical values. The evaluation shows that PIM-ORAM alleviates the increase of memory bus usage and ORAM access latency when the ORAM capacity increases.
Byeongsu Woo, Kha Dinh Duy, Youngkwang Han, Brent ByungHoon Kang, Hojoon Lee 0001
ACSAC5
2025 Dependable Code Repair with LLMs: AI-Driven Vulnerability Detection and Automated Patching
abstract
The rapid proliferation of software vulnerabilities has created an urgent need for intelligent, automated methods to detect and mitigate security flaws at scale. Traditional vulnerability analysis depends heavily on manual inspection and domain-specific expertise, which are increasingly inadequate in the era of generative AI-driven code development. This research proposes an AI-based automated vulnerability detection and secure code generation framework that leverages multi-modal datasets, including source code and binaries, to achieve end-to- end automation across the vulnerability lifecycle: detection, patch generation, and validation. The system integrates explainable AI (XAI)-based vulnerability cause analysis, generative patch synthesis, system-level defensive code generation, Rust-based memory safety transformation, and differential privacy mechanisms for model confidentiality. Developed through a Korea- U.S. joint research initiative, this project aims to establish an internationally deployable platform for trustworthy and privacy- preserving AI -driven software security. The proposed research contributes both foundational methods and operational tools toward self-healing, explainable, and secure-by-design software ecosystems.
Sungmin Han, Hyoungshick Kim, Hojoon Lee 0001, Hyungon Moon, Yuseok Jeon, Ho Bae, Donghyun Yeo, Gail-Joon Ahn, Sangkyun Lee 0002
PRDC3
2025 INCOGNITOS: A Practical Unikernel Design for Full-System Obfuscation in Confidential Virtual Machines
abstract
Recent works have repeatedly proven the practicality of side-channel attacks in undermining the confidentiality guarantees of Trusted Execution Environments such as Intel SGX. Meanwhile, the trusted execution in the cloud is witnessing a trend shift towards confidential virtual machines (CVMs). Unfortunately, several side-channel attacks have survived the shift and are feasible even for CVMs, along with the new attacks discovered on the CVM architectures. Previous works have explored defensive measures for securing userspace enclaves (i.e., Intel SGX) against side-channel attacks. However, the design space for a CVM-based obfuscation execution engine is largely unexplored. This paper proposes a unikernel design named NCOGNITOS provide full-system obfuscation for CVM-based cloud workloads. INCOGNITOS fully embraces unikernel principles such as minimized TCB and direct hardware access to render full-system obfuscation feasible. INCOGNITOS retrofits two key OS components, the scheduler and memory management, to implement a novel adaptive obfuscation scheme. INCOGNITOS's scheduling is designed to be self-sovereign from the timer interrupts from the untrusted hypervisor with its synchronous tick delivery. This allows INCOGNITOS to reliably monitor the frequency of the hypervisor's possession of execution control (i.e., VMExits) and adjust the frequency of memory rerandomization performed by the paging subsystem, which transparently performs memory rerandomization through direct MMU access. The resulting INCOGNITOS design makes a case for a self-obfuscating unikernel as a secure CVM deployment strategy while further advancing the obfuscation technique compared to previous works. Evaluation results demonstrate INCOGNITOS'S resilience against CVM attacks and show that its adaptive obfuscation scheme enables practical performance for real-world programs.
Kha Dinh Duy, Hajeong Lim, Hojoon Lee 0001
SP4
2024 (In)visible Privacy Indicator: Security Analysis of Privacy Indicator on Android Devices
abstract
In Android 12, Google introduced a new security feature called the privacy indicator to protect users from spyware. The privacy indicator visually alerts users by displaying a green circle in the notification bar when an application accesses the camera. While this feature initially appears effective, our work has identified two possible attack scenarios that can undermine it. The first attack uses screen overlay techniques with a higher Z-order and deceptive status bar layouts to make it difficult to see the privacy indicator. In a user study involving 44 participants, only 13.6% of participants recognized the indicator under UI overlay attacks, compared to 63.6% in default Android 12 settings. The second attack exploits device configurations to disable the privacy indicator. Our findings were reported to the developers of the Android system UI at Samsung Electronics and the Google Issue Tracker, and we received acknowledgments from both parties. As countermeasures, we recommend ensuring the integrity of the privacy indicator using trusted execution facilities. We introduce a proof-of-concept solution called SEPI (Security-Enhanced Privacy Indicator), which utilizes a secure hypervisor and ARM TrustZone. SEPI is designed to detect camera and microphone activities, subsequently displaying the relevant indicator with the highest Z-order in a securely isolated display buffer. Our experimental findings revealed only a minimal 3.3% reduction in benchmark scores compared to the device's default operational state. The SEPI privacy indicator is displayed with a negligible mean delay of 20.92 ms.
