EDBT 2026 Demo / reviewers in the wild / expert
Ki-Woong Park
dblp:64/4410
· DBLP profile ↗
30ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0002-3377-223XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 2 first-author · 2 since 2021Computer networks · 5 · 1 first-author · 3 since 2021Security and privacy · 5 · 2 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Databases, data management, data science and information retrieval · 3Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AIoT-Blockchain Security for Supply Chain Threats in IEC 61850 Substations Using Informer-Powered Reinforcement LearningabstractIEC 61850 substations enable fast-speed digital communication among intelligent electronic devices (IEDs) for power system automatic control, monitoring, and protection. Their remote configurability and interoperability, however, make them vulnerable to highly advanced cyberattacks, mainly supply chain attacks. While existing methods, such as intrusion detection systems (IDS) and machine learning (ML)-based anomaly detection, provide partial protection, they often lack resilience against evolving attacks and real-time mitigation capabilities. We present an artificial intelligence of things (AIoT) blockchain security framework that uses Informer-augmented proximal policy optimization (PPO) for adaptive cyber defense, along with Hyperledger Fabric, for tamper-proof and automated security enforcement. The novelty of the proposed framework over state-of-the-art research lies in its combination of anomaly detection, dynamic threat mitigation, and auditable policy execution. Our security tests demonstrate robustness against zero-day and synthetic adversarial attacks, while preserving privacy and integrity. Experimental findings demonstrate that Informer-PPO attains 98.4% detection accuracy and 35 ms response time, representing improvements of 3.6%, 5.0%, and 9.1% in accuracy and 32.7%, 51.4%, and 63.2% faster response time compared to Transformer-PPO, long short-term memory (LSTM)-PPO, and convolutional neural network (CNN)-PPO baselines, respectively. Blockchain-enabled policy enforcement is accomplished within 42–50 ms, facilitating scalable real-time protection for IEC 61850 substations. Lilia Tightiz, Lien Minh Dang, Ki-Woong Park |
IEEE Internet Things J. | 3 |
| 2025 | A Self-Synchronizing Cyber Deception Framework via Infrastructure as Code ReflectionabstractAs cyberattacks become more sophisticated, the us e of honeypots has emerged as an alternative to proactively collec t attackers' exploit strategies. However, conventional honeypots o ften lack realism and require much human effort to deploy and m aintain in modern IT infrastructures. This excessive cost in resou rces creates a major obstacle to their widespread use. To address these challenges, this paper proposes a self-synchronizing cyber d eception framework that upholds the declarative approach of I nfrastructure as Code (IaC), maintaining idempotency and consis tency while automatically generating a deceptive environment. O ur framework treats the target system's laC files as a blueprint to automatically generate and deploy a high-fidelity, “digital twin” deception environment. Our framework uses an automated pip eli ne to analyze the laC file, apply the predefined transformation ru les, and dynamically build new container images - replicating stru ctural elements while replacing the core application logic with a h oneypot. After deployment, the framework keeps the deceptive en vironment synchronized with the original system by automaticall y re-deploying the pipeline in response to any changes in the sour ce laC file, increasing fidelity and reducing management costs. T he implementation of this prototype successfully shows a reductio n in the manual effort required for deploying and maintaining de ception environments, presenting a scalable and sustainable fram ework for active defense. This provides a strong foundation for b uilding the next-generation defense mechanisms that can adapt to both evolving cyberattacks and changing infrastructure. Junyeong Park, Sayeon Kim, Woohyun Jang, Yeon-Jae Kim, Shinwoo Shim, Olmi Lee, Ki-Woong Park |
PRDC | 7 |
| 2025 | SafeAcc: A lightweight and accurate user identification scheme using location-identity learning for indoor Internet access
Mohsen Ali Alawami, Sang-Hoon Choi, Ki-Woong Park |
J. Netw. Comput. Appl. | 3 |
