Brent ByungHoon Kang

dblp:17/6702 · DBLP profile ↗
← Back
54ranked-venue papers
3as first author
15since 2021 · last 2026
0000-0001-8984-1006ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 38 · 1 first-author · 9 since 2021Systems, architecture and hardware · 9 · 2 first-authorArtificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Timestep-Compressed Attack on Spiking Neural Networks Through Timestep-Level Backpropagation
abstract
State-of-the-art (SOTA) gradient-based adversarial attacks on spiking neural networks (SNNs), which largely rely on extending FGSM and PGD frameworks, face a critical limitation: substantial attack latency from multi-timestep processing, rendering them infeasible for practical real-time applications. This inefficiency stems from their design as direct extensions of ANN paradigms, which fail to exploit key SNN properties. In this paper, we propose the timestep compressed attack (TCA), a novel framework that significantly reduces attack latency. TCA introduces two components founded on key insights into SNN behavior. First, timestep-level backpropagation (TLBP) is based on our finding that global temporal information in backpropagation to generate perturbations is not critical for an attack’s success, enabling per-timestep evaluation for early stopping. Second, adversarial membrane potential reuse (A-MPR) is motivated by the observation that initial timesteps are inefficiently spent accumulating membrane potential, a warm-up phase that can be pre-calculated and reused. Our experiments on VGG-11 and ResNet-17 with the CIFAR-10/100 and CIFAR10-DVS datasets show that TCA significantly reduces the required attack latency by up to 56.6% and 57.1% compared to SOTA methods in white-box and black-box settings, respectively, while maintaining a comparable attack success rate.
Donghwa Kang, Doohyun Kim, Sang-Ki Ko, Jinkyu Lee 0001, Hyeongboo Baek, Brent ByungHoon Kang
AAAI6
2025 PIM-ORAM: Towards Oblivious RAM Primitives in Commodity Processing-In-Memory
abstract
Oblivious RAM (ORAM) is theoretically proven to render memory access patterns of a computation completely uniform, mitigating memory side-channel attacks. However, it is accompanied by orders of magnitude slower memory access latency and, thus, is often impractical in many circumstances. On the other hand, Processing-In-Memory (PIM) has been advancing as a solution to accelerate memory-intensive work-loads and mitigate the memory wall problem. In this paper, we explore the new direction of in-DRAM oblivious RAM with a design named PIM-ORAM. We retrofit the currently available commodity PIM hardware to provide future direction for secure computation on PIM, and design PIM-ORAM. Our design proposes split-data ORAM, a parallelizable in-memory ORAM scheme that takes full advantage of the parallel computing power of the PIM while retaining the original security guarantee of ORAM and dealing with the constraints existing in the commodity PIM. We evaluate PIM-ORAM using the PIM -enabled testbed cloud to provide more realistic numerical values. The evaluation shows that PIM-ORAM alleviates the increase of memory bus usage and ORAM access latency when the ORAM capacity increases.
Byeongsu Woo, Kha Dinh Duy, Youngkwang Han, Brent ByungHoon Kang, Hojoon Lee 0001
ACSAC4
2025 BankTweak: Adversarial Attack Against Multi-Object Trackers by Manipulating Feature Banks
abstract
Modern multi-object tracking (MOT) predominantly relies on the tracking-by-detection paradigm to construct object trajectories. Traditional MOT attacks primarily degrade detection quality in specific frames only, lacking efficiency, while state-of-the-art (SOTA) approaches induce persistent identity (ID) switches by manipulating object positions during the association phase, even after the attack ends. In this paper, we reveal that these SOTA attacks can be easily counteracted by adjusting distance-related parameters in the association phase, exposing their lack of robustness. To overcome these limitations, we propose BankTweak, a novel adversarial attack targeting feature-based MOT systems to induce persistent ID switches (efficiency) without modifying object positions (robustness). BankTweak exploits a critical vulnerability in the Hungarian matching algorithm of MOT systems by strategically injecting altered features into feature banks during the association phase. Extensive experiments on MOT17 and MOT20 datasets, combining various detectors, feature extractors, and trackers, demonstrate that BankTweak significantly outperforms SOTA attacks up to 11.8 times, exposing fundamental vulnerabilities in the tracking-by-detection framework.
Woojin Shin, Donghwa Kang, Daejin Choi, Brent ByungHoon Kang, Jinkyu Lee 0001, Hyeongboo Baek
IJCAI4
2025 CF-DETR: Coarse-to-Fine Transformer for Real-Time Object Detection
abstract
Detection Transformers (DETR) are increasingly adopted in autonomous vehicle (AV) perception systems due to their superior accuracy over convolutional networks. However, concurrently executing multiple DETR tasks presents significant challenges in meeting firm real-time deadlines (R1) and high accuracy requirements (R2), particularly for safety-critical objects, while navigating the inherent latency-accuracy trade-off under resource constraints. Existing real-time DNN scheduling approaches often treat models generically, failing to leverage Transformer-specific properties for efficient resource allocation. To address these challenges, we propose CF-DETR, an integrated system featuring a novel coarse-to-fine Transformer architecture and a dedicated real-time scheduling framework NPFP**. CF-DETR employs three key strategies (A1: coarse-to-fine inference, A2: selective fine inference, A3: multi-level batch inference) that exploit Transformer properties to dynamically adjust patch granularity and attention scope based on object criticality, aiming to satisfy R2. The NPFP** scheduling framework (A4) orchestrates these adaptive mechanisms A1-A3. It partitions each DETR task into a safety-critical coarse subtask for guaranteed critical object detection within its deadline (ensuring R1), and an optional fine subtask for enhanced overall accuracy (R2), while managing individual and batched execution. Our extensive evaluations on server, GPU-enabled embedded platforms, and actual AV platforms demonstrate that CF-DETR, under an NPFP** policy, successfully meets strict timing guarantees for critical operations and achieves significantly higher accuracy compared to existing baselines across diverse AV workloads.
