EDBT 2026 Demo / reviewers in the wild / expert
Seungwon Shin 0001
dblp:84/3319-1
· DBLP profile ↗
96ranked-venue papers
12as first author
47since 2021 · last 2026
0000-0002-1077-5606ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 47 · 7 first-author · 23 since 2021Computer networks · 31 · 5 first-author · 11 since 2021Systems, architecture and hardware · 10 · 7 since 2021Artificial intelligence and machine learning · 6 · 6 since 2021Databases, data management, data science and information retrieval · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RDNet: An RDMA-aware Container Network Interface for Cloud Environments
Myoungsung You, Minjae Seo, Seungwon Shin 0001, Jaehyun Nam |
INFOCOM | 3 |
| 2026 | HybridMesh: A Hardware-software Hybrid Approach for Accelerating Service Mesh Ingress
Myoungsung You, Jaehyun Nam, Minjae Seo, Taejune Park, Seungwon Shin 0001 |
NSDI | 5 |
| 2026 | BeaCon: Automatic container policy generation using environment-aware dynamic analysis
Haney Kang, Eduard Marin, Myoungsung You, Diego Perino, Seungwon Shin 0001, Jinwoo Kim 0006 |
Comput. Secur. | 5 |
| 2026 | SecTracer: A framework for uncovering the root causes of network intrusions via security provenance
Hyunmin Seo, Hwanjo Heo, Anduo Wang, Seungwon Shin 0001, Jinwoo Kim 0006 |
Comput. Secur. | 5 |
| 2026 | PassREfinder-FL: Privacy-preserving credential stuffing risk prediction via graph-based federated learning for representing password reuse between websites
Jaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin, Seungwon Shin 0001, Jinwoo Kim 0006 |
Expert Syst. Appl. | 5 |
| 2026 | AccelFaaS: Accelerating FaaS via Pre-Warmed Memory and Control Channel Offloading
Seong-Joong Kim, Seungwon Shin 0001, Myoungsung You |
IEEE Trans. Cloud Comput. | 2 |
| 2025 | MOEVIL: Poisoning Experts to Compromise the Safety of Mixture-of-Experts LLMsabstractMixture-of-Experts (MoE) has emerged as a prominent architecture for scaling large language models (LLMs). In particular, leveraging readily available fine-tuned LLMs as experts provides an efficient and flexible approach to developing MoE LLMs. However, integrating highly capable but untrustworthy LLMs into an MoE system poses a significant safety risk, potentially compromising the overall safety of the MoE LLM system. To date, no study has explored how adversaries compromise an MoE LLM service by introducing a poisoned expert LLM. In this paper, we introduce MOEVIL, a novel expert poisoning attack designed to compromise the safety of MoE LLMs. We address the dissipation of harmful effects from a target expert within MoE systems by conducting harmful preference learning. Next, we strategically manipulate this expert's latent vector to deceive the gating networks. This manipulation indirectly steers routing decisions toward the poisoned expert when generating responses to harmful queries. MOEVIL demonstrates strong attack performance across diverse MoE configurations based on both Llama and Qwen LLMs, even when poisoning only a single expert. MOEVIL increases the harmfulness score from 0.58 to 79.42 in a Llama-based MoE LLM, outperforming existing harmful poisoning attacks. Furthermore, our results demonstrate that even safety alignment, when combined with an efficient MoE training strategy, fails to fully mitigate these risks. Our findings demonstrate the significant threat posed by harmful experts in MoE systems, underscoring the need for robust safety measures in MoE-based LLM development. Our implementation is available at https://github.com/jaehanwork/MoEvil. Jaehan Kim, Seung Ho Na, Minkyoo Song, Seungwon Shin 0001, Sooel Son |
ACSAC | 4 |
| 2025 | AVXProbe: Enhancing Website Fingerprinting with Side-Channel-Assisted Kernel-Level Traces
Suryeon Kim, Seung Ho Na, Jaehan Kim, Seungwon Shin 0001, Hyunwoo Choi |
AsiaCCS | 4 |
| 2025 | Improbable Bigrams Expose Vulnerabilities of Incomplete Tokens in Byte-Level TokenizersabstractTokenization is a crucial step that bridges human-readable text with model-readable discrete tokens.However, recent studies have revealed that tokenizers can be exploited to elicit unwanted model behaviors.In this work, we investigate incomplete tokens, i.e., undecodable tokens with stray bytes resulting from bytelevel byte-pair encoding (BPE) tokenization.We hypothesize that such tokens are heavily reliant on their adjacent tokens and are fragile when paired with unfamiliar tokens.To demonstrate this vulnerability, we introduce improbable bigrams: out-of-distribution combinations of incomplete tokens designed to exploit their dependency.Our experiments show that improbable bigrams are significantly prone to hallucinatory behaviors.Surprisingly, the same phrases have drastically lower rates of hallucination (90% reduction in Llama3.1)when an alternative tokenization is used.We caution against the potential vulnerabilities introduced by byte-level BPE tokenizers, which may introduce blind spots to language models. Eugene Jang, Kimin Lee, Jin-Woo Chung, Keuntae Park, Seungwon Shin 0001 |
EMNLP | 5 |
| 2025 | MUFFLER: Secure Tor Traffic Obfuscation with Dynamic Connection Shuffling and SplittingabstractTor, a widely utilized privacy network, enables anonymous communication but is vulnerable to flow correlation attacks that deanonymize users by correlating traffic patterns from Tor's ingress and egress segments. Various defenses have been developed to mitigate these attacks; however, they have two critical limitations: (i) significant network overhead during obfuscation and (ii) a lack of dynamic obfuscation for egress segments, exposing traffic patterns to adversaries. In response, we introduce MUFFLER, a novel connection-level traffic obfuscation system designed to secure Tor egress traffic. It dynamically maps real connections to a distinct set of virtual connections between the final Tor nodes and targeted services, either public or hidden. This approach creates egress traffic patterns fundamentally different from those at ingress segments without adding intentional padding bytes or timing delays. The mapping of real and virtual connections is adjusted in real-time based on ongoing network conditions, thwarting adversaries' efforts to detect egress traffic patterns. Extensive evaluations show that MUFFLER mitigates powerful correlation attacks with a TPR of 1% at an FPR of 10−2while imposing only a 2.17% bandwidth overhead. Moreover, it achieves up to 27x lower latency overhead than existing solutions and seamlessly integrates with the current Tor architecture. Minjae Seo, Myoungsung You, Jaehan Kim, Taejune Park, Seungwon Shin 0001, Jinwoo Kim 0006 |
INFOCOM | 5 |
| 2025 | Covering Cracks in Content Moderation: Delexicalized Distant Supervision for Illicit Drug Jargon DetectionabstractIn light of rising drug-related concerns and the increasing role of social media, sales and discussions of illicit drugs have become commonplace online. Social media platforms hosting user-generated content must therefore perform content moderation, which is a difficult task due to the vast amount of jargon used in drug discussions. Previous works on drug jargon detection were limited to extracting a list of terms, but these approaches have fundamental problems in practical application. First, they are trivially evaded using word substitutions. Second, they cannot distinguish whether euphemistic terms (pot, crack) are being used as drugs or as their benign meanings. We argue that drug content moderation should be done using contexts, rather than relying on a banlist. However, manually annotated datasets for training such a task are not only expensive but also prone to becoming obsolete. We present JEDIS, a framework for detecting illicit drug jargon terms by analyzing their contexts. JEDIS utilizes a novel approach that combines distant supervision and delexicalization, which allows JEDIS to be trained without human-labeled data while being robust to new terms and euphemisms. Experiments on two manually annotated datasets show JEDIS significantly outperforms state-of-the-art word-based baselines in terms of F1-score and detection coverage in drug jargon detection. We also conduct qualitative analysis that demonstrates JEDIS is robust against pitfalls faced by existing approaches. Minkyoo Song, Eugene Jang, Jaehan Kim, Seungwon Shin 0001 |
KDD (1) | 4 |
| 2025 | Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding
Hanna Kim, Eugene Jang, Dayeon Yim, Kicheol Kim, Jin-Woo Chung, Seungwon Shin 0001, Xiaojing Liao |
NDSS | 8 |
| 2025 | HardMesh: Enabling High-performance Service Mesh Ingress Processing with SmartNICsabstractService meshes have become essential for enabling microservices in cloud environments; however, they also introduce substantial network overhead. In particular, the ingress gateway, which serves as the primary entry point for external traffic, has emerged as a major performance bottleneck due to CPU-intensive traffic analysis and prolonged forwarding paths through multiple network stack layers. Our analysis indicates that these inefficiencies can result in a 4-fold reduction in network throughput and increased CPU resource consumption. In response, we propose HardMesh, a hardware-software hybrid ingress gateway that leverages a Smart-NIC for high-performance traffic analysis and efficient traffic routing. This process is augmented by a lightweight CPU-based proxy for traffic management. Evaluations show that HardMesh outperforms existing ingress gateways, achieving up to 4.4× higher throughput while providing the same range of traffic management services. Myoungsung You, Jaehyun Nam, Minjae Seo, Taejune Park, Seungwon Shin 0001 |
SIGCOMM | 5 |
| 2025 | When LLMs Go Online: The Emerging Threat of Web-Enabled LLMs
Hanna Kim, Minkyoo Song, Seung Ho Na, Seungwon Shin 0001, Kimin Lee |
USENIX Security Symposium | 4 |
| 2025 | Refusal Is Not an Option: Unlearning Safety Alignment of Large Language Models
Minkyoo Song, Hanna Kim, Jaehan Kim, Seungwon Shin 0001, Sooel Son |
USENIX Security Symposium | 4 |
| 2024 | HardWhale: A Hardware-Isolated Network Security Enforcement System for Cloud EnvironmentsabstractWith the increasing popularity of containers for deploying microservices, ensuring the security of container networks has become a vital concern. However, current security solutions rely on a host's operating system (OS) to enforce network policies for container traffic. This design incurs severe overhead and cannot guarantee container network security when attackers gain access to the host's OS. Therefore, we propose HardWhale, a hardware-isolated network security enforcement system for containers that delivers high-performance and robust network security without depending on the host's OS. HardWhale leverages a smartNIC, physically isolating the entire container traffic inspection stack from the host and accelerating inspection tasks. Inspection policies securely reside within the smartNIC and are updated in runtime without involving the host, due to our isolated policy management mechanism. This design ensures robust network security for containers, even if the host is exposed to attackers. Evaluations show that HardWhale protects containers against various network attacks in compromised environments and improves HTTP throughput threefold and HTTP latency 2.3-fold compared to state-of-the-art solutions. Myoungsung You, Jaehyun Nam, Hyunmin Seo, Minjae Seo, Jaehan Kim, Dongmin Choi, Seungwon Shin 0001 |
ICDCS | 7 |
| 2024 | DRAINCLoG: Detecting Rogue Accounts with Illegally-obtained NFTs using Classifiers Learned on Graphs
Hanna Kim, Eugene Jang, Jin-Woo Chung, Seungwon Shin 0001 |
NDSS | 7 |
