EDBT 2026 Demo / reviewers in the wild / expert
Seunghoon Woo
dblp:201/9210
· DBLP profile ↗
14ranked-venue papers
5as first author
13since 2021 · last 2025
0000-0002-5455-0804ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 9 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ZCover: Uncovering Z-Wave Controller Vulnerabilities Through Systematic Security Analysis of Application Layer ImplementationabstractThe increasing use of smart home technologies has raised concerns about security vulnerabilities, particularly in Z-Wave systems. Existing approaches hold the promise of assessing Z-Wave security in slave devices but fall short of being effectively applied to discover vulnerabilities in Z-Wave controllers, which are central to Z-Wave systems. We present ZCover, a framework for systematically analyzing the application layer of Z-Wave controllers to uncover security vulnerabilities. By extracting the known and unknown properties of the Z-Wave controller and utilizing mutation that considers the correlations of the Z-Wave packet frame fields, ZCover can effectively discover unknown vulnerabilities in the target Z-Wave controller. Evaluation on nine real-world Z-Wave devices showed that ZCover outperformed existing Z-Wave security research, by discovering 15 previously unknown critical vulnerabilities with 12 new CVE IDs assigned. ZCover can be utilized as a resource for ensuring the security of Z-Wave controllers in building a secure Z-Wave smart home. Carlos Nkuba Kayembe, Jimin Kang, Seunghoon Woo, Heejo Lee |
DSN | 3 |
| 2025 | Tiver: Identifying Adaptive Versions of C/C++ Third-Party Open-Source Components Using a Code Clustering TechniqueabstractReusing open-source software (OSS) provides significant benefits but also poses risks from propagated vulnerabilities. While tracking OSS component versions helps mitigate threats, existing approaches typically map a single version to the reused codebase. This coarse-grained approach overlooks the coexistence of multiple versions, leading to ineffective OSS management. Moreover, identifying component versions is further complicated by noise codes, such as shared algorithmic code across different OSS, and duplicate components caused by redundant OSS reuse. In this paper, we introduce the concept of the adaptive version, a one-stop solution to represent the version diversity of reused OSS. To identify adaptive versions, we present Tiver, which employs two key techniques: (1) fine-grained function-level versioning and (2) OSS code clustering to identify duplicate components and remove noise. This enables precise identification of OSS reuse locations and adaptive versions, effectively mitigating risks associated with OSS reuse. Evaluation of 2,025 popular C/C++ software revealed that 67% of OSS components contained multiple versions, averaging over three versions per component. Nonetheless, Tiver effectively identified adaptive versions with 88.46% precision and 91.63% recall in duplicate component distinction, and 86% precision and 86.84% recall in eliminating noise, while existing approaches barely achieved 42% recall in distinguishing duplicates and did not address noise. Further experiments showed that Tiver could enhance vulnerability management and be applied to Software Bills of Materials (SBOM) to improve supply chain security. Youngjae Choi, Seunghoon Woo |
ICSE | 2 |
| 2025 | Cryptbara: Dependency-Guided Detection of Python Cryptographic API MisusesabstractWe present Cryptbara, a precise approach for detecting Python cryptographic API misuses. Cryptographic APIs are widely used to ensure data security, but their improper use can inadvertently compromise the security of entire systems. Existing approaches often fail to capture how cryptographic objects are initialized and used across inter-procedural contexts, limiting their ability to detect context-dependent misuses. In contrast, the key innovation of Cryptbara lies in synergistically combining static dependency analysis with LLM reasoning guided by dependency context, enabling context-sensitive misuse detection. To this end, Cryptbara extracts intra- and inter-procedural dependencies from Python code and encodes them into context-rich prompts, allowing the LLM to perform semantically-aware analysis despite syntactic complexity. We evaluated Cryptbara on two benchmarks containing real-world cryptographic API misuses. Cryptbara achieved F1 scores of 95.43% and 84%, outperforming existing approaches that achieved at most 73.68% and 70.59% F1 scores, respectively. Cryptbara further demonstrated its practical impact by discovering previously unknown misuses in popular Python repositories, with 22 representative cases reported to and confirmed by maintainers. Seogyeong Cho, Seungeun Yu, Seunghoon Woo |