Woojin Shin, Donghwa Kang, Byeongyun Park, Brent ByungHoon Kang, Jinkyu Lee 0001, Hyeongboo Baek
RTSS4
2025 Discriminator to grade classification results of neural networks via Prediction Error Tracking Method
Gyuyoung Lee, Changjo Yun, Sungjin Kim 0002, Brent ByungHoon Kang
Knowl. Based Syst.4
2025 A Novel Efficient Crash Consistency Solution Enabling Rollback Recovery for Secure NVM in Low-Power Energy Harvesting Systems
abstract
Energy Harvesting Systems (EHSs) frequently suffer power failures and are particularly deployed in remote and open environments where physical access attacks on Non-volatile Memories (NVMs) are practical. However, prior crash consistency solutions for secure NVM were designed only for conventional power-rich systems with the assumption that enough power is steadily supplied. Moreover, the prior solutions rely on roll-forward recovery and cause a significant performance overhead in low-power EHSs. To achieve a low-cost and high-performance crash-consistent secure NVM working on low-power EHSs, this paper presents Milestone, the first efficient crash consistency solution that introduces a novel hybrid checkpoint mechanism to enable a rollback recovery for secure NVM working in frequent power failures.The hybrid checkpointing atomically (1) undo-logs data updates from program writes and (2) redo-logs the updates of security metadata associated with the data updates when an adaptive hardware timer expires. In particular, Milestone discovers an optimized eager update method for the security metadata that can be performed in parallel with the program writes to NVM by leveraging the rollback recovery. Our experimental results demonstrate that Milestone significantly outperforms the state-of-the-art roll-forward recovery-based solution for secure NVM running on low-power EHSs, achieving up to a 1.87x speedup, on average.
Youngkwang Han, Jongouk Choi, Kazi Abu Zubair, Amro Awad, Changhee Jung, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.7
2024 Interstellar: Fully Partitioned and Efficient Security Monitoring Hardware Near a Processor Core for Protecting Systems against Attacks on Privileged Software
abstract
The existing approaches to instruction trace-based security monitoring hardware are dependent on the privileged software, which presents a significant challenge in defending against attacks on privileged software itself. To address this challenge, we propose Interstellar, which introduces a partitioned hardware near the CPU's main core and leverages the benefit of hardware-level security monitoring. Interstellar is fully partitioned, parallelized, and simultaneously detecting security monitoring hardware. Interstellar's design makes malicious software hard to reverse-engineer how Interstellar detects the attacks, and Interstellar efficiently protects the system against the attacks on the privileged software(e.g., Trusted Execution Environment (TEE)). Moreover, Interstellar not only monitors but also blocks various attacks in a timely manner without stalling a CPU core by designing with a finite-state machine.
Yongho Song, Byeongsu Woo, Youngkwang Han, Brent ByungHoon Kang
CCS4
2024 SuM: Efficient shadow stack protection on ARM Cortex-M
Wonwoo Choi, Minjae Seo, Seongman Lee, Brent ByungHoon Kang
Comput. Secur.4
2023 EnclaveVPN: Toward Optimized Utilization of Enclave Page Cache and Practical Performance of Data Plane for Security-Enhanced Cloud VPN
abstract
A cloud Virtual Private Network (VPN) is an essential infrastructure for tenants to connect their on-premise networks with a cloud network. However, tenants are often reluctant to adopt the cloud VPN because of security concerns, such as key disclosure, impersonation, and packet sniffing. Software Guard Extensions (SGX) is a good candidate to address the security concerns because it can create enclaves in the isolated memory (i.e., Enclave Page Cache (EPC)) to protect security-sensitive code and data from malicious access. In this paper, we propose EnclaveVPN, which supports a security-enhanced IPsec gateway using SGX with optimized EPC utilization and practical performance of the data plane. EnclaveVPN leverages enclaves to manage cryptographic keys and execute cryptographic operations for the IPsec gateway. EnclaveVPN allows only encrypted packets to be transmitted within and to/from the cloud network and presents features for optimizing EPC utilization and minimizing overhead in the data plane. We implemented a prototype on a real SGX v1.0 machine (Xeon E-2286M 2.40GHz 8-core CPU). The experiment and benchmark results showed that EnclaveVPN saved the EPC up to 62.5 and achieved approximately 87 of the data plane performance of the non-SGX IPsec gateway.
