We advance least-privilege and zero-trust security through three complementary research directions: cloud-native workload protection, efficient systems-level enforcement, and intelligent security policy engineering.
We investigate security risks arising from workload identities, permissions, and service interactions in cloud-native applications. Focusing on Kubernetes orchestration and serverless execution chains, we develop protections against privilege abuse and authorization bypass across service boundaries.
Kubernetes orchestration and workload-identity security
Serverless IAM and function-chain authorization
Cross-service trust boundaries and privilege propagation
We design mechanisms that monitor and constrain execution at the operating-system and network data-plane layers. Using eBPF, LSM, XDP, and SmartNICs, we investigate how to intercept security-relevant operations, strengthen workload isolation, and enforce runtime restrictions with low overhead.
Stateful system-call filtering and process isolation
Confidential computing for containers and virtual machines
Programmable packet processing and security offloading
We automate the construction and maintenance of security policies from user intent, program semantics, and runtime evidence. Combining program analysis with NLP, LLMs, and agentic AI, we generate and translate policies, identify conflicts, and verify whether policies reflect intended access requirements as systems evolve.
Intent and context-aware policy generation and permission inference
Cross-platform policy translation and semantic consistency
Policy conflict detection, verification, and adaptation
"Design and Implementation of an Intelligent Centralized Security Policy Control System for Zero Trust in Cloud-Native Environments," National Research Foundation of Korea (NRF), Principal Investigator, Sep.2025-Aug.2028 (ongoing)
"The Development of Darkweb Hidden Service Identification and Real IP Trace Technology," Institute for Information & Communications Technology Planning & Evaluation (IITP), Co-Principal Investigator, Apr.2022-Dec.2025 (completed)
"Design and implementation of security-enhanced intelligent container network systems for secure cloud environment," National Research Foundation of Korea (NRF), Principal Investigator, Mar.2022-Feb.2025 (completed)