Jun-Ho Huh

dblp:58/3207 · also Jun Ho Huh, Jun-ho Huh, Junho Huh · DBLP profile ↗
← Back
52ranked-venue papers
12as first author
17since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 5 first-author · 2 since 2021Systems, architecture and hardware · 15 · 6 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 10 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Computer networks · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 "I just have faith in my wallet to not mismanage my crypto": Investigating Changes in Users' Security Perceptions Post-FTX Collapse
Nivedita Singh, Jun-Ho Huh, Hyoungshick Kim, Taesoo Kim
CHI3
2025 Understanding and Improving User Adoption and Security Awareness in Password Checkup Services
Sanghak Oh, Heewon Baek, Jun-Ho Huh, Woojin Jeon, Ian Oakley, Hyoungshick Kim
CHI3
2025 Preventing Artificially Inflated SMS Attacks through Large-Scale Traffic Inspection
Jun-Ho Huh, Hyejin Shin, Sunwoo Ahn, Hayoon Yi, Joonho Cho, Minchae Lim, Nu-El Choi
USENIX Security Symposium1
2025 A Survey of Cyber Security for Maritime Autonomous Surface Ships: Opportunities, Challenges, and Future Directions
abstract
With the evolution of information and communication technology, the shipping industry, responsible for the highest volume of international trade in goods, has experienced significant advantages in terms of cost-effectiveness and the safety of ship operations. However, the implementation of a network with an open interface has compromised network and system security, leading to heightened vulnerability to external cyber-attacks. This survey analyzes the security research trends at four stages of Maritime Autonomous Surface Ships (MASS) and provides an overview of state-of-the-art strategies for enhancing security at the final Level 4, based on key achievements and limitations. In particular, we examine the major research and development efforts for MASS Levels 2 and 3, which include remote control functionalities, emphasizing the importance of security research in the areas of remote control, unmanned ships, and international agreements. The study then focuses on the key achievements and limitations within these three areas. Additionally, we propose seven research areas necessary for the final Level 4 and highlight the importance of developing security architectures that consider maritime stakeholders and foster international consensus. Finally, this study aims to present the current research limitations and future directions to guide researchers interested in contributing to the field of autonomous ship security.
Uinam Son, Jun-Ho Huh
IEEE Trans. Intell. Transp. Syst.2
2024 SkullID: Through-Skull Sound Conduction based Authentication for Smartglasses
abstract
This paper investigates the use of through-skull sound conduction to authenticate smartglass users. We mount a surface transducer on the right mastoid process to play cue signals and capture skull-transformed audio responses through contact microphones on various skull locations. We use the resultant bio-acoustic information as classification features. In an initial single-session study (N=25), we achieved mean Equal Error Rates (EERs) of 5.68% and 7.95% with microphones on the brow and left mastoid process. Combining the two signals substantially improves performance (to 2.35% EER). A subsequent multi-session study (N=30) demonstrates EERs are maintained over three recalls and, additionally, shows robustness to donning variations and background noise (achieving 2.72% EER). In a follow-up usability study over one week, participants report high levels of usability (as expressed by SUS scores) and that only modest workload is required to authenticate. Finally, a security analysis demonstrates the system’s robustness to spoofing and imitation attacks.
Hyejin Shin, Jun-Ho Huh, Bum Jun Kwon, Iljoo Kim, Eunyong Cheon, HongMin Kim, Choong-Hoon Lee, Ian Oakley
CHI2
2024 I2SR: Immediate Interrupt Service Routine on RISC-V MCU to Control mmWave RF Transceivers
abstract
In 5G technology, millimeter Wave (mmWave), known as Frequency Range 2 (FR2), is one of the candidates for next-generation mobile communications. However, the adoption of mmWave technology in transceiver systems faces challenges in terms of strict latency requirements, due to the significantly increased number of control and compensation tasks. In this paper, we propose a novel interrupt architecture, Immediate Interrupt Service Routine (I2SR) on a RISC-V MCU, enabling zero-latency context switching. Applied to the mmWave transceiver, our I2SR MCU efficiently handles the mmWave tasks by removing context switching overhead. In our experiment, I2SR architecture reduces the overall MCU utilization by 30.6% compared to the baseline MCU, thereby demonstrating that I2SR architecture satisfies the strict latency requirements essential for mmWave applications.
