Nariyoshi Yamai

dblp:02/5133 · DBLP profile ↗
← Back
23ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0003-2651-2701ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 14 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 1 first-author · 4 since 2021Computer networks · 3 · 1 first-authorSecurity and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Concept of HAOpsSC: Toward Decentralized Operations for Ensuring High Availability in Consortium Blockchain-based Systems
Tatsuya Sato, Taku Shimosawa, Nariyoshi Yamai
ICBC3
2024 Suggestion of JP Zone Authoritative DNS Server Locations by Country Analysis of Query IP Address
abstract
IP anycast is a technology that assigns a common IP address to multiple devices on the Internet. With the recent development of the Internet, the use of anycast technology in the operation of authoritative DNS servers is crucial to ensure stability, reliability, and accessibility. The main objective of IP anycast is to reduce response time for DNS queries. However, in the multisite deployment of anycast, there are many cases where the traffic distribution anticipated for fast query response is not achieved even after the installation of new sites. This paper focuses on the number of hops of DNS queries and makes suggestions to encourage domestic processing of DNS queries sent from within the country for a fast response time. As a result, the domestic consumption rate in the Netherlands is below 70% and the network has room for improvement. And adding a node for JP zone authoritative DNS server in Ireland, where there are many queries to the German and UK nodes, would improve the effectiveness of anycasting.
Katsuya Sugizaki, Rei Nakagawa, Nariyoshi Yamai, Shinta Sato, Takeshi Mitamura
APCC3
2024 Privacy Preserved Achievement Method for OCSP Status and Supported Protocols in Full-DoH Architecture
abstract
Currently, efforts to protect privacy information through encrypted DNS communications are becoming increasingly active. The encryption of DNS, standardized by the IETF, predominantly uses TLS. However, the use of TLS for encrypting DNS communications results in the leakage of privacy information during the certificate revocation process. This paper proposes a new method for certificate revocation verification in encrypted DNS communications, presents a way to enhance the protection of privacy information, and outlines a research plan for further investigation.
Satoru Sunahara, Yong Jin 0001, Katsuyoshi Iida, Nariyoshi Yamai, Yoshiaki Takai
COMPSAC4
2023 Trustworthy Name Resolution Using TLS Certificates with DoT-enabled Authoritative DNS Servers
abstract
The Domain Name System (DNS) plays an important and indispensable role in supporting the modern Internet. Meanwhile, if the DNS message is not encrypted anyway, malicious third parties can exploit the communication channel and cause phishing scams and malware infection. Several countermeasures against this issue already exist, such as Domain Name System Security Extensions (DNSSEC), which guarantees the validity of DNS resource records by adding digital signatures to the DNS messages, and DNS over TLS (DoT), which encrypts a part of the communication channel of domain name resolution process. However, each of these solutions has its own merit and demerit, and neither of them has been implemented on a global scale. Therefore, in this paper, a trustworthy domain name resolution method using TLS certificates with DoT-enabled authoritative DNS servers is proposed. Specifically, the DoT-based name resolution is extended to authoritative DNS servers and the certificate validation is allowed on the end terminals. Moreover, the domain name resolution process is accelerated by obtaining the certificates on the end terminal via the DNS full-service resolver. The evaluation results confirmed that the prototype system worked as designed and it is expected to provide trustworthy domain name resolution service with privacy preservation.
Toshio Murakami, Kenta Shimabukuro, Nao Sato, Rei Nakagawa, Yong Jin 0001, Nariyoshi Yamai
COMPSAC6
2023 BillingOpsSC: Smart Contract-based Service Billing Management Method for Consortium Blockchain-based Systems
abstract
Enterprises have paid attention to consortium blockchains, in which multiple authorized organizations participate to form a consortium, in contrast to public blockchains, which consist of unspecified participants. Since a system using a blockchain is based on participants providing/using resources such as nodes to each other, a mechanism to motivate participants to provide resources is important. Typically, a public blockchain realizes an incentive mechanism for providing nodes by unspecified participants through mining rewards and transaction fees associated with a consensus algorithm such as PoW on the platform layer. On the other hand, a consortium blockchain usually does not have an incentive mechanism in the platform itself. In order to maintain and operate a consortium, it is essential that participating organizations provide resources or pay the costs of providing resources. However, because participating organizations use different percentages of the resources, a uniform fee could cause unfairness among the organizations. Therefore, it is necessary to manage billing to remove the gap between the costs borne and the actual usage or/and the unfairness among participants in the consortium. This research aims to realize a billing management method for consortium blockchain-based systems. We propose a smart contract-based service billing management mechanism named "BillingOpsSC" to ensure cross-organizational transparency for billing calculation and management. Furthermore, to ensure fairness among participants, we design a billing calculation model based on metering of the "contribution" by each organization such as providing resources, and the system "usage" by each organization, in the consortium. We implement a prototype of the proposed method including the billing management mechanism and calculation model for Hyperledger Fabric, which is one of the major consortium blockchains, and evaluate the method using the prototype. The results show that our proposed method is effective in ensuring transparency and fairness in billing management among multiple organizations.
Tatsuya Sato, Taku Shimosawa, Nariyoshi Yamai
COMPSAC3
2023 Verification Method of Associated Domain Names Using Certificates by Applying DNS over TLS to Authoritative Servers
abstract
DNS over Transport Layer Security (DoT) has been standardized in the Domain Name System (DNS) to protect the confidentiality of communications between stub resolvers and recursive resolvers. In addition, the standardization for introducing encrypted communication between recursive resolvers and authoritative servers is in progress in IETF. In this paper, we assume that authoritative servers have X.509 certificates to support DoT and propose a mechanism that enables users to determine whether or not a domain name that is similar to or closely associated with a legitimate domain name (possibly a "cousin domain") is actually associated with it.
