Jeonil Kang

dblp:74/5173 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
0since 2021 · last 2020
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 4 · 2 first-authorComputer networks · 2Systems, architecture and hardware · 1Security and privacy · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Network security · 67% Authentication and access control · 14% Usable security · 14%
Computer networks
1 paper
Wireless networking · 100%

Topics — the 5 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › attack strategy
man-in-the-middle attack
0.412020
Catch Me If You Can: Rogue Access Point Detection Using Intentional Channel Interference · IEEE Trans. Mob. Comput. 2020
Network security › wireless network security
rogue access point detection
0.412020
Catch Me If You Can: Rogue Access Point Detection Using Intentional Channel Interference · IEEE Trans. Mob. Comput. 2020
Authentication and access control › knowledge-based authentication
graphical password
0.212014
Keylogging-Resistant Visual Authentication Protocols · IEEE Trans. Mob. Comput. 2014
Usable security
security-usability tradeoff
0.212014
Keylogging-Resistant Visual Authentication Protocols · IEEE Trans. Mob. Comput. 2014
Wireless networking
WLAN
0.112020
Catch Me If You Can: Rogue Access Point Detection Using Intentional Channel Interference · IEEE Trans. Mob. Comput. 2020

Methods — techniques the papers use, named apart from their topics

intentional channel interference · 0.9experimental evaluation · 0.9user study · 0.2prototype · 0.2
YearPublicationVenuePosition
2020 Catch Me If You Can: Rogue Access Point Detection Using Intentional Channel Interference
abstract
In this paper, we introduce a powerful hardware-based rogue access point (PrAP), which can relay back and forth traffic between a legitimate AP and a wireless station, and act as a man-in-the-middle attacker. Our PrAP is built of two dedicated wireless routers interconnected physically, and can relay traffic rapidly between a station and a legitimate AP. Through experiments, we demonstrate that the state-of-the-art time-based rogue AP (rAP) detectors cannot detect our PrAP, although perhaps effective against software-based rAP. In demonstrating that, we unveil new insight into fundamentals of time-based detectors for software-based rAPs and their operation: such techniques are only capable of detecting rAPs due to the speed of wireless AP bridging. To address the threat of such PrAPs, we propose a new tool for network administrators, a PrAP-Hunter based on intentional channel interference. Our PrAP-Hunter is highly accurate, even under heavy traffic scenarios. Using a high-performance (desktop) and low-performance (mobile phone) experimental setups of our PrAP-Hunter in various deployment scenarios, we demonstrate close to 100 percent of detection rate, compared to 60 percent detection rate by the state-of-the-art. We show that our PrAP-Hunter is fast (takes 5-10 seconds), does not require any prior knowledge, and can be deployed in the wild by real-world experiments at 10 coffee shops.
RhongHo Jang, Jeonil Kang, David Mohaisen, DaeHun Nyang
IEEE Trans. Mob. Comput.2
2018 Digitalseal: a Transaction Authentication Tool for Online and Offline Transactions
abstract
We introduce DigitalSeal, a transaction authentication tool that works in both online and offline use scenarios. Digi-talSeal is a digital scanner that reads transaction information sent by an issuing entity of the DigitalSeal reader for authentication, and the information is encoded using a specially crafted bar-code. DigitalSeal views various pieces of transaction information for users to verify and proceed with transaction authentication. DigitalSeal is generic, and is capable of reading information viewed on paper, computer monitors (similarly, kiosk monitors), and mobile phones. A prototype of DigitalSeal is built using a Arduino UNO, four LLS05-A sensors, four TCRT5000 sensors, a 1602 LCD and a 9V battery.
Changhun Jung, Jeonil Kang, David Mohaisen, DaeHun Nyang
ICASSP2
2017 Rogue Access Point Detector Using Characteristics of Channel Overlapping in 802.11n
abstract
