Search arXiv⌕ Search

arXiv subjects

Seoyoung Kweon

Publications and source records attributed to Seoyoung Kweon.

3 recordsLinked to original sources

Something to Talk About: Social Media as a Lens on Healthcare Ransomware Events

In the modern era, ransomware attacks on critical healthcare organizations---like hospitals and insurers---are frequent, with impacts ranging from leaked private health information all the way to serious disruptions of urgent, time-sensitive clinical operations. Unfortunately, legal and economic incentives make it uncommon for hospitals to share basic information about these attacks, their scope, and the downstream impacts to patient care. In this paper, we explore the use of public social media posts---authored both by hospitals and by individuals---to garner more detailed insights about these attacks and their effects. We collect 1,628 Facebook and Reddit posts from 2018--2024, design and evaluate techniques to match post data to 212 ground-truth ransomware attacks, and conduct quantitative and qualitative analyses that explore the impacts such attacks have on critical hospital infrastructure, patient care, and providers. We conclude by discussing the promise and limitations of leveraging social data to study the impact of ransomware attacks and highlight areas of future research.

cs.CR↗

FOX: Coverage-guided Fuzzing as Online Stochastic Control

Fuzzing is an effective technique for discovering software vulnerabilities by generating random test inputs and executing them against the target program. However, fuzzing large and complex programs remains challenging due to difficulties in uncovering deeply hidden vulnerabilities. This paper addresses the limitations of existing coverage-guided fuzzers, focusing on the scheduler and mutator components. Existing schedulers suffer from information sparsity and the inability to handle fine-grained feedback metrics. The mutators are agnostic of target program branches, leading to wasted computation and slower coverage exploration. To overcome these issues, we propose an end-to-end online stochastic control formulation for coverage-guided fuzzing. Our approach incorporates a novel scheduler and custom mutator that can adapt to branch logic, maximizing aggregate edge coverage achieved over multiple stages. The scheduler utilizes fine-grained branch distance measures to identify frontier branches, where new coverage is likely to be achieved. The mutator leverages branch distance information to perform efficient and targeted seed mutations, leading to robust progress with minimal overhead. We present FOX, a proof-of-concept implementation of our control-theoretic approach, and compare it to industry-standard coverage-guided fuzzers. 6 CPU-years of extensive evaluations on the FuzzBench dataset and complex real-world programs (a total of 38 test programs) demonstrate that FOX outperforms existing state-of-the-art fuzzers, achieving average coverage improvements up to 26.45% in real-world standalone programs and 6.59% in FuzzBench programs over the state-of-the-art AFL++. In addition, it uncovers 20 unique bugs in popular real-world applications including eight that are previously unknown, showcasing real-world security impact.

cs.CR↗

What Makes A Video Radicalizing? Identifying Sources of Influence in QAnon Videos

In recent years, radicalization is being increasingly attempted on video-sharing platforms. Previous studies have been proposed to identify online radicalization using generic social context analysis, without taking into account comprehensive viewer traits and how those can affect viewers' perception of radicalizing content. To address the challenge, we examine QAnon, a conspiracy-based radicalizing group, and have designed a comprehensive questionnaire aiming to understand viewers' perceptions of QAnon videos. We outline the traits of viewers that QAnon videos are the most appealing to, and identify influential factors that impact viewers' perception of the videos.

cs.SI↗