AI and Cybersecurity

AlJuhaiman, Hessa Abdulaziz, Qazi Emad-ul-Haq, Kyounggon Kim, and Seokhee Lee. "Automated Cyber Threat Intelligence Extraction from Distributed Honeypots: A Hybrid Machine Learning Approach." Electronics (2079-9292) 15, no. 13 (2026): 2900. 

Mostafa, Moallim, Seokhee Lee, Ibrahim Alzahrani, Faisal Abdulaziz Alfouzan, and Kim Kyounggon. "AI-Amplification Indicator: An Actor-Level Scoring Framework for Ransomware Operations on the Dark Web." Journal of Cybersecurity and Privacy 6, no. 2 (2026): 70. (Corresponding author)

Alqahtani, Mohammad, Abdulkarim Amin, Kyounggon Kim, and Seokhee Lee. "Enhancing SCADA Security in Critical Infrastructure: A Multi-Layered Architecture Using IoT-Based Monitoring and AI-Driven Anomaly Detection." International Journal of Advanced Computer Science and Applications 17, no. 1 (2026).

Jang, Se-Young, Su-Yeon Yoon, Jae-Woong Jung, Dong-Hun Lee, Seong-Hun Choi, Soo-Kyung Jun, Yu-Bin Kim, Young-Seon Ju, and Kyounggon Kim. "Building UI/UX Dataset for Dark Pattern Detection and YOLOv12x-based Real-Time Object Recognition Detection System." arXiv preprint arXiv:2512.18269 (2025).

Alhuwayshil, Sarah, Sundaresan Ramachandran, and Kyounggon Kim. "Enhancing Ransomware Threat Detection: Risk-Aware Classification via Windows API Call Analysis and Hybrid ML/DL Models." Journal of Cybersecurity and Privacy 5, no. 4 (2025): 96.

Hong, Jiwon, Hyeongmin Kim, Suhyeon Oh, Yerin Im, Hyeonseong Jeong, Hyunmin Kim, Eunkueng Jang, and Kyounggon Kim. "Combating phishing and script-based attacks: a novel machine learning framework for improved client-side security: J. Hong et al." The Journal of Supercomputing 81, no. 1 (2025): 69.

Kim, Hyunmin, InSeok Kim, and Kyounggon Kim. "AIBFT: artificial intelligence browser forensic toolkit." Forensic Science International: Digital Investigation 36 (2021): 301091.

 

Offensive Cybersecurity and Cyber Attacks 

Lee, Seongmin, Yonghun No, Juwon Cho, Guckhyeon Jin, Jeongho Kim, Jeongmin Lee, Sanghyun Jeon, Faisal Abdulaziz Alfouzan, and Kyounggon Kim. "Securing Maritime Autonomous Surface Ships: Cyber Threat Scenarios and Testbed Validation." IEEE Access 13 (2025): 10311-10325.

Kim, Kyounggon, Istabraq Mohammed Alshenaifi, Sundaresan Ramachandran, Jisu Kim, Tanveer Zia, and Abdulrazaq Almorjan. "Cybersecurity and cyber forensics for smart cities: A comprehensive literature review and survey." Sensors 23, no. 7 (2023): 3681.

Kim, Hee Yeon, Ji Hoon Kim, Ho Kyun Oh, Beom Jin Lee, Si Woo Mun, Jeong Hoon Shin, and Kyounggon Kim. "DAPP: automatic detection and analysis of prototype pollution vulnerability in Node. js modules." International Journal of Information Security 21, no. 1 (2022): 1-23.

Kim, Kyounggon, Faisal Abdulaziz Alfouzan, and Huykang Kim. "Cyber-attack scoring model based on the offensive cybersecurity framework." Applied Sciences 11, no. 16 (2021): 7738.

Lee, GyungMin, ShinWoo Shim, ByoungMo Cho, TaeKyu Kim, and Kyounggon Kim. "Fileless cyberattacks: Analysis and classification." Etri Journal 43, no. 2 (2021): 332-343.

Kim, Kyounggon, Jun Seok Kim, Seonghoon Jeong, Jo-Hee Park, and Huy Kang Kim. "Cybersecurity for autonomous vehicles: Review of attacks and defense." Computers & security 103 (2021): 102150.

Kim, Kyounggon, Kiyoon Cho, Jihwan Lim, Young Ho Jung, Min Seok Sung, Seong Beom Kim, and Huy Kang Kim. "What’s your protocol: Vulnerabilities and security threats related to Z-Wave protocol." Pervasive and Mobile Computing 66 (2020): 101211.

Ji-Young, Kong, Lim Jong In, and Kim Kyoung Gon. "The all-purpose sword: North Korea's cyber operations and strategies." In 2019 11th International Conference on Cyber Conflict (CyCon), vol. 900, pp. 1-20. IEEE, 2019.

 

Ransomware 

Mostafa, Moallim, Seokhee Lee, Ibrahim Alzahrani, Faisal Abdulaziz Alfouzan, and Kim Kyounggon. "AI-Amplification Indicator: An Actor-Level Scoring Framework for Ransomware Operations on the Dark Web." Journal of Cybersecurity and Privacy 6, no. 2 (2026): 70.