| 2024 | PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse between Websites on a GraphabstractThe prevalence of credential stuffing has caused devastating harm to online users who tend to reuse passwords across websites. In response, researchers have made efforts to detect users who set the same passwords or malicious logins. However, existing detection methods sacrifice the usability of passwords by inhibiting password creation or website access. Moreover, the complicated mechanisms for sharing account information hinder their deployment in practice. In this work, we propose a risk prediction framework to prevent credential stuffing attacks before disrupting user behaviors rather than relying on detection. To this end, we newly define the relationship between websites in which users are highly likely to reuse passwords and represent it as an edge on a website graph using graph neural networks. We then perform a link prediction task to identify the risk of credential stuffing between websites. Our framework is applicable to a large number of arbitrary websites by utilizing public website information and linking newly observed website nodes to the graph. The evaluation on a real-world credential dataset consisting of 360 million accounts breached from 22,378 websites shows that our model successfully predicts credential stuffing risk among websites by achieving F1-scores of 0.9559 and 0.9100 in two different graph learning settings, respectively. In addition, we demonstrate the effectiveness of each design strategy and validate that the prediction results can be utilized to quantify the expected rates of password reuse as risk scores. Jaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin, Seungwon Shin 0001 |
SP | 5 |
| 2024 | Prefetch for Fun and Profit: A Revisit of Prefetch Attacks on Apple M1
Hyunwoo Choi, Suryeon Kim, Seungwon Shin 0001 |
USENIX Security Symposium | 3 |
| 2024 | Enhancing security in SDN: Systematizing attacks and defenses from a penetration perspective
Jinwoo Kim 0006, Minjae Seo, Seungsoo Lee 0001, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu, Seungwon Shin 0001 |
Comput. Networks | 8 |
| 2024 | Hyperion: Hardware-Based High-Performance and Secure System for Container NetworksabstractContainers have become the predominant virtualization technique for deploying microservices in cloud environments. However, container networking, critical for microservice functionality, often introduces significant overhead and resource consumption, potentially degrading the performance of microservices. This challenge arises from the complexity of the software-based network data plane, responsible for network virtualization and access control within container traffic. To tackle this challenge, we proposeHyperion, a novel hardware-based container networking system that prioritizes high performance and security. Leveraging smartNICs, commonly found in cloud environments,Hyperionimplements a fully-functional container network data plane, encompassing network virtualization and access control. It also has the capability to dynamically optimize its data plane for agile responses to frequent changes in container environments, ensuring up-to-date data plane operation. This hardware-based design empowersHyperionto significantly improve the overall container networking performance without relying on the host system resources. Notably,Hyperionseamlessly integrates with existing containerized applications without necessitating modifications. Our evaluation shows that compared to state-of-the-art solutions,Hyperionachieves significant improvements in HTTP container communication latency and throughput by up to 2.25x and 4.3x, respectively. Furthermore, it reduces CPU utilization associated with container networking by up to 4x. Myoungsung You, Minjae Seo, Jaehan Kim, Seungwon Shin 0001, Jaehyun Nam |
IEEE Trans. Cloud Comput. | 4 |
| 2024 | Ambusher: Exploring the Security of Distributed SDN Controllers Through Protocol State FuzzingabstractDistributed SDN (Software-Defined Networking) controllers have rapidly become an integral element ofWide Area Networks (WAN), particularly within SD-WAN, providing scalability and fault-tolerance for expansive network infrastructures. However, the architecture of these controllers introduces new potential attack surfaces that have thus far received inadequate attention. In response to these concerns, we introduceAmbusher, a testing tool designed to discover vulnerabilities within protocols used in distributed SDN controllers.Ambusherachieves this by leveragingprotocol state fuzzing, which systematically finds attack scenarios based on an inferred state machine. Since learning states from a cluster is complicated,Ambusherproposes a novel methodology that extracts a single and relatively simple state machine, achieving efficient state-based fuzzing. Our evaluation ofAmbusher, conducted on a real SD-WAN deployment spanning two campus networks and one enterprise network, illustrates its ability to uncover 6 potential vulnerabilities in the widely used distributed controller platform. Jinwoo Kim 0006, Minjae Seo, Eduard Marin, Seungsoo Lee 0001, Jaehyun Nam, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | DarkBERT: A Language Model for the Dark Side of the InternetabstractRecent research has suggested that there are clear differences in the language used in the Dark Web compared to that of the Surface Web.As studies on the Dark Web commonly require textual analysis of the domain, language models specific to the Dark Web may provide valuable insights to researchers.In this work, we introduce DarkBERT, a language model pretrained on Dark Web data.We describe the steps taken to filter and compile the text data used to train DarkBERT to combat the extreme lexical and structural diversity of the Dark Web that may be detrimental to building a proper representation of the domain.We evaluate Dark-BERT and its vanilla counterpart along with other widely used language models to validate the benefits that a Dark Web domain specific model offers in various use cases.Our evaluations show that DarkBERT outperforms current language models and may serve as a valuable resource for future research on the Dark Web. Youngjin Jin, Eugene Jang, Jin-Woo Chung, Seungwon Shin 0001 |
ACL (1) | 6 |
| 2023 | Cryonics: Trustworthy Function-as-a-Service using Snapshot-based EnclavesabstractRecent research has proposed the use of trusted execution environments (TEEs), such as SGX, in serverless computing to safeguard against threats from insecure system software, malicious co-located tenants, or suspicious cloud operators. However, integrating SGX, one of the most mature TEE, with serverless computing results in significant performance degradation due to the function startup latency caused by enclave creation. This performance degradation arises because SGX is not designed with serverless function startup procedures in mind, where numerous application codes, libraries, and data are re-initialized upon each function invocation. The inherent limitations of SGX contribute to significant performance degradation, whether through the addition of every page into the enclave, or the restriction of page permissions, which ultimately cause TLB flushes, context switches, and re-entering the enclave. In this paper, we first take key observations resident in the intrinsic features of the server-less function and propose Cryonics, a method of serving snapshot-based enclave that accelerates the startup time of the function instance by creating a future-proof working set of that. We consider the page locality and obsolete pages of the enclaved function instance to create a lightweight working set used for serving requests. Our evaluation shows that Cryonics achieves up to 100x outperformed startup time compared to existing cold-start-based methods and reveals the stability of the startup time. Seong-Joong Kim, Myoungsung You, Byung Joon Kim, Seungwon Shin 0001 |
SoCC | 4 |
| 2023 | HELIOS: Hardware-assisted High-performance Security Extension for Cloud NetworkingabstractWith the increasing adoption of containerization in cloud services, container networking has become a critical concern, as it enables the agile deployment of microservices but also introduces new vulnerabilities susceptible to network attacks, posing a threat to container environments. While several security solutions have been introduced to address this concern, they unfortunately exhibit significant shortcomings, including security vulnerabilities and limited performance. We thus propose Helios, a novel hardware-based network security extension that addresses the security and performance limitations in existing solutions. Leveraging a smartNIC, Helios enhances both the security and performance facets of container networking through two key mechanisms: (i) the establishment of physically isolated container communication channels and (ii) the network security engines fully offloaded to the smartNIC. Our evaluation shows that Helios mitigates various network threats initiated from both container- and host-side while performing up to 3x faster than the existing solutions in container communication. Myoungsung You, Jaehyun Nam, Minjae Seo, Seungwon Shin 0001 |
SoCC | 4 |
| 2023 | AVX Timing Side-Channel Attacks against Address Space Layout RandomizationabstractModern x86 processors support an AVX instruction set to boost performance. However, this extension may cause security issues. We discovered that there are vulnerable properties in implementing masked load/store instructions. Based on this, we present a novel AVX timing side-channel attack that can defeat address space layout randomization. We demonstrate the significance of our attack by showing User and Kernel ASLR breaks on the recent Intel and AMD processors in various environments, including cloud computing systems, an SGX enclave (a fine-grained ASLR break), and major operating systems. We further demonstrate that our attack can be used to infer user behavior, such as Bluetooth events and mouse movements. We highlight that stronger isolation or more fine-grained randomization should be adopted to successfully mitigate our presented attacks. Hyunwoo Choi, Suryeon Kim, Seungwon Shin 0001 |
DAC | 3 |
| 2023 | Evolving Bots: The New Generation of Comment Bots and their Underlying Scam Campaigns in YouTubeabstractThis paper presents a pioneering investigation into a novel form of scam advertising method on YouTube, termed "social scam bots'' (SSBs). These bots have evolved to emulate benign user behavior by posting comments and engaging with other users, oftentimes appearing prominently among the top rated comments. We analyzed the YouTube video comments and proposed a method to identify SSBs and extract the underlying scam domains. Our study revealed 1,134 SSBs promoting 72 scam campaigns responsible for infecting 31.73% of crawled videos. Further investigation revealed that SSBs exhibit advances that surpass traditional bots. Notably, they targeted specific audience by aligning scam campaigns with related video content, effectively leveraging the YouTube recommendation algorithm. We monitored these SSBs over a period of six months, enabling us to evaluate the effectiveness of YouTube's mitigation efforts. We also uncovered various strategies they use to evade mitigation attempts, including a novel strategy called "self-engagement," aimed at boosting their comment ranking. By shedding light on the phenomenon of SSBs and their evolving tactics, our study aims to raise awareness and contribute to the prevention of these malicious actors, ultimately fostering a safer online platform. Seung Ho Na, Sumin Cho, Seungwon Shin 0001 |
IMC | 3 |
| 2023 | Partitioning Ethereum without Eclipsing It
Hwanjo Heo, Seungwon Woo, Taeung Yoon, Min Suk Kang, Seungwon Shin 0001 |
NDSS | 5 |
