SearcharxivSearch

arXiv subjects

Seonghoon Jeong

Publications and source records attributed to Seonghoon Jeong.

6 recordsLinked to original sources

DRIFT: Drift-Resilient Invariant-Feature Transformer for DGA Detection

Domain Generation Algorithms (DGAs) evolve continuously to evade botnet detection, posing a persistent challenge for dependable network defense. While deep learning-based detectors achieve strong performance under static conditions, they suffer severe degradation when facing temporal drift. Through a 9-year longitudinal study (2017-2025), we empirically show that state-of-the-art character- and word-based DGA classifiers rapidly lose effectiveness as new DGA variants emerge. To address this problem, we propose a drift-resilient Transformer-based framework that learns invariant representations through a hybrid tokenization strategy and multi-task self-supervised pre-training. The model integrates (i) character-level encoding to capture stochastic morphological patterns and (ii) subword-level encoding for word-based DGAs. Three pre-training tasks enable the model to learn robust structural and contextual features prior to supervised fine-tuning. Comprehensive evaluations demonstrate that our method significantly mitigates temporal degradation and consistently outperforms state-of-the-art baselines in forward-chaining experiments. The proposed approach offers a dependable foundation for long-term DGA defense in evolving threat landscapes. Our code is available at: https://github.com/snsec-net/2026-DSN-DRIFT.

cs.CR

The Vehicle May Be Sick: Denial of Diagnostic Services by Exploiting the CAN Transport Protocol

Vehicle diagnostics has become essential for detecting in-vehicle errors and ensuring safety. While the Unified Diagnostic Services (UDS) protocol is widely adopted for diagnostic operations, it relies on the ISO 15765-2 standard as the transport protocol over the Controller Area Network (CAN), which was designed without inherent security considerations. In this paper, we identify eight novel attack scenarios that exploit specific transport layer mechanisms in the ISO 15765-2 standard, including Flow Control manipulation, Sequence Number violations, and error handling abuses. We evaluate these attacks on a real passenger vehicle using two distinct diagnostic tools to demonstrate their practical impact. Our results confirm that three of these attack scenarios successfully induce denial of diagnostic services, leading to abnormal diagnostic results such as concealed faults and manipulated sensor readings. These findings highlight critical vulnerabilities that can deceive technicians and drivers, potentially exposing vehicles to significant safety risks.

cs.CR

X-CANIDS: Signal-Aware Explainable Intrusion Detection System for Controller Area Network-Based In-Vehicle Network

Controller Area Network (CAN) is an essential networking protocol that connects multiple electronic control units (ECUs) in a vehicle. However, CAN-based in-vehicle networks (IVNs) face security risks owing to the CAN mechanisms. An adversary can sabotage a vehicle by leveraging the security risks if they can access the CAN bus. Thus, recent actions and cybersecurity regulations (e.g., UNR 155) require carmakers to implement intrusion detection systems (IDSs) in their vehicles. The IDS should detect cyberattacks and provide additional information to analyze conducted attacks. Although many IDSs have been proposed, considerations regarding their feasibility and explainability remain lacking. This study proposes X-CANIDS, which is a novel IDS for CAN-based IVNs. X-CANIDS dissects the payloads in CAN messages into human-understandable signals using a CAN database. The signals improve the intrusion detection performance compared with the use of bit representations of raw payloads. These signals also enable an understanding of which signal or ECU is under attack. X-CANIDS can detect zero-day attacks because it does not require any labeled dataset in the training phase. We confirmed the feasibility of the proposed method through a benchmark test on an automotive-grade embedded device with a GPU. The results of this work will be valuable to carmakers and researchers considering the installation of in-vehicle IDSs for their vehicles.

cs.CR

Convolutional Neural Network-based Intrusion Detection System for AVTP Streams in Automotive Ethernet-based Networks

Connected and autonomous vehicles (CAVs) are an innovative form of traditional vehicles. Automotive Ethernet replaces the controller area network and FlexRay to support the large throughput required by high-definition applications. As CAVs have numerous functions, they exhibit a large attack surface and an increased vulnerability to attacks. However, no previous studies have focused on intrusion detection in automotive Ethernet-based networks. In this paper, we present an intrusion detection method for detecting audio-video transport protocol (AVTP) stream injection attacks in automotive Ethernet-based networks. To the best of our knowledge, this is the first such method developed for automotive Ethernet. The proposed intrusion detection model is based on feature generation and a convolutional neural network (CNN). To evaluate our intrusion detection system, we built a physical BroadR-Reach-based testbed and captured real AVTP packets. The experimental results show that the model exhibits outstanding performance: the F1-score and recall are greater than 0.9704 and 0.9949, respectively. In terms of the inference time per input and the generation intervals of AVTP traffic, our CNN model can readily be employed for real-time detection.

cs.CR

Study of quality assurance regulations for linear accelerators in Korea: A comparison study between the current status in Korea and the international guidelines

Quality assurance (QA) for medical linear accelerators is indispensable for appropriate cancer treatment. Some international organizations and western advanced countries provide QA guidelines for linear accelerators. Currently, QA regulations for linear accelerators in Korean hospitals specify a system in which each hospital stipulates its independent hospital-based protocols for QA procedures (HP_QAPs) and conducts QA based on these HP_QAPs while regulatory authorities verify whether items under these HP_QAPs have been performed. However, because this regulatory method cannot guarantee the quality of universal treatment, and QA items with tolerance criteria are different in many hospitals, the presentation of standardized QA items and tolerance criteria is essential. In this study, QA items in HP_QAPs from various hospitals and those presented by international organizations. Concordance rates between QA items for linear accelerators that were presented by the aforementioned organizations and those currently being implemented in Korean hospitals were shown to exhibit a daily QA of 50%, a weekly QA of 22%, a monthly QA of 43%, and an annual QA of 65%, and the overall concordance rates of all QA items were approximately 48%. In comparison between QA items being implemented in Korean hospitals and those being implemented in western advanced countries, concordance rates were shown to exhibit a daily QA of 50%, a weekly QA of 33%, a monthly QA of 60%, and an annual QA of 67%, and the overall concordance rate of all QA items were approximately 57%. The results of this study indicate that the HP_QAPs currently implemented by Korean hospitals as QA standards for linear accelerators used in radiation therapy do not meet international standards. To solve this problem, it is necessary to develop national standardized QA items and procedures for linear accelerators.

physics.med-ph

Preliminary Study for Dosimetric Characteristics of 3D-printed Materials with Megavoltage Photons

In these days, 3D-printer is on the rise in various fields including radiation therapy. This preliminary study aimed to estimate the dose characteristics of the 3D-printer materials which could be used as the compensator or immobilizer in radiation treatment. The cubes which have 5cm length and different densities as 50%, 75% and 100% were printed by 3D-printer. A planning CT scans for cubes were performed using a CT simulator (Brilliance CT, Philips Medical System, Netherlands). Dose distributions behind the cube were calculated when 6MV photon beam passed through cube. The dose response for 3D-printed cube, air and water were measured by using EBT3 film and 2D array detector. When results of air case were normalized to 100, dose calculated by TPS and measured dose of 50% and 75% cube were 96~99. Measured and calculated doses of water and 100% cube were 82~84. HU values of 50%, 75% and 100% were -910, -860 and -10, respectively. From these results, 3D-printer in radiotherapy could be used for medical purpose accurately.

physics.med-ph