Sangwoo Park 0005, Jun-Ho Huh, Sanghyo Jeong, Inhwan Kim, Jae Min Kim
DATE3
2024 I Experienced More than 10 DeFi Scams: On DeFi Users' Perception of Security Breaches and Countermeasures
Jun-Ho Huh, HyungSeok Han, Jaehyuk Lee, Jihae Ahn, Frank Li 0001, Hyoungshick Kim, Taesoo Kim
USENIX Security Symposium2
2024 COVID-19 monitoring system: in-browser face mask detection application using deep learning
Thi-Ngot Pham, Viet-Hoan Nguyen, Jun-Ho Huh
Multim. Tools Appl.3
2023 GestureMeter: Design and Evaluation of a Gesture Password Strength Meter
abstract
Gestures drawn on touchscreens have been proposed as an authentication method to secure access to smartphones. They provide good usability and a theoretically large password space. However, recent work has demonstrated that users tend to select simple or similar gestures as their passwords, rendering them susceptible to dictionary based guessing attacks. To improve their security, this paper describes a novel gesture password strength meter that interactively provides security assessments and improvement suggestions based on a scoring algorithm that combines a probabilistic model, a gesture dictionary, and a set of novel stroke heuristics. We evaluate this system in both online and offline settings and show it supports creation of gestures that are significantly more resistant to guessing attacks (by up to 67%) while also maintaining performance on usability metrics such as recall success rate and time. We conclude that gesture password strength meters can help users select more secure gesture passwords.
Eunyong Cheon, Jun-Ho Huh, Ian Oakley
CHI2
2023 Mobile robot: automatic speech recognition application for automation and STEM education
Tran Duy Thanh, Dang Huy Truong, Hoanh-Su Le, Jun-Ho Huh
Soft Comput.4
2023 Integration of improved YOLOv5 for face mask detector and auto-labeling to generate dataset for fighting against COVID-19
abstract
One of the most effective deterrent methods is using face masks to prevent the spread of the virus during the COVID-19 pandemic. Deep learning face mask detection networks have been implemented into COVID-19 monitoring systems to provide effective supervision for public areas. However, previous works have limitations: the challenge of real-time performance (i.e., fast inference and low accuracy) and training datasets. The current study aims to propose a comprehensive solution by creating a new face mask dataset and improving the YOLOv5 baseline to balance accuracy and detection time. Particularly, we improve YOLOv5 by adding coordinate attention (CA) module into the baseline backbone following two different schemes, namely YOLOv5s-CA and YOLOV5s-C3CA. In detail, we train three models with a Kaggle dataset of 853 images consisting of three categories: without a mask "NM," with mask "M," and incorrectly worn mask "IWM" classes. The experimental results show that our modified YOLOv5 with CA module achieves the highest accuracy [email protected] of 93.9% compared with 87% of baseline and detection time per image of 8.0 ms (125 FPS). In addition, we build an integrated system of improved YOLOv5-CA and auto-labeling module to create a new face mask dataset of 7110 images with more than 3500 labels for three categories from YouTube videos. Our proposed YOLOv5-CA and the state-of-the-art detection models (i.e., YOLOX, YOLOv6, and YOLOv7) are trained on our 7110 images dataset. In our dataset, the YOLOv5-CA performance enhances with [email protected] of 96.8%. The results indicate the enhancement of the improved YOLOv5-CA model compared with several state-of-the-art works.