Brent ByungHoon Kang
RAID2
2023 Harnessing the x86 Intermediate Rings for Intra-Process Isolation
abstract
Modern applications often involve the processing of sensitive information. However, the lack of privilege separation within the user space leaves sensitive application secrets such as cryptographic keys just as unprotected as a ”hello world” string. Cutting-edge hardware-supported security features are being introduced. However, the features are often vendor-specific or lack compatibility with older generations of the processors. The situation leaves developers with no portable solution to incorporate protection for the sensitive application component. We propose LOTRx86, a fundamental and portable approach for user-space privilege separation. Our approach creates a more privileged user execution layer calledPrivUserby harnessing the underused intermediate privilege levels on the x86 architecture. The PrivUser memory space, a set of pages within process address space that are inaccessible to user mode, is a safe place for application secrets and routines that access them. We implement the LOTRx86 ABI that exports theprivcallinterface to users to invoke secret handling routines in PrivUser. This way, sensitive application operations that involve the secrets are performed in a strictly controlled manner. The memory access control in our architecture isprivilege-based, accessing the protected application secret only requires a change in the privilege, eliminating the need for costly remote procedure calls or change in address space. We evaluated our platform by developing a proof-of-concept LOTRx86-enabled web server that employs our architecture to securely access its private key during an SSL connection. We conducted a set of experiments, including a performance measurement on the PoC onbothIntel and AMD PCs, and confirmed that LOTRx86 incurs only a limited performance overhead.
Hojoon Lee 0001, Chihyun Song, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.3
2022 EmuID: Detecting presence of emulation through microarchitectural characteristic on ARM
Yeseul Choi, Yunjong Jeong, Daehee Jang, Brent ByungHoon Kang, Hojoon Lee 0001
Comput. Secur.4
2022 3rdParTEE: Securing Third-Party IoT Services Using the Trusted Execution Environment
abstract
Advancements in the Internet of Things (IoT) have resulted in the connection and deployment of numerous smart and embedded devices. Although such devices enable various services such as smart grids, they attract more attackers to the IoT world. A trusted execution environment (TEE), which can be created by using TrustZone technology, is a promising security artifact for protecting critical operations and sensitive data of IoT devices. Unfortunately, although TrustZone is available in most ARM architecture-based devices ranging from microcontrollers to high-end smart devices, it has not been widely adopted by third-party IoT service providers because of its limited access. That is, because the TEE is maintained by the TEE platform vendors to preserve its security. Therefore, third parties must adhere to strict policies and procedures to ensure the deployment of trusted services in the TEE. This aspect hinders the fast development and deployment of IoT services. In this work, we propose 3rdParTEE to address this problem by enabling third-party IoT service providers to readily run their trusted services, thereby minimizing their dependency on the TEE maintainers. Specifically, 3rdParTEE facilitates the secure running of the third-party’s native kernel driver in the TEE without hampering the security of the existing TEE components. To demonstrate the effectiveness of our approach, we ran three kernel drivers for maintaining the IoT services platform (e.g., kernel integrity check) in the TEE. Additionally, during the performance evaluation, we observed a reasonable performance overhead of up to 7% when running the kernel drivers in such a secure manner.
Jin Soo Jang, Brent ByungHoon Kang
IEEE Internet Things J.2
2022 SaVioR: Thwarting Stack-Based Memory Safety Violations by Randomizing Stack Layout
abstract
Stack-based memory corruption vulnerabilities have been exploited, allowing attackers to execute arbitrary code and read/write arbitrary memory. Although several solutions have been proposed to prevent memory errors on the stack, they are either limited to a specific type of attack (either spatial or temporal attacks) or cause significant performance degradation. In this article, we introduce SaVioR, an efficient and comprehensive stack protection mechanism. The key technique involves randomization of the stack layout to reduce its predictability and exploitability. SaVioR isolates an individual object from spatially and temporally adjacent vulnerable objects and randomizes each object's location, which prevents attackers from predicting the stack layout and thus reduces the likelihood of memory errors being exploited. We implemented SaVioR based on the LLVM compiler framework and applied it to the SPEC CPU2006 benchmarks and real-world applications. Our security evaluation showed that SaVioR provides a high degree of randomness in the stack layout and thus reduces the likelihood of successful exploitation of spatial and temporal memory errors on the stack. Our performance evaluation also demonstrated that it incurs a modest performance overhead (14 percent) with the SPEC CPU2006 benchmark suite, which improves performance compared to the state-of-the-art stack protection while achieving a comparable security level.
Seongman Lee, Hyeonwoo Kang, Jin Soo Jang, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.4
2021 AI-HydRa: Advanced hybrid approach using random forest and deep learning for malware classification
abstract
The extremely diffused architecture of the Internet enables the propagation of malware and presents a significant challenge for the development of defenses against such malware propagation. Although machine learning-based malware detection models can improve approaches in response to this problem, their detection rates vary according to their features and classification methods. Single machine learning approaches for malware detection can vary in effectiveness according to the suitability of their classifiers despite the use of an appropriate training dataset. Some classifiers result in high detection rates with a malicious training dataset but have low detection rates with a benign training dataset, and false positive rates are particularly dependent on the use of appropriate classifiers. In this paper, we propose a machine learning-based hybrid decision model that can achieve a high detection rate with a low false positive rate. This hybrid model combines a random forest and a deep learning model using 12 hidden layers to determine malware and benign files, respectively. This model also includes certain proposed voting rules to make final decisions. In an experiment involving 6,395 atypical samples, this hybrid decision model achieved a higher detection rate (85.1% and standard deviation of 0.006) than that of the prior model (65.5%) without voting rules.
