Jin-Myeong Shin

dblp:225/0383 · also Jinmyeong Shin · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0001-8580-6887ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Security and privacy · 1
YearPublicationVenuePosition
2026 Container-Specific Service Mesh-Based System for Mitigating Lateral Movement Attacks
abstract
The dynamic nature of containers within a Kubernetes cluster substantially expands the potential attack surface. In particular, lateral movement attacks enable adversaries to compromise additional subsystems after gaining initial access. To defend against lateral movement attacks, most anomaly detection methods rely on offline learning using system call data accumulated over a period of time. However, such offline learning methods struggle to capture the unique system call patterns of individual containers and lack adaptability to changes caused by frequent container updates. To address these limitations, we propose a new service mesh-based system for online learning of container-specific system call patterns observed under cloud-native microservice environments. The proposed service mesh-based system consists of three key functional processes as follows: (i) a zero-copy-based system call collection process, which leverages eBPF for efficient monitoring; (ii) an anomaly detection and container isolation process, which employs lightweight machine learning models, and leverages a proxy container for swift traffic control; and (iii) a container-specific online learning process, which continuously updates anomaly detection models by learning observed system call sequences. From the experimental results, we show that the proposed zero-copy-based system call collection process significantly improves system call collection speeds by as much as 4.5 times and shows lower CPU usage by as much as half compared to other state-of-the-art methods. Furthermore, the container-specific online learning process consistently outperforms offline learning approaches across various system call datasets and maintains stable detection performance by continuously adapting to behavioral changes caused by container updates over time.
Geon-Woo Yoon, Jin-Myeong Shin, Jae-Seok Kim, Seunghyuk Kim, Jaeyoung Jeong, Yoon-Ho Choi
IEEE Trans. Cloud Comput.2
2024 Zero-SAD: Zero-Shot Learning Using Synthetic Abnormal Data for Abnormal Behavior Detection on Private Cloud
abstract
While many studies have been conducted to detect abnormal behavior in cloud environments by analyzing system call sequences, these studies often cannot be applied to real-world cloud environments since they do not consider actual user behavior and rely on publicly available datasets. In actual cloud environments, the frequency of duplicate system calls is significantly higher than that observed in these datasets. This discrepancy necessitates a considerably larger scale of analysis to fully understand the sequential relationships among system calls. In this paper, we propose a practical abnormal behavior detection system for private cloud environments. The proposed system comprises of a deduplicated embedding process that efficiently represents duplicate system calls occurring within the cloud into a single embedding vector and a zero-shot abnormal behavior detection process that rapidly analyzes the large volume of system call sequences generated by numerous users through a zero-shot learning model. To demonstrate the practicality of our proposed system, we use both publicly available datasets and datasets directly collected from real cloud environments by implementing attacks from the MITRE ATT&CK framework as a proof of concept (PoC). Experimental results show that our system achieved an accuracy an accuracy of 92.13%, and it can detect attacks 5.48 times faster than existing research.
Jae-Seok Kim, Joonho Seo, SeonJin Hwang, Jin-Myeong Shin, Yoon-Ho Choi
SoCC4
2023 PIHA: Detection method using perceptual image hashing against query-based adversarial attacks
Seok-Hwan Choi 0001, Jin-Myeong Shin, Yoon-Ho Choi
Future Gener. Comput. Syst.2
2019 Unsupervised multi-stage attack detection framework without details on single-stage attacks
Jin-Myeong Shin, Seok-Hwan Choi 0001, Peng Liu 0005, Yoon-Ho Choi
Future Gener. Comput. Syst.1
2019 Dynamic Nonparametric Random Forest Using Covariance
abstract
As the representative ensemble machine learning method, the Random Forest (RF) algorithm has widely been used in diverse applications on behalf of the fast learning speed and the high classification accuracy. Research on RF can be classified into two categories: (1) improving the classification accuracy and (2) decreasing the number of trees in a forest. However, most of papers related to the performance improvement of RF have focused on improving the classification accuracy. Only some papers have focused on reducing the number of trees in a forest. In this paper, we propose a new Covariance-Based Dynamic RF algorithm, called C-DRF. Compared to the previous works, while ensuring the good-enough classification accuracy, the proposed C-DRF algorithm reduces the number of trees. Specifically, by computing the covariance between the number of trees in a forest and F -measure at each iteration, the proposed algorithm determines whether to increase the number of trees composing a forest. To evaluate the performance of the proposed C-DRF algorithm, we compared the learning time, the test time, and the memory usage with the original RF algorithm under the different areas of datasets. Under the same or higher classification accuracy, it is shown that the proposed C-DRF algorithm improves the performance of the original RF algorithm by as much as 58.68% at learning time, 47.91% at test time, and 68.06% in memory usage on average. As a practical application area, we also show that the proposed C-DRF algorithm is more efficient than the state-of-the-art RF algorithms in Network Intrusion Detection (NID) area.
Seok-Hwan Choi 0001, Jin-Myeong Shin, Yoon-Ho Choi
Secur. Commun. Networks2