Thi-Ngot Pham, Viet-Hoan Nguyen, Jun-Ho Huh
J. Supercomput.3
2023 New machine learning model based on the time factor for e-commerce recommendation systems
Tran Duy Thanh, Jun-Ho Huh
J. Supercomput.2
2023 Forecast of seasonal consumption behavior of consumers and privacy-preserving data mining with new S-Apriori algorithm
Tran Duy Thanh, Jun-Ho Huh
J. Supercomput.2
2023 Building a Lucy hybrid model for grocery sales forecasting based on time series
Tran Duy Thanh, Jun-Ho Huh, Jae-Hwan Kim
J. Supercomput.2
2022 Optimizing patient transportation by applying cloud computing and big data analysis
Hong-Danh Thai, Jun-Ho Huh
J. Supercomput.2
2022 Building a model to exploit association rules and analyze purchasing behavior based on rough set theory
Tran Duy Thanh, Jun-Ho Huh
J. Supercomput.2
2021 On Smartphone Users' Difficulty with Understanding Implicit Authentication
abstract
Implicit authentication (IA) has recently become a popular approach for providing physical security on smartphones. It relies on behavioral traits (e.g., gait patterns) for user identification, instead of biometric data or knowledge of a PIN. However, it is not yet known whether users can understand the semantics of this technology well enough to use it properly. We bridge this knowledge gap by evaluating how Android’s Smart Lock (SL), which is the first widely deployed IA solution on smartphones, is understood by its users. We conducted a qualitative user study (N=26) and an online survey (N=331). The results suggest that users often have difficulty understanding SL semantics, leaving them unable to judge when their phone would be (un)locked. We found that various aspects of SL, such as its capabilities and its authentication factors, are confusing for the users. We also found that depth of smartphone adoption is a significant antecedent of SL comprehension.
Masoud Mehrabi Koushki, Borke Obada-Obieh, Jun-Ho Huh, Konstantin Beznosov
CHI3
2020 ResMax: Detecting Voice Spoofing Attacks with Residual Network and Max Feature Map
abstract
The “2019 Automatic Speaker Verification Spoofing And Countermeasures Challenge” (ASVspoof) competition aimed to facilitate the design of highly accurate voice spoofing attack detection systems. the competition did not emphasize model complexity and latency requirements; such constraints are strict and integral in real-world deployment. Hence, most of the top performing solutions from the competition all used an ensemble approach, and combined multiple complex deep learning models to maximize detection accuracy - this kind of approach would sit uneasily with real-world deployment constraints. To design a lightweight system, we combined the notions of skip connection (from ResNet) and max feature map (from Light CNN), and evaluated the accuracy of the system using the ASVspoof 2019 dataset. With an optimized constant Q transform (CQT) feature, our single model achieved a replay attack detection equal error rate (EER) of 0.37% on the evaluation set, surpassing the top ensemble system from the competition that achieved an EER of 0.39%.
Il-Youp Kwak, Sungsu Kwag, Jun-Ho Huh, Choong-Hoon Lee, Youngbae Jeon, Jeong-Hwan Hwang, Jiwon Yoon 0001
ICPR4
2020 Is Implicit Authentication on Smartphones Really Popular? On Android Users' Perception of "Smart Lock for Android"
abstract
Implicit authentication (IA) on smartphones has gained a lot of attention from the research community over the past decade. IA leverages behavioral and contextual data to identify users without requiring explicit input, and thus can alleviate the burden of smartphone unlocking. The reported studies on users’ perception of IA have painted a very positive picture, showing that more than 60% of their respective participants are interested in adopting IA, should it become available on their devices. These studies, however, have all been done either in lab environments, or with low- to medium-fidelity prototypes, which limits their generalizability and ecological validity. Therefore, the question of “how would smartphone users perceive a commercialized IA scheme in a realistic setting?” remains unanswered. To bridge this knowledge gap, we report on the findings of our qualitative user study (N = 26) and our online survey (N = 343) to understand how Android users perceive Smart Lock (SL). SL is the first and currently only widely-deployed IA scheme for smartphones. We found that SL is not a widely adopted technology, even among those who have an SL-enabled phone and are aware of the existence of the feature. Conversely, we found unclear usefulness, and perceived lack of security, among others, to be major adoption barriers that caused the SL adoption rate to be as low as 13%. To provide a theoretical framework for explaining SL adoption, we propose an extended version of the technology acceptance model (TAM), called SL-TAM, which sheds light on the importance of factors such as perceived security and utility on SL adoption.
Masoud Mehrabi Koushki, Borke Obada-Obieh, Jun-Ho Huh, Konstantin Beznosov
MobileHCI3
2020 Gesture Authentication for Smartphones: Evaluation of Gesture Password Selection Policies
abstract
Touchscreen gestures are attracting research attention as an authentication method. While studies have showcased their usability, it has proven more complex to determine, let alone enhance, their security. Problems stem both from the small scale of current data sets and the fact that gestures are matched imprecisely - by a distance metric. This makes it challenging to assess entropy with traditional algorithms. To address these problems, we captured a large set of gesture passwords (N=2594) from crowd workers, and developed a security assessment framework that can calculate partial guessing entropy estimates, and generate dictionaries that crack 23.13% or more gestures in online attacks (within 20 guesses). To improve the entropy of gesture passwords, we designed novel blacklist and lexical policies to, respectively, restrict and inspire gesture creation. We close by validating both our security assessment framework and policies in a new crowd-sourced study (N=4000). Our blacklists increase entropy and resistance to dictionary based guessing attacks.
