Byung Il Kwak

dblp:159/2395 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
5since 2021 · last 2024
0000-0002-2009-4580ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 AERO: Automotive Ethernet Real-Time Observer for Anomaly Detection in In-Vehicle Networks
abstract
Automotive Ethernet enables high-bandwidth in-vehicle networking, facilitating the transmission of sensor data among electronic control units. However, the increasing connectivity and potential vulnerability inheritance in connected and autonomous vehicles expose them to security risks. To address this challenge, an intrusion detection system (IDS) capable of analyzing automotive Ethernet traffic and detecting anomalies is essential. In thisarticle, we propose automotive Ethernet real-time observer (AERO), an unsupervised network IDS designed to protect in-vehicle networks. AERO consists of three components: a feature extractor that constructs three multimodal features, a neural network for processing the extracted features, and an online anomaly detector that calculates outlier scores in real time. We evaluate the performance of AERO using the TOW-IDS automotive Ethernet intrusion dataset. The experimental results demonstrate that AERO achieves high detection performance across five different attack types and is highly applicable to automotive-grade devices for real-time anomaly detection.
Seonghoon Jeong 0001, Huy Kang Kim, Mee Lan Han, Byung Il Kwak
IEEE Trans. Ind. Informatics4
2023 TOW-IDS: Intrusion Detection System Based on Three Overlapped Wavelets for Automotive Ethernet
abstract
Devices that ensure vehicle and driver safety or provide services to drivers generate a substantial amount of network traffic. The traffic is transmitted to the In-Vehicle Network (IVN) depending on the defined function. Consequently, to quickly process a lot of traffic transmitted to the IVN, an advanced network protocol such as Automotive Ethernet is necessary. However, owing to the connectivity reinforcement between devices inside a vehicle and external networks, attack vectors and vulnerabilities can be easily inherited from an established Ethernet to Automotive Ethernet. The present study proposes a method for detecting and identifying abnormalities in Automotive Ethernet based on wavelet transform and deep convolutional neural network. First, we define attack scenarios and extract normal and abnormal data corresponding to these scenarios. Second, we conduct several preprocesses, such as fixing the packet size and normalizing the network image data. Finally, we conduct extensive evaluations of the proposed method’s performance, considering the size of network image data and multi-resolution levels. The results demonstrate that the proposed method can effectively detect an abnormality. Furthermore, the results suggest that the our method is more effective in terms of time-cost compared to default ResNet and EfficientNet methods.
Mee Lan Han, Byung Il Kwak, Huy Kang Kim
IEEE Trans. Inf. Forensics Secur.2
2021 Cosine similarity based anomaly detection methodology for the CAN bus
Byung Il Kwak, Mee Lan Han, Huy Kang Kim
Expert Syst. Appl.1
2021 Event-Triggered Interval-Based Anomaly Detection and Attack Identification Methods for an In-Vehicle Network
abstract
Vehicle communication technology has been steadily progressing alongside the convergence of the in-vehicle network (IVN) and wireless communication technology. The communication with various external networks further reinforces the connectivity between the inside and outside of a vehicle. However, this bears risks of malicious packet attacks on computer-assisted mechanical mechanisms that are capable of hijacking the vehicle's functions. The present study proposes a method to detect and identify abnormalities in vehicular networks based on the periodic event-triggered interval of the controller area network (CAN) messages. To this end, we first define four attack scenarios and then extract normal and abnormal driving data corresponding to these scenarios. Next, we analyze the CAN ID's event-triggered interval and measure statistical moments depending on the defined time-window. Finally, we conduct extensive evaluations of the proposed methods' performance by considering different attack scenarios and three types of machine learning models. The results demonstrate that the proposed method can effectively detect an abnormality in the IVN, with up to 99% accuracy. Our results suggest that when tree-based machine learning models are used as the classifier, the proposed method of attack identification can achieve more than 94% accuracy.