| 2023 | Witnessing Erosion of Membership Inference Defenses: Understanding Effects of Data Drift in Membership PrivacyabstractData drift is the phenomenon when the input data distribution in testing time is different from the training time. This strengthens the generalization gap in a model, which is known to severely deteriorate the model’s performance. Meanwhile, previous studies state that membership inference attacks (MIA) take advantage of the generalization gap of a machine learning model. By transitive logic, we can deduce that data drift would affect these privacy attacks. In this work, we consider data drift when applied to the privacy threat of MIA. As the first work to explore the detrimental extent of data drift on membership privacy, we conduct a literature review on current MIA defense works under selected dimensions associated with data drift. Our study reveals that not only has data drift never been tested in MIA defense, but there is also no infrastructure to juxtapose data drift with MIA defense. We overcome this by proposing a design for simulating authentic and synthetic data drift and evaluate the benchmark MIA defense methods on various settings. The evaluation shows that data drift strongly enhances the attack success rate of MIA, regardless of defense. In this, we propose MIAdapt, a proof of concept of a MIA defense that allows update in data drift. From this evaluation, we provide security insight into possible solutions in negating the effects of data drift. We hope our work brings attention to the threat of data drift and instigates the development of MIA defense that are adaptable to data drift. Seung Ho Na, Kwanwoo Kim, Seungwon Shin 0001 |
RAID | 3 |
| 2023 | Extended data plane architecture for in-network security services in software-defined networks
Jinwoo Kim 0006, Yeonkeun Kim, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001, Taejune Park |
Comput. Secur. | 5 |
| 2023 | AVX-TSCHA: Leaking information through AVX extensions in commercial processorsabstractModern x86 processors support an AVX instruction set to boost performance. However, this extension set may also cause security issues. We discovered that there are vulnerable properties in the implementation of the masked load/store instructions. First, these instructions can suppress exceptions caused by invalid or inaccessible memory access. Second, the execution time of these instructions leaks the current state of the page mappings, permissions, and TLB states. Based on this, we present a novel AVX timing side-channel attack that can defeat address space layout randomization. We demonstrate the significance of our side-channel attack by showing User and Kernel ASLR breaks on the recent Intel and AMD processors in various environments, including cloud computing systems (Amazon AWS, Google GCP, and Microsoft Azure), an SGX enclave (a fine-grained ASLR break), and major OSes (Linux, Windows, and macOS). Our attack can identify the Linux kernel's base address in 0.29 ms as well as those of loaded kernel modules in 2.24 ms, with a near-zero error rate. We further demonstrate that our attack can be used to infer user behavior, such as mouse movements and data transmissions over the network. Our evaluation results on multiple mobile, desktop, and server processors (a total of 26 Intel and AMD CPUs) show that 1) the AVX timing side-channel works on the vast majority of Intel processors (from the Sandy Bridge microarchitecture) as well as AMD processors (from the Zen microarchitecture onward) and 2) our KASLR breaks are very fast and reliable. To the best of our knowledge, our attack is the first to demonstrate a KASLR break on both the recent Intel Alder Lake and AMD Zen 3 CPUs. We highlight that more robust isolation or fine-grained randomization should be adopted to mitigate our presented attacks successfully. Suryeon Kim, Seungwon Shin 0001, Hyunwoo Choi |
Comput. Secur. | 2 |
| 2023 | Secure Inter-Container Communications Using XDP/eBPFabstractWhile the use of containerization technologies for virtual application deployment has grown at an astonishing rate, the question of the robustness of container networking has not been well scrutinized from a security perspective, even though inter-container networking is indispensable for microservices. Thus, this paper first analyzes container networks from a security perspective, discussing the implications based on their architectural limitations. Then, it presents Bastion+, a secure inter-container communication bridge. Bastion+ introduces ($i$) a network security enforcement stack that provides fine-grained control per container application and securely isolates inter- container traffic in a point-to-point manner. Bastion+ also supports ($ii$) selective security function chaining, enabling various security functions to be chained between containers for further security inspections (e.g., deep packet inspection) according to the container’s network context. Bastion+ incorporates ($iii$) a security policy assistant that helps an administrator discover inter-container networking dependencies correctly. Our evaluation demonstrates how Bastion+ can effectively mitigate several adversarial attacks in container networks while improving the overall performance up to 25.4% within single-host containers and 17.7% for cross-host container communications. Jaehyun Nam, Seungsoo Lee 0001, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 2022 | Closing the Loophole: Rethinking Reconstruction Attacks in Federated Learning from a Privacy StandpointabstractFederated Learning was deemed as a private distributed learning framework due to the separation of data from the central server. However, recent works have shown that privacy attacks can extract various forms of private information from legacy federated learning. Previous literature describe differential privacy to be effective against membership inference attacks and attribute inference attacks, but our experiments show them to be vulnerable against reconstruction attacks. To understand this outcome, we execute a systematic study of privacy attacks from the standpoint of privacy. The privacy characteristics that reconstruction attacks infringe are different from other privacy attacks, and we suggest that privacy breach occurred at different levels. From our study, reconstruction attack defense methods entail heavy computation or communication costs. To this end, we propose Fragmented Federated Learning (FFL), a lightweight solution against reconstruction attacks. This framework utilizes a simple yet novel gradient obscuring algorithm based on a newly proposed concept called the global gradient and determines which layers are safe for submission to the server. We show empirically in diverse settings that our framework improves practical data privacy of clients in federated learning with an acceptable performance trade-off without increasing communication cost. We aim to provide a new perspective to privacy in federated learning and hope this privacy differentiation can improve future privacy-preserving methods. Seung Ho Na, Hyeong Gwon Hong, Junmo Kim 0002, Seungwon Shin 0001 |
ACSAC | 4 |
| 2022 | Heimdallr: Fingerprinting SD-WAN Control-Plane Architecture via Encrypted Control TrafficabstractSoftware-defined wide area network (SD-WAN) has emerged as a new paradigm for steering a large-scale network flexibly by adopting distributed software-defined network (SDN) controllers. The key to building a logically centralized but physically distributed control-plane is running diverse cluster management protocols to achieve consistency through an exchange of control traffic. Meanwhile, we observe that the control traffic exposes unique time-series patterns and directional relationships due to the operational structure even though the traffic is encrypted, and this pattern can disclose confidential information such as control-plane topology and protocol dependencies, which can be exploited for severe attacks. With this insight, we propose a new SD-WAN fingerprinting system, called Heimdallr. It analyzes periodical and operational patterns of SD-WAN cluster management protocols and the context of flow directions from the collected control traffic utilizing a deep learning-based approach, so that it can classify the cluster management protocols automatically from miscellaneous control traffic datasets. Our evaluation, which is performed in a realistic SD-WAN environment consisting of geographically distant three campus networks and one enterprise network shows that Heimdallr can classify SD-WAN control traffic with ≥ 93%, identify individual protocols with ≥ 80% macro F-1 scores, and finally can infer control-plane topology with ≥ 70% similarity. Minjae Seo, Jaehan Kim, Eduard Marin, Myoungsung You, Taejune Park, Seungsoo Lee 0001, Seungwon Shin 0001, Jinwoo Kim 0006 |
ACSAC | 7 |
| 2022 | Meta-Path-based Fake News Detection Leveraging Multi-level Social Context InformationabstractFake news, false or misleading information presented as news, has a significant impact on many aspects of society, such as in politics or healthcare domains. Due to the deceiving nature of fake news, applying Natural Language Processing (NLP) techniques to the news content alone is insufficient. Therefore, more information is required to improve fake news detection, such as the multi-level social context (news publishers and engaged users in social media) information and the temporal information of user engagement. The proper usage of this information, however, introduces three chronic difficulties: 1) multi-level social context information is hard to be used without information loss, 2) temporal information of user engagement is hard to be used along with multi-level social context information, and 3) news representation with multi-level social context and temporal information is hard to be learned in an end-to-end manner. To overcome all three difficulties, we propose a novel fake news detection framework, Hetero-SCAN. We use Meta-Path, a composite relation connecting two node types, to extract meaningful multi-level social context information without loss. We then propose Meta-Path instance encoding and aggregation methods to capture the temporal information of user engagement and learn news representation end-to-end. According to our experiment, Hetero-SCAN yields significant performance improvement over state-of-the-art fake news detection methods. Kwanwoo Kim, Seung Ho Na, Seungwon Shin 0001 |
CIKM | 4 |
| 2022 | MECaNIC: SmartNIC to Assist URLLC Processing in Multi-Access Edge Computing PlatformsabstractMulti-access edge computing (MEC) providing server capabilities at near end-users is introduced to enable Ultra Reliable Low Latency Communication (URLLC) for mission-critical and time-sensitive networked services. However, the current MEC simply shortens the physical travel distance of traffic but does not include any architectural approach for supporting URLLC. As a result, MEC implicates resource contention issues, and important packets can be easily delayed or lost, resulting in critical flaws for those services. To address these problems, we introduce MECaNIC, which extends the data plane of MEC to SmartNIC and assists URLLC of MEC. It provides i) precise packet scheduling that handles traffic priorities into two dimensions of reliability and latency, and ii) task offloading that accelerates MEC applications, including payload matching and response caching. The prototype implemented using NetFPGA shows that MECaNIC reduces the average latency of the high-priority traffic from$2,883\ \mu s$to$397\ \mu s$while ensuring packet delivery, even when the traffic competes with other lower priority traffic. Also, task offloading improves a MEC's payload processing 4-fold and reduces file downloading time and video random access time by 44% and 17%, respectively. Taejune Park, Myoungsung You, Youngjin Jin, Kilho Lee, Seungwon Shin 0001 |
ICNP | 6 |
| 2022 | Shedding New Light on the Language of the Dark WebabstractYoungjin Jin, Eugene Jang, Yongjae Lee, Seungwon Shin, Jin-Woo Chung. Proceedings of the 2022 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. 2022. Youngjin Jin, Eugene Jang, Seungwon Shin 0001, Jin-Woo Chung |
NAACL-HLT | 4 |
| 2022 | EqualNet: A Secure and Practical Defense for Long-term Network Topology Obfuscation
Jinwoo Kim 0006, Eduard Marin, Mauro Conti, Seungwon Shin 0001 |
NDSS | 4 |
| 2022 | Vulcan: Automatic extraction and analysis of cyber threat intelligence from unstructured text
Hyeonseong Jo, Seungwon Shin 0001 |
Comput. Secur. | 3 |
| 2022 | Reconfigurable regular expression matching architecture for real-time pattern update and payload inspection
Jaehyun Nam, Seung Ho Na, Seungwon Shin 0001, Taejune Park |
J. Netw. Comput. Appl. | 3 |