| 2024 | Poster: Clipped Quantization and Huffman Coding for Efficient Secure Transfer in Federated LearningabstractFederated Learning(FL) has become an emerging method that trains private data by distributed learning of shared parameter, however, it has high communication overhead and is still exposed to attack on the model parameters. To minimize the communication overhead of federated learning while preserving its accuracy and security, we considered a combination of techniques with gradient quantization, clipping, and Huffman coding. Our system produces reduced parameters through quantization and clipping, then encodes the parameters through Huffman coding, which further increases the compression ratio as well as security of the parameters to be transmitted. Preliminary results identify that the scheme can significantly reduce the amount of transferring while preserving accuracy and security. Seung-Ho Lim, Ki-Woong Park |
SEC | 3 |
| 2024 | BLEnD: A Benchmark for LLMs on Everyday Knowledge in Diverse Cultures and LanguagesabstractLarge language models (LLMs) often lack culture-specific everyday knowledge, especially across diverse regions and non-English languages. Existing benchmarks for evaluating LLMs' cultural sensitivities are usually limited to a single language or online sources like Wikipedia, which may not reflect the daily habits, customs, and lifestyles of different regions. That is, information about the food people eat for their birthday celebrations, spices they typically use, musical instruments youngsters play or the sports they practice in school is not always explicitly written online. To address this issue, we introduce BLEnD, a hand-crafted benchmark designed to evaluate LLMs' everyday knowledge across diverse cultures and languages. The benchmark comprises 52.6k question-answer pairs from 16 countries/regions, in 13 different languages, including low-resource ones such as Amharic, Assamese, Azerbaijani, Hausa, and Sundanese. We evaluate LLMs in two formats: short-answer questions, and multiple-choice questions. We show that LLMs perform better in cultures that are more present online, with a maximum 57.34% difference in GPT-4, the best-performing model, in the short-answer format.Furthermore, we find that LLMs perform better in their local languages for mid-to-high-resource languages. Interestingly, for languages deemed to be low-resource, LLMs provide better answers in English. We make our dataset publicly available at: https://github.com/nlee0212/BLEnD. Junho Myung, Nayeon Lee, Yi Zhou 0019, Jiho Jin, Rifki Afina Putri, Dimosthenis Antypas, Hsuvas Borkakoty, Eunsu Kim, Carla Pérez-Almendros, Abinew Ali Ayele, Víctor Gutiérrez-Basulto, Yazmín Ibáñez-García, Hwaran Lee, Shamsuddeen Hassan Muhammad, Ki-Woong Park, Anar Rzayev, Nina White, Seid Muhie Yimam, Mohammad Taher Pilehvar, Nedjma Ousidhoum, José Camacho-Collados, Alice Oh |
NeurIPS | 15 |
| 2023 | Pwnable-Sherpa: An interactive coaching system with a case study of pwnable challengesabstractTo improve their cybersecurity knowledge and skills, students participate in a competitive game called capture the flag (CTF). CTF is used as an educational tool to improve students’ cybersecurity competency by solving challenges. As system vulnerabilities are the leading cause of cyberattacks on critical systems , cybersecurity personnel with knowledge and skills to detect system vulnerabilities are increasingly in demand. In this context, the importance of challenges concerning system vulnerabilities, such as pwnable, is gradually increasing in CTF competitions. Unlike other CTF challenges, solving a pwnable challenge requires considerable knowledge and skill. However, traditional evaluation methods in CTF (i.e., pass or non-pass) provide limited feedback regarding knowledge and skill gaps. To investigate this issue, we analyzed the results of the CTF competitions held by our research team over the past three years (2017, 2018, and 2020). Our analysis revealed the necessity for a new evaluation system that can provide detailed feedback to students, while reducing the grading burden on educators. Thus, to provide detailed feedback, we propose a cybersecurity training platform, Pwnable-Sherpa, which sets three detailed evaluation points for a given pwnable challenge. In addition, we designed our training platform with a multi-container architecture and an LLVM dummy pass, thereby saving time by grading each detailed assessment simultaneously rather than sequentially. Sung-Kyung Kim, Eun-Tae Jang, Hanjin Park, Ki-Woong Park |
Comput. Secur. | 4 |
| 2022 | Cloud-BlackBox: Toward practical recording and tracking of VM swarms for multifaceted cloud inspection
Sang-Hoon Choi, Ki-Woong Park |
Future Gener. Comput. Syst. | 2 |
