Kookmin People

Winner of the Best Paper Award at the 2026 Korea Computer Science Conference / Research Team Led by Professor Lim Se-Min (Department of Artificial Intelligence)

  • 26.09.21 / 홍유민
Date 2026-09-21 Hit 16

“Rule Management and Runtime Update Framework for a 100GbE FPGA-Based Packet Inspection System,” authored by the SATA Lab in the Department of Software Engineering at Kookmin University’s College of Software Convergence (President Jeong Seung Ryul), undergraduate student Park Sang-jun, and Professor Lim Se-min, was honored with the Outstanding Paper Award in the Undergraduate/Junior Paper Competition category at the 2026 Korea Computer Conference (KCC2026), organized by the Korean Information Science Society—the nation’s largest academic conference in the field of computer science—held at the Jeju International Convention Center from June 24 to 26. The award-winning paper addresses technology for dynamically replacing defense rules in ultra-high-speed network security devices during operation.
 
Hackers do not wait for security updates to complete. This research went beyond the question of “how quickly can we scan?” to focus on how to modify defense rules while continuing the scanning process. The key lies in treating the rules not as elements tied to a fixed hardware configuration, but as data that can be replaced on the fly.
To achieve this, “two layers of defense” were implemented within an FPGA chip. While one storage area supports scanning with the current rules, the other loads and verifies new rules. Once ready, the filters, patterns, and processing information associated with the rules are switched over all at once to prevent the old and new rules from getting mixed up. If the previous rules remain in the other storage area, the system can revert to that version.
 
The research team evaluated a prototype supporting approximately 65,000 normalized rules on an AMD/Xilinx Alveo U50. The entire setup process, including rule preparation, took 214.4 milliseconds, while activating new rules after loading and verification took approximately 15 microseconds (0.000015 seconds). This separates the time-consuming preparation phase from the moment of actual application. The two rule repositories totaled 12.66 MiB and utilized only the FPGA’s internal memory, without HBM or external DRAM.
 
Park Sang-jun, the paper’s first author, said, “We expect this to be applicable to intrusion detection and prevention systems in the cloud and data centers, as well as FPGA-based network security devices.” He added, “It also has potential for the deployment and management of security policies, allowing defense rules to be rapidly applied in response to new attack patterns and restored to previous versions if problems arise.”

This content is translated from Korean to English using the AI translation service DeepL and may contain translation errors such as jargon/pronouns.

If you find any, please send your feedback to kookminpr@kookmin.ac.kr so we can correct them.

 

View original article [click]

Winner of the Best Paper Award at the 2026 Korea Computer Science Conference / Research Team Led by Professor Lim Se-Min (Department of Artificial Intelligence)

Date 2026-09-21 Hit 16

“Rule Management and Runtime Update Framework for a 100GbE FPGA-Based Packet Inspection System,” authored by the SATA Lab in the Department of Software Engineering at Kookmin University’s College of Software Convergence (President Jeong Seung Ryul), undergraduate student Park Sang-jun, and Professor Lim Se-min, was honored with the Outstanding Paper Award in the Undergraduate/Junior Paper Competition category at the 2026 Korea Computer Conference (KCC2026), organized by the Korean Information Science Society—the nation’s largest academic conference in the field of computer science—held at the Jeju International Convention Center from June 24 to 26. The award-winning paper addresses technology for dynamically replacing defense rules in ultra-high-speed network security devices during operation.
 
Hackers do not wait for security updates to complete. This research went beyond the question of “how quickly can we scan?” to focus on how to modify defense rules while continuing the scanning process. The key lies in treating the rules not as elements tied to a fixed hardware configuration, but as data that can be replaced on the fly.
To achieve this, “two layers of defense” were implemented within an FPGA chip. While one storage area supports scanning with the current rules, the other loads and verifies new rules. Once ready, the filters, patterns, and processing information associated with the rules are switched over all at once to prevent the old and new rules from getting mixed up. If the previous rules remain in the other storage area, the system can revert to that version.
 
The research team evaluated a prototype supporting approximately 65,000 normalized rules on an AMD/Xilinx Alveo U50. The entire setup process, including rule preparation, took 214.4 milliseconds, while activating new rules after loading and verification took approximately 15 microseconds (0.000015 seconds). This separates the time-consuming preparation phase from the moment of actual application. The two rule repositories totaled 12.66 MiB and utilized only the FPGA’s internal memory, without HBM or external DRAM.
 
Park Sang-jun, the paper’s first author, said, “We expect this to be applicable to intrusion detection and prevention systems in the cloud and data centers, as well as FPGA-based network security devices.” He added, “It also has potential for the deployment and management of security policies, allowing defense rules to be rapidly applied in response to new attack patterns and restored to previous versions if problems arise.”

This content is translated from Korean to English using the AI translation service DeepL and may contain translation errors such as jargon/pronouns.

If you find any, please send your feedback to kookminpr@kookmin.ac.kr so we can correct them.

 

View original article [click]

TOP