| 2022 | A Framework for Policy Inconsistency Detection in Software-Defined NetworksabstractSoftware-Defined Networking (SDN) has aggressively grown in data center networks, telecommunication providers, and enterprises by virtue of its programmable and extensible control plane. Also, there have been many kinds of research on the security of SDN components along with the growth of SDN. Some of them have inspected network policy inconsistency problems that can severely cause network reliability and security issues in SDN. However, they do not consider whether a single network policy itself is corrupted during processing inside and between SDN components. In this paper, we thus focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among those components. We then present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise inOpenFlownetworks, the most prevalent SDN protocol. To prove its feasibility, we applied AudiSDN to two widely used SDN controllers, Floodlight and ONOS, and uncovered three separate CVEs (Common Vulnerabilities and Exposures) that cause the network policy inconsistencies among SDN components. Furthermore, we investigate the design flaws that cause the inconsistencies in modern SDN components, suggesting specific validations to address such a serious but understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 7 |
| 2021 | Reinhardt: Real-time Reconfigurable Hardware Architecture for Regular Expression Matching in DPIabstractRegular expression (regex) matching is an integral part of deep packet inspection (DPI) but a major bottleneck due to its low performance. For regex matching (REM) acceleration, FPGA-based studies have emerged and exploited parallelism by matching multiple regex patterns concurrently. However, even though guaranteeing high-performance, existing FPGA-based regex solutions do not still support dynamic updates in run time. Hence, it was inappropriate as a DPI function due to frequently altered malicious signatures. In this work, we introduce Reinhardt, a real-time reconfigurable hardware architecture for REM. Reinhardt represents regex patterns as a combination of reconfigurable cells in hardware and updates regex patterns in real-time while providing high performance. We implement the prototype using NetFPGA-SUME, and our evaluation demonstrates that Reinhardt updates hundreds of patterns within a second and achieves up to 10 Gbps throughput (max. hardware bandwidth). Our case studies show that Reinhardt can operate as NIDS/NIPS and as the REM accelerator for them. Taejune Park, Jaehyun Nam, Seung Ho Na, Jaewoong Chung, Seungwon Shin 0001 |
ACSAC | 5 |
| 2021 | Behind Block Explorers: Public Blockchain Measurement and Security ImplicationabstractBlockchain data has become a popular subject in studying various aspects of blockchains including the security of underlying mechanisms. However, the main chain block data, usually available from block explorer services, does not serve as a sufficient source of transaction and block dynamics that are only visible from a large-scale event measurement. In this paper, the transaction and block arrival events of the two popular public blockchains, i.e., Bitcoin and Ethereum, are measured to investigate the hidden dynamics of blockchain networks. We share our key findings and security implications including a false universal assumption of previous mining related studies and an invalid transaction propagation problem that can be exploited to launch a Denial-of-Service attack on a network. Hwanjo Heo, Seungwon Shin 0001 |
ICDCS | 2 |
| 2021 | Formullar: An FPGA-based network testing tool for flexible and precise measurement of ultra-low latency networking systems
Taejune Park, Seungwon Shin 0001, Insik Shin, Kilho Lee |
Comput. Networks | 2 |
| 2021 | Understanding Block and Transaction Logs of Permissionless Blockchain NetworksabstractPublic blockchain records are widely studied in various aspects such as cryptocurrency abuse, anti-money-laundering, and monetary flow of businesses. However, the final blockchain records, usually available from block explorer services or querying locally stored data of blockchain nodes, do not provide abundant and dynamic event logs that are only visible from a live large-scale measurement. In this paper, we collect the network logs of three popular permissionless blockchains, that is, Bitcoin, Ethereum, and EOS. The discrepancy between observed events and the public block data is studied via a noble analysis model provided with the soundness of measurement. We share our key findings including a false universal assumption of previous mining-related studies and the block/transaction arrival characteristics. Hwanjo Heo, Seungwon Shin 0001 |
Secur. Commun. Networks | 2 |
| 2021 | GapFinder: Finding Inconsistency of Security Information From Unstructured TextabstractTextual data mining of open source intelligence on the Web has become an increasingly important topic across a wide range of domains such as business, law enforcement, military, and cybersecurity. Text mining efforts utilize natural language processing to transform unstructured web content into structured forms that can drive various machine learning applications and data indexing services. For example, applications for text mining in cybersecurity have produced a range of threat intelligence services that serve the IT industry. However, a less studied problem is that of automating the identification of semantic inconsistencies among various text input sources. In this paper, we introduce GapFinder, a new inconsistency checking system for identifying semantic inconsistencies within the cybersecurity domain. Specifically, we examine the problem of identifying technical inconsistencies that arise in the functional descriptions of open source malware threat reporting information. Our evaluation, using tens of thousands of relations derived from web-based malware threat reports, demonstrates the ability of GapFinder to identify the presence of inconsistencies. Hyeonseong Jo, Jinwoo Kim 0006, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | BottleNet: Hiding Network Bottlenecks Using SDN-Based Topology DeceptionabstractThe robustness of a network’s connectivity to other networks is often highly dependent on a few critical nodes and links that tie the network to the larger topology. The failure or degradation to such network bottlenecks can result in outages that may propagate throughout the network. Unfortunately, the presence of the bottlenecks also offers opportunities for targetedlink flooding attacks (LFAs). Researchers have proposed a new and promising defense to counter LFAs, referred to astopology deception. This strategy centers on hindering the discovery of bottlenecks by presenting false trace responses to adversaries as they perform topological probing of the target network. Even though the goal of topology deception centers on obscuring critical links, node dependencies can be exploited by an adversary. However, current approaches do not consider a wide range of metrics that may reveal important and diverse aspects of network bottlenecks. Furthermore, existing approaches create a simple form of virtual topology, which is subject to relatively easy detection by the adversary, reducing its effectiveness. In this paper, we propose a comprehensive topology deception framework, which we refer to as BottleNet. Our suggested approach can analyze various network topology features both with respect to static and dynamic metrics and then use this information to identify bottlenecks, finally producing complex virtual topologies that are resilient to adversarial detection. Jinwoo Kim 0006, Jaehyun Nam, Suyeol Lee, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2020 | AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksabstractAt the foundation of every network security architecture lies the premise that formulated network flow policies are reliably deployed and enforced by the network infrastructure. However, software-defined networks (SDNs) add a particular challenge to satisfying this premise, as for SDNs the flow pol-icy implementation spans multiple applications and abstraction layers across the SDN stack. In this paper, we focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among these components. This question is rather essential, as when such inconsistencies arise the implications to the security and reliability of the network are devastating. We present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise in OpenFlow networks, the most prevalent SDN protocol used today. We also present results from applying AudiSDN to two widely used SDN controllers, Floodlight and ONOS. In fact, our test results have led to the filing of 3 separate CVE reports. We believe that the approach presented in this paper is applicable to the breadth of OpenFlow platforms used today, and that its broader usage will help to address a serious but yet understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
INFOCOM | 6 |
| 2020 | BASTION: A Security Enforcement Network Stack for Container Networks
Jaehyun Nam, Seungsoo Lee 0001, Hyunmin Seo, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
USENIX ATC | 6 |
| 2020 | A comprehensive security assessment framework for software-defined networks
Seungsoo Lee 0001, Jinwoo Kim 0006, Seungwon Woo, Changhoon Yoon, Sandra Scott-Hayward, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
Comput. Secur. | 8 |
| 2020 | Automated Permission Model Generation for Securing SDN Control-PlaneabstractAn important consideration in software-defined networks (SDNs), is that one SDN application, through a bug or API misuse, can break an entire SDN. While previous works have tried to mitigate such concerns by implementing access control mechanisms (permission models) for an SDN controller, they commonly require serious manual efforts in creating a permission model. Moreover, they do not support flexible permission models, and they are often tightly coupled with a specific SDN controller. To address such limitations, we introduce an automated permission generation and verification system called VOGUE. A distinguishing aspect of VOGUE is that it automatically generates flexible permission models and yet is completely separated from the SDN controller implementation. To demonstrate the feasibility of our approach, we implement a prototype, evaluate its completeness and soundness, and examine its performance. In addition, to show the effectiveness of VOGUE, we demonstrate its use cases and security impact to SDN in the context of popular SDN controllers. Heedo Kang, Vinod Yegneswaran, Shalini Ghosh, Phillip A. Porras, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | Dynamic Control for On-Demand Interference-Managed WLAN InfrastructuresabstractIn order to handle a high traffic demand, dense wireless local area networks (WLANs) have been deployed rapidly in the past years. However, dense WLANs cause two critical issues: wastage of energy and severe interference. To address these issues, the centralized management of dense WLANs has been emerged as a powerful paradigm for improving energy efficiency as well as avoiding severe interference. In this paper, we study the joint optimization problem of power-operation modes in access points (APs), channel selections and user-AP associations for improving energy efficiency and avoiding interference without sacrificing users' demands. To this end, we first formulate it as a mixed-integer programming using the popular Lyapunov approach, but it turns out to be computationally intractable, i.e., NP-hard. To address the issue, we propose a polynomial-time approximation algorithm and prove that it achieves a constant-factor approximation guarantee under mild assumptions. The main novelty underlying our algorithm design is based on a linear programming relaxation combining with two different greedy rounding schemes, where each achieves a constant-factor approximation in different regimes of parameters. We verify the performance of the proposed algorithm via extensive simulations and also demonstrate its practicability by implementing it at commercial APs using a Software-defined Networking framework. Results from our experiments show that it reduces the wasted energy significantly while maintaining even higher throughput. Seokhyun Kim, Kimin Lee, Yeonkeun Kim, Jinwoo Shin, Seungwon Shin 0001, Song Chong |