Yurak Choe, Hyungseok Yu, Taeho Kim 0001, Shinjae Lee, Hojoon Lee 0001, Hyoungshick Kim
AsiaCCS5
2024 uMMU: Securing Data Confidentiality with Unobservable Memory Subsystem
abstract
Ensuring data confidentiality in a computing system's memory hierarchy proved to be a formidable challenge with the large attack surface. Diverse and powerful attacks threaten data confidentiality. Memory safety is notoriously hard to achieve with unsafe languages, thereby empowering adversaries with unauthorized memory accesses, as represented by the HeartBleed incident. More recently, microarchitectural side channel attacks reign as a prevalent threat against data confidentiality that affects program execution including the safeguarded ones inside TEEs.
Hajeong Lim, Hojoon Lee 0001
CCS3
2024 RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of Rust
Kyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim, Hojoon Lee 0001
USENIX Security Symposium5
2023 Capacity: Cryptographically-Enforced In-Process Capabilities for Modern ARM Architectures
abstract
In-process compartmentalization and access control have been actively explored to provide in-place and efficient isolation of in-process security domains. Many works have proposed compartmentalization schemes that leverage hardware features, most notably using the new page-based memory isolation feature called Protection Keys for Userspace (PKU) on x86. Unfortunately, the modern ARM architecture does not have an equivalent feature. Instead, newer ARM architectures introduced Pointer Authentication (PA) and Memory Tagging Extension (MTE), adapting the reference validation model for memory safety and runtime exploit mitigation. We argue that those features have been underexplored in the context of compartmentalization and that they can be retrofitted to implement a capability-based in-process access control scheme.
Kha Dinh Duy, Kyuwon Cho, Taehyun Noh, Hojoon Lee 0001
CCS4
2023 SE-PIM: In-Memory Acceleration of Data-Intensive Confidential Computing
abstract
Demand for data-intensive workloads and confidential computing are the prominent research directions shaping the future of cloud computing. Computer architectures are evolving to accommodate the computing of large data. Meanwhile, a plethora of works has explored protecting the confidentiality of the in-cloud computation in the context of hardware-based secure enclaves. However, the approach has faced challenges in achieving efficient large data computation. In this paper, we present a novel design, calledse-pim, that retrofits Processing-In-Memory (PIM) as a data-intensive confidential computing accelerator. PIM-accelerated computation renders large data computation highly efficient by minimizing data movement. Based on our observation that moving computation closer to memory can achieve efficiency of computation and confidentiality of the processed information simultaneously, we study the advantages of confidential computinginsidememory. We construct our findings into a software-hardware co-design calledse-pim. Our design illustrates the advantages of PIM-based confidential computing acceleration. We study the challenges in adapting PIM in confidential computing and propose a set of imperative changes, as well as a programming model that can utilize them. Our evaluation showsse-pimcan provide a side-channel resistant secure computation offloading and run data-intensive applications with negligible performance overhead compared to the baseline PIM model.
Kha Dinh Duy, Hojoon Lee 0001
IEEE Trans. Cloud Comput.2
2023 DID We Miss Anything?: Towards Privacy-Preserving Decentralized ID Architecture
abstract
Decentralized Identity (DID) is emerging as a new digital identity management scheme that promises users complete control of their personal data and identification without central authority involvement. The World Wide Web Consortium (W3C) has drafted the DID standard and provided reference implementations. We conduct a security analysis of the W3C DID standard and the reference universal resolver implementation, focusing on user privacy in the DID resolving process. The universal resolver is the key component in the architecture that processes DID requests and DID document retrievals. Our analysis demonstrates that privacy issues can arise due to the imprudent design of the universal resolver. Furthermore, we found that side-channels in the DID document caching schemes of real-world DID services can entail privacy concerns. Motivated by our security analysis, we present a novel DID resolving design, called Oblivira, to enable obliviously DID resolving. Oblivira is a secure resolving agent with a small footprint that enforces the universal resolver to resolve requests without knowing their content. We also propose a privacy-preserving DID document caching scheme that eliminates side-channels. Our evaluation results show that Oblivira only incurs approximately 2.6% of overhead on average with different resolver settings (3, 6, and 12 threads).
