Software Security Research Group

Software Security Lab (SoftSec) is a research lab in the Sungkyunkwan University that focuses on improving the security of real-world systems such as Android, Blockchain, Automotive, and Cloud. For this, we develop automated techniques for finding new vulnerabilities and methodologies for helping programmers to develop secure systems. To achieve our goal, we use techniques in software engineering, programming language, and security fields.

We are interested in the following research fields.

  • Hacking. We study hacking techniques and analyze systems to find new vulnerabilities.
  • Security Development Lifecycle (SDL). We research SDL to help developers to build secure systems.
  • Program Analysis & Testing. We develop tools and frameworks that find vulnerabilities in software automatically. Recently, we developed static analyzers for blockchain and Android and a dynamic testing framework for JVMs.
  • Empirical Security. We collect datasets and analyze data to understand problems in real-world systems. Recently, we conducted empirical security research on software running on the blockchain platform.

Joining the Lab
We are actively recruiting motivated graduate/undergraduate students and postdoctoral researchers.

대학원생, 학부연구생, 포닥 연구원을 모집중입니다.

자동차, 안드로이드, 블록체인, 클라우드와 같은 4차산업 시대에 핵심이라고 볼 수 있는 시스템에서 새로운 보안 문제를 찾고 해결하는 연구를 진행하고 있습니다. 구체적으로, 저희 연구실에서는 1) 해킹 기술을 활용하여 시스템에 새로운 보안 문제를 찾는 연구. 2) 소프트웨어 테스팅 및 프로그램 분석 기술을 활용하여 소프트웨어에 존재하는 보안 취약점을 자동으로 찾는 연구. 3) 실증 연구를 통해 실제 데이터를 기반으로 시스템/소프트웨어의 보안 수준을 파악하는 연구. 4) 보안 개발 방법론 (SDL)에 대한 연구. 5) 머신러닝 알고리즘을 활용하여 공격을 탐지하는 연구를 진행하고 있습니다.

관심있는 학생들의 많은 지원 부탁드립니다. email: sungjaeh@skku.edu

News

Jan. 01, 2026

Unveiling the Underground Phishing Ecosystem: A 12-Year Longitudinal Study of Deep and Dark Web Forums, has been accepted to WWW 2026

Dec. 23, 2025

OCPPuzz: Specification-driven Fuzzing of Charging Station Management Systems with Large Language Model, has been accpeted to FSE 2026

Dec. 15, 2025

A Deep Dive into Function Inlining and its Security Implications for ML-based Binary Analysis, has been accepted to NDSS 2026

Dec. 01, 2025

From Rules to LLM-Enhanced Templates: A Hybrid ALPG Code Generation System, has been accepted to ICSE SEIP 2026

Nov. 21, 2024

The paper, All You Need is Attention: Lightweight Attention-based Data Augmentation for Text Classification, has been accepted to EMNLP-Findings 2024

Feb. 23, 2024

The paper, An Empirical Study of JVMs’ Behaviors on Erroneous JNI Interoperations, has been accepted to IEEE Transactions on Software Engineering (TSE)

January. 23, 2024

The paper, R2I: A Relative Readability Metric for Decompiled Code, has been accepted to FSE 2024

September. 22, 2023

The paper, RT-Blockchain:Achieving Time-Predictable Transactions, has been accepted to RTSS 2023

... see all News