Suyeon Yoo, Sungjin Kim 0002, Seungjae Kim, Brent ByungHoon Kang
Inf. Sci.4
2021 On the Analysis of Byte-Granularity Heap Randomization
abstract
Heap randomization, in general, has been a well-trodden area; however, the efficacy of byte-granularity randomization has never been fully explored as misalignment raises various concerns. Modern heap exploits often abuse the determinism in word alignment, and modern CPU architecture better supports unaligned access (since Nehalem). Based on such new developments, we conduct an in-depth analysis of evaluating the efficacy of byte-granularity heap randomization in three folds: (i) security effectiveness, (ii) performance impact, and (iii) compatibility analysis to measure deployment cost. Security discussion is based on 20 CVE case studies. To measure performance details, we conduct cycle-level microbenchmarks and report that the performance cost is highly concentrated to edge cases depending on the L1-cache line. Based on such analysis, we design and implement an allocator suited for byte-granularity heap randomization. On the negative side, our analysis suggests that byte-granularity heap randomization has high deployment cost due to various implementation conflicts. We enumerate the problematic compatibility issues using Coreutils, Nginx, and ChakraCore benchmarks.
Daehee Jang, Jonghwan Kim, Hojoon Lee 0001, Minjoon Park, Yunjong Jung, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.7
2020 SelMon: reinforcing mobile device security with self-protected trust anchor
abstract
Higher privileged trust anchors such as thin hypervisors and Trust-Zone have been adopted to protect mobile OSs. For instance, the Samsung Knox security platform implements a kernel integrity monitor based on a hardware-assisted virtualization technique for 64-bit devices. Although it protects the OS kernel integrity, the monitoring platform itself can be a target of attackers if it encompasses exploitable bugs. In this paper, we propose SelMon, a portable way of self-protecting kernel integrity monitors without introducing another higher privileged trust anchor. To this end, we first logically separate the regions of the integrity monitor into two parts: privileged and non-privileged regions. Then, we ensure that only the privileged region code can access the critical data objects that can be exploited to compromise the monitor integrity (e.g., the hypervisor page table). The non-critical operations in terms of preserving the monitor integrity are conducted in the non-privileged region. In addition to the privilege separation, we also illustrate how to utilize the general hardware features, watchpoint and data execution prevention (DEP), to ensure the robustness of the separation. In the evaluation, it was found that our approach imposes a negligible overhead of 2% in the worst case with SPEC CPU2006.
Jin Soo Jang, Brent ByungHoon Kang
MobiSys2
2020 Agamotto: Accelerating Kernel Driver Fuzzing with Lightweight Virtual Machine Checkpoints
Dokyung Song, Felicitas Hetzelt, Jonghwan Kim, Brent ByungHoon Kang, Jean-Pierre Seifert, Michael Franz
USENIX Security Symposium4
2020 Retrofitting the Partially Privileged Mode for TEE Communication Channel Protection
abstract
ARM TrustZone provides a Trusted Execution Environment (TEE) to isolate security-critical services, which are generally invoked from the Rich Execution Environment (REE) through a communication channel established by executing the Secure Monitor Call (SMC) with the general registers configured as input parameters. Unfortunately, the communication channel has been abused by adversaries to incur misbehavior of the TEE, to analyze the internal working of the TEE, and to exploit its vulnerabilities. We therefore propose the TEE defense (TFence) framework that enables the creation of a partially privileged (par-priv) process, which benefits from the coordination of the system mode and virtualization extension. More specifically, on ARM architecture, direct invocation of hypercall and SMC is not allowed in the user process; however, we limitedly escalate the privilege of the process to enable it to directly communicate with trust anchors such as hypervisor and TrustZone. This approach enabled us to remove the kernel dependency when the process communicates with the TEE, which also reduces the attack surface to the critical part of the application involved in the communication. Besides, direct communication with the hypervisor facilitates the adoption of application-shielding approaches to protect the critical part and to restrict arbitrary access to the TEE.
Jin Soo Jang, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.2
2019 In-process Memory Isolation Using Hardware Watchpoint
abstract
Memory disclosure vulnerabilities have been exploited in the leaking of application secret data such as crypto keys (e.g., the Heartbleed Bug). To ameliorate this problem, we propose an in-process memory isolation mechanism by leveraging a common hardwarefeature, namely, hardware debugging. Specifically, we utilize a watchpoint to monitor a particular memory region containing secret data. We implemented the PoC of our approach based on the 64-bit ARM architecture, including the kernel patches and user APIs that help developers benefit from isolated memory use. We applied the approach to open-source applications such as OpenSSL and AESCrypt. The results of a performance evaluation show that our approach incurs a small amount of overhead.
Jin Soo Jang, Brent ByungHoon Kang
DAC2
2019 Revisiting the ARM Debug Facility for OS Kernel Security
abstract
Hardware debugging facilities, such as watchpoints, have been used for software development and analysis. In this paper, we expanded the use of watchpoints as a hardware security primitive for enhancing the runtime security of mobile devices. By analyzing the watchpoints in detail, we derived useful watchpoint properties that can be exploited to build security applications. Based on our analysis, we designed example applications for hardening the OS kernel by exploiting watchpoints. The proposed applications were implemented on a Juno development board with 64-bit ARM architecture (ARMv8). Hardening the kernel by fully enabling the proposed schemes was found to impose reasonable overhead, i.e., 3% with SPEC CPU2006.