Eunyong Cheon, Yonghwan Shin, Jun-Ho Huh, Hyoungshick Kim, Ian Oakley
SP3
2020 Void: A fast and light voice liveness detection system
M. Ejaz Ahmed, Il-Youp Kwak, Jun-Ho Huh, Iljoo Kim, Taekkyung Oh, Hyoungshick Kim
USENIX Security Symposium3
2020 On the Security and Usability Implications of Providing Multiple Authentication Choices on Smartphones: The More, the Better?
abstract
The latest smartphones have started providing multiple authentication options including PINs, patterns, and passwords (knowledge based), as well as face, fingerprint, iris, and voice identification (biometric-based). In this article, we conducted two user studies to investigate how the convenience and security of unlocking phones are influenced by the provision of multiple authentication options. In a task-based user study with 52 participants, we analyze how participants choose an option to unlock their smartphone in daily life. The user study results demonstrate that providing multiple biometric-based authentication choices does not really influence convenience, because fingerprint had monopolistic dominance in the usage of unlock methods (111 of a total of 115 unlock trials that used a biometric-based authentication factor) due to users’ habitual behavior and fastness in unlocking phones. However, convenience was influenced by the provision of both knowledge-based and biometric-based authentication categories, as biometric-based authentication options were used in combination with knowledge-based authentication options—pattern was another frequently used unlock method. Our findings were confirmed and generalized through a follow-up survey with 327 participants. First, knowledge-based and biometric-based authentication options are used interchangeably. Second, providing multiple authentication options for knowledge-based authentication may influence convenience—both PINs (55.7%) and patterns (39.2%) are quite evenly used. Last, in contrast to knowledge-based authentication, providing multiple authentication choices for biometric-based authentication has less influence on choosing unlock options—fingerprint scanner is the most frequently used option (134 of 187 unlock methods used among biometric-based authentication options).
Geumhwan Cho, Jun-Ho Huh, Soolin Kim, Junsung Cho, Heesung Park, Yenah Lee, Konstantin Beznosov, Hyoungshick Kim
ACM Trans. Priv. Secur.2
2020 Reefer container monitoring system using PLC-based communication technology for maritime edge computing
Jun-Ho Huh
J. Supercomput.1
2019 Voice Presentation Attack Detection through Text-Converted Voice Command Analysis
abstract
Voice assistants are quickly being upgraded to support advanced, security-critical commands such as unlocking devices, checking emails, and making payments. In this paper, we explore the feasibility of using users' text-converted voice command utterances as classification features to help identify users' genuine commands, and detect suspicious commands. To maintain high detection accuracy, our approach starts with a globally trained attack detection model (immediately available for new users), and gradually switches to a user-specific model tailored to the utterance patterns of a target user. To evaluate accuracy, we used a real-world voice assistant dataset consisting of about 34.6 million voice commands collected from 2.6 million users. Our evaluation results show that this approach is capable of achieving about 3.4% equal error rate (EER), detecting 95.7% of attacks when an optimal threshold value is used. As for those who frequently use security-critical (attack-like) commands, we still achieve EER below 5%.
Il-Youp Kwak, Jun-Ho Huh, Seung Taek Han, Iljoo Kim, Jiwon Yoon 0001
CHI2
2019 A location-based mobile health care facility search system for senior citizens
Jun-Ho Huh, Tae-Jung Kim
J. Supercomput.1
2019 Blockchain-based mobile fingerprint verification and automatic log-in platform for future computing
Jun-Ho Huh, Kyungryong Seo
J. Supercomput.1
2019 An effective security measures for nuclear power plant using big data analysis approach
Sangdo Lee, Jun-Ho Huh
J. Supercomput.2
2018 The Personal Identification Chord: A Four ButtonAuthentication System for Smartwatches
abstract
Smartwatches support access to a wide range of private information but little is known about the security and usability of existing smartwatch screen lock mechanisms. Prior studies suggest that smartwatch authentication via standard techniques such as 4-digit PINs is challenging and error-prone. We conducted interviews to shed light on current practices, revealing that smartwatch users consider the ten-key keypad required for PIN entry to be hard to use due to its small button sizes. To address this issue, we propose the Personal Identification Chord (PIC), an authentication system based on a four-button chorded keypad that enables users to enter ten different inputs via taps to one or two larger buttons. Two studies assessing usability and security of our technique indicate PICs lead to increases in setup and (modestly) recall time, but can be entered accurately while maintaining high recall rates and may improve guessing entropy compared to PINs.