Siwon Huh, Myungkyu Shim, Simon S. Woo, Hyoungshick Kim, Hojoon Lee 0001
IEEE Trans. Dependable Secur. Comput.6
2023 Harnessing the x86 Intermediate Rings for Intra-Process Isolation
abstract
Modern applications often involve the processing of sensitive information. However, the lack of privilege separation within the user space leaves sensitive application secrets such as cryptographic keys just as unprotected as a ”hello world” string. Cutting-edge hardware-supported security features are being introduced. However, the features are often vendor-specific or lack compatibility with older generations of the processors. The situation leaves developers with no portable solution to incorporate protection for the sensitive application component. We propose LOTRx86, a fundamental and portable approach for user-space privilege separation. Our approach creates a more privileged user execution layer calledPrivUserby harnessing the underused intermediate privilege levels on the x86 architecture. The PrivUser memory space, a set of pages within process address space that are inaccessible to user mode, is a safe place for application secrets and routines that access them. We implement the LOTRx86 ABI that exports theprivcallinterface to users to invoke secret handling routines in PrivUser. This way, sensitive application operations that involve the secrets are performed in a strictly controlled manner. The memory access control in our architecture isprivilege-based, accessing the protected application secret only requires a change in the privilege, eliminating the need for costly remote procedure calls or change in address space. We evaluated our platform by developing a proof-of-concept LOTRx86-enabled web server that employs our architecture to securely access its private key during an SSL connection. We conducted a set of experiments, including a performance measurement on the PoC onbothIntel and AMD PCs, and confirmed that LOTRx86 incurs only a limited performance overhead.
Hojoon Lee 0001, Chihyun Song, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.1
2022 EmuID: Detecting presence of emulation through microarchitectural characteristic on ARM
Yeseul Choi, Yunjong Jeong, Daehee Jang, Brent ByungHoon Kang, Hojoon Lee 0001
Comput. Secur.5
2021 On the Analysis of Byte-Granularity Heap Randomization
abstract
Heap randomization, in general, has been a well-trodden area; however, the efficacy of byte-granularity randomization has never been fully explored as misalignment raises various concerns. Modern heap exploits often abuse the determinism in word alignment, and modern CPU architecture better supports unaligned access (since Nehalem). Based on such new developments, we conduct an in-depth analysis of evaluating the efficacy of byte-granularity heap randomization in three folds: (i) security effectiveness, (ii) performance impact, and (iii) compatibility analysis to measure deployment cost. Security discussion is based on 20 CVE case studies. To measure performance details, we conduct cycle-level microbenchmarks and report that the performance cost is highly concentrated to edge cases depending on the L1-cache line. Based on such analysis, we design and implement an allocator suited for byte-granularity heap randomization. On the negative side, our analysis suggests that byte-granularity heap randomization has high deployment cost due to various implementation conflicts. We enumerate the problematic compatibility issues using Coreutils, Nginx, and ChakraCore benchmarks.
Daehee Jang, Jonghwan Kim, Hojoon Lee 0001, Minjoon Park, Yunjong Jung, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.3
2019 KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object
abstract
External hardware-based kernel integrity monitors have been proposed to mitigate kernel-level malwares. However, the existing external approaches have been limited to monitoring the static regions of kernel while the latest rootkits manipulate the dynamic kernel objects. To address the issue, we present KI-Mon, a hardware-based platform that introduces event-triggered monitoring techniques for kernel dynamic objects. KI-Mon advances the bus traffic snooping technique to not only detect memory write traffic on the host bus but also filter out all but meaningful traffic to generate events. We show how kernel invariant verification software can be developed around these events, and also provide a set of APIs for additional invariant verification development. We also report our findings and considerations on the unique challenges for external monitors – such as cache coherency, dynamic object tracing. We introduce host-side kernel changes that alleviate these issues that involve changes in kernel's object allocation and cache policy control. We have built a prototype of KI-Mon on the ARM architecture to demonstrate the efficacy of KI-Mon's event-triggered mechanism in terms of performance overhead for the monitored host system and the processor usage of the KI-Mon processor.
Hojoon Lee 0001, Hyungon Moon, Ingoo Heo, Daehee Jang, Jin Soo Jang, Yunheung Paek, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.1
2018 Lord of the x86 Rings: A Portable User Mode Privilege Separation Architecture on x86
abstract
Modern applications often involve processing of sensitive information. However, the lack of privilege separation within the user space leaves sensitive application secret such as cryptographic keys just as unprotected as a "hello world" string. Cutting-edge hardware-supported security features are being introduced. However, the features are often vendor-specific or lack compatibility with older generations of the processors. The situation leaves developers with no portable solution to incorporate protection for the sensitive application component. We propose LOTRx86, a fundamental and portable approach for user-space privilege separation. Our approach creates a more privileged user execution layer called PrivUser by harnessing the underused intermediate privilege levels on the x86 architecture. The PrivUser memory space, a set of pages within process address space that are inaccessible to user mode, is a safe place for application secrets and routines that access them. We implement the LOTRx86 ABI that exports the privcall interface to users to invoke secret handling routines in PrivUser. This way, sensitive application operations that involve the secrets are performed in a strictly controlled manner. The memory access control in our architecture is privilege-based, accessing the protected application secret only requires a change in the privilege, eliminating the need for costly remote procedure calls or change in address space. We evaluated our platform by developing a proof-of-concept LOTRx86-enabled web server that employs our architecture to securely access its private key during an SSL connection. We conducted a set of experiments including a performance measurement on the PoC on both Intel and AMD PCs, and confirmed that LOTRx86 incurs only a limited performance overhead.