Jin Soo Jang, Brent ByungHoon Kang
DAC2
2019 POLaR: Per-Allocation Object Layout Randomization
abstract
Object Layout Randomization (OLR) is a memory randomization approach that makes unpredictable in-object memory layout by shuffling and relocating each member fields of the object. This defense approach has significant security effect for mitigating various types of memory error attacks. However, the current state-of-the-art enforces OLR while compile time. It makes diversified object layout for each binary, but the layout remains equal across the execution. This approach can be effective in case the program binary is hidden from attackers. However, there are several limitations: (i) the security efficacy is built with the premise that the binary is safely undisclosed from adversaries, (ii) the randomized object layout is identical across multiple executions, and (iii) the programmer should manually specify which objects should be affected by OLR. In this paper, we introduce Per-allocation Object Layout Randomization(POLaR): the first dynamic approach of OLR suited for public binaries. The randomization mechanism of POLaR is applied at runtime, and the randomization makes unique object layout even for the same type of instances. As a result, POLaR achieves two previously unmet security primitives. (i) The randomization does not break upon the exposure of the binary. (ii) Repeating the same attack does not result in deterministic behavior. In addition, we also implemented the TaintClass framework based on DFSan project to optimize/automate the target object selection process. To show the efficacy of POLaR, we use several public open-source software and SPEC2006 benchmark suites.
Jonghwan Kim, Daehee Jang, Yunjong Jeong, Brent ByungHoon Kang
DSN4
2019 MoHoP: A protocol providing for both mobility management and host privacy
Jaehyun Park 0002, Jaehee Ha, Brent ByungHoon Kang, Myungchul Kim 0001
Comput. Networks3
2019 Rethinking anti-emulation techniques for large-scale software deployment
Daehee Jang, Yunjong Jeong, Sungman Lee, Minjoon Park, Kuenhwan Kwak, Donguk Kim 0003, Brent ByungHoon Kang
Comput. Secur.7
2019 Securing a communication channel for the trusted execution environment
Jin Soo Jang, Brent ByungHoon Kang
Comput. Secur.2
2019 SGX-LEGO: Fine-grained SGX controlled-channel attack and its countermeasure
Deokjin Kim, Daehee Jang, Minjoon Park, Yunjong Jeong, Jonghwan Kim, Seokjin Choi, Brent ByungHoon Kang
Comput. Secur.7
2019 eMotion: An SGX extension for migrating enclaves
Sungjin Park 0001, Brent ByungHoon Kang, Kwangjo Kim
Comput. Secur.3
2019 KI-Mon ARM: A Hardware-Assisted Event-triggered Monitoring Platform for Mutable Kernel Object
abstract
External hardware-based kernel integrity monitors have been proposed to mitigate kernel-level malwares. However, the existing external approaches have been limited to monitoring the static regions of kernel while the latest rootkits manipulate the dynamic kernel objects. To address the issue, we present KI-Mon, a hardware-based platform that introduces event-triggered monitoring techniques for kernel dynamic objects. KI-Mon advances the bus traffic snooping technique to not only detect memory write traffic on the host bus but also filter out all but meaningful traffic to generate events. We show how kernel invariant verification software can be developed around these events, and also provide a set of APIs for additional invariant verification development. We also report our findings and considerations on the unique challenges for external monitors – such as cache coherency, dynamic object tracing. We introduce host-side kernel changes that alleviate these issues that involve changes in kernel's object allocation and cache policy control. We have built a prototype of KI-Mon on the ARM architecture to demonstrate the efficacy of KI-Mon's event-triggered mechanism in terms of performance overhead for the monitored host system and the processor usage of the KI-Mon processor.
Hojoon Lee 0001, Hyungon Moon, Ingoo Heo, Daehee Jang, Jin Soo Jang, Yunheung Paek, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.8
2018 Lord of the x86 Rings: A Portable User Mode Privilege Separation Architecture on x86
abstract
Modern applications often involve processing of sensitive information. However, the lack of privilege separation within the user space leaves sensitive application secret such as cryptographic keys just as unprotected as a "hello world" string. Cutting-edge hardware-supported security features are being introduced. However, the features are often vendor-specific or lack compatibility with older generations of the processors. The situation leaves developers with no portable solution to incorporate protection for the sensitive application component. We propose LOTRx86, a fundamental and portable approach for user-space privilege separation. Our approach creates a more privileged user execution layer called PrivUser by harnessing the underused intermediate privilege levels on the x86 architecture. The PrivUser memory space, a set of pages within process address space that are inaccessible to user mode, is a safe place for application secrets and routines that access them. We implement the LOTRx86 ABI that exports the privcall interface to users to invoke secret handling routines in PrivUser. This way, sensitive application operations that involve the secrets are performed in a strictly controlled manner. The memory access control in our architecture is privilege-based, accessing the protected application secret only requires a change in the privilege, eliminating the need for costly remote procedure calls or change in address space. We evaluated our platform by developing a proof-of-concept LOTRx86-enabled web server that employs our architecture to securely access its private key during an SSL connection. We conducted a set of experiments including a performance measurement on the PoC on both Intel and AMD PCs, and confirmed that LOTRx86 incurs only a limited performance overhead.
Hojoon Lee 0001, Chihyun Song, Brent ByungHoon Kang
CCS3
2018 Hypernel: a hardware-assisted framework for kernel protection without nested paging
abstract
Large OS kernels always suffer from attacks due to their numerous inherent vulnerabilities. To protect the kernel, hypervisors have been employed by many security solutions. However, relying on a hypervisor has a detrimental impact on the system performance due mainly to nested paging. In this paper, we present Hypernel, a security framework combining hardware and software components to address this problem. Hypersec, the software component, provides an isolated execution environment for security solutions, and the hardware monitor component enables a word-granularity monitoring capability on the kernel memory. Our evaluation shows that Hypernel efficiently fulfills the role of a security framework, while imposing mere 3.1% of runtime overhead on the system.