In this work, we introduce a powerful hardware-based rogue access point (PrAP), which can relay traffic between a legitimate AP and a wireless station back and forth, and act as a man-in-the-middle attacker. Our PrAP is built of two dedicated wireless routers interconnected physically, and can relay traffic rapidly between a station and a legitimate AP. Through extensive experiments, we demonstrate that the state-of-the-art time-based rogue AP (rAP) detectors cannot detect our PrAP, although effective against software-based rAP. To defend against PrAPs, we propose PrAP-Hunter based on intentional channel interference. PrAP-Hunter is highly accurate, even under heavy traffic scenarios. Using a high-performance (desktop) and low-performance (mobile) experimental setups of our PrAP-Hunter in various deployment scenarios, we demonstrate close to 100% of detection rate, compared to 60% detection rate by the state-of-the-art. We show that PrAP-Hunter is fast (takes 5-10 sec), does not require any prior knowledge, and can be deployed in the wild by real world experiments at 10 coffee shops.
RhongHo Jang, Jeonil Kang, David Mohaisen, DaeHun Nyang
ICDCS2
2017 Highly-accurate rogue access point detection using intentional channel interference: poster
abstract
In this work, we introduce a powerful hardware-based rogue access point (PrAP), which can relay traffic between a legitimate AP and a wireless station, and act as a man-in-the-middle attacker. To defend against PrAPs, we propose PrAP-Hunter based on intentional channel interference. We demonstrate close to 100% of detection rate, compared to 60% detection rate by the state-of-the-art.
RhongHo Jang, Jeonil Kang, David Mohaisen, DaeHun Nyang
WISEC2
2017 A Privacy-Preserving Mobile Payment System for Mass Transit
abstract
In the near future, mobile payment systems based on smartphones are expected to be widely applied in various environments, including transit services. When passengers use mass transit, their private information, such as their identity and route, may be made available to some related organizations, such as transit agencies, financial institutions, mobile carriers, and providers of smart cards, among others, even when the passengers may not want their information to be revealed. To protect passenger privacy, this paper proposes a privacy-preserving transit payment system based on traceable signatures, identity-based signatures, and anonymous signatures. In addition to passenger privacy, the proposed system facilitates the proactive blocking of misbehaving passengers, free-transfer services (or transfer discount), and postpaid programs. We demonstrate that the performance of this system is good enough for immediate deployment based on various experiments.
Jeonil Kang, DaeHun Nyang
IEEE Trans. Intell. Transp. Syst.1
2014 Two-factor face authentication using matrix permutation transformation and a user password
Jeonil Kang, DaeHun Nyang, KyungHee Lee
Inf. Sci.1
2014 Keylogging-Resistant Visual Authentication Protocols
abstract
The design of secure authentication protocols is quite challenging, considering that various kinds of root kits reside in Personal Computers (PCs) to observe user's behavior and to make PCs untrusted devices. Involving human in authentication protocols, while promising, is not easy because of their limited capability of computation and memorization. Therefore, relying on users to enhance security necessarily degrades the usability. On the other hand, relaxing assumptions and rigorous security design to improve the user experience can lead to security breaches that can harm the users' trust. In this paper, we demonstrate how careful visualization design can enhance not only the security but also the usability of authentication. To that end, we propose two visual authentication protocols: one is a one-time-password protocol, and the other is a password-based authentication protocol. Through rigorous analysis, we verify that our protocols are immune to many of the challenging authentication attacks applicable in the literature. Furthermore, using an extensive case study on a prototype of our protocols, we highlight the potential of our approach for real-world deployment: we were able to achieve a high level of usability while satisfying stringent security requirements.
DaeHun Nyang, David Mohaisen, Jeonil Kang
IEEE Trans. Mob. Comput.3
2008 Protection Techniques of Secret Information in Non-tamper Proof Devices of Smart Home Network
David Mohaisen, YoungJae Maeng, Jeonil Kang, DaeHun Nyang, KyungHee Lee, Dowon Hong, Jong Wook Han
UIC3
2007 Proactive Code Verification Protocol in Wireless Sensor Network
Young-Geun Choi, Jeonil Kang, DaeHun Nyang
ICCSA (2)2
2007 Certificate Issuing Using Proxy and Threshold Signatures in Self-initialized Ad Hoc Network
Jeonil Kang, DaeHun Nyang, David Mohaisen, Young-Geun Choi, KoonSoon Kim
ICCSA (3)1
2006 Distributed Certificate Authority Under the GRID-Location Aided Routing Protocol
Jihyung Lim, DaeHun Nyang, Jeonil Kang, KyungHee Lee, Hyotaek Lim
ICCSA (4)3