IEEE/ACM Trans. Netw. | 5 |
| 2019 | Rethinking Network Policy Coordination: A Database PerspectiveabstractDatabase usage in the context of networking has been focusing on managing factual data --- network state. But database systems are also renowned for mediating among semantic data --- data integrity constraints (ICs) that capture network policies. This paper asks if and how can database systems help with coordinating network policies in the semantically rich environment of SDN and BGP. We identify several problems --- disparate policies buried in the network that hinders rather than facilitates coordination; manual control flow orchestration of SDN policies that burdens the SDN programmer; and overlooked conflicts among interdomain routing policies that, though induced by multiple ASes, are only manifested within a single AS. Driven by these unique problems, we present a preliminary database solution that, using ICs as a unifying knowledge representation, employs automated reasoning to anticipate and to adjust the interplay between policies and the rest of the networking world. Anduo Wang, Seungwon Shin 0001, Eduard C. Dragut |
APNet | 2 |
| 2019 | Poster: TCLP: Enforcing Least Privileges to Prevent Containers from Kernel VulnerabilitiesabstractWhile containerization has emerged as a lightweight approach to package, deploy, and run legacy applications in a resource-efficient manner, the shared kernel-resource model used by containers introduces critical security concerns. Specifically, the abuse of system calls by a compromised container can trigger the security vulnerabilities of a host kernel. Unfortunately, even though existing solutions provide powerful protection mechanisms against such issues, how to define the capabilities of containers is still up to operators. In this work, we thus introduce TCLP, a dynamic analysis system that helps operators configure the least capabilities of containers to protect not only themselves but also a host. TCLP monitors the system calls triggered by containers in run time and finds the least capabilities required to run the containers based on the collected system calls. Finally, operators configure the minimal capabilities discovered by TCLP for their containers, reducing the risk of kernel vulnerabilities. Suyeol Lee, Junsik Seo, Jaehyun Nam, Seungwon Shin 0001 |
CCS | 4 |
| 2019 | DPX: Data-Plane eXtensions for SDN Security Service Instantiation
Taejune Park, Yeonkeun Kim, Vinod Yegneswaran, Phillip A. Porras, Zhaoyan Xu, KyoungSoo Park, Seungwon Shin 0001 |
DIMVA | 7 |
| 2019 | Cybercriminal Minds: An investigative study of cryptocurrency abuses in the Dark Web
Changhoon Yoon, Heedo Kang, Yeonkeun Kim, Yongdae Kim, Dongsu Han, Sooel Son, Seungwon Shin 0001 |
NDSS | 8 |
| 2019 | Doppelgängers on the Dark Web: A Large-scale Assessment on Phishing Hidden Web ServicesabstractAnonymous network services on the World Wide Web have emerged as a new web architecture, called the Dark Web. The Dark Web has been notorious for harboring cybercriminals abusing anonymity. At the same time, the Dark Web has been a last resort for people who seek freedom of the press as well as avoid censorship. This anonymous nature allows website operators to conceal their identity and thereby leads users to have difficulties in determining the authenticity of websites. Phishers abuse this perplexing authenticity to lure victims; however, only a little is known about the prevalence of phishing attacks on the Dark Web. Changhoon Yoon, Kwanwoo Kim, Yongdae Kim, Seungwon Shin 0001, Sooel Son |
WWW | 4 |
| 2019 | Astraea: Towards an effective and usable application permission system for SDN
Heedo Kang, Changhoon Yoon, Seungwon Shin 0001 |
Comput. Networks | 3 |
| 2019 | SODA: A software-defined security framework for IoT environments
Yeonkeun Kim, Jaehyun Nam, Taejune Park, Sandra Scott-Hayward, Seungwon Shin 0001 |
Comput. Networks | 5 |
| 2019 | MC-SDN: Supporting Mixed-Criticality Real-Time Communication Using Software-Defined NetworkingabstractDespite recent advances, there still remain many problems to design reliable cyber-physical systems. One of the typical problems is to achieve a seemingly conflicting goal, which is to support timely delivery of real-time flows while improving resource efficiency. Recently, the concept of mixed-criticality (MC) has been widely accepted as useful in addressing the goal for real-time resource management. However, it has not been yet studied well for real-time communication. In this paper, we present the first approach to support MC flow scheduling on switched Ethernet networks leveraging an emerging network architecture, software-defined networking (SDN). Though SDN provides flexible and programmatic ways to control packet forwarding and scheduling, it yet raises several challenges to enable real-time MC flow scheduling on SDN, including: 1) how to handle (i.e., drop or re-prioritize) out-of-mode packets in the middle of the network when the criticality mode changes and 2) how the mode change affects end-to-end transmission delays. Addressing such challenges, we develop MC-SDN that supports real-time MC flow scheduling by extending SDN-enabled switches and OpenFlow protocols. It manages and schedules MC packets in different ways depending on the system criticality mode. To this end, we carefully design the mode change protocol that provides analytic mode change delay bound, and then resolve implementation issues for system architecture. For evaluation, we implement a prototype of MC-SDN on top of Open vSwitch, and integrate it into a real world network testbed as well as a 1/10 autonomous vehicle. Our extensive evaluations with the network testbed and vehicle deployment show that MC-SDN supports MC flow scheduling with minimal delays on forwarding rule updates and it brings a significant improvement in safety in a real-world application scenario. Kilho Lee, Taejune Park, Hoon Sung Chwa, Jinkyu Lee 0001, Seungwon Shin 0001, Insik Shin |
IEEE Internet Things J. | 6 |
| 2019 | Guest Editors' Introduction: Special Section on Security in Emerging Networking TechnologiesabstractThe papers in this special section examine security in emerging networking technologies. Network infrastructure is undergoing a major shift away from ossified hardware-based networks to programmable software-based networks. One compelling example of this paradigm shift is the advent of Software- Defined Networking (SDN). A traditional network mixes control and traffic processing logic in single hardware devices, making the network more complex and harder to manage. SDN has addressed this issue by decoupling the control plane in network devices from the data plane to simplify production networks. On the other hand, enterprise networks are populated with a large number of proprietary and expensive hardware-based middleboxes, such as firewall, IDS/IPS, and load balancing. Hardware-based middleboxes present significant drawbacks such as high costs, management complexity, slow time to market, and unscalability. Network Function Virtualization (NFV) was proposed as another new network paradigm to address those drawbacks by replacing hardware-based network functions with virtualized software systems running on generic and inexpensive commodity hardware. Given their benefits, SDN and NFV have recently attracted significant attention from both academia and industry. Gail-Joon Ahn, Guofei Gu, Hongxin Hu, Seungwon Shin 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2019 | Operator-Defined Reconfigurable Network OS for Software-Defined NetworksabstractBarista is a novel architecture that seeks to enable flexible and customizable instantiations of network operating systems (NOSs) for software-defined networks (SDNs). As the NOS is the strategic control center of an SDN, implementing logic for management of network switches as well as higher-level applications, its design is critical to the welfare of the network. In this paper, we focus on three aspects of composable controller design: component synthesis, dynamic event control, and predictive NOS assessment. First, the modular design of the Barista enables flexible composition of functionalities prevalent in contemporary SDN controllers. Second, its event handling mechanism enables dynamic customization of control flows in a NOS. Third, its predictive NOS assessment helps to discover the optimal composition for the requirements specified by operators. These capabilities allow Barista operators to optimally select functionalities and dynamically handle events for their operating requirements while maximizing the resource utilization of the given system. Our results demonstrate that Barista can synthesize NOSs with many functionalities found in commodity controllers with competitive performance profiles. Jaehyun Nam, Hyeonseong Jo, Yeonkeun Kim, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2018 | Who is knocking on the Telnet Port: A Large-Scale Empirical Study of Network ScanningabstractNetwork scanning is the primary procedure preceding many network attacks. Until recently, network scanning has been widely studied to report a continued growth in volume and Internet-wide trends including the underpinning of distributed scannings by lingering Internet worms. It is, nevertheless, imperative to keep us informed with the current state of network scanning, for factual and comprehensive understanding of the security threats we are facing, and new trends to serve as the presage of imminent threats. Hwanjo Heo, Seungwon Shin 0001 |
AsiaCCS | 2 |
| 2018 | Knowledge Seeking on The Shadow BrokersabstractThe Shadow Brokers (TSB) are an infamous group of hackers responsible for major cybercrime incidents. There are currently few studies on TSB, and to prevent their attacks in the future, we believe it is necessary to study them beforehand. This study constructs a relation graph of all the entities concerning TSB using identifiers in the Web. We introduce a systematic approach to finding relations among entities using a case study based on identifiers and clearness of relations. Our investigation covers data from both the Surface Web and Dark Web, with our Dark Web data consisting of over 40 million Dark Web webpages. We have uncovered many hacking forums, hacking groups, and individuals having a relation with TSB using our method. The relation graph of TSB will become a stepping stone in developing a knowledge base of TSB. Seung Ho Na, Kwanwoo Kim, Seungwon Shin 0001 |
CCS | 3 |
| 2018 | CloudRand: Building Heterogeneous and Moving-Target Network InterfacesabstractSome fundamental reasons why our networked systems are still vulnerable to network attacks are because (1) they are more open than necessary; (2) they arehomogeneous, i.e., the same way to exploit a vulnerability on one machine is easily applicable to many other machines (which is particularly a severe issue in cloud computing environments when virtual machines images are heavily reused/cloned); (3) current networked services are merelystatic targets, i.e., they are easily predictable and do not change. While network authentication and access control mechanisms such as firewall and VPN can help reduce the openness (mostly at network perimeter level), they do not help much on the latter two factors. To bridge the gap and greatly complement existing network authentication/access control mechanisms, we propose CloudRand, a new framework to make networked systems/services in the cloudheterogeneous(every host has a different networking interface) andmoving targets(such interfaces keep changing and they are unpredictable to untrusted entities). Inspired by the previous work on host-level (memory or instruction) Address Space Randomization (ASR), we build a lightweight solution to randomize network service interfaces. Thus, even derived from the same image, each virtual machine can have very different network service interfaces and they keep changing to further reduce the attack surface. CloudRand is an application-independent security service, orthogonal to existing application/network security mechanisms such as authentication, encryption, and access control. To fit into different environments such as clouds or enterprise networks, we provide various prototype systems at different levels for flexible deployment choices, e.g., host level (kernel drivers for both Linux and Windows), network level (based on Click modular router or software-defined networking technology), virtual machine hypervisor level (based on Xen), and application level (browser plugin). Our extensive evaluation shows that this solution has low overhead, and it can it can significantly reduce the network attack surface and successfully defeat malware epidemic attacks. Seungwon Shin 0001, Zhaoyan Xu, Yeonkeun Kim, Guofei Gu |