Donghyun Kwon, Kuenwhee Oh, Junmo Park, Seungyong Yang, Yeongpil Cho, Brent ByungHoon Kang, Yunheung Paek
DAC6
2018 FriSM: Malicious Exploit Kit Detection via Feature-Based String-Similarity Matching
Sungjin Kim 0002, Brent ByungHoon Kang
SecureComm (1)2
2018 Malicious URL protection based on attackers' habitual behavioral analysis
Sungjin Kim 0002, Jinkook Kim, Brent ByungHoon Kang
Comput. Secur.3
2018 A dynamic per-context verification of kernel address integrity from external monitors
Hojoon Lee 0001, Yunheung Paek, Brent ByungHoon Kang
Comput. Secur.4
2018 Domain Isolated Kernel: A lightweight sandbox for untrusted kernel extensions
Valentin J. M. Manès, Daehee Jang, Chanho Ryu, Brent ByungHoon Kang
Comput. Secur.4
2018 PrivateZone: Providing a Private Execution Environment Using ARM TrustZone
abstract
ARM TrustZone is widely used to provide a Trusted Execution Environment (TEE) for mobile devices. However, the use of TrustZone is limited because TrustZone resources are only available for some pre-authorized applications. In other words, only alliances of the TrustZone OS vendors and device manufacturers can use TrustZone to secure their services. To help overcome this problem, we designed the PrivateZone framework to enable individual developers to utilize TrustZone resources. Using PrivateZone, developers can run Security Critical Logics (SCL) in a Private Execution Environment (PrEE). The advantage of PrivateZone is its leveraging of TrustZone resources without undermining the security of existing services in the TEE. To guarantee this, PrivateZone creates a PrEE using a memory region that is isolated from both the Rich Execution Environment (REE) and TEE. In this paper, we describe the design and implementation of PrivateZone. The prototype of PrivateZone was implemented on an Arndale board with a Cortex-A15 dual-core processor. We built PrivateZone by exploring both security and virtualization extensions of the ARM architecture. To illustrate the usage and the efficacy of PrivateZone, we developed an Android application based on PrivateZone framework, and evaluated the performance overhead imposed on the OS in the REE and SCLs in the PrEE.
Jin Soo Jang, Changho Choi, Jae-Hyuk Lee, Nohyun Kwak, Seongman Lee, Yeseul Choi, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.7
2017 Hacking in Darkness: Return-oriented Programming against Secure Enclaves
Jae-Hyuk Lee, Jin Soo Jang, Yeongjin Jang, Nohyun Kwak, Yeseul Choi, Changho Choi, Taesoo Kim, Marcus Peinado, Brent ByungHoon Kang
USENIX Security Symposium9
2017 S-OpenSGX: A system-level platform for exploring SGX enclave-based computing
Changho Choi, Nohyun Kwak, Jin Soo Jang, Daehee Jang, Kuenwhee Oh, Kyungsoo Kwag, Brent ByungHoon Kang
Comput. Secur.7
2017 Invi-server: Reducing the attack surfaces by making protected server invisible on networks
Jaehyun Park 0002, Myungchul Kim 0001, Brent ByungHoon Kang
Comput. Secur.4
2017 Detecting and Preventing Kernel Rootkit Attacks with Bus Snooping
abstract
To protect the integrity of operating system kernels, we presentVigilare system, a kernel integrity monitor that is architected to snoop the bus traffic of the host system from a separate independent hardware. Thissnoop-based monitoringenabled by the Vigilare system, overcomes the limitations of thesnapshot-based monitoringemployed in previous kernel integrity monitoring solutions. Being based on inspecting snapshots collected over a certain interval, the previous hardware-based monitoring solutions cannot detecttransient attacksthat can occur in between snapshots, and cannot protect the kernel against permanent damage. We implemented three prototypes of the Vigilare system by addingSnooperhardware connections module to the host system for bus snooping, and a snapshot-based monitor to be comared with, in order to evaluate the benefit of snoop-based monitoring. The prototypes of Vigilare system detected all the transient attacks and the second one protected the kernel with negligible performance degradation while the snapshot-based monitor could not detect all the attacks and induced considerable performance degradation as much as 10 percent in our tuned STREAM benchmark test.
Hyungon Moon, Hojoon Lee 0001, Ingoo Heo, Yunheung Paek, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.6
2016 OpenSGX: An Open Platform for SGX Research
Prerit Jain, Soham Jayesh Desai, Ming-Wei Shih, Taesoo Kim, Seong-Min Kim, Jae-Hyuk Lee, Changho Choi, Youjung Shin, Brent ByungHoon Kang, Dongsu Han
NDSS9
2016 On-demand bootstrapping mechanism for isolated cryptographic operations on commodity accelerators
Yonggon Kim, Ohmin Kwon 0001, Jin Soo Jang, Seongwook Jin, Hyeongboo Baek, Brent ByungHoon Kang, Hyunsoo Yoon
Comput. Secur.6
2016 Vulnerabilities of network OS and mitigation with state-based permission system
abstract
Abstract The advancement of software defined networking (SDN) is redefining traditional computer networking architecture. The role of the control plane of SDN is of such importance that SDNs are referred to as network operating systems (OSs). However, the robustness and security of the network OS has been overlooked. In this paper, we report three main issues pertaining to network OSs. First, we identified vulnerabilities that could be exploited by malicious or buggy applications running on network OSs. We also identified four major attack vectors that could undermine network OS operations: denial of service, global data manipulation, control plane poisoning, and system shell execution. Further, it was demonstrated that real‐world attacks can be launched on commonly used network OSs without significant effort. Second, we present a method to address the attacks by analyzing network applications running on network OSs to identify their behavioral features, which enabled the extraction of a permission set for each network application. Based on this work, a permission‐based malicious network application detector was introduced, which examines the permission set of each application and prevents it from executing without permission. Our system shows almost no performance overhead. Copyright © 2015 John Wiley & Sons, Ltd.