ASE | 3 |
| 2025 | A large-scale analysis of the effectiveness of publicly reported security patches
Seunghoon Woo, Eunjin Choi, Heejo Lee |
Comput. Secur. | 1 |
| 2024 | BloomFuzz: Unveiling Bluetooth L2CAP Vulnerabilities via State Cluster Fuzzing with Target-Oriented State Machines
Pyeongju Ahn, Yeonseok Jang, Seunghoon Woo, Heejo Lee |
ESORICS (3) | 3 |
| 2024 | CNEPS: A Precise Approach for Examining Dependencies among Third-Party C/C++ Open-Source ComponentsabstractThe rise in open-source software (OSS) reuse has led to intricate dependencies among third-party components, increasing the demand for precise dependency analysis. However, owing to the presence of reused files that are difficult to identify the originating components (i.e., indistinguishable files) and duplicated components, precisely identifying component dependencies is becoming challenging. Yoonjong Na, Seunghoon Woo, Joomyeong Lee, Heejo Lee |
ICSE | 2 |
| 2023 | V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification Techniques
Seunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo Oh |
USENIX Security Symposium | 1 |
| 2022 | L2Fuzz: Discovering Bluetooth L2CAP Vulnerabilities Using Stateful Fuzz TestingabstractBluetooth Basic Rate/Enhanced Data Rate (BR/EDR) is a wireless technology used in billions of devices. Recently, several Bluetooth fuzzing studies have been conducted to detect vulnerabilities in Bluetooth devices, but they fall short of effectively generating malformed packets. In this paper, we propose L2FUZZ, a stateful fuzzer to detect vulnerabilities in Bluetooth BR/EDR Logical Link Control and Adaptation Protocol (L2CAP) layer. By selecting valid commands for each state and mutating only the core fields of packets, L2FUZZ can generate valid malformed packets that are less likely to be rejected by the target device. Our experimental results confirmed that: (1) L2FUZZ generates up to 46 times more malformed packets with a much less packet rejection ratio compared to the existing techniques, and (2) L2FUZZ detected five zero-day vulnerabilities from eight real-world Bluetooth devices. Haram Park, Carlos Nkuba Kayembe, Seunghoon Woo, Heejo Lee |
DSN | 3 |
| 2022 | MOVERY: A Precise Approach for Modified Vulnerable Code Clone Discovery from Modified Open-Source Software Components
Seunghoon Woo, Hyunji Hong, Eunjin Choi, Heejo Lee |
USENIX Security Symposium | 1 |
| 2021 | Dicos: Discovering Insecure Code Snippets from Stack Overflow Posts by Leveraging User DiscussionsabstractOnline Q&A fora such as Stack Overflow assist developers to solve their faced coding problems. Despite the advantages, Stack Overflow has the potential to provide insecure code snippets that, if reused, can compromise the security of the entire software. Hyunji Hong, Seunghoon Woo, Heejo Lee |
ACSAC | 2 |
| 2021 | OCTOPOCS: Automatic Verification of Propagated Vulnerable Code Using Reformed Proofs of ConceptabstractAddressing vulnerability propagation has become a major issue in software ecosystems. Existing approaches hold the promise of detecting widespread vulnerabilities but cannot be applied to verify effectively whether propagated vulnerable code still poses threats. We present OCTOPOCS, which uses a reformed Proof-of-Concept (PoC), to verify whether a vulnerability is propagated. Using context-aware taint analysis, OCTOPOCS extracts crash primitives (the parts used in the shared code area between the original vulnerable software and propagated software) from the original PoC. OCTOPOCS then utilizes directed symbolic execution to generate guiding inputs that direct the execution of the propagated software from the entry point to the shared code area. Thereafter, OCTOPOCS creates a new PoC by combining crash primitives and guiding inputs. It finally verifies the propagated vulnerability using the created PoC. We evaluated OCTOPOCS with 15 real-world C and C++ vulnerable software pairs, with results showing that OCTOPOCS successfully verified 14 propagated vulnerabilities. Seongkyeong Kwon, Seunghoon Woo, Gangmo Seong, Heejo Lee |
