김형석 교수
Hyung Seok Kim
KAIST 과학기술정책대학원 · 컴퓨터과학
연구실 소개
김형석 교수의 연구실은 시스템 소프트웨어 및 바이너리 분석 분야에서 핵심적인 연구를 수행하고 있습니다. 특히 가상화 환경에서의 실시간 시스템 지원, 보안 기능을 내장한 바이너리 분석, 어셈블러 테스트를 위한 고성능 퍼지 기반 기법 등 실질적인 시스템 보안과 성능 최적화를 목표로 하고 있습니다. 또한, 아키텍처에 종속되지 않는 기능 식별 기술과 하드웨어 보조 보안 기능의 분석을 통해 바이너리의 내재적 특성을 깊이 있게 이해하는 데 초점을 맞추고 있습니다.
연구 현황
연구 성과 추이
표시된 성과는 수집된 데이터 기준으로 산출되며, 일부 차이가 있을 수 있습니다.
주요 논문
8Virtualization has been receiving increasing attention in embedded real-time systems. However, real-time systems, whose correctness depends on timing requirements, are not easily applicable to virtualization since virtualization mainly focuses on functional correctness. A hierarchical scheduling framework (HSF) provides a method of composing the complex timing requirements of real-time systems. There have been several works on the implementation of the HSF. Although the scheduling framework of v
Although most companies operate a firewall to protect their information assets, they have difficulties in identifying the control conditions of firewalls. This study proposes an analysis tool to visualize segment-based firewall rules to facilitate verification of the current control conditions. The proposed visualization tool analyzes the current control conditions of packets automatically, thereby eliminating the need for manual inspection as before, and displays the conditions with a visualiza
Current function identification techniques have been mostly focused on a specific set of binaries compiled for a specific CPU architecture. While recent deep-learning-based approaches theoretically can handle binaries from different architectures, they require significant computation resources for training and inference, making their use less practical. Furthermore, due to the lack of interpretability of such models, it is fundamentally difficult to gain insight from them. Hence, in this paper,
As CPU vendors introduce various hardware-assisted security features, modern compilers have started to produce binaries containing security-related instructions. Interestingly, such instructions tend to alter the shape of resulting binaries, which can potentially affect the effectiveness of binary analysis. This paper presents the first systematic study on the implication of the Intel CET (Control-flow Enforcement Technology) instructions on function identification. Our study finds that CET-rele
Assembler is a critical component of the compiler toolchain, which has been less tested than the other components. Unfortunately, current grammar-based fuzzing techniques suffer from several challenges when testing assemblers. First, each different assembler accepts different grammar rules and syntaxes, and there are no existing assembly grammar specifications. Second, not every assembler is open-source, which makes it difficult to extract grammar rules from the source code. While existing black
A description is given of the structure and the implementation of the TDX-10 software, which is a large-scale electronic switching system with distributed control architecture. The system structure is layered into three levels, a system, a subsystem, and a block. A system, the top level, is divided into many subsystems, each devoted to a specific function. Each subsystem is broken down into many building blocks which consist of several program files. As a basic loading unit in a processor, an ex
대표 연구 분야
김형석 교수의 연구를 Nubint에서 더 깊이 살펴보세요
이 연구실의 논문을 앱에서 열어 AI와 함께 읽고, 핵심을 요약하고, 내 글에 인용하세요.