Ian Oakley, Jun-Ho Huh, Junsung Cho, Geumhwan Cho, Md. Rasel Islam, Hyoungshick Kim
AsiaCCS2
2018 An Optimization Theory of Home Occupants' Access Data for Determining Smart Grid Service
Seung-Mo Je, Jun-Ho Huh
PDCAT2
2018 I'm Listening to your Location! Inferring User Location with Acoustic Side Channels
abstract
Electrical network frequency (ENF) signals have common patterns that can be used as signatures for identifying recorded time and location of videos and sound. To enable cost-efficient, reliable and scalable location inference, we created a reference map of ENF signals representing hundreds of locations world wide -- extracting real-world ENF signals from online multimedia streaming services (e.g., YouTube and Explore). Based on this reference map of ENF signals, we propose a novel side-channel attack that can identify the physical location of where a target video or sound was recorded or streamed from. Our attack does not require any expensive ENF signal receiver nor any software to be installed on a victim»s device -- all we need is the recorded video or sound files to perform the attack and they are collected from world wide web. The evaluation results show that our attack can infer the intra-grid location of the recorded audio files with an accuracy of $76$% when those files are $5$ minutes or longer. We also showed that our proposed attack works well even when video and audio data are processed within a certain distortion range with audio codecs used in real VoIP applications.
Youngbae Jeon, Hyoungshick Kim, Jun-Ho Huh, Jiwon Yoon 0001
WWW5
2018 Bi-directional education contents using VR equipments and augmented reality
Tae-Jung Kim, Jun-Ho Huh, Jin-Mo Kim
Multim. Tools Appl.2
2017 Boosting the Guessing Attack Performance on Android Lock Patterns with Smudge Attacks
abstract
Android allows 20 consecutive fail attempts on unlocking a device. This makes it difficult for pure guessing attacks to crack user patterns on a stolen device before it permanently locks itself. We investigate the effectiveness of combining Markov model-based guessing attacks with smudge attacks on unlocking Android devices within 20 attempts. Detected smudges are used to pre-compute all the possible segments and patterns, significantly reducing the pattern space that needs to be brute-forced. Our Markov-model was trained using 70% of a real-world pattern dataset that consists of 312 patterns. We recruited 12 participants to draw the remaining 30% on Samsung Galaxy S4, and used smudges they left behind to analyze the performance of the combined attack. Our results show that this combined method can significantly improve the performance of pure guessing attacks, cracking 74.17% of patterns compared to just 13.33% when the Markov model-based guessing attack was performed alone---those results were collected from a naive usage scenario where the participants were merely asked to unlock a given device. Even under a more complex scenario that asked the participants to use the Facebook app for a few minutes---obscuring smudges were added as a result---our combined attack, at 31.94%, still outperformed the pure guessing attack at 13.33%. Obscuring smudges can significantly affect the performance of smudge-based attacks. Based on this finding, we recommend that a mitigation technique should be designed to help users add obscurity, e.g., by asking users to draw a second random pattern upon unlocking a device.
Seunghun Cha, Sungsu Kwag, Hyoungshick Kim, Jun-Ho Huh
AsiaCCS4
2017 I'm too Busy to Reset my LinkedIn Password: On the Effectiveness of Password Reset Emails
abstract
A common security practice used to deal with a password breach is locking user accounts and sending out an email to tell users that they need to reset their password to unlock their account. This paper evaluates the effectiveness of this security practice based on the password reset email that LinkedIn sent out around May 2016, and through an online survey conducted on 249 LinkedIn users who received that email. Our evaluation shows that only about 46% of the participants reset their passwords. The mean time taken to reset password was 26.3 days, revealing that a significant proportion of the participants reset their password a few weeks, or even months after first receiving the email. Our findings suggest that more effective persuasive measures need to be added to convince users to reset their password in a timely manner, and further reduce the risks associated with delaying password resets.