| 2022 | iContainer: Consecutive checkpointing with rapid resilience for immortal container-based servicesabstractContainer-based cloud services that can achieve scalability at a low cost by dividing a complex system into instances, functions, or applications are essential for the operation of mission-critical industrial systems. Mission assurance and survivability are required as core elements and unique functions for these services to be the basic environment of major systems. In particular, a mission-critical system operating environment must guarantee service resilience that can provide stable services even in a situation where it is impossible because of cyberattacks or service failures. To solve this problem, we propose iContainer, which stands for Immortal Container. It provides stable services by quickly returning to the point desired by a user when a failure occurs by continuously recording container services. If efficient checkpoints are available, the lifecycles of containers are recorded and services are rolled back to a previous point desired by a user when a critical event occurs. iContainer has three contributions. First, it minimizes checkpointing operations through checkpoint zoning. We remove unnecessary checkpointing operations through a semantic-aware hot/cold container classification scheme for zones where data changes rarely occur. Second, rapid checkpointing is achieved through dirty-page tracking. We minimize checkpoint data (read/write) operations by efficiently tracking the memory area. Consequently, iContainer reduces the checkpoint execution time by 3.27 times compared to the conventional checkpointing scheme, and the size of the data generated by repetitive checkpointing is reduced by 69.2%. Third, iContainer includes rapid checkpoint restoration and flexible restore points. We designed the software-defined checkpoint/restore (SDCR) tool, which enables the rapid restoration and flexible selection of checkpoints and restore points. Experimental results show that it takes 337 ms on average from the detection of a service failure until stable service operation. Thus, the rollback time of SDCR is approximately 1.93 times faster than the conventional checkpointing tool, checkpoint/restore in userspace (CRIU). The experiment was conducted in an environment where a web service was operated. Moreover, iContainer can be utilized for service error restoration and as data for identifying the causes of accidents in the event of an attack or security accident because it records the lifecycle of containers through checkpoints. Sang-Hoon Choi, Ki-Woong Park |
J. Netw. Comput. Appl. | 2 |
| 2020 | Suicidal Risk Detection for Military PersonnelabstractWe analyze social media for detecting the suicidal risk of military personnel, which is especially crucial for countries with compulsory military service such as the Republic of Korea.From a widely-used Korean social Q&A site, we collect posts containing military-relevant content written by active-duty military personnel.We then annotate the posts with two groups of experts: military experts and mental health experts.Our dataset includes 2,791 posts with 13,955 corresponding expert annotations of suicidal risk levels, and this dataset is available to researchers who consent to research ethics agreement.Using various finetuned state-of-the-art language models, we predict the level of suicide risk, reaching .88F1 score for classifying the risks. Ki-Woong Park, Jaimeen Ahn, Alice Oh |
EMNLP (1) | 2 |
| 2020 | Acoustic-decoy: Detection of adversarial examples through audio modification on speech recognition systemabstractDeep neural networks (DNNs) display good performance in the domains of recognition and prediction, such as on tasks of image recognition, speech recognition, video recognition, and pattern analysis. However, adversarial examples, created by inserting a small amount of noise into the original samples, can be a serious threat because they can cause misclassification by the DNN. Adversarial examples have been studied primarily in the context of images, but their effect in the audio context is now drawing considerable interest as well. For example, by adding a small distortion to an original audio sample, imperceptible to humans, an audio adversarial example can be created that humans hear as error-free but that causes misunderstanding by a machine. Therefore, it is necessary to create a method of defense for resisting audio adversarial examples. In this paper, we propose an acoustic-decoy method for detecting audio adversarial examples. Its key feature is that it adds well-formalized distortions using audio modification that are sufficient to change the classification result of an adversarial example but do not affect the classification result of an original sample. Experimental results show that the proposed scheme can detect adversarial examples by reducing the similarity rate for an adversarial example to 6.21%, 1.27%, and 0.66% using low-pass filtering (with 12 dB roll-off), 8-bit reduction, and audio silence removal techniques, respectively. It can detect an audio adversarial example with a success rate of 97% by performing a comparison with the initial audio sample. Hyun Kwon, Hyunsoo Yoon, Ki-Woong Park |
