EDBT 2026 Demo / reviewers in the wild / expert
Youngdon Jung
dblp:196/6732
· DBLP profile ↗
4ranked-venue papers
0as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Storage systems · 100% | |
| Network and information security
2 papers |
Malware analysis · 100% |
Topics — the 8 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Storage systems
flash and SSD |
0.9 | 2 | 2021 | SSD-Assisted Ransomware Detection and Data Recovery Techniques · IEEE Trans. Computers 2021 RansomBlocker: a Low-Overhead Ransomware-Proof SSD · DAC 2019 |
Storage systems
storage reliability |
0.9 | 2 | 2021 | SSD-Assisted Ransomware Detection and Data Recovery Techniques · IEEE Trans. Computers 2021 RansomBlocker: a Low-Overhead Ransomware-Proof SSD · DAC 2019 |
Storage systems › storage reliability
data recovery |
0.5 | 1 | 2021 | SSD-Assisted Ransomware Detection and Data Recovery Techniques · IEEE Trans. Computers 2021 |
Malware analysis › ransomware
ransomware detection |
0.4 | 1 | 2019 | RansomBlocker: a Low-Overhead Ransomware-Proof SSD · DAC 2019 |
Storage systems › flash and SSD › flash memory
flash storage |
0.4 | 1 | 2019 | Alleviating Garbage Collection Interference Through Spatial Separation in All Flash Arrays · USENIX ATC 2019 |
Storage systems › flash and SSD
SSD array |
0.4 | 1 | 2019 | Alleviating Garbage Collection Interference Through Spatial Separation in All Flash Arrays · USENIX ATC 2019 |
Malware analysis
ransomware |
0.1 | 1 | 2021 | SSD-Assisted Ransomware Detection and Data Recovery Techniques · IEEE Trans. Computers 2021 |
Storage systems › flash and SSD
SSD performance |
0.1 | 1 | 2019 | Alleviating Garbage Collection Interference Through Spatial Separation in All Flash Arrays · USENIX ATC 2019 |
Methods — techniques the papers use, named apart from their topics
i/o pattern monitoring · 1.0delayed deletion · 1.0entropy-based detection · 0.8CNN-based detection · 0.8spatial separation · 0.4garbage collection management · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | SSD-Assisted Ransomware Detection and Data Recovery TechniquesabstractAs ransomware attacks have been prevalent, it becomes crucial to make anti-ransomware solutions that defend against ransomwares. In this article, we propose a new ransomware defense system, calledSSD-Insider++, which prevents users’ files from being damaged by ransomware attacks. SSD-Insider++ is embedded into an SSD controller as a form of firmware. By being separated from a host machine, it not only provides more robust data protection than software-based ones which are vulnerable to evasion attacks, but also offers interoperability with various platforms. SSD-Insider++ is composed of two novel features, ransomware detection and perfect data recovery, which are tightly integrated with each other. The detection algorithm observes I/O patterns of a host system and decides whether the host is being attacked by ransomwares in an early stage. Once an encryption attack is detected, the recovery algorithm is triggered to recover original files by leveraging a delayed deletion feature of an SSD at a low cost. Our experimental results show that SSD-Insider++ achieves high accuracy of detecting ransomwares with 0 percent FRR/FAR in most cases and provides an instant data recovery with 0 percent data loss. The overhead of running SSD-Insider++ is negligible – only 80$n$s and 226$n$s are spent more for handling 4-KB reads and writes, respectively. SungHa Baek, Youngdon Jung, David Mohaisen, Sungjin Lee 0001, DaeHun Nyang |
IEEE Trans. Computers | 2 |
| 2019 | RansomBlocker: a Low-Overhead Ransomware-Proof SSDabstractWe present a low-overhead ransomware-proof SSD, called RansomBlocker (RBlocker). RBlocker provides 100% full protections against all possible ransomware attacks by delaying every data deletion until no attack is guaranteed. To reduce storage overheads of the delayed deletion, RBlocker employs a time-out based backup policy. Based on the fact that ransomware must store encrypted version of target files, early deletions of obsolete data are allowed if no encrypted write was detected for a short interval. Otherwise, RBlocker keeps the data for an interval long enough to guarantee no attack condition. For an accurate in-line detection of encrypted writes, we leverages entropy- and CNN-based detectors in an integrated fashion. Our experimental results show that RBlocker can defend all types of ransomware attacks with negligible overheads. Jisung Park 0001, Youngdon Jung, Jonghoon Won, Minji Kang, Sungjin Lee 0001, Jihong Kim 0001 |
DAC | 2 |
| 2019 | Alleviating Garbage Collection Interference Through Spatial Separation in All Flash Arrays
Kwanghyun Lim, Youngdon Jung, Sungjin Lee 0001, Changwoo Min, Sam H. Noh |
USENIX ATC | 3 |
| 2018 | SSD-Insider: Internal Defense of Solid-State Drive against Ransomware with Perfect Data RecoveryabstractRansomware is a malware that encrypts victim's data, where the decryption key is released after a ransom is paid by the data owner to the attacker. Many ransomware attacks were reported recently, making anti-ransomware a crucial need in security operation, and an issue for the security community to tackle. In this paper, we propose a new approach to defending against ransomware inside NAND flash-based SSDs. To realize the idea of defense-inside-SSDs, both a lightweight detection technique and a perfect recovery algorithm to be used as a part of SSDs firmware should be developed. To this end, we propose a new set of lightweight behavioral features on ran-somware's overwriting pattern, which are invariant across various ransomwares. Our features rely on observing the block I/O request headers only, and not the payload. For perfect and instant recovery, we also propose using the delayed deletion feature of SSDs, which is intrinsic to NAND flash. To demonstrate their feasibility, we implement our algorithms atop an open-channel SSD as a working prototype called SSD-Insider. In experiments using eight real-world and two in-house ransomwares with various background applications running, SSD-Insider achieved a detection accuracy 0% FRR/FAR in most scenarios, and only 5% FAR when heavy overwriting resembling ransomware's data wiping occurs. SSD-Insider detects ransomware activity within 10s, and recovers instantly an infected SSD within 1s with 0% data loss. The additional software overheads incurred by the SSD-Insider is just 147 ns and 254 ns for 4-KB reads and writes, respectively, which is negligible considering NAND chip latency (50-1000 μs). SungHa Baek, Youngdon Jung, David Mohaisen, Sungjin Lee 0001, DaeHun Nyang |
ICDCS | 2 |