Mee Lan Han, Byung Il Kwak, Huy Kang Kim
IEEE Trans. Inf. Forensics Secur.2
2021 Driver Identification Based on Wavelet Transform Using Driving Patterns
abstract
The modern automotive system, based on the convergence of information and communication technologies, is equipped with various functions to ensure vehicle safety and convenience of the driver. A driver-identification technology is an effective method to perform vehicle-theft detection. It can also provide customized driver-personalization services, such as healthcare or insurance. In this article, we propose and evaluate a driver-identification method based on wavelet transform by performing driving-pattern analysis for each driver. We compare the performances of three different machine-learning algorithms, namely Support Vector Machine (SVM), Random Forest, and XGBoost for performing driver identification. The proposed method is applicable to both binary and multiclass classifications for the driving data of five drivers. In the case of motorway, the XGBoost classifier identifies each driver and delivers an accuracy of up to 96.18% in binary classification and an accuracy of 91.6% in multiclass classification. Moreover, in the case of an urban road, the SVM classifier achieves an accuracy of up to 95.07% in binary classification and accuracy of 89.06% in multiclass classification. The proposed method provides a context for a better understanding of the association between driver behavior, which is an in-vehicle event, and mechanical reactions. Our results shall help researchers to broaden the understanding of driver identification using in-vehicle data.
Byung Il Kwak, Mee Lan Han, Huy Kang Kim
IEEE Trans. Ind. Informatics1
2019 CBR-Based Decision Support Methodology for Cybercrime Investigation: Focused on the Data-Driven Website Defacement Analysis
abstract
Criminal profiling is a useful technique to identify the most plausible suspects based on the evidence discovered at the crime scene. Similar to offline criminal profiling, in-depth profiling for cybercrime investigation is useful in analysing cyberattacks and for speculating on the identities of the criminals. Every cybercrime committed by the same hacker or hacking group has unique traits such as attack purpose, attack methods, and target. These unique traits are revealed in the evidence of cybercrime; in some cases, these unique traits are well hidden in the evidence such that it cannot be easily perceived. Therefore, a complete analysis of several factors concerning cybercrime can provide an investigator with concrete evidence to attribute the attacks and narrow down the scope of the criminal data and grasp the criminals in the end. We herein propose a decision support methodology based on the case-based reasoning (CBR) for cybercrime investigation. This study focuses on the massive data-driven analysis of website defacement. Our primary aim in this study is to demonstrate the practicality of the proposed methodology as a proof of concept. The assessment of website defacement was performed through the similarity measure and the clustering processing in the reasoning engine based on the CBR. Our results show that the proposed methodology that focuses on the investigation enables a better understanding and interpretation of website defacement and assists in inferring the hacker’s behavioural traits from the available evidence concerning website defacement. The results of the case studies demonstrate that our proposed methodology is beneficial for understanding the behaviour and motivation of the hacker and that our proposed data-driven analytic methodology can be utilized as a decision support system for cybercrime investigation.
Mee Lan Han, Byung Il Kwak, Huy Kang Kim
Secur. Commun. Networks2
2016 Know your master: Driver profiling-based anti-theft method
abstract
Although many anti-theft technologies are implemented, auto-theft is still increasing. Also, security vulnerabilities of cars can be used for auto-theft by neutralizing anti-theft system. This keyless auto-theft attack will be increased as cars adopt computerized electronic devices more. To detect auto-theft efficiently, we propose the driver verification method that analyzes driving patterns using measurements from the sensor in the vehicle. In our model, we add mechanical features of automotive parts that are excluded in previous works, but can be differentiated by drivers' driving behaviors. We design the model that uses significant features through feature selection to reduce the time cost of feature processing and improve the detection performance. Further, we enrich the feature set by deriving statistical features such as mean, median, and standard deviation. This minimizes the effect of fluctuation of feature values per driver and finally generates the reliable model. We also analyze the effect of the size of sliding window on performance to detect the time point when the detection becomes reliable and to inform owners the theft event as soon as possible. We apply our model with real driving and show the contribution of our work to the literature of driver identification.
Byung Il Kwak, Huy Kang Kim
PST1