Jun-Ho Huh, Hyoungshick Kim, Swathi S. V. P. Rayala, Rakesh Bobba, Konstantin Beznosov
CHI1
2017 SysPal: System-Guided Pattern Locks for Android
abstract
To improve the security of user-chosen Android screen lock patterns, we propose a novel system-guided pattern lock scheme called "SysPal" that mandates the use of a small number of randomly selected points while selecting a pattern. Users are given the freedom to use those mandated points at any position. We conducted a large-scale online study with 1,717 participants to evaluate the security and usability of three SysPal policies, varying the number of mandatory points that must be used (upon selecting a pattern) from one to three. Our results suggest that the two SysPal policies that mandate the use of one and two points can help users select significantly more secure patterns compared to the current Android policy: 22.58% and 23.19% fewer patterns were cracked. Those two SysPal policies, however, did not show any statistically significant inferiority in pattern recall success rate (the percentage of participants who correctly recalled their pattern after 24 hours). In our lab study, we asked participants to install our screen unlock application on their own Android device, and observed their real-life phone unlock behaviors for a day. Again, our lab study did not show any statistically significant difference in memorability for those two SysPal policies compared to the current Android policy.
Geumhwan Cho, Jun-Ho Huh, Junsung Cho, Seongyeol Oh, Youngbae Song, Hyoungshick Kim
IEEE Symposium on Security and Privacy2
2016 Stopping Amplified DNS DDoS Attacks through Distributed Query Rate Sharing
abstract
An Amplified DNS DDoS (ADD) attack involves tens of thousands of DNS resolvers that send huge volumes of amplified DNS responses to a single victim host, quickly flooding the victim's network bandwidth. Because ADD attacks are distributed, it is difficult for individual DNS resolvers to detect them based on local DNS query rates alone. Even if a victim detects an ADD attack, it cannot stop the attacker from flooding its network bandwidth. To address this problem, we present a novel mitigation system called"Distributed Rate Sharing based Amplified DNS-DDoS Attack Mitigation" (DRS-ADAM). DRS-ADAM facilitates DNS query rate sharing between DNS resolvers that are involved in an attack to detect and completely stop an ADD attack. Each DNS resolver quickly builds the global DNS query rate for potential victims by accumulating the shared rate values, and uses that global rate to make mitigation decisions locally. DRS-ADAM can be easily deployed through a small software update on resolvers and victim hosts, and does not require any additional server component. Our simulation results show that DRS-ADAM can contain the peak attack rates close to a victim's acceptable threshold values (which are far smaller than their sustainable bandwidth) at all times, regardless of the number of resolvers involved in ADD attacks. ADD attacks can be fully mitigated within a few seconds.
Saurabh Verma, Ali Hamieh, Jun-Ho Huh, Henrik Holm, S. Raj Rajagopalan, Maciej Korczynski, Nina H. Fefferman
ARES3
2016 On the Guessability of Resident Registration Numbers in South Korea
Youngbae Song, Hyoungshick Kim, Jun-Ho Huh
ACISP (1)3
2016 POSTER: WiPING: Wi-Fi signal-based PIN Guessing attack
abstract
This paper presents a new type of online password guessing attack called "WiPING" (Wi-Fi signal-based PIN Guessing attack) to guess a victim's PIN (Personal Identification Number) within a small number of unlock attempts. WiPING uses wireless signal patterns identified from observing sequential finger movements involved in typing a PIN to unlock a mobile device. A list of possible PIN candidates is generated from the wireless signal patterns, and is used to improve performance of PIN guessing attacks. We implemented a proof-of-concept attack to demonstrate the feasibility of WiPING. Our results showed that WiPING could be practically effective: while pure guessing attacks failed to guess all 20 PINs, WiPING successfully guessed two PINs.