ICCCN | 1 |
| 2018 | INDAGO: A New Framework For Detecting Malicious SDN ApplicationsabstractSoftware-Defined Networking (SDN) controllers not only provide centralized control of SDNs, but also implement open and programmable APIs to ultimately establish an open network environment, where anyone can develop and deliver useful SDN applications. In such an environment, malicious SDN applications can be easily developed and distributed by untrusted entities and can even possess full control of SDNs. Thus, the security threat of malicious SDN applications must be taken seriously. In this paper, we propose a novel system, called Indago, which statically analyzes SDN applications to model their behavioral profiles, and finally, it automatically detects malicious SDN applications with a machine learning approach. We implement a prototype system and evaluate its effectiveness with real world SDN applications and malware. Our evaluation results show that the system can detect most known SDN malware with a high detection rate and low error rates. Changhoon Yoon, Seungwon Shin 0001, Sang Kil Cha |
ICNP | 3 |
| 2018 | Barista: An Event-centric NOS Composition Framework for Software-Defined NetworksabstractAs the network operating system (NOS) is the strategic control center of a software-defined network (SDN), its design is critical to the welfare of the network. Contemporary research has largely focused on specialized NOSs that seek to optimize controller design across one or a few dimensions (e.g., scalability, performance, or security) due to fundamental differences in architectural trade-offs needed to support competing demands. We thus designed Barista, as a new framework that enables flexible and customizable instantiations of network operating systems (NOSs) supporting diverse design choices. The Barista framework incorporates two mechanisms to harmonize architectural differences across design choices: component synthesis and dynamic event control. First, the modular design of the Barista framework enables flexible composition of functionalities prevalent in contemporary SDN controllers. Second, its event-handling mechanism enables dynamic adjustment of control flows in a NOS. These capabilities allow operators to easily enable functionalities and dynamically handle associated events, thereby satisfying network operating requirements. Our results demonstrate that Barista can synthesize NOSs with many functionalities found in commodity NOSs with competitive performance profiles. Jaehyun Nam, Hyeonseong Jo, Yeonkeun Kim, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
INFOCOM | 6 |
| 2018 | Towards a Security-Enhanced Cloud PlatformabstractWhile cloud computing platform becomes popular and works as a platform for network function virtualization (NFV), the security of the cloud also becomes an important subject. However, although there are many works about security mechanisms, there has not been much research into what problems can occur when these conventional mechanisms are applied to the cloud system. Thus, we have given more attention to the robustness of communications resided in the cloud, not security mechanism itself, and found that security threats could arise from communication between cloud services and identification process. To cope with this problem, we propose three approaches: integrative identification system in a single cloud service, action-based token authorization, and partially encrypted communication between the identification system and cloud services. By implementing these approaches to open-source cloud computing platform, Openstack, we show that our approaches are feasible. Junsik Seo, Jaehyun Nam, Seungwon Shin 0001 |
PRDC | 3 |
| 2018 | MC-SDN: Supporting Mixed-Criticality Scheduling on Switched-Ethernet Using Software-Defined NetworkingabstractIn this paper, we present the first approach to support mixed-criticality (MC) flow scheduling on switched Ethernet networks leveraging an emerging network architecture, Software-Defined Networking (SDN). Though SDN provides flexible and programmatic ways to control packet forwarding and scheduling, it yet raises several challenges to enable real-time MC flow scheduling on SDN, including i) how to handle (i.e., drop or reprioritize) out-of-mode packets in the middle of the network when the criticality mode changes, and ii) how the mode change affects end-to-end transmission delays. Addressing such challenges, we develop MC-SDN that supports real-time MC flow scheduling by extending SDN-enabled switches and OpenFlow protocols. It manages and schedules MC packets in different ways depending on the system criticality mode. To this end, we carefully design the mode change protocol that provides analytic mode change delay bound, and then resolve implementation issues for system architecture. For evaluation, we implement a prototype of MC-SDN on top of Open vSwitch, and integrate it into a real world network testbed as well as a 1/10 autonomous vehicle. Our extensive evaluations with the network testbed and vehicle deployment show that MC-SDN supports MC flow scheduling with minimal delays on forwarding rule updates and it brings a significant improvement in safety in a real-world application scenario. Kilho Lee, Taejune Park, Hoon Sung Chwa, Jinkyu Lee 0001, Seungwon Shin 0001, Insik Shin |
RTSS | 6 |
| 2018 | NOSArmor: Building a Secure Network Operating SystemabstractSoftware-Defined Networking (SDN), controlling underlying network devices (i.e., data plane) in a logically centralized manner, is now actively adopted in many real world networking environments. It is clear that a network administrator can easily understand and manage his networking environments with the help of SDN. In SDN, a network operating system (NOS), also known as an SDN controller, is the most critical component because it should be involved in all transactions for controlling network devices, and thus the security of NOS cannot be highly exaggerated. However, in spite of its importance, no previous works have thoroughly investigated the security of NOS. In this work, to address this problem, we present the NOSArmor, which integrates several security mechanisms, named as security building block (SBB), into a consolidated SDN controller. NOSArmor consists of eight SBBs and each of them addresses different security principles of network assets. For example, while role-based authorization focuses on securing confidentiality of internal storage from malicious applications, OpenFlow protocol verifier protects availability of core service in the controller from malformed control messages received from switches. In addition, NOSArmor shows competitive performance compared to existing other controllers (i.e., ONOS, Floodlight) with secureness of network assets. Hyeonseong Jo, Jaehyun Nam, Seungwon Shin 0001 |
Secur. Commun. Networks | 3 |
| 2018 | Duo: Software Defined Intrusion Tolerant System Using Dual ClusterabstractAn intrusion tolerant system (ITS) is a network security system that is composed of redundant virtual servers that are online only in a short time window, called exposure time. The servers are periodically recovered to their clean state, and any infected servers are refreshed again, so attackers have insufficient time to succeed in breaking into the servers. However, there is a conflicting interest in determining exposure time, short for security and long for performance. In other words, the short exposure time can increase security but requires more servers to run in order to process requests in a timely manner. In this paper, we propose Duo, an ITS incorporated in SDN, which can reduce exposure time without consuming computing resources. In Duo, there are two types of servers: some servers with long exposure time (White server) and others with short exposure time (Gray server). Then, Duo classifies traffic into benign and suspicious with the help of SDN/NFV technology that also allows dynamically forwarding the classified traffic to White and Gray servers, respectively, based on the classification result. By reducing exposure time of a set of servers, Duo can decrease exposure time on average. We have implemented the prototype of Duo and evaluated its performance in a realistic environment. Hyunmin Seo, Changhoon Yoon, Seungwon Shin 0001, Hyunsoo Yoon |
Secur. Commun. Networks | 5 |
| 2017 | A Security-Mode for Carrier-Grade SDN ControllersabstractManagement approaches to modern networks are increasingly influenced by software-defined networks (SDNs), and this increased influence is reflected in the growth of commercially available innovative SDN-based switches, controllers and applications. To date, there have been a number of commercial and open-source SDN operating systems (NOS) introduced for various purposes, including distributed controller frameworks targeting large, carrier-grade networks such as the Open Network Operating System (ONOS) and OpenDayLight (ODL). These frameworks are distinguished by their (i) elastic cluster controller architecture, (ii) network virtualization support, and (iii) modular design. Given their flexible design, growing list of supported features, and collaborative community support, these are attractive hosting platforms for a wide range of third-party distributed network management applications. This paper identifies the common security requirements for policy enforcement in such distributed controller environments. We present the design of a network application permission-enforcement model and an integrated security subsystem (SM-ONOS) for managing distributed applications running on an ONOS controller. We discuss the underlying motivations of its security extensions and their implications for improving our understanding of how to securely manage large-scale SDNs. Our performance assessments demonstrate that the security-mode extension imposed reasonable overheads (ranging from 5 to 20% for 1-7 node clusters). Changhoon Yoon, Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran, Heedo Kang, Martin W. Fong, Brian O'Connor, Thomas Vachuska |
ACSAC | 2 |
| 2017 | Bridging the architectural gap between NOS design principles in software-defined networksabstractWe design Barista, as a new framework that seeks to enable flexible and customizable instantiations of network operating systems (NOSs) supporting diverse design choices, using two key features that harmonize architectural differences across design choices: component synthesis and dynamic event control. With these capabilities, Barista operators to easily enable functionalities and dynamically adjust the control flows among those functionalities. Jaehyun Nam, Hyeonseong Jo, Yeonkeun Kim, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
SoCC | 6 |