Jaehyun Park 0002, Seungwon Shin 0001, Brent ByungHoon Kang
Secur. Commun. Networks5
2015 SeCReT: Secure Channel between Rich Execution Environment and Trusted Execution Environment
Jin Soo Jang, Sunjune Kong, Daegyeong Kim, Brent ByungHoon Kang
NDSS5
2015 Implementing an Application-Specific Instruction-Set Processor for System-Level Dynamic Program Analysis Engines
abstract
In recent years, dynamic program analysis (DPA) has been widely used in various fields such as profiling, finding bugs, and security. However, existing solutions have their own weaknesses. Software solutions provide flexibility in DPA but they suffer from tremendous performance overhead. In contrast, core-level hardware engines rely on specialized integrated logics and attain extremely fast computation, but they have a limited functional extensibility because the logics are tightly coupled with the host processor. To mend this, a prior system-level approach utilizes an existing channel to integrate their hardware without necessitating the host architecture modification and introduced great potential in performance. Nevertheless, the prior work does not address the detailed design and implementation of the engine, which is quite essential to leverage the deployment on real systems. To address this, in this article, we propose an implementation of programmable DPA hardware engine, called program analysis unit (PAU). PAU is an application-specific instruction-set processor (ASIP) whose instruction set is customized to reflect common features of various DPA methods. With the specialized architecture and programmability of software, our PAU aims at fast computation and sufficient flexibility. In our case studies on several DPA techniques, we show that our ASIP approach can be successfully applicable to complex DPA schemes while providing hardware-backed power in performance and software-based flexibility in analysis. Recent experiments on our FPGA prototype revealed that the performance of PAU is 4.7-13.6 times faster than pure software DPA, and the power/area consumption is also acceptably small compared to today's mobile processors.
Ingoo Heo, Yongje Lee, Changho Choi, Jinyong Lee, Brent ByungHoon Kang, Yunheung Paek
ACM Trans. Design Autom. Electr. Syst.6
2014 ATRA: Address Translation Redirection Attack against Hardware-based External Monitors
abstract
Hardware-based external monitors have been proposed as a trustworthy method for protecting the kernel integrity. We introduce the design and implementation of Address Translation Redirection Attack (ATRA) that enables complete evasion of the hardware-based external monitor that anchors its trust on a separate processor. ATRA circumvents the external monitor by redirecting the memory access to critical kernel objects into a non-monitored region. Despite the seriousness of the ATRA issue, the address translation integrity has been assumed in many hardware-based external monitors and the possibility of its exploitation has been suggested yet many considered hypothetical. We explore the intricate details of ATRA, explain major challenges in realizing ATRA in practice, and address them with two types of ATRA called Memory-bound ATRA and Register-bound ATRA. Our evaluations with benchmarks show that ATRA does not introduce a noticeable performance degradation to the host system, proving practical applicability of the attack to alert the researchers to seriously address ATRA in designing future external monitors.
Daehee Jang, Hojoon Lee 0001, Daehyeok Kim, Daegyeong Kim, Brent ByungHoon Kang
CCS6
2014 Rosemary: A Robust, Secure, and High-performance Network Operating System
abstract
Within the hierarchy of the Software Defined Network (SDN) network stack, the control layer operates as the critical middleware facilitator of interactions between the data plane and the network applications, which govern flow routing decisions. In the OpenFlow implementation of the SDN model, the control layer, commonly referred to as a network operating system (NOS), has been realized by a range of competing implementations that offer various performance and functionality advantages: Floodlight, POX, NOX, and ONIX. In this paper we focus on the question of control layer resilience, when rapidly developed prototype network applications go awry, or third-party network applications incorporate unexpected vulnerabilities, fatal instabilities, or even malicious logic. We demonstrate how simple and common failures in a network application may lead to loss of the control layer, and in effect, loss of network control. To address these concerns we present the ROSEMARY controller, which implements a network application containment and resilience strategy based around the notion of spawning applications independently within a micro-NOS. ROSEMARY distinguishes itself by its blend of process containment, resource utilization monitoring, and an application permission structure, all designed to prevent common failures of network applications from halting operation of the SDN Stack. We present our design and implementation of ROSEMARY, along with an extensive evaluation of its performance relative to several of the mostly well-known and widely used controllers. Rather than imposing significant performance costs, we find that with the integration of two optimization features, ROSEMARY offers a competitive performance advantage over the majority of other controllers.
Seungwon Shin 0001, YongJoo Song, Taekyung Lee, Sangho Lee 0003, Jaewoong Chung, Phillip A. Porras, Vinod Yegneswaran, Brent ByungHoon Kang
CCS9
2014 Identifying users with application-specific command streams
abstract
This paper proposes and describes an active authentication model based on user profiles built from user-issued commands when interacting with GUI-based application. Previous behavioral models derived from user issued commands were limited to analyzing the user's interaction with the *Nix (Linux or Unix) command shell program. Human-computer interaction (HCI) research has explored the idea of building users profiles based on their behavioral patterns when interacting with such graphical interfaces. It did so by analyzing the user's keystroke and/or mouse dynamics. However, none had explored the idea of creating profiles by capturing users' usage characteristics when interacting with a specific application beyond how a user strikes the keyboard or moves the mouse across the screen. We obtain and utilize a dataset of user command streams collected from working with Microsoft (MS) Word to serve as a test bed. User profiles are first built using MS Word commands and identification takes place using machine learning algorithms. Best performance in terms of both accuracy and Area under the Curve (AUC) for Receiver Operating Characteristic (ROC) curve is reported using Random Forests (RF) and AdaBoost with random forests.