Hojoon Lee 0001, Chihyun Song, Brent ByungHoon Kang
CCS1
2018 A dynamic per-context verification of kernel address integrity from external monitors
Hojoon Lee 0001, Yunheung Paek, Brent ByungHoon Kang
Comput. Secur.1
2017 Detecting and Preventing Kernel Rootkit Attacks with Bus Snooping
abstract
To protect the integrity of operating system kernels, we presentVigilare system, a kernel integrity monitor that is architected to snoop the bus traffic of the host system from a separate independent hardware. Thissnoop-based monitoringenabled by the Vigilare system, overcomes the limitations of thesnapshot-based monitoringemployed in previous kernel integrity monitoring solutions. Being based on inspecting snapshots collected over a certain interval, the previous hardware-based monitoring solutions cannot detecttransient attacksthat can occur in between snapshots, and cannot protect the kernel against permanent damage. We implemented three prototypes of the Vigilare system by addingSnooperhardware connections module to the host system for bus snooping, and a snapshot-based monitor to be comared with, in order to evaluate the benefit of snoop-based monitoring. The prototypes of Vigilare system detected all the transient attacks and the second one protected the kernel with negligible performance degradation while the snapshot-based monitor could not detect all the attacks and induced considerable performance degradation as much as 10 percent in our tuned STREAM benchmark test.
Hyungon Moon, Hojoon Lee 0001, Ingoo Heo, Yunheung Paek, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.2
2014 ATRA: Address Translation Redirection Attack against Hardware-based External Monitors
abstract
Hardware-based external monitors have been proposed as a trustworthy method for protecting the kernel integrity. We introduce the design and implementation of Address Translation Redirection Attack (ATRA) that enables complete evasion of the hardware-based external monitor that anchors its trust on a separate processor. ATRA circumvents the external monitor by redirecting the memory access to critical kernel objects into a non-monitored region. Despite the seriousness of the ATRA issue, the address translation integrity has been assumed in many hardware-based external monitors and the possibility of its exploitation has been suggested yet many considered hypothetical. We explore the intricate details of ATRA, explain major challenges in realizing ATRA in practice, and address them with two types of ATRA called Memory-bound ATRA and Register-bound ATRA. Our evaluations with benchmarks show that ATRA does not introduce a noticeable performance degradation to the host system, proving practical applicability of the attack to alert the researchers to seriously address ATRA in designing future external monitors.
Daehee Jang, Hojoon Lee 0001, Daehyeok Kim, Daegyeong Kim, Brent ByungHoon Kang
CCS2
2013 KI-Mon: A Hardware-assisted Event-triggered Monitoring Platform for Mutable Kernel Object
Hojoon Lee 0001, Hyungon Moon, Daehee Jang, Yunheung Paek, Brent ByungHoon Kang
USENIX Security Symposium1
2012 Vigilare: toward snoop-based kernel integrity monitor
abstract
In this paper, we present Vigilare system, a kernel integrity monitor that is architected to snoop the bus traffic of the host system from a separate independent hardware. This snoop-based monitoring enabled by the Vigilare system, overcomes the limitations of the snapshot-based monitoring employed in previous kernel integrity monitoring solutions. Being based on inspecting snapshots collected over a certain interval, the previous hardware-based monitoring solutions cannot detect transient attacks that can occur in between snapshots. We implemented a prototype of the Vigilare system on Gaisler's grlib-based system-on-a-chip (SoC) by adding Snooper hardware connections module to the host system for bus snooping. To evaluate the benefit of snoop-based monitoring, we also implemented similar SoC with a snapshot-based monitor to be compared with. The Vigilare system detected all the transient attacks without performance degradation while the snapshot-based monitor could not detect all the attacks and induced considerable performance degradation as much as 10% in our tuned STREAM benchmark test.
Hyungon Moon, Hojoon Lee 0001, Yunheung Paek, Brent ByungHoon Kang
CCS2