| 2017 | Athena: A Framework for Scalable Anomaly Detection in Software-Defined NetworksabstractNetwork-based anomaly detection is a well-mined area of research, with many projects that have produced algorithms to detect suspicious and anomalous activities at strategic points in a network. In this paper, we examine how to integrate an anomaly detection development framework into existing software-defined network (SDN) infrastructures to support sophisticated anomaly detection services across the entire network data plane, not just at network egress boundaries. We present Athena as a new SDN-based software solution that exports a well-structured development interface and provides general purpose functions for rapidly synthesizing a wide range of anomaly detection services and network monitoring functions with minimal programming effort. Athena is a fully distributed application hosting architecture, enabling a unique degree of scalability from prior SDN security monitoring and analysis projects. We discuss example use-case scenarios with Athena's development libraries, and evaluate system performance with respect to usability, scalability, and overhead in real world environments. Jinwoo Kim 0006, Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran |
DSN | 3 |
| 2017 | Mobility of Everything (MoE): An Integrated and Distributed Mobility ManagementabstractEverything can be mobile, from end-hosts to applications. The need for mobility management is rising rapidly due to the increasing number of mobile devices and the advent of new types of mobile object, such as Internet of Things devices, connected vehicles, wearable devices, and virtual machines. In order to support various types of mobility, we propose an integrated and distributed mobility management approach, called Mobility of Everything (MoE). The MoE approach uses an object ID whose value is used to determine a specific edge switch that an object is connected with. In addition, the approach distributes binding information of an object ID and an IP address of edge switch throughout the network. We implement our approach on both an emulation environment and a testbed with software switches. Our evaluation results demonstrate that the MoE approach achieves seamless and scalable handover of end-hosts and applications. Sangyup Han, Jaehyun Park 0002, Haeun Kim, Jaehee Ha, Seungwon Shin 0001, Sungwon Kang, Myungchul Kim 0001 |
ICCCN | 5 |
| 2017 | DELTA: A Security Assessment Framework for Software-Defined Networks
Seungsoo Lee 0001, Changhoon Yoon, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras |
NDSS | 4 |
| 2017 | Flow Wars: Systemizing the Attack Surface and Defenses in Software-Defined NetworksabstractEmerging software defined network (SDN) stacks have introduced an entirely new attack surface that is exploitable from a wide range of launch points. Through an analysis of the various attack strategies reported in prior work, and through our own efforts to enumerate new and variant attack strategies, we have gained two insights. First, we observe that different SDN controller implementations, developed independently by different groups, seem to manifest common sets of pitfalls and design weakness that enable the extensive set of attacks compiled in this paper. Second, through a principled exploration of the underlying design and implementation weaknesses that enables these attacks, we introduce a taxonomy to offer insight into the common pitfalls that enable SDN stacks to be broken or destabilized when fielded within hostile computing environments. This paper first captures our understanding of the SDN attack surface through a comprehensive survey of existing SDN attack studies, which we extend by enumerating 12 new vectors for SDN abuse. We then organize these vulnerabilities within the well-known confidentiality, integrity, and availability model, assess the severity of these attacks by replicating them in a physical SDN testbed, and evaluate them against three popular SDN controllers. We also evaluate the impact of these attacks against published SDN defense solutions. Finally, we abstract our findings to offer the research and development communities with a deeper understanding of the common design and implementation pitfalls that are enabling the abuse of SDN networks. Changhoon Yoon, Seungsoo Lee 0001, Heedo Kang, Taejune Park, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
IEEE/ACM Trans. Netw. | 5 |
| 2016 | QoSE: Quality of security a network security framework with distributed NFVabstractAn effort to deploy security devices by the network provider has been increasing as the network is being exposed to various types of network attacks. However, network providers are incapable of handling all types of attacks as each security device is designed for a certain purpose. If an attack breaks out, only one particular device becomes busy in terms of resource usage while others being idle. Moreover, it is hard to adjust a level of security service with respect to the importance of network flow. To address these issues, we propose a new security solution, QoSE, which provides adaptive security services based on Network Function Virtualization (NFV). QoSE provides a capability to manage resource usage that the network flow is not concentrated on a specific node. We design QoSE considering a distributed NFV environment to avoid a single point of failure and a bottleneck problem. Our proposed solution has also shown a quick recovery from fault situation. In addition, we provide a novel resource optimization algorithm to operate security services efficiently. We have implemented a prototype system to verify our ideas and have checked that QoSE shows reasonable performance compared with a common device. Taejune Park, Yeonkeun Kim, Jaehyun Park 0002, Hyunmin Suh, Byeongdo Hong, Seungwon Shin 0001 |
ICC | 6 |
| 2016 | Enhancing Network Security through Software Defined Networking (SDN)abstractSoftware Defined Networking (SDN) is an emerging technology that attracts significant attention from both industry and academia recently. By decoupling the control logic from the closed and proprietary implementations of traditional network devices, it enables researchers and practitioners to design new innovative network functions/protocols in a much more flexible, powerful, and easier way. We believe SDN provides new research opportunities to security, and it can greatly impact network security research in many different ways. However, till today, SDN has not been well recognized by the security community yet. In this systematic survey on SDN security, we investigate how the new features provided by SDN can help enhance network security and information security process. By systematically reasoning the opportunities introduced by SDN to network security, we hope to provide new insights for future research in this important area. Seungwon Shin 0001, Lei Xu 0024, Sungmin Hong, Guofei Gu |
ICCCN | 1 |
| 2016 | Vulnerabilities of network OS and mitigation with state-based permission systemabstractAbstract The advancement of software defined networking (SDN) is redefining traditional computer networking architecture. The role of the control plane of SDN is of such importance that SDNs are referred to as network operating systems (OSs). However, the robustness and security of the network OS has been overlooked. In this paper, we report three main issues pertaining to network OSs. First, we identified vulnerabilities that could be exploited by malicious or buggy applications running on network OSs. We also identified four major attack vectors that could undermine network OS operations: denial of service, global data manipulation, control plane poisoning, and system shell execution. Further, it was demonstrated that real‐world attacks can be launched on commonly used network OSs without significant effort. Second, we present a method to address the attacks by analyzing network applications running on network OSs to identify their behavioral features, which enabled the extraction of a permission set for each network application. Based on this work, a permission‐based malicious network application detector was introduced, which examines the permission set of each application and prevents it from executing without permission. Our system shows almost no performance overhead. Copyright © 2015 John Wiley & Sons, Ltd. Jaehyun Park 0002, Seungwon Shin 0001, Brent ByungHoon Kang |
Secur. Commun. Networks | 4 |
| 2015 | SPIRIT: A Framework for Profiling SDNabstractSoftware-Defined Networking (SDN), which separates the control and data plane of network, is strongly considered as a promising future networking architecture. Compared with legacy networking architecture, it allows to enable a variety of innovative network functions at much less cost and effort. Accordingly, each component of SDN is also being rapidly realized, and one of the most noticeable SDN component implementations would be SDN controllers, such as ONOS or Floodlight. One advantage of these SDN controllers is capability of hosting various network applications to enable innovative network functions, however, it is crucial to analyze these applications before the actual deployment as they may directly affect the performance of the managed network. To be more specific, SDN applications may contain performance bugs that unnecessarily consume significant system resource or produce critical bottlenecks in the controller. In this paper, we introduce an automatic SDN application profiling framework, SPIRIT, which reduces the human effort in revealing any performance bugs that might exist in SDN applications. In order to show the effectiveness of our framework, we reveal new performance bugs exist in ONOS and Floodlight applications. Heedo Kang, Seungsoo Lee 0001, Changhoon Yoon, Seungwon Shin 0001 |
ICNP | 5 |
| 2015 | POSTER: A Collaborative Approach on Behavior-Based Android Malware Detection
Chanwoo Bae 0001, Jesung Jung, Jaehyun Nam, Seungwon Shin 0001 |
SecureComm | 4 |
| 2015 | Enabling security functions with SDN: A feasibility study
Changhoon Yoon, Taejune Park, Seungsoo Lee 0001, Heedo Kang, Seungwon Shin 0001, Zonghua Zhang |
Comput. Networks | 5 |
| 2015 | A First Step Toward Network Security Virtualization: From Concept To PrototypeabstractNetwork security management is becoming more and more complicated in recent years, considering the need of deploying more and more network security devices/middle-boxes at various locations inside the already complicated networks. A grand challenge in this situation is that current management is inflexible and the security resource utilization is not efficient. The flexible deployment and utilization of proper security devices at reasonable places at needed time with low management cost is extremely difficult. In this paper, we present a new concept of network security virtualization, which virtualizes security resources/functions to network administrators/users, and thus maximally utilizing existing security devices/middle-boxes. In addition, it enables security protection to desirable networks with minimal management cost. To verify this concept, we further design and implement a prototype system, NETSECVISOR, which can utilize existing pre-installed (fixed-location) security devices and leverage software-defined networking technology to virtualize network security functions. At its core, NETSECVISOR contains: 1) a simple script language to register security services and policies; 2) a set of routing algorithms to determine optimal routing paths for different security policies based on different needs; and 3) a set of security response functions/strategies to handle security incidents. We deploy NETSECVISOR in both virtual test networks and a commercial switch environment to evaluate its performance and feasibility. The evaluation results show that our prototype only adds a very small overhead while providing desired network security virtualization to network users/administrators. Seungwon Shin 0001, Haopei Wang, Guofei Gu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Rosemary: A Robust, Secure, and High-performance Network Operating SystemabstractWithin the hierarchy of the Software Defined Network (SDN) network stack, the control layer operates as the critical middleware facilitator of interactions between the data plane and the network applications, which govern flow routing decisions. In the OpenFlow implementation of the SDN model, the control layer, commonly referred to as a network operating system (NOS), has been realized by a range of competing implementations that offer various performance and functionality advantages: Floodlight, POX, NOX, and ONIX. In this paper we focus on the question of control layer resilience, when rapidly developed prototype network applications go awry, or third-party network applications incorporate unexpected vulnerabilities, fatal instabilities, or even malicious logic. We demonstrate how simple and common failures in a network application may lead to loss of the control layer, and in effect, loss of network control. To address these concerns we present the ROSEMARY controller, which implements a network application containment and resilience strategy based around the notion of spawning applications independently within a micro-NOS. ROSEMARY distinguishes itself by its blend of process containment, resource utilization monitoring, and an application permission structure, all designed to prevent common failures of network applications from halting operation of the SDN Stack. We present our design and implementation of ROSEMARY, along with an extensive evaluation of its performance relative to several of the mostly well-known and widely used controllers. Rather than imposing significant performance costs, we find that with the integration of two optimization features, ROSEMARY offers a competitive performance advantage over the majority of other controllers. Seungwon Shin 0001, YongJoo Song, Taekyung Lee, Sangho Lee 0003, Jaewoong Chung, Phillip A. Porras, Vinod Yegneswaran, Brent ByungHoon Kang |