Ala'a El Masri, Harry Wechsler, Peter Likarish, Brent ByungHoon Kang
PST4
2013 KI-Mon: A Hardware-assisted Event-triggered Monitoring Platform for Mutable Kernel Object
Hojoon Lee 0001, Hyungon Moon, Daehee Jang, Yunheung Paek, Brent ByungHoon Kang
USENIX Security Symposium7
2012 Vigilare: toward snoop-based kernel integrity monitor
abstract
In this paper, we present Vigilare system, a kernel integrity monitor that is architected to snoop the bus traffic of the host system from a separate independent hardware. This snoop-based monitoring enabled by the Vigilare system, overcomes the limitations of the snapshot-based monitoring employed in previous kernel integrity monitoring solutions. Being based on inspecting snapshots collected over a certain interval, the previous hardware-based monitoring solutions cannot detect transient attacks that can occur in between snapshots. We implemented a prototype of the Vigilare system on Gaisler's grlib-based system-on-a-chip (SoC) by adding Snooper hardware connections module to the host system for bus snooping. To evaluate the benefit of snoop-based monitoring, we also implemented similar SoC with a snapshot-based monitor to be compared with. The Vigilare system detected all the transient attacks without performance degradation while the snapshot-based monitor could not detect all the attacks and induced considerable performance degradation as much as 10% in our tuned STREAM benchmark test.
Hyungon Moon, Hojoon Lee 0001, Yunheung Paek, Brent ByungHoon Kang
CCS6
2012 DoubleGuard: Detecting Intrusions in Multitier Web Applications
abstract
Internet services and applications have become an inextricable part of daily life, enabling communication and the management of personal information from anywhere. To accommodate this increase in application and data complexity, web services have moved to a multitiered design wherein the webserver runs the application front-end logic and data are outsourced to a database or file server. In this paper, we present DoubleGuard, an IDS system that models the network behavior of user sessions across both the front-end webserver and the back-end database. By monitoring both web and subsequent database requests, we are able to ferret out attacks that an independent IDS would not be able to identify. Furthermore, we quantify the limitations of any multitier IDS in terms of training sessions and functionality coverage. We implemented DoubleGuard using an Apache webserver with MySQL and lightweight virtualization. We then collected and processed real-world traffic over a 15-day period of system deployment in both dynamic and static web applications. Finally, using DoubleGuard, we were able to expose a wide range of attacks with 100 percent accuracy while maintaining 0 percent false positives for static web services and 0.6 percent false positives for dynamic web services.
Meixing Le, Angelos Stavrou, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.3
2009 Towards complete node enumeration in a peer-to-peer botnet
abstract
Modern advanced botnets may employ a decentralized peer-to-peer overlay network to bootstrap and maintain their command and control channels, making them more resilient to traditional mitigation efforts such as server incapacitation. As an alternative strategy, the malware defense community has been trying to identify the bot-infected hosts and enumerate the IP addresses of the participating nodes so that the list can be used by system administrators to identify local infections, block spam emails sent from bots, and configure firewalls to protect local users. Enumerating the infected hosts, however, has presented challenges. One cannot identify infected hosts behind firewalls or NAT devices by employing crawlers, a commonly used enumeration technique where recursive get-peerlist lookup requests are sent newly discovered IP addresses of infected hosts. As many bot-infected machines in homes or offices are behind firewall or NAT devices, these crawler-based enumeration methods would miss a large portions of botnet infections. In this paper, we present the Passive P2P Monitor (PPM), which can enumerate the infected hosts regardless whether or not they are behind a firewall or NAT. As an empirical study, we examined the Storm botnet and enumerated its infected hosts using the PPM. We also improve our PPM design by incorporating a FireWall Checker (FWC) to identify nodes behind a firewall. Our experiment with the peer-to-peer Storm botnet shows that more than 40% of bots that contact the PPM are behind firewall or NAT devices, implying that crawler-based enumeration techniques would miss out a significant portion of the botnet population. Finally, we show that the PPM's coverage is based on a probability-based coverage model that we derived from the empirical observation of the Storm botnet.
Brent ByungHoon Kang, Eric Chan-Tin, Christopher P. Lee 0001, James Tyra, Hun Jeong Kang, Chris Nunnery, Zachariah Wadler, Greg Sinclair, Nicholas Hopper, David Dagon, Yongdae Kim
AsiaCCS1
2008 Concord: A Secure Mobile Data Authorization Framework for Regulatory Compliance
Gautam Singaraju, Brent ByungHoon Kang
LISA2
2007 RepuScore: Collaborative Reputation Management Framework for Email Infrastructure
Gautam Singaraju, Brent ByungHoon Kang
LISA2
2006 Privilege Messaging: An Authorization Framework over Email Infrastructure
Brent ByungHoon Kang, Gautam Singaraju, Sumeet Jain
LISA1
2005 RegColl: Centralized Registry Framework for Infrastructure System Management
Brent ByungHoon Kang, Vikram Sharma 0002, Pratik Thanki
LISA1