Ransomware Trends Report in Arab Countries 2025

Kim, Kyounggon, Seokhee Lee, Sundaresan Ramachandran, and Ibrahim Alzahrani. "Cryptocurrency-driven ransomware syndicates operating on the darknet: A focused examination of the Arab world." Egyptian Informatics Journal 30 (2025): 100665.

Almorjan, Abdulrazaq, Kyounggon Kim, and Norah Alilwit. Nauss ransomware trends report in Arab countries 2020-2022. جامعة نايف العربية للعلوم الأمنية, 2023.‎

Ramachandran, Sundaresan, Jeet Rami, Abhinav Shah, Kyounggon Kim, and Digvijaysinh Mahendrasinh Rathod. "Defence against crypto-ransomware families using dynamic binary instrumentation and DLL injection." International Journal of Electronic Security and Digital Forensics 15, no. 4 (2023): 424-442.

Lee, Suhyeon, Huy Kang Kim, and Kyounggon Kim. "Ransomware protection using the moving target defense perspective." Computers & Electrical Engineering 78 (2019): 288-299.

 

Threat Modeling and CTI

Jung, Sehee, Haeun Lee, Sungjin Kim, Sangyoon Lee, and Kyounggon Kim. "STRIDE‐Based Threat Modeling for Smart Hazard Analysis and Critical Control Points in the Korean Food Industry." Systems Engineering (2026): e70045.

Kim, ChaeYoung, and Kyounggon Kim. "Poster: FORESIGHT, A Unified Framework for Threat Modeling and Risk Assessment in Robotics and IoT." NDSS Symposium (2025)

Lee, Seongmin, Yonghun No, Juwon Cho, Guckhyeon Jin, Jeongho Kim, Jeongmin Lee, Sanghyun Jeon, Faisal Abdulaziz Alfouzan, and Kyounggon Kim. "Securing Maritime Autonomous Surface Ships: Cyber Threat Scenarios and Testbed Validation." IEEE Access 13 (2025): 10311-10325.

Lee, Seokhee, Aisha Abdu Hassan Mujammami, and Kyounggon Kim. "Leveraging Social Networks for Cyber Threat Intelligence: Analyzing Attack Trends and TTPs in the Arab World." IEEE Access 13 (2024): 5679-5693.

Alzahrani, Ibrahim Yahya, Seokhee Lee, and Kyounggon Kim. "Enhancing cyber-threat intelligence in the Arab world: Leveraging IoC and MISP integration." Electronics 13, no. 13 (2024): 2526.

Kim, Kyoung Ho, Kyounggon Kim, and Huy Kang Kim. "STRIDE‐based threat modeling and DREAD evaluation for the distributed control system in the oil refinery." ETRI Journal 44, no. 6 (2022): 991-1003.

Cho, So-Hyeon, Dong-Seok Kang, Min-Song Kang, Hyeon-Soo Kim, Jin-Woong Bae, Chung-Il Lee, Han-Byeol Ji, Yo-Han Won, Hyeon-Kyeong Hong, and Kyounggon Kim. "A study on threat modeling in smart greenhouses." Journal of Information Security and Cybercrimes Research 3, no. 1 (2020): 1-12.

Oh, In-Kyung, Jae-Wan Seo, Min-Kyu Lee, Tae-Hoon Lee, Yu-Na Han, Ui-Seong Park, Han-Byeol Ji, Jong-Ho Lee, Kyu-Hyung Cho, and Kyounggon Kim. "Derivation of security requirements of smart TV based on STRIDE threat modeling." Journal of The Korea Institute of Information Security & Cryptology 30, no. 2 (2020): 213-230.

 

 

Research and Development projects

Network Forensics [Mind Map]

 

2019

  • A Study on the System and Information Security Technology for the Use of CDM for Public Interest
    • Development of information security management system and level of protection and verification tools based on the legal system in the medical field for the utilization of multi-institutional CDM.
    • Project period: 2019.09 ~ 2021.12. 
    • Funding institution: Ministry of Health and Welfare
    • Research institution: Korea University
  • A Study of Classification and Similarity for Fileless cyberattack 
    • Project period: 2019.04 ~ 2019.12.
    • Funding institution: LIG Nex1
    • Research institution: Korea University 

  • Security Vulnerability Response Law Improvement Study Group
    • Project period: 2019.09 ~ 2019.11.
    • Funding institution: Korea Internet & Security Agency (KISA)

  • Automatic Analysis for NodeJS Modules
    • Project period: 2019.09 ~ 2019.12.
    • Funding institution: Korea Information Technology Research Institute (KITRI)
    • Research institution: KITRI BoB (Best of Best Program)
    • Reporting vulnerability: CVE-2019-17592

2018

  • Z-Wave security vulnerability research 
    • Project period: 2018.09 ~ 2018.12. 
    • Funding institution: Korea Information Technology Research Institute (KITRI)
    • Research institution: KITRI BoB (Best of Best Program)
    • Reporting vulnerability: CVE-2018-19983