CCS | 1 |
| 2014 | Run Away If You Can: - Persistent Jamming Attacks against Channel Hopping Wi-Fi Devices in Dense Networks
Il-Gu Lee, Hyunwoo Choi, Yongdae Kim, Seungwon Shin 0001, Myungchul Kim 0001 |
RAID | 4 |
| 2013 | AVANT-GUARD: scalable and vigilant switch flow management in software-defined networksabstractAmong the leading reference implementations of the Software Defined Networking (SDN) paradigm is the OpenFlow framework, which decouples the control plane into a centralized application. In this paper, we consider two aspects of OpenFlow that pose security challenges, and we propose two solutions that could address these concerns. The first challenge is the inherent communication bottleneck that arises between the data plane and the control plane, which an adversary could exploit by mounting a "control plane saturation attack" that disrupts network operations. Indeed, even well-mined adversarial models, such as scanning or denial-of-service (DoS) activity, can produce more potent impacts on OpenFlow networks than traditional networks. To address this challenge, we introduce an extension to the OpenFlow data plane called "connection migration", which dramatically reduces the amount of data-to-control-plane interactions that arise during such attacks. The second challenge is that of enabling the control plane to expedite both detection of, and responses to, the changing flow dynamics within the data plane. For this, we introduce "actuating triggers" over the data plane's existing statistics collection services. These triggers are inserted by control layer applications to both register for asynchronous call backs, and insert conditional flow rules that are only activated when a trigger condition is detected within the data plane's statistics module. We present Avant-Guard, an implementation of our two data plane extensions, evaluate the performance impact, and examine its use for developing more scalable and resilient SDN security services. Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
CCS | 1 |
| 2013 | Model checking invariant security properties in OpenFlowabstractThe OpenFlow (OF) switching specification represents an innovative and open standard for enabling the dynamic programming of flow control policies in production networks. Unfortunately, thus far researchers have paid little attention to the development of methods for verifying that dynamic flow policies inserted within an OpenFlow network do not violate the network's underlying security policy. We introduce Flover, a model checking system which verifies that the aggregate of flow policies instantiated within an OpenFlow network does not violate the network's security policy. We have implemented Flover using the Yices SMT solver, which we then integrated into NOX, a popular OpenFlow network controller. Flover provides NOX a formal validation of the OpenFlow network's security posture. Sooel Son, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
ICC | 2 |
| 2013 | FRESCO: Modular Composable Security Services for Software-Defined Networks
Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran, Martin W. Fong, Guofei Gu, Mabry Tyson |
NDSS | 1 |
| 2013 | EFFORT: A new host-network cooperated framework for efficient and effective bot malware detection
Seungwon Shin 0001, Zhaoyan Xu, Guofei Gu |
Comput. Networks | 1 |
| 2012 | CloudWatcher: Network security monitoring using OpenFlow in dynamic cloud networks (or: How to provide security monitoring as a service in clouds?)abstractCloud computing is becoming a popular paradigm. Many recent new services are based on cloud environments, and a lot of people are using cloud networks. Since many diverse hosts and network configurations coexist in a cloud network, it is essential to protect each of them in the cloud network from threats. To do this, basically, we can employ existing network security devices, but applying them to a cloud network requires more considerations for its complexity, dynamism, and diversity. In this paper, we propose a new framework, CloudWatcher, which provides monitoring services for large and dynamic cloud networks. This framework automatically detours network packets to be inspected by pre-installed network security devices. In addition, all these operations can be implemented by writing a simple policy script, thus, a cloud network administrator is able to protect his cloud network easily. We have implemented the proposed framework, and evaluated it on different test network environments. Seungwon Shin 0001, Guofei Gu |
ICNP | 1 |
| 2012 | EFFORT: Efficient and effective bot malware detectionabstractTo detect bots, a lot of detection approaches have been proposed at host or network level so far and both approaches have clear advantages and disadvantages. In this paper, we propose EFFORT, a new host-network cooperated detection framework attempting to overcome shortcomings of both approaches while still keeping both advantages, i.e., effectiveness and efficiency. Based on intrinsic characteristics of bots, we propose a multi-module approach to correlate information from different host- and network-level aspects and design a multi-layered architecture to efficiently coordinate modules to perform heavy monitoring only when necessary. We have implemented our proposed system and evaluated on real-world benign and malicious programs running on several diverse real-life office and home machines for several days. The final results show that our system can detect all 15 real-world bots (e.g., Waledac, Storm) with low false positives (0.68%) and with minimal overhead. We believe EFFORT raises a higher bar and this host-network cooperated design represents a timely effort and a right direction in the malware battle. Seungwon Shin 0001, Zhaoyan Xu, Guofei Gu |
INFOCOM | 1 |
| 2012 | Analyzing spammers' social networks for fun and profit: a case study of cyber criminal ecosystem on twitterabstractIn this paper, we perform an empirical analysis of the cyber criminal ecosystem on Twitter. Essentially, through analyzing inner social relationships in the criminal account community, we find that criminal accounts tend to be socially connected, forming a small-world network. We also find that criminal hubs, sitting in the center of the social graph, are more inclined to follow criminal accounts. Through analyzing outer social relationships between criminal accounts and their social friends outside the criminal account community, we reveal three categories of accounts that have close friendships with criminal accounts. Through these analyses, we provide a novel and effective criminal account inference algorithm by exploiting criminal accounts' social relationships and semantic coordinations. Chao Yang 0022, Robert Chandler Harkreader, Jialong Zhang 0001, Seungwon Shin 0001, Guofei Gu |
WWW | 4 |
| 2012 | A Large-Scale Empirical Study of ConfickerabstractConficker is the most recent widespread, well-known worm/bot. According to several reports, it has infected about 7 million to 15 million hosts and the victims are still increasing even now. In this paper, we analyze Conficker infections at a large scale, about 25 million victims, and study various interesting aspects about this state-of-the-art malware. By analyzing Conficker, we intend to understand current and new trends in malware propagation, which could be very helpful in predicting future malware trends and providing insights for future malware defense. We observe that Conficker has some very different victim distribution patterns compared to many previous generation worms/botnets, suggesting that new malware spreading models and defense strategies are likely needed. We measure the potential power of Conficker to estimate its effects on the networks/hosts when it performs malicious operations. Furthermore, we intend to determine how well a reputation-based blacklisting approach can perform when faced with new malware threats such as Conficker. We cross-check several DNS blacklists and IP/AS reputation data from Dshield and FIRE and our evaluation shows that unlike a previous study which shows that a blacklist-based approach can detect most bots, these reputation-based approaches did relatively poorly for Conficker. This raises a question of how we can improve and complement existing reputation-based techniques to prepare for future malware defense? Based on this, we look into some insights for defenders. We show that neighborhood watch is a surprisingly effective approach in the case of Conficker. This suggests that security alert sharing/correlation (particularly among neighborhood networks) could be a promising approach and play a more important role for future malware defense. Seungwon Shin 0001, Guofei Gu, A. L. Narasimha Reddy, Christopher P. Lee 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2011 | Cross-Analysis of Botnet Victims: New Insights and Implications
Seungwon Shin 0001, Raymond Lin, Guofei Gu |
RAID | 1 |
| 2010 | Conficker and beyond: a large-scale empirical studyabstractConficker [26] is the most recent widespread, well-known worm/bot. According to several reports [16, 28], it has infected about 7 million to 15 million hosts and the victims are still increasing even now. In this paper, we analyze Conficker infections at a large scale, including about 25 millions victims, and study various interesting aspects about this state-of-the-art malware. By analyzing Conficker, we intend to understand current and new trends in malware propagation, which could be very helpful in predicting future malware trends and providing insights for future malware defense. We observe that Conficker has some very different victim distribution patterns compared to many previous generation worms/botnets, suggesting that new malware spreading models and defense strategies are likely needed. Furthermore, we intend to determine how well a reputation-based blacklisting approach can perform when faced with new malware threats such as Conficker. We cross-check several DNS blacklists and IP/AS reputation data from Dshield [6] and FIRE [7], and our evaluation shows that unlike a previous study [18] which shows that a blacklist-based approach can detect most bots, these reputation-based approaches did relatively poorly for Conficker. This raised the question, how can we improve and complement existing reputation-based techniques to prepare for future malware defense? Finally, we look into some insights for defenders. We show that neighborhood watch is a surprisingly effective approach in the Conficker case. This suggests that security alert sharing/correlation (particularly among neighborhood networks) could be a promising approach and play a more important role for future malware defense. Seungwon Shin 0001, Guofei Gu |
ACSAC | 1 |