SPCA: Stream Parser Confusion Attack for Web Application Firewall Evasion in HTTP/2
Kyungrok Choi*, Woonghee Lee*, Junbeom Hur
* Equal contributionWeb + Mobile Security Researcher
I’m Woonghee Lee (이웅희), a Ph.D. candidate at Korea University’s Information System Security Lab. I measure how real-world web and mobile systems diverge from their security assumptions.
01 / Publications
Peer-reviewed research in leading web and security venues. My name is highlighted.
Kyungrok Choi*, Woonghee Lee*, Junbeom Hur
* Equal contributionWoonghee Lee, Junbeom Hur, Hyunsoo Kwon
Woonghee Lee, Junbeom Hur, Doowon Kim
Yoonjung Choi*, Woonghee Lee*, Junbeom Hur
* Equal contributionHyejin Lee, Woonghee Lee, Kyungrok Choi, Junbeom Hur
Woonghee Lee, Donghee Kim, Junbeom Hur
Yeomin Jeong, Woonghee Lee, Junbeom Hur
02 / Experience & academic life
Research experience, talks, awards, and service beyond peer-reviewed publications.
ACM CCS · Taipei, Taiwan
Ph.D. Job Talk · SWCS · Seoul
ACM ASIACCS · Singapore
The ACM Web Conference · Singapore
Outstanding Award, National Cryptographic Competition
Korea University College of Informatics · Spring & Fall
The Web Conference (WWW)
Discrete Mathematics · Information Security
03 / Responsible disclosure
Coordinated disclosure of our HTTP/2 request-body inspection findings led to two CVE assignments for AWS WAF deployments.
AWS acknowledged Kyungrok Choi, Woonghee Lee, and Junbeom Hur for the coordinated vulnerability disclosure.
AWS security bulletin04 / Research focus
I study the gap between systems as designed and systems in the wild—measuring security failures across browsers, mobile ecosystems, phishing, and web infrastructure.
Testing whether embedded browsing surfaces preserve the trust guarantees users expect from the open web.
Studying phishing kits, shared scripts, infrastructure, and evasion techniques through large-scale measurements.
Following sensitive data across apps, in-app browsers, WebViews, and the third-party SDKs connecting them.
Analyzing security boundaries and unexpected interactions among CAPTCHAs, WAFs, CDNs, and modern protocols.
05 / Contact
Interested in collaboration around web security, mobile ecosystems, or large-scale security measurement? I’d be glad to hear from you.