Seunghun Cha, Geumhwan Cho, Jun-Ho Huh, Hyoungshick Kim
CCS4
2016 Advanced metering infrastructure design and test bed experiment using intelligent agents: focusing on the PLC network base technology for Smart Grid system
Jun-Ho Huh, Sugarbayar Otgonchimeg, Kyungryong Seo
J. Supercomput.1
2015 Surpass: System-initiated User-replaceable Passwords
abstract
System-generated random passwords have maximum password security and are highly resistant to guessing attacks. However, few systems use such passwords because they are difficult to remember. In this paper, we propose a system-initiated password scheme called "Surpass" that lets users replace few characters in a random password to make it more memorable. We conducted a large-scale online study to evaluate the usability and security of four Surpass policies, varying the number of character replacements allowed from 1 to 4 in randomly-generated 8-character passwords. The study results suggest that some Surpass policies (with 3 and 4 character replacements) outperform by 11% to 13% the original randomly-generated password policy in memorability, while showing a small increase in the percentage of cracked passwords. When compared to a user-generated password complexity policy (that mandates the use of numbers, symbols, and uppercase letters) the Surpass policy with 4-character replacements did not show statistically significant inferiority in memorability. Our qualitative lab study showed similar trends. This Surpass policy demonstrated significant superiority in security though, with 21% fewer cracked passwords than the user-generated password policy.
Jun-Ho Huh, Seongyeol Oh, Hyoungshick Kim, Konstantin Beznosov, Apurva Mohan, S. Raj Rajagopalan
CCS1
2015 On the Effectiveness of Pattern Lock Strength Meters: Measuring the Strength of Real World Pattern Locks
abstract
We propose an effective pattern lock strength meter to help users choose stronger pattern locks on Android devices. To evaluate the effectiveness of the proposed meter with a real world dataset (i.e., with complete ecological validity), we created an Android application called EnCloud that allows users to encrypt their Dropbox files. 101 pattern locks generated by real EnCloud users were collected and analyzed, where some portion of the users were provided with the meter support. Our statistical analysis indicates that about 10% of the pattern locks that were generated without the meter support could be compromised through just 16 guessing attempts. As for the pattern locks that were generated with the meter support, that number goes up to 48 guessing attempts, showing significant improvement in security. Our recommendation is to implement a strength meter in the next version of Android.
Youngbae Song, Geumhwan Cho, Seongyeol Oh, Hyoungshick Kim, Jun-Ho Huh
CHI5
2015 DIAMoND: Distributed Intrusion/Anomaly Monitoring for Nonparametric Detection
abstract
In this paper, we describe a fully nonparametric, scalable, distributed detection algorithm for intrusion/anomaly detection in networks. We discuss how this approach addresses a growing trend in distributed attacks while also providing solutions to problems commonly associated with distributed detection systems. We explore the impacts to detection performance from network topology, from the defined range of distributed communication for each node, and from involving only a small percent of total nodes in the network in the distributed detection communication. We evaluate our algorithm using a software-based testing implementation, and demonstrate up to 20% improvement in detection capability over parallel, isolated anomaly detectors for both stealthy port scans and DDoS attacks.
Maciej Korczynski, Ali Hamieh, Jun-Ho Huh, Henrik Holm, S. Raj Rajagopalan, Nina H. Fefferman
ICCCN3
2015 Visualizing Privacy Risks of Mobile Applications through a Privacy Meter
Jina Kang, Hyoungshick Kim, Yun-Gyung Cheong, Jun-Ho Huh
ISPEC4
2015 On the Memorability of System-generated PINs: Can Chunking Help?
Jun-Ho Huh, Hyoungshick Kim, Rakesh Bobba, Masooda N. Bashir, Konstantin Beznosov
SOUPS1
2014 Replacing Cryptographic Keys in AMI Mesh Networks with Small Latency
Incheol Shin, Jun-Ho Huh, Sinkyu Kim, Jung Taek Seo
Mob. Networks Appl.2
2013 An empirical study on the software integrity of virtual appliances: are you really getting what you paid for?
abstract
Virtual appliances (VAs) are ready-to-use virtual machine images that are configured for specific purposes. For example, a virtual machine image that contains all the software necessary to develop and host a JSP-based website is typically available as a "Java Web Starter" VA. Currently there are many VA repositories from which users can download VAs and instantiate them on Infrastructure-as-a-Service (IaaS) clouds, allowing them to quickly launch their services. This marketplace, however, lacks adequate mechanisms that allow users to a priori assess whether a specific VA is really configured with the software that it is expected to be configured with. This paper evaluates the integrity of software packages installed on real-world VAs, through the use of a software whitelist-based framework, and finds that indeed there is a lot of variance in the software integrity of packages across VAs. Analysis of 151 Amazon VAs using this framework shows that about 9% of real-world VAs have significant numbers of software packages that contain unknown files, making them potentially untrusted. Virus scanners flagged just half of the VAs in that 9% as malicious, demonstrating that virus scanning alone is not sufficient to help users select a trustable VA and that a priori software integrity assessment has a role to play.
