Kyungho Joo

dblp:218/7966 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
5since 2021 · last 2024
0000-0002-8310-6980ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2024 DROPSYS: Detection of ROP attacks using system information
Seon Kwon Kim, Hongjoo Jin, Kyungho Joo
Comput. Secur.3
2024 Enhancing Security of HRP UWB Ranging System Based on Channel Characteristic Analysis
abstract
Ultra-wideband (UWB) communication is emerging as a prominent technology to enhance the security of proximity verification systems (e.g., passive keyless entry and start systems, financial payment, and user authentication) against signal-relaying attacks. Leveraging the short-duration pulse (1–2 ns) in the physical-layer pulse, UWB communication enables a precise Time-of-Arrival (ToA) measurement for the received frame, which in turn leads to precise distance measurement. The current UWB communication is based on the IEEE 802.15.4z standard, which defines a scrambled timestamp sequence (STS) field that provides a secure ranging capability. However, exploiting the lack of integrity checks in the STS field, recent studies showed that an attacker could maliciously reduce the distance measurement between UWB devices. In this article, we present a distance reduction attack detection method for high-rate pulse repetition frequency (HRP) UWB ranging system. The proposed method analyzes the distribution of the channel impulse response (CIR) computed at the receiver for a ToA measurement. Since IEEE standard-compliant devices measure the ToA based on the CIR, our method can be widely implemented for commercial-off-the-shelf (COTS) devices. Through simulation and real-world experiments, we show that our method can effectively detect distance reduction attacks with a false alarm rate of 1%.
Kyungho Joo, Wonsuk Choi 0001
IEEE Internet Things J.1
2024 Securing Passive Keyless Entry and Start System in Modern Vehicles Based on LF-Band Signal Analysis
abstract
The low-frequency-band (LF-band) communication in the passive keyless entry and start (PKES) system is basically designed to enable short-range communication (1 to 2 m) through which a key fob determines whether it is in the vicinity of its paired vehicle. However, this short-range communication is vulnerable because it is unable to precisely verify the distance, as the LF-band signals can be easily relayed or amplified. In this article, we present a novel method (named low-frequency fingerprinting,LOFI) to detect LF-band signals generated by an attacker.LOFIis designed as a subauthentication method that supports existing authentication systems for PKES systems. Through a series of experiments, we demonstrate thatLOFIeffectively detects attacks on the PKES system, achieving an average false positive rate (FPR) of 0.92% and an average false negative rate (FNR) of 0.01% under Non-Line-of-Sight (NLoS) conditions. Moreover, using a physics-based ray-tracing simulation, we analyze detection boundaries against feature impersonation attackers.
Kyungho Joo, Hyo Jin Jo, Wonsuk Choi 0001
IEEE Internet Things J.1
2023 Protecting HRP UWB Ranging System Against Distance Reduction Attacks
abstract
Ultra-wideband (UWB) communication is an emerging technology that enables secure ranging and localization. Since UWB communication enables measuring an exact distance, enhanced security would be expected based on it. Recently, however, it has been demonstrated that a distance measured by IEEE 802.15.4z high-rate pulse repetition frequency (HRP) UWB ranging system can be maliciously reduced. The HRP UWB ranging system is widely adopted by smartphone manufacturers such as Samsung and Apple.
Kyungho Joo, Dong Hoon Lee 0001, Yeonseon Jeong, Wonsuk Choi 0001
CCS1
2023 Poster: Unveiling the Impact of Patch Placement: Adversarial Patch Attacks on Monocular Depth Estimation
abstract
For autonomous driving systems, cameras and LiDAR sensors are necessary devices that provide precise depth information by which positions and sizes of objects can be identified. Moreover, recent advances in deep learning have extended their capabilities to include monocular camera setup for depth estimation. Compared with the conventional devices like LiDAR or stereo cameras for the depth estimation, the monocular camera enables to estimate depths with a low cost. It is known that the depth estimation models for the monocular camera are vulnerable to adversarial examples. However, most adversarial attacks against the monocular depth estimation have been conducted with targeted patches that are placed on a target object. It is known that the targeted patch outperforms the adjacent and remote patch that is placed beyond the target object, when it comes to an attack success rate. However, the adjacent and remote patch would provide high flexibility in patch placement, as it can be placed beyond the target object's scope. In this paper, we experimentally confirm that the patch placement significantly affects the attack success rates, particularly in specific regions.
Gyungeun Yun, Kyungho Joo, Wonsuk Choi 0001, Dong Hoon Lee 0001
CCS2
2020 Hold the Door! Fingerprinting Your Car Key to Prevent Keyless Entry Car Theft
Kyungho Joo, Wonsuk Choi 0001, Dong Hoon Lee 0001
NDSS1
2018 VoltageIDS: Low-Level Communication Characteristics for Automotive Intrusion Detection System
abstract
The proliferation of computerized functions aimed at enhancing drivers' safety and convenience has increased the number of vehicular attack surfaces accordingly. The fundamental vulnerability is caused by the fact that the controller area network protocol, a de facto standard for in-vehicle networks, does not support message origin authentication. Several methods to resolve this problem have been suggested. However, most of them require modification of the CAN protocol and have their own vulnerabilities. In this paper, we focus on securing in-vehicle CAN networks, proposing a novel automotive intrusion detection system (so-called VoltageIDS). The system leverages the inimitable characteristics of an electrical CAN signal as a fingerprint of the electronic control units. The noteworthy contributions are that VoltageIDS does not require any modification of the current system and has been validated on actual vehicles while driving on the road. VoltageIDS is also the first automotive intrusion detection system capable of distinguishing between errors and the bus-off attack. Our experimental results on a CAN bus prototype and on real vehicles show that VoltageIDS detects intrusions in the in-vehicle CAN network. Moreover, we evaluate VoltageIDS while a vehicle is moving.
Wonsuk Choi 0001, Kyungho Joo, Hyo Jin Jo, Moon Chan Park, Dong Hoon Lee 0001
IEEE Trans. Inf. Forensics Secur.2