Neurocomputing | 3 |
| 2020 | Compatible byte-addressable direct I/O for peripheral memory devices in Linux
Sung Hoon Baek, Ki-Woong Park |
Inf. Syst. | 2 |
| 2019 | POSTER: Detecting Audio Adversarial Example through Audio ModificationabstractDeep neural networks (DNNs) perform well in the fields of image recognition, speech recognition, pattern analysis, and intrusion detection. However, DNNs are vulnerable to adversarial examples that add a small amount of noise to the original samples. These adversarial examples have mainly been studied in the field of images, but their effect on the audio field is currently of great interest. For example, adding small distortion that is difficult to identify by humans to the original sample can create audio adversarial examples that allow humans to hear without errors, but only to misunderstand the machine. Therefore, a defense method against audio adversarial examples is needed because it is a threat in this audio field. In this paper, we propose a method to detect audio adversarial examples. The key point of this method is to add a new low level distortion using audio modification, so that the classification result of the adversarial example changes sensitively. On the other hand, the original sample has little change in the classification result for low level distortion. Using this feature, we propose a method to detect audio adversarial examples. To verify the proposed method, we used the Mozilla Common Voice dataset and the DeepSpeech model as the target model. Based on the experimental results, it was found that the accuracy of the adversarial example decreased to 6.21% at approximately 12 dB. It can detect the audio adversarial example compared to the initial audio sample. Hyun Kwon, Hyunsoo Yoon, Ki-Woong Park |
CCS | 3 |
| 2019 | UAV-Undertaker: Securely Verifiable Remote Erasure Scheme with a Countdown-Concept for UAV via Randomized Data SynchronizationabstractUnmanned aerial vehicles (UAVs) play an increasingly core role in modern warfare, with powerful but tiny embedded computing systems actively applied in the military field. Confidential data, such as military secrets, may be stored inside military devices such as UAVs, and the capture or loss of such data could cause significant damage to national security. Therefore, the development of securely verifiable remote erasure techniques for military devices is considered a core technology. In this study, we devised a verifiable remote erasure scheme with a countdown-concept using randomized data synchronization to satisfy securely verifiable remote erasure technology. The scheme allows the GCS (Ground Control Station) to remotely erase data stored in the UAV, even on loss of communication, and returns proof of erasure to GCS after erasure. Our approach classifies the accumulated data stored in the UAV as a new data type and applies the characteristics of that data type to generate the proof of erasure. We select a small-volume data sample (rather than all of the data) and perform prior learning only on that sample; in this way, we can obtain the probative power of the evidence of erasure with a relatively small amount of traffic. When we want to erase data of 100 Mbytes of remote device, 100 Mbytes of data transfer is required for related work, whereas our system has data transfer according to the ratio of amount of randomly selected data. By doing this, communication stability can be acquired even in unstable communication situations where the maximum traffic can change or not be predicted. Furthermore, when the UAV sends the proof of erasure to the GCS, the UAV does its best to perform the erasure operation given its situation. Taek-Young Youn, Daeseon Choi, Ki-Woong Park |
Wirel. Commun. Mob. Comput. | 4 |
| 2018 | Friend-safe evasion attack: An adversarial example that is correctly recognized by a friendly classifier
Hyun Kwon, Yongchul Kim, Ki-Woong Park, Hyunsoo Yoon, Daeseon Choi |
Comput. Secur. | 3 |
| 2016 | A fully persistent and consistent read/write cache using flash-based general SSDs for desktop workloads
Sung Hoon Baek, Ki-Woong Park |
Inf. Syst. | 2 |
| 2015 | Malfinder: Accelerated Malware Classification System through Filtering on Manycore SystemabstractControl flow matching methods have been utilized to detect malware variants. However, as the number of malware variants has soared, it has become harder and harder to detect all malware variants while maintaining high accuracy. Even though many researchers have proposed control flow matching methods, there is still a trade-off between accuracy and performance. To solve this trade-off, we designed Malfinder, a method based on approximate matching, which is accurate but slow. To overcome its low performance, we resolve its performance bottleneck and non-parallelism on three fronts: I-Filter for identical string matching, table division to exclude unnecessary comparisons with some malware and dynamic resource allocation for efficient parallelism. Our performance evaluation shows that the total performance improvement is 280.9 times. Taegyu Kim, Woomin Hwang, Chulmin Kim, Dong-Jae Shin, Ki-Woong Park, Kyu Ho Park 0002 |
