EDBT 2026 Demo / reviewers in the wild / expert
Hyerean Jang
dblp:267/7352
· DBLP profile ↗
5ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0003-4100-9338ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MimicCall: Bypassing System Call Filters via Kernel Function RedundancyabstractModern operating systems often employ system call filtering to limit untrusted code's access to kernel resources, thereby reducing the kernel attack surface. However, existing filters operate at the system call interface level and often overlook the internal reuse of kernel functions across multiple system calls. This paper identifies and systematically analyzes a class of filter bypasses we term Mimic Calls, wherein alternative, permitted system calls invoke the same vulnerable functions as restricted ones. We present an automated analysis framework that traces syscall-to-function mappings using ftrace, leveraging system calls' test cases to cover diverse system call behaviors, using Syzkaller. Our evaluation of a recent Linux kernel demonstrates that even semantically distinct system calls share extensive kernel logic, and that thousands of patched CVE functions are accessible via multiple call paths. We further analyze filters generated by five representative tools and show that all tools are exposed of vulnerable functions through allowed MimicCalls. Case studies on CVE-2016-4486, CVE-2016-9793, and CVE-2017-7184 validate the practical impact of our findings, demonstrating that real-world exploits can be adapted to bypass filtering. Our results reveal a fundamental limitation in system call level defenses and underscore the need for more semantically informed filtering strategies. Songah Joo, Minchan Park, Hyerean Jang, Young-joo Shin |
ACSAC | 3 |
| 2025 | Cache Demote for Fast Eviction Set Construction and Page Table Attribute Leakage
Hyerean Jang, Young-joo Shin |
ESORICS (3) | 2 |
| 2024 | SysBumps: Exploiting Speculative Execution in System Calls for Breaking KASLR in macOS for Apple SiliconabstractApple silicon is the proprietary ARM-based processor that powers the mainstream of Apple devices. The move to this proprietary architecture presents unique challenges in addressing security issues, requiring huge research efforts into the security of Apple silicon-based systems. In this paper, we study the security of KASLR, the randomization-based kernel hardening technique, on the state-of-the-art macOS system equipped with Apple silicon processors. Because KASLR has been subject to many microarchitectural side-channel attacks, the latest operating systems, including macOS, use kernel isolation, which separates the kernel page table from the userspace table. Kernel isolation in macOS provides a barrier to KASLR break attacks. To overcome this, we exploit speculative execution in system calls. By using Spectre-type gadgets in system calls, an unprivileged attacker can cause translations of the attacker's chosen kernel addresses, causing the TLB to change according to the validity of the address. This allows the construction of an attack primitive that breaks KASLR bypassing kernel isolation. Since the TLB is used as a side-channel source, we reverse-engineer the hidden internals of the TLB on various M-series processors using a hardware performance monitoring unit. Based on our attack primitive, we implement SysBumps, the first KASLR break attack on macOS for Apple silicon. Throughout evaluation, we show that SysBumps can effectively break KASLR across different M-series processors and macOS versions. We also discuss possible mitigations against the proposed attack. Hyerean Jang, Young-joo Shin |
CCS | 1 |
| 2022 | Avengers, Assemble! Survey of WebAssembly Security SolutionsabstractWebAssembly, abbreviated as Wasm, has emerged as a new paradigm in cloud-native developments owing to its promising properties. Native execution speed and fast startup time make Wasm an alternative for container-based cloud applications. Despite its security-by-design strategy, however, WebAssembly suffers from a variety of vulnerabilities and weaknesses, which hinder its rapid adoption in cloud computing. For instance, the native execution performance attracted cybercriminals to abuse Wasm binaries for the purpose of resource stealing such as cryptojacking. Without proper defense mechanisms, Wasm-based malware would proliferate, causing huge financial loss of cloud users. Moreover, the design principle that allows type-unsafe languages such as C/C++ inherently induces various memory bugs in an Wasm binary. Efficient and robust vulnerability analysis techniques are necessary to protect benign cloud-native Wasm applications from being exploited by attackers. Due to the young age of WebAssembly, however, there are few works in the literature that provide developers guidance to such security techniques. This makes developers to hesitate considering Wasm as their cloud-native platform. In this paper, we surveyed various techniques and methods for Wasm binary security proposed in the literature and systematically classified them according to certain criteria. As a result, we propose future research directions regarding the current lack of WebAssembly binary security research. Hyerean Jang, Young-joo Shin |
CLOUD | 2 |
| 2020 | IBV-CFI: Efficient fine-grained control-flow integrity preserving CFG precision
Hyerean Jang, Moon Chan Park, Dong Hoon Lee 0001 |
Comput. Secur. | 1 |