DSN | 2 |
| 2021 | Centris: A Precise and Scalable Approach for Identifying Modified Open-Source Software ReuseabstractOpen-source software (OSS) is widely reused as it provides convenience and efficiency in software development. Despite evident benefits, unmanaged OSS components can introduce threats, such as vulnerability propagation and license violation. Unfortunately, however, identifying reused OSS components is a challenge as the reused OSS is predominantly modified and nested. In this paper, we propose CENTRIS, a precise and scalable approach for identifying modified OSS reuse. By segmenting an OSS code base and detecting the reuse of a unique part of the OSS only, CENTRIS is capable of precisely identifying modified OSS reuse in the presence of nested OSS components. For scalability, CENTRIS eliminates redundant code comparisons and accelerates the search using hash functions. When we applied CENTRIS on 10,241 widely-employed GitHub projects, comprising 229,326 versions and 80 billion lines of code, we observed that modified OSS reuse is a norm in software development, occurring 20 times more frequently than exact reuse. Nonetheless, CENTRIS identified reused OSS components with 91% precision and 94% recall in less than a minute per application on average, whereas a recent clone detection technique, which does not take into account modified and nested OSS reuse, hardly reached 10% precision and 40% recall. Seunghoon Woo, Sunghan Park, Seulbae Kim, Heejo Lee, Hakjoo Oh |
ICSE | 1 |
| 2021 | V0Finder: Discovering the Correct Origin of Publicly Reported Software Vulnerabilities
Seunghoon Woo, Sunghan Park, Heejo Lee, Sven Dietrich |
USENIX Security Symposium | 1 |
| 2017 | VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoveryabstractThe ecosystem of open source software (OSS) has been growing considerably in size. In addition, code clones - code fragments that are copied and pasted within or between software systems - are also proliferating. Although code cloning may expedite the process of software development, it often critically affects the security of software because vulnerabilities and bugs can easily be propagated through code clones. These vulnerable code clones are increasing in conjunction with the growth of OSS, potentially contaminating many systems. Although researchers have attempted to detect code clones for decades, most of these attempts fail to scale to the size of the ever-growing OSS code base. The lack of scalability prevents software developers from readily managing code clones and associated vulnerabilities. Moreover, most existing clone detection techniques focus overly on merely detecting clones and this impairs their ability to accurately find "vulnerable" clones. In this paper, we propose VUDDY, an approach for the scalable detection of vulnerable code clones, which is capable of detecting security vulnerabilities in large software programs efficiently and accurately. Its extreme scalability is achieved by leveraging function-level granularity and a length-filtering technique that reduces the number of signature comparisons. This efficient design enables VUDDY to preprocess a billion lines of code in 14 hour and 17 minutes, after which it requires a few seconds to identify code clones. In addition, we designed a security-aware abstraction technique that renders VUDDY resilient to common modifications in cloned code, while preserving the vulnerable conditions even after the abstraction is applied. This extends the scope of VUDDY to identifying variants of known vulnerabilities, with high accuracy. In this study, we describe its principles and evaluate its efficacy and effectiveness by comparing it with existing mechanisms and presenting the vulnerabilities it detected. VUDDY outperformed four state-of-the-art code clone detection techniques in terms of both scalability and accuracy, and proved its effectiveness by detecting zero-day vulnerabilities in widely used software systems, such as Apache HTTPD and Ubuntu OS Distribution. Seulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo Oh |
IEEE Symposium on Security and Privacy | 2 |