ICISSP | 5 |
| 2015 | Parity Resynchronization using a Block-level Journaling for Software RAID
Sung Hoon Baek, Ki-Woong Park |
Inf. Syst. | 2 |
| 2015 | Reference Pattern-Aware Instant Memory Balancing for Consolidated Virtual Machineson ManycoresabstractMemory contention among consolidated VMs on the same hardware has created the need for repetitive memory balancing operations. In an attempt to provide a prompt memory balancing mechanism, we found problems with the retardation of memory reallocation by the reclamation delay. The scheduling of the VMs and their VCPUs generates the delay, the dirtiness of the candidate pages for balancing makes the delay fluctuated, and a conflict of two reclamation policies between the guest OS and the hypervisor deteriorates the application performance. As a remedy to these problems, we propose HyperDealer2 (HD2), which selects the victim pages based on the reference patterns of clean pages, reclaims them with hypervisor-level paging, and reallocates those pages with explicit ballooning of the recipient guest OS. HD2 eliminates the involvement of victim VMs in memory reclamation and extends the dwell time of reclaimed pages in the reclaimed state. Consequently, HD2 significantly reduces the time taken to reallocate memory with a low overhead and enhances the value of additional memory for the recipient VMs. The experimental results of HD2 show that the execution time of memory-intensive applications in the recipient VM is reduced by up to 50 percent in spite of less than 2 percent performance penalty. Woomin Hwang, Ki-Woong Park, Kyu Ho Park 0002 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2014 | Adaptive wear-leveling algorithm for PRAM main memory with a DRAM bufferabstractPhase Change RAM (PRAM) is a candidate to replace DRAM main memory due to its low idle power consumption and high scalability. However, its latency and endurance have generated problems in fulfilling its main memory role. The latency can be treated with a DRAM buffer, but the endurance problem remains, with three critical points that need to be improved despite the use of, existing wear-leveling algorithms. First, existing DRAM buffering schemes do not consider write count distribution. Second, swapping and shifting operations are performed statically. Finally, swapping and shifting operations are loosely coupled with a DRAM buffer. As a remedy to these drawbacks, we propose an adaptive wear-leveling algorithm that consists of three novel schemes for PRAM main memory with a DRAM buffer. The PRAM-aware DRAM buffering scheme reduces the write count and prevents skewed writing by considering the write count and clean data based on the least recently used (LRU) scheme. The adaptive multiple swapping and shifting scheme makes the write count even with the dynamic operation timing, the number of swapping pages being based on the workload pattern. Our DRAM buffer-aware swapping and shifting scheme reduces overhead by curbing additional swapping and shifting operations, thus reducing unnecessary write operations. To evaluate the wear-leveling effect, we have implemented a PIN-based wear-leveling simulator. The evaluation confirms that the PRAM lifetime increases from 0.68 years with the previous wear-leveling algorithm to 5.32 years with the adaptive wear-leveling algorithm. Sung Kyu Park, Min Kyu Maeng, Ki-Woong Park, Kyu Ho Park 0002 |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2013 | THEMIS: A Mutually Verifiable Billing System for the Cloud Computing EnvironmentabstractWith the widespread adoption of cloud computing, the ability to record and account for the usage of cloud resources in a credible and verifiable way has become critical for cloud service providers and users alike. The success of such a billing system depends on several factors: The billing transactions must have integrity and nonrepudiation capabilities; the billing transactions must be nonobstructive and have a minimal computation cost; and the service level agreement (SLA) monitoring should be provided in a trusted manner. Existing billing systems are limited in terms of security capabilities or computational overhead. In this paper, we propose a secure and nonobstructive billing system called THEMIS as a remedy for these limitations. The system uses a novel concept of a cloud