Skip to main content

Seungwon Shin

Korea Advanced Institute of Science and Technology · Computer Science

About the Lab

Professor Seungwon Shin's research lab specializes in software-defined networking (SDN) security, with a focus on identifying and mitigating novel attack surfaces in SDN architectures. The lab investigates critical vulnerabilities such as control plane saturation, resource consumption attacks, and resilience of network operating systems (NOS) under malicious or faulty application loads. It also explores practical security frameworks for dynamic and complex environments, such as cloud networks, through automated monitoring and traffic inspection solutions. The lab's work bridges theoretical security research with real-world deployment challenges in modern network infrastructures.

SDN securitynetwork resiliencecontrol plane attackscloud network monitoringresource consumption attacks

Research Overview

Papers
140
Total Citations
4,164
Papers (5y)
52
Primary Field
Computer Science

Research Output Trend

Figures are computed from collected data and may differ slightly.

Publications per year (5y)
52total
2022
2023
2024
2025
2026
Citations per year (5y)
302total
20222023202420252026

Selected Papers

15
1
Article|555 citations·2013
AVANT-GUARD
Seungwon Shin, Vinod Yegneswaran, Phillip Porras, Guofei Gu

Among the leading reference implementations of the Software Defined Networking (SDN) paradigm is the OpenFlow framework, which decouples the control plane into a centralized application. In this paper, we consider two aspects of OpenFlow that pose security challenges, and we propose two solutions that could address these concerns. The first challenge is the inherent communication bottleneck that arises between the data plane and the control plane, which an adversary could exploit by mounting a "

Computer Networks and CommunicationsComputer Science
2
Article|315 citations·2013
Attacking software-defined networks
Seungwon Shin, Guofei Gu

In this paper, for the first time we show a new attack to fin- gerprint SDN networks and further launch efficient resource consumption attacks. This attack demonstrates that SDN brings new security issues that may not be ignored. We provide the first feasibility study of such attack and hope to stimulate further studies in SDN security research.

Computer Networks and CommunicationsComputer Science
3
Article|193 citations·2014
Rosemary
Seungwon Shin, Yongjoo Song, Taekyung Lee, Sang-Ho Lee, Jaewoong Chung, Phillip Porras, Vinod Yegneswaran, Jiseong Noh, Brent Byunghoon Kang

Within the hierarchy of the Software Defined Network (SDN) network stack, the control layer operates as the critical middleware facilitator of interactions between the data plane and the network applications, which govern flow routing decisions. In the OpenFlow implementation of the SDN model, the control layer, commonly referred to as a network operating system (NOS), has been realized by a range of competing implementations that offer various performance and functionality advantages: Floodligh

Computer Networks and CommunicationsComputer Science
4
Article|185 citations·2012
CloudWatcher: Network security monitoring using OpenFlow in dynamic cloud networks (or: How to provide security monitoring as a service in clouds?)
Seungwon Shin, Guofei Gu

Cloud computing is becoming a popular paradigm. Many recent new services are based on cloud environments, and a lot of people are using cloud networks. Since many diverse hosts and network configurations coexist in a cloud network, it is essential to protect each of them in the cloud network from threats. To do this, basically, we can employ existing network security devices, but applying them to a cloud network requires more considerations for its complexity, dynamism, and diversity. In this pa

Computer Networks and CommunicationsComputer Science
5
Article|125 citations·2016
Enhancing Network Security through Software Defined Networking (SDN)
Seungwon Shin, Lei Xu, Sungmin Hong, Guofei Gu

Software Defined Networking (SDN) is an emerging technology that attracts significant attention from both industry and academia recently. By decoupling the control logic from the closed and proprietary implementations of traditional network devices, it enables researchers and practitioners to design new innovative network functions/protocols in a much more flexible, powerful, and easier way. We believe SDN provides new research opportunities to security, and it can greatly impact network securit

Computer Networks and CommunicationsComputer Science
6
Article|83 citations·2010
Conficker and beyond
Seungwon Shin, Guofei Gu

Conficker [26] is the most recent widespread, well-known worm/bot. According to several reports [16, 28], it has infected about 7 million to 15 million hosts and the victims are still increasing even now. In this paper, we analyze Conficker infections at a large scale, including about 25 millions victims, and study various interesting aspects about this state-of-the-art malware. By analyzing Conficker, we intend to understand current and new trends in malware propagation, which could be very hel

