UNIST UNIST

ADMISSIONS

Giving UNIST Bulletin
Open mobile menu
 

UNIST site map

Close All menus
STUDENT
 
NEWS CENTER

NEWS CENTER

Discover not only Research Findings and event news, but also the diverse facets of UNIST presented by reporters and writers.

UNIST News

UNIST Earns Korea's First Internet Defense Prize at USENIX Security

Professor Seongil Wi's team uncovers 35 security bugs in six major browsers with BUIzz, while earning additional recognition for the paper.

  • Community
  • JooHyeon Heo
  • 2026.08.27
  • 3034

UNIST Earns Korea's First Internet Defense Prize at USENIX Security

A browser-security system, developed by Professor Seongil Wi of the Department of Computer Science and Engineering at UNIST, has received the Internet Defense Prize  at the 2026 USENIX Security Symposium, marking the first time a Korean institution has won the Meta-funded award.


The system, BUIzz, found 35 security bugs and three functional bugs across six major web browsers, including Chrome, Firefox, and Edge. Unlike conventional approaches that largely examine what happens within webpages, BUizz looks for vulnerabilities that emerge as people interact with the browser itself. 


Opening a link in a new tab or split view, dragging it to the address bar, or reopening a closed tab may seem routine. But these actions can expose inconsistencies in how browsers enforce security rules. In some cases, sensitive login cookies may be sent to external sites or malicious scripts may run when they should be blocked, putting account information and browsing data at risk. 


BUizz automatically simulates these interactions and checks whether browser protections continue to work as intended. The researchers reported the vulnerabilities they found to browser vendors and received $14,700 in bug bounties last year. 


Professor Wi and Mingi Jung, a master's student and first author of the paper, donated KRW 10 million from the proceeds to UNIST's Department of Computer Science and Engineering.


The work was presented at the 35th USENIX Security Symposium, one of the world's leading conferences in computer security, held August 12–14 in Baltimore, Maryland. This year, 362 papers were accepted from 3,028 submissions, an acceptance rate of about 12 percent.


Funded by Meta, the Internet Defense Prize has recognized research with the potential to improve internet security in practice since 2014. Three papers received the prize this year, with the UNIST team receiving a $25,000 gift award in research support.


The paper, “BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface,” also received runner-up recognition for the Distinguished Paper Award, reflecting the work's research contribution alongside its practical impact.


“Previous browser-security research has largely focused on problems within webpages,” Jung said. “We looked instead at vulnerabilities that emerge through the way people actually use browsers, such as opening and closing tabs or moving links between windows.”


“For us, the value of security research goes beyond publication—it lies in solving real-world problems,” Professor Wi said. “We will continue working on practical security and safety challenges in web browsers and artificial intelligence.”


The research was conducted with Professor Mijung Kim and Donggyu Kim of the Department of Computer Science and Engineering at UNIST. It was supported by the National Research Foundation of Korea (NRF) and the Institute of Information & Communications Technology Planning & Evaluation (IITP).