Wooseok Kang

dblp:49/8196 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
2since 2021 · last 2024
0000-0002-9318-1511ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Program analysis · 38% Runtime systems and virtual machines · 32% Compilers and program optimization · 25%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 8 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Runtime systems and virtual machines › dynamic compilation
just-in-time compilation
0.812024
Translation Validation for JIT Compiler in the V8 JavaScript Engine · ICSE 2024
Compilers and program optimization › verified compilation
translation validation
0.812024
Translation Validation for JIT Compiler in the V8 JavaScript Engine · ICSE 2024
Systems and software security › vulnerability discovery › software vulnerability detection
recurring vulnerability detection
0.612022
TRACER: Signature-based Static Analysis for Detecting Recurring Vulnerabilities · CCS 2022
Systems and software security
vulnerability discovery
0.612022
TRACER: Signature-based Static Analysis for Detecting Recurring Vulnerabilities · CCS 2022
Program analysis
static analysis
0.612022
TRACER: Signature-based Static Analysis for Detecting Recurring Vulnerabilities · CCS 2022
Program analysis › static analysis
taint analysis
0.612022
TRACER: Signature-based Static Analysis for Detecting Recurring Vulnerabilities · CCS 2022
Runtime systems and virtual machines › virtual machine implementation
javascript engine
0.212024
Translation Validation for JIT Compiler in the V8 JavaScript Engine · ICSE 2024
Software maintenance and evolution
code reuse
0.212022
TRACER: Signature-based Static Analysis for Detecting Recurring Vulnerabilities · CCS 2022

Methods — techniques the papers use, named apart from their topics

taint analysis · 1.1signature-based analysis · 1.1staged validation · 0.8fuzzing · 0.8SMT encoding · 0.8
YearPublicationVenuePosition
2024 Translation Validation for JIT Compiler in the V8 JavaScript Engine
abstract
We present TurboTV, a translation validator for the JavaScript (JS) just-in-time (JIT) compiler of V8. While JS engines have become a crucial part of various software systems, their emerging adaption of JIT compilation makes it increasingly challenging to ensure their correctness. We tackle this problem with an SMT-based translation validation (TV) that checks whether a specific compilation is semantically correct. We formally define the semantics of IR of TurboFan (JIT compiler of V8) as SMT encoding. For efficient validation, we design a staged strategy for JS JIT compilers. This allows us to decompose the whole correctness checking into simpler ones. Furthermore, we utilize fuzzing to achieve practical TV. We generate a large number of JS functions using a fuzzer to trigger various optimization passes of TurboFan and validate their compilation using TurboTV. Lastly, we demonstrate that TurboTV can also be used for cross-language TV. We show that TurboTV can validate the translation chain from LLVM IR to TurboFan IR, collaborating with an off-the-shelf TV tool for LLVM. We evaluated TurboTV on various sets of JS and LLVM programs. TurboTV effectively validated a large number of compilations of TurboFan with a low false positive rate and discovered a new miscompilation in LLVM.
Seungwan Kwon, Jaeseong Kwon, Wooseok Kang, Juneyoung Lee, Kihong Heo
ICSE3
2022 TRACER: Signature-based Static Analysis for Detecting Recurring Vulnerabilities
abstract
Similar software vulnerabilities recur because developers reuse existing vulnerable code, or make similar mistakes when implementing the same logic. Recently, various analysis techniques have been proposed to find syntactically recurring vulnerabilities via code reuse. However, limited attention has been devoted to semantically recurring ones that share the same vulnerable behavior in different code structures. In this paper, we present a general analysis framework, called TRACER, for detecting such recurring vulnerabilities. TRACER is based on a taint analysis that can detect various types of vulnerabilities. For a given set of known vulnerabilities, the taint analysis extracts vulnerable traces and establishes a signature database of them. When a new unseen program is analyzed, TRACER compares all potentially vulnerable traces reported by the analysis with the known vulnerability signatures. Then, TRACER reports a list of potential vulnerabilities ranked by the similarity score. We evaluate TRACER on 273 Debian packages in C/C++. Our experiment results demonstrate that TRACER is able to find 281 previously unknown vulnerabilities with 6 CVE identifiers assigned.
Wooseok Kang, Byoungho Son, Kihong Heo
CCS1
2009 Coordinate Interleaved Hybrid Transmission For MIMO-OFDM Systems
abstract
MIMO-OFDM systems would provide both multiplexing gain and diversity gain in order to improve the system capacity and the receive performance. This paper introduces the coordinate interleaved hybrid transmission for use in MIMO- OFDM systems to meet such requirements. The proposed CID- SFBC-OFDM and CID-STBC-OFDM combine the coordinate interleaver with Double SFBC-OFDM and Double STBC-OFDM to achieve additional diversity gain whilst retaining their spatial multiplexing gain. Our simulation results show that CID-SFBC- OFDM and CID-STBC-OFDM outperform the conventional schemes in typical urban (TU) channel.
Wooseok Kang, Soon Up Hwang, Jin-Yong Choi, Sungho Jeon 0001, Jong-Soo Seo
VTC Spring1