notary authority for the supervision of billing. The cloud notary authority generates mutually verifiable binding information that can be used to resolve future disputes between a user and a cloud service provider in a computationally efficient way. Furthermore, to provide a forgery-resistive SLA monitoring mechanism, we devised a SLA monitoring module enhanced with a trusted platform module (TPM), called S-Mon. The performance evaluation confirms that the overall latency of THEMIS billing transactions (avg. 4.89 ms) is much shorter than the latency of public key infrastructure (PKI)-based billing transactions (avg. 82.51 ms), though THEMIS guarantees identical security features as a PKI. This work has been undertaken on a real cloud computing service called iCubeCloud. Ki-Woong Park, Jaesun Han, JaeWoong Chung, Kyu Ho Park 0002 |
IEEE Trans. Serv. Comput. | 1 |
| 2012 | OPAMP: Evaluation Framework for Optimal Page Allocation of Hybrid Main Memory ArchitectureabstractMain memory as a hybrid between DRAM and nonvolatile memory is rapidly considered as a basic building block of computing systems. Despite widely-performed researches no one can confirm whether hybrid memory is at its full performance in terms of energy consumption, time delay or both. The main problem is that evaluating their performance in comparison with the optimal performance is challenging since deriving the optimal value is NP-complete. In this paper, we design and implement an evaluation framework termed OPAMP, which calculates optimal performance of the hybrid memory environment. This system gathers workload, specification of DRAM and PRAM, and environmental parameters of the hybrid main memory. After that, it calculates the maximum performance under the corresponding conditions. We suggest the way of deriving the optimal value by profiling instead of page migration which is the mainstream of recent researches on hybrid main memory system. Also, proportion of DRAM's size to PRAM's and proportion of DRAM's usage space to PRAM's are impactive factors. While designing hybrid main memory, those two variables must be determined carefully and OPAMP gives the guideline to the researchers. Jong Hun Choi, Seong-Min Kim, Chulmin Kim, Ki-Woong Park, Kyu Ho Park 0002 |
ICPADS | 4 |
| 2012 | Resource Management of Manycores with a Hierarchical and a Hybrid Main Memory for MN-MATE Cloud NodeabstractThe advent of manycore in computing architecture causes severe energy consumption and memory wall problem. Emerging technologies such as on-chip DRAM and nonvolatile memory (NVRAM) receive attention as promising solutions for them. Nonvolatile memory is a viable DRAM replacement, achieving competitive performance at lower power consumption. On-chip DRAM extends the memory bandwidth. The confluence of these trends offers a new opportunity to rethink traditional computing system and memory hierarchies. In an attempt to mitigate the energy and memory wall, we propose MN-MATE, a novel architecture and management techniques for resource allocation of a number of cores, onchip DRAM, and large size of off-chip DRAM and NVRAM. In MN-MATE, each guest OS utilizes cores and various memories allocated by the hypervisor. Based on the knowledge about the allocated resources, a guest OS co-schedules tasks accessing different types of memory with complementary access intensity. Memory management system of the OS utilizes on-chip DRAM as a part of main memory having low latency. It also selects proper location of data from the three types of memory based on the data's access characteristics. Preliminary experimental results show that these techniques with the new architecture improve system performance and reduce energy consumption. Kyu Ho Park 0002, Sung Kyu Park, Woomin Hwang, Hyunchul Seok, Dong-Jae Shin, Ki-Woong Park |
SERVICES | 6 |
| 2011 | MN-GEMS: A Timing-Aware Simulator for a Cloud Node with Manycore, DRAM, and Non-volatile MemoriesabstractIn this paper, we describe a part of our on-going research project aimed at the management of many core and Hybrid Main Memory with DRAM and Non-Volatile RAMs (NVRAMs).By the needs of simulation and through investigation of the requirements for the target management system, we found that the simulation platform requires support for many core, a timing-aware simulation of hybrid memory with DRAM and NVRAM, and a Performance Monitoring Unit (PMU).Therefore, we built MN-GEMS, a full-system simulator for the consolidated VMs of a cloud node satisfying all these requirements. Woomin Hwang, Ki-Woong Park, Kyu Ho Park 0002 |
IEEE CLOUD | 2 |