Computer Networks and CommunicationsComputer Science
7
Article|75 citations·2022
Vulcan: Automatic extraction and analysis of cyber threat intelligence from unstructured text
Hyeonseong Jo, Yongjae Lee, Seungwon Shin
SJR Q1Computers & Security
Information SystemsComputer Science
8
Article|67 citations·2015
A First Step Toward Network Security Virtualization: From Concept To Prototype
Seungwon Shin, Haopei Wang, Guofei Gu
SJR Q1IEEE Transactions on Information Forensics and Security

Network security management is becoming more and more complicated in recent years, considering the need of deploying more and more network security devices/middle-boxes at various locations inside the already complicated networks. A grand challenge in this situation is that current management is inflexible and the security resource utilization is not efficient. The flexible deployment and utilization of proper security devices at reasonable places at needed time with low management cost is extre

Computer Networks and CommunicationsComputer Science
9
Article|65 citations·2011
A Large-Scale Empirical Study of Conficker
Seungwon Shin, Guofei Gu, Narasimha Reddy, Christopher P. Lee
SJR Q1IEEE Transactions on Information Forensics and Security

Conficker is the most recent widespread, well-known worm/bot. According to several reports, it has infected about 7 million to 15 million hosts and the victims are still increasing even now. In this paper, we analyze Conficker infections at a large scale, about 25 million victims, and study various interesting aspects about this state-of-the-art malware. By analyzing Conficker, we intend to understand current and new trends in malware propagation, which could be very helpful in predicting future

Computer Networks and CommunicationsComputer Science
10
Article|50 citations·2006
Malware prevalence in the KaZaA file-sharing network
Seungwon Shin, Jaeyeon Jung, Hari Balakrishnan

In recent years, more than 200 viruses have been reported to use a peer-to-peer (P2P) file-sharing network as a propagation vector. Disguised as files that are frequently exchanged over P2P networks, these malicious programs infect the user's host if downloaded and opened, leaving their copies in the user's sharing folder for further propagation. Using a light-weight crawler built for the KaZaA file-sharing network, we study the prevalence of malware in this popular P2P network, the malware's pr

Computer Networks and CommunicationsComputer Science
11
Article|40 citations·2019
SODA: A software-defined security framework for IoT environments
Yeonkeun Kim, Jaehyun Nam, Taejune Park, Sandra Scott-Hayward, Seungwon Shin
SJR Q1Computer NetworksOA
Computer Networks and CommunicationsComputer Science
12
Article|37 citations·2020
A comprehensive security assessment framework for software-defined networks
Seungsoo Lee, Jinwoo Kim, Seungwon Woo, Changhoon Yoon, Sandra Scott-Hayward, Vinod Yegneswaran, Phillip Porras, Seungwon Shin
SJR Q1Computers & Security
Computer Networks and CommunicationsComputer Science
13
Article|20 citations·2005
D-SAT: Detecting SYN Flooding Attack by Two-Stage Statistical Approach
Seungwon Shin, Kiyoung Kim, Jongsoo Jang

We propose D-SAT (detecting SYN flooding attack by two-stage statistical approach) system that is simple and robust approach to detect SYN flooding attacks by observing network traffic. Instead of managing all ongoing traffic on the network, D-SAT only monitors SYN count and ratio between SYN and other TCP packets at first time. And it detects SYN flooding and finds victims more accurately in its second stage. To make the detection mechanism robustly and easily, D-SAT uses CUSUM (cumulative sum)

Computer Networks and CommunicationsComputer Science
14
Book Chapter|18 citations·2011
Cross-Analysis of Botnet Victims: New Insights and Implications
Seungwon Shin, Raymond Tzer Pin Lin, Guofei Gu
SJR Q2Lecture notes in computer science
Computer Networks and CommunicationsComputer Science
15
Article|16 citations·2013
EFFORT: A new host–network cooperated framework for efficient and effective bot malware detection
Seungwon Shin, Zhaoyan Xu, Guofei Gu
SJR Q1Computer Networks
Computer Networks and CommunicationsComputer Science

Research Areas

Computer Networks and CommunicationsArtificial IntelligenceInformation SystemsSignal ProcessingHardware and ArchitectureSociology and Political Science

Dive deeper into Seungwon Shin's research on Nubint

Open this lab's papers in the app to read with AI, summarize, and cite in your writing.