송주현 (juhyun167)
Education
-
M.S. in Electrical Engineering (Sep. 2024 - Present)
- Advisor: Insu Yun
- KAIST, Daejeon, Korea
-
B.S. in Computer Science (Mar. 2018 - Aug. 2024)
- Korea University, Seoul, Korea
Experience
-
Security Research Intern (Mar. 2023 - Jun. 2023)
- Samsung Electronics
-
Cyber Operations Specialist (Aug. 2021 - Feb. 2023)
- Republic of Korea Army
-
Vulnerability Assessment Trainee (Jul. 2020 - Mar. 2021)
- Best of the BEST 9th, KITRI
- Ranked in the top 10 contestants. (Hall of Fame)
Talks
- Towards Comprehensive Fuzzing of TrustZone TAs
- .HACK Conference 2024, Seoul, Korea (Slide)
Publications
International Journal
- DTA: Run TrustZone TAs Outside the Secure World for Security Testing
- Juhyun Song, Eunji Jo, and Jaehyu Kim
- IEEE Access, January 2024
Projects
- Fuzzing I/O communications in Windows device drivers (Sep. 2020 - Dec. 2020)
- Contributed to Kronl fuzzer development and found 20+ vulnerabilities.
Honors and Awards
-
FIESTA: Finantial Institutes’ Event on Security Threat Analysis (2023)
- 3rd place (Team xerophthalmia)
-
MIST Minister Prize (2021)
- Selected for KITRI Best of the Best 9th top 10 contestants. (prize reward 10M KRW)
Vulnerability Disclosure
-
CVE-2021-27965 (collective work)
- Privilege escalation in MSI Dragon Center
-
KVE-2020-1585, KVE-2020-1604 (collective work)
- Privilege escalation in T* gaming software and N* keyboard security solution. (Reported to KISA bug bounty)
-
NBB-1705
- Stored XSS in kin.naver.com (Reported to Naver bug bounty)
Certifications
- Craftsman Bartender (2024)
- National Certification, HRDK, Korea