| 2011 | ACCENT: Cognitive cryptography plugged compression for SSL/TLS-based cloud computing servicesabstractEmerging cloud services, including mobile offices, Web-based storage services, and content delivery services, run diverse workloads under various device platforms, networks, and cloud service providers. They have been realized on top of SSL/TLS, which is the de facto protocol for end-to-end secure communication over the Internet. In an attempt to achieve a cognitive SSL/TLS with heterogeneous environments (device, network, and cloud) and workload awareness, we thoroughly analyze SSL/TLS-based data communication and identify three critical mismatches in a conventional SSL/TLS-based data transmission. The first mismatch is the performance of loosely coupled encryption-compression and communication routines that lead to underutilized computation and communication resources. The second mismatch is that the conventional SSL/TLS only provides a static compression mode, irrespective of the dynamically changing status of each SSL/TLS connection and the computing power gap between the cloud service provider and diverse device platforms. The third is the memory allocation overhead due to frequent compression switching in the SSL/TLS. As a remedy to these rudimentary operations, we present a system called an Adaptive Cryptography Plugged Compression Network (ACCENT) for SSL/TLS-based cloud services. It is comprised of the following three novel mechanisms, each of which aims to provide an optimal SSL/TLS communication and maximize the network transfer performance of an SSL/TLS protocol stack: tightly-coupled threaded SSL/TLS coding, floating scale-based adaptive compression negotiation, and unified memory allocation for seamless compression switching. We implemented and tested the mechanisms in OpenSSL-1.0.0. ACCENT is integrated into the Web-interface layer and SSL/TLS-based secure storage service within a real cloud computing service, called iCubeCloud , as the key primitive for SSL/TLS-based data delivery over the Internet. Ki-Woong Park, Kyu Ho Park 0002 |
ACM Trans. Internet Techn. | 1 |
| 2010 | HyperDealer: Reference-Pattern-Aware Instant Memory Balancing for Consolidated Virtual MachinesabstractMemory contention among consolidated virtual machines (VMs) creates the need for a memory balancing operation. In an attempt to provide a prompt memory balancing mechanism, we found problems with the retardation of memory transfer by the reclamation delay. The scheduling of the VMs generates the delay, and a conflicts of two reclamation policies between the guest OS and the hypervisor deteriorates it. As a remedy to these problems, we propose HyperDealer, which selects the victim page by applying reference patterns, reclaims the pages with hypervisor-level paging, and transfers those pages with ballooning of the guest OS. Our scheme eliminates the involvement of the victim VM in memory balancing and extends the dwell time of reclaimed pages in the reclaimed state. Consequently, HyperDealer significantly reduces the time taken to transfer memory with a low overhead and enhances the value of additional memory for the recipient VM. The experimental results of our scheme show that the application performance in the recipient VM is 11% more time-efficient and has a penalty which is 50% less than previous approaches. Woomin Hwang, Yangwoo Roh, Youngwoo Park, Ki-Woong Park, Kyu Ho Park 0002 |
IEEE CLOUD | 4 |
| 2010 | THEMIS: Towards Mutually Verifiable Billing Transactions in the Cloud Computing EnvironmentabstractThe ability to record and keep account of the usage of cloud resources in a credible and verifiable way is a precursor to widespread cloud deployment and availability because usage information is potentially sensitive and must be verifiably accurate. In an attempt to provide a mutually verifiable resource usage and billing mechanism, we found that the frequent asymmetric key operations of a digital signature lead to excessive computations and a bottleneck of billing transactions. As a remedy for these limitations, we propose a mutually verifiable billing system called THEMIS. The system, which introduces the concept of a cloud notary authority for the supervision of billing, makes billing more objective and acceptable to users and cloud service providers. THEMIS generates mutually verifiable binding information that can be used to resolve future disputes between a user and a cloud service provider. Because THEMIS does not require any asymmetric key operations of users and providers, it provides a level of security that is identical to that of a Public Key Infrastructure (PKI) and it minimizes the latency of billing transactions. This work has been undertaken on a real cloud computing service called iCube Cloud. Ki-Woong Park, Sung Kyu Park, Jaesun Han, Kyu Ho Park 0002 |
IEEE CLOUD | 1 |
