We conduct research and develop technologies aimed at enhancing the security of the universal interface—the Web. Our goal is to proactively detect and report web threats through cutting-edge techniques such as penetration testing, fuzz testing, static analysis, and artificial intelligence.
Web browsers are the trusted foundation on which billions of people run untrusted code every day. We study whether that trust is justified—analyzing the security mechanisms of browsers and the web platform, and building automated techniques that uncover flaws in their design and implementation.
Most of the software people rely on every day now runs on the Web. We develop techniques to discover, analyze, and eliminate vulnerabilities in web applications and their execution environments at scale, combining automated testing, program analysis, and attacker-driven insight.
The web economy runs on user data—and criminals exploit the same channels. We investigate how people are tracked, deceived, and defrauded online, and design robust defenses that detect and disrupt these threats in the wild.
AI systems are becoming a new interface to the Web—and a new attack surface. We work in both directions: security for AI, protecting AI agents from emerging threats such as prompt injection and jailbreaking, and AI for security, harnessing AI to strengthen security testing, vulnerability analysis, and automated defense.
© WebSec Lab @ UNIST. All Rights Reserved.