Jun-Ho Huh, Mirko Montanari, Derek Dagit, Rakesh Bobba, Yoonjoo Choi, Roy H. Campbell
AsiaCCS1
2013 Towards SDN enabled network control delegation in clouds
abstract
In today's IaaS clouds users only get a logical view of the underlying network and have limited control. Delegating more control to end users would be beneficial but would also raise security concerns for the provider. Emerging Software Defined Networking (SDN) technologies have the capabilities to facilitate delegation of network controls and provide some level of network abstractions to end users. However, any delegation solution should try to balance the level of controls delegated to end users with the security constraints of the provider. In this paper, we propose a SDN-based framework to facilitate delegation of some network controls to end users, providing the means to monitor and configure their own slices of the underlying networks. Using two instantiations of this framework, we illustrate the tradeoffs between security and the level of network abstractions provided to end users.
Muhammad Salman Malik, Mirko Montanari, Jun-Ho Huh, Rakesh Bobba, Roy H. Campbell
DSN3
2013 Assessing software integrity of virtual appliances through software whitelists
Jun-Ho Huh, Mirko Montanari, Derek Dagit, Rakesh Bobba, Yoonjoo Choi, Roy H. Campbell
NDSS1
2012 A framework integrating attribute-based policies into role-based access control
abstract
Integrated role-based access control (RBAC) and attribute-based access control (ABAC) is emerging as a promising paradigm. This paper proposes a framework that uses attribute-based policies to create a more traditional RBAC model. RBAC has been widely used, but has weaknesses: it is labor-intensive and time-consuming to build a model instance, and a pure RBAC system lacks flexibility to efficiently adapt to changing users, objects, and security policies. Particularly, it is impractical to manually make (and maintain) user to role assignments and role to permission assignments in industrial context characterized by a large number of users and/or security objects. ABAC has features complimentary to RBAC, and merging RBAC and ABAC has become an important research topic. This paper proposes a new approach to integrating ABAC with RBAC, by modeling RBAC in two levels. The aboveground level is a standard RBAC model extended with "environment". This level retains the simplicity of RBAC, supporting RBAC model verification/review. The "underground" level is used to represent security knowledge in terms of attribute-based policies, which automatically create the simple RBAC model in the aboveground level. These attribute-based policies bring to RBAC the advantages of ABAC: they are easy to build and easy to adapt to changes. Using this framework, we tackle the problem of permission assignment for large scale applications. This model is motivated by the characteristics and requirements of industrial control systems, and reflects in part certain approaches and practices common in the industry.
Jingwei Huang 0002, David M. Nicol, Rakesh Bobba, Jun-Ho Huh
SACMAT4
2012 PIN selection policies: Are they really effective?
Hyoungshick Kim, Jun-Ho Huh
Comput. Secur.2
2011 Managing application whitelists in trusted distributed systems
Jun-Ho Huh, John Lyle, Cornelius Namiluko, Andrew P. Martin
Future Gener. Comput. Syst.1
2010 Hybrid spam filtering for mobile communication
Jiwon Yoon 0001, Hyoungshick Kim, Jun-Ho Huh
Comput. Secur.3
2009 Towards a Trustable Virtual Organisation
abstract
In many scientific disciplines, the models, data and methods used to produce results have significant commercial value. Researchers in these sectors are often unwilling to exploit the full potential of grid computing because there remains a `trust gap' between their security requirements and present solutions. We describe two trustable architectures, one applicable for a computational grid and the other for a data grid. Both allow the participants to verify the security configurations of others as well as report their own through a remote configuration management service. The grid jobs are dispatched to only those trustworthy, and guaranteed to run in protected execution environments. Furthermore, our trustworthy analysis server enables statistical analyses to be performed on sensitive raw data --- collected from multiple domains --- without disclosing it to anyone.
Jun-Ho Huh, Andrew P. Martin
ISPA1