| 2010 | MN-Mate: Resource Management of Manycores with DRAM and Nonvolatile MemoriesabstractThe advent of many core era breaks the performance wall but it causes severe energy consumption. NVRAM as a main memory can be a good solution to reduce energy consumption due to large size of DRAM. In this paper, we propose MN-MATE, a novel architecture and management techniques for resource allocation of a number of cores and large size of DRAM and NVRAM. In MN-MATE, a hyper visor partitions and allocates cores and memory for guest OSes dynamically. It is clear that optimized matching of heterogeneous cores, DRAM, and NVRAM enhances system performance. Selective locating of data in a main memory composed of DRAM and NVRAM significantly reduces energy consumptions. Preliminary results show that integration of dynamic resource partitioning and selective memory allocation scheme with MN-MATE reduces energy usage significantly and suppresses performance loss from NVRAM's characteristics. Kyu Ho Park 0002, Youngwoo Park, Woomin Hwang, Ki-Woong Park |
HPCC | 4 |
| 2010 | BLAST: Applying Streaming Ciphers Into Outsourced Cloud StorageabstractProviding secure and efficient outsourced storage is a precursor to widespread cloud deployment and availability. For this purpose, existing designs mainly rely on block ciphers, although stream ciphers are more computationally-efficient than block ciphers. This paper presents a construction of secure storage, BLAST, enhanced with a stream cipher rather than a block cipher with a novel block accessible encryption mechanism based on streaming ciphers. In BLAST, a hierarchical tree generated in the form of an n-level quad tree is created for each user during the registration phase of the storage system. When a user wants to access the outsourced storage, the user can access their data after encrypting or decrypting it using a sequence of key stream frames derived from the hierarchical tree. The experimental results show that the proposed system achieves significant improved performance than normal streaming/block cipher-based secure storage system in terms of throughput and access latency. Ki-Woong Park, Chulmin Kim, Kyu Ho Park 0002 |
ICPADS | 1 |
| 2009 | An intuitive data transfer technique using bartender's gesturesabstractThis technical demonstration presents Cocktail, a gesture-based mobile interaction system, which is designed for providing a user-friendly way of exchanging multimedia data with intuitive gestures. Our system is motivated by bartenders who make cocktails with interesting gestures, such as pouring and shaking. These gestures are used in our interaction system for data transfer and contents creation: a user can pour (transfer) data in his/her mobile phone to other devices in the same way that a bartender pours drinks to a shaker. The user can also mix music files and pictures into a multimedia content, such as a music video file, by shaking the mobile phone, as a bartender does to mix different drinks into a cocktail. We have implemented a prototype of Cocktail using smart phones and demonstrate its usability. Jong-Woon Yoo, Woong Ho Choi, Ki-Woong Park, Kyu Ho Park 0002 |
ACM Multimedia | 3 |
| 2008 | Computationally Efficient PKI-Based Single Sign-On Protocol, PKASSO for Mobile DevicesabstractIn an attempt to expand Public Key Infrastructure (PKI) usage to a ubiquitous and mobile computing environment, we found that the deployment of the PKI on a resource-constrained device such as an 8-bit microprocessor leads to user-obstructive latency or additional circuitry for the operations. To alleviate these limitations, we propose a new PKI-based authentication protocol and security infrastructure, namely, PKASSO, which is enhanced with the single sign-on and delegation technology that is used especially for mobile devices with restricted computation power. PKASSO offloads complex PKI operations from the mobile devices to the infrastructure so as to keep the hardware and software complexity of the devices as low as possible. In addition, even though a conventional delegation mechanism cannot support a nonrepudiation mechanism against malicious user behavior, PKASSO can provide such a mechanism by devising a referee server that, on one hand, generates binding information between a device and authentication messages and, on the other hand, retains the information in its local storage for future accusation. We present the detailed design and performance evaluation of PKASSO and offer a protocol analysis in terms of user authentication latency and the completeness of the protocol. According to the performance evaluation, the authentication latency of our infrastructure (which averages 0.082 second) is much shorter than the authentication latency of a conventional PKI-based authentication latency (which averages 5.01 seconds). Ki-Woong Park, Sang Seok Lim, Kyu Ho Park 0002 |
IEEE Trans. Computers | 1 |