Nariyoshi Yamai, Yong Jin 0001, Toshio Murakami, Rei Nakagawa
COMPSAC1
2020 A Detour Strategy for Visiting Phishing URLs Based on Dynamic DNS Response Policy Zone
abstract
Email based Uniform Resource Locator (URL) distribution is one of the popular ways for starting phishing attacks. Conventional anti-phishing solutions rely on security facilities and investigate all incoming emails. This makes the security facilities get overloaded and cause consequences of upgrades or new deployments even with no better options. This paper presents a novel detour strategy for the traffic of visiting potential phishing URLs based on dynamic Domain Name System (DNS) Response Policy Zone (RPZ) in order to mitigate the overloads on security facilities. In the strategy, the URLs included in the incoming emails will be extracted and the corresponding Fully Qualified Domain Name (FQDN) will be registered in the RPZ of the local DNS cache server with mapping the IP address of a special Hypertext Transfer Protocol (HTTP) proxy. The contribution of the approach is to avoid heavy investigations on all incoming emails and mitigate the overloads on security facilities by directing the traffic to phishing URLs to the special HTTP proxy connected with a set of security facilities conducting various inspections. The evaluation results on the prototype system showed that the URL extraction and FQDN registration were finished before the emails had been delivered and accesses to the URLs were successfully directed to the special HTTP proxy. The results of overhead measurements also confirmed that the proposed strategy only affected the internal email server with 11% of performance decrease on the prototype system.
Yong Jin 0001, Masahiko Tomoishi, Nariyoshi Yamai
ISNCC3
2019 A Traffic Distribution System Among Multiple Terminals Using MPTCP in Multihomed Network Environment
abstract
Mobile terminals usually have access to the Internet via a wireless station such as a Wi-Fi access point (AP). If the number of such terminals connected to the same station/AP increases, their throughput decreases because they share bandwidth of the station/AP. To solve this problem, some traffic distribution mechanism among terminals is necessary. In this paper, we propose a dynamic traffic distribution system among multiple mobile terminals connecting to the Internet via a special VPN server with MultiPath TCP (MPTCP). In this scheme, the VPN server keeps track of conditions of all stations/APs and switches some paths between the VPN server and some terminals accordingly. Simulation experiments shows that the proposed method can distribute traffic among multiple terminals effectively.
Ryuji Asakura, Reido Horigome, Nariyoshi Yamai, Naoya Kitagawa, Satoshi Ohzahata
COMPSAC (1)3
2019 Spam Domain Detection Method Using Active DNS Data and E-Mail Reception Log
abstract
E-mail is widespread and an essential communication technology in modern times. Since e-mail has problems with spam mails and spoofed e-mails, countermeasures are required. Although SPF, DKIM and DMARC have been proposed as sender domain authentication, these mechanisms cannot detect non-spoofing spam mails. To overcome this issue, this paper proposes a method to detect spam domains by supervised learning with features extracted from e-mail reception log and active DNS data, such as the result of Sender Authentication, the Sender IP address, the number of each DNS record, and so on. As a result of the experiment, our method can detect spam domains with 88.09% accuracy and 97.11% precision. We confirmed that our method can detect spam domains with detection accuracy 19.40% higher than the previous study by utilizing not only active DNS data but also e-mail reception log in combination.
Kenya Dan, Naoya Kitagawa, Shuji Sakuraba, Nariyoshi Yamai
COMPSAC (1)4
2018 Throughput Improvement of MPTCP by Selective Bicasting with Cross-Layer Control in Wireless Environment
abstract
A mobile device equipped with multiple wireless network interfaces has capability to improve throughput and availability by means of Multipath TCP (MPTCP) communication with alternating the primary (active) interface according to the current wireless network condition. To realize this ability, we proposed MPTCP selective bicasting which bicasts only retransmission request packets and retransmission packets. However, this method as a problem that it would not improve throughput so much when the condition of wireless communication deteriorates since it bicasts packets only after the transport layer detects packet losses. In this paper, we propose a method to improve throughput which bicasts packets before the transport layer detects packet losses by means of cross-layer control. Based on the frame loss rate in the data link layer, this method sends dropping packets via the alternative interface earlier than the previous method. Simulation results shows that the proposed method improves throughput without sending so many packets via the alternative interface.
Masami Fukuyama, Nariyoshi Yamai, Satoshi Ohzahata, Naoya Kitagawa
COMPSAC (2)2
2018 Alternating Primary Subflow in MPTCP by External Program without Kernel Modification
abstract
When users's terminals with multiple wireless network interfaces such as Wi-Fi and LTE have access to the Internet, traffic congestion often occurs since many of them use the same Access Point (AP) of Wi-Fi network for example. To migigate this congestion, we consider a network configuration that can perform dynamic traffic shaing with special VPN servers communicating with users' terminal through Multipath TCP (MPTCP). These VPN servers have a function than can select a primary subflow for each terminal dynamically according to the current conditions of APS. However, implementation of this function into server program reduces software maintainability and increases implementation cost. In this paper, we propose a subflow switching method using an external program to solve these problems. With this program, the VPN server can switch the primary subflows without modification.
Reido Horigome, Nariyoshi Yamai, Naoya Kitagawa, Satoshi Ohzahata
COMPSAC (1)2
2018 Message from the NCIW Program Co-chairs
abstract
Presents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record.
Behrooz A. Shirazi, Nariyoshi Yamai
COMPSAC (1)2
2018 Access Control Model for IoT Environment Including Automated Configuration
abstract
While the number of IoT devices continues increasing, proper access control of the device is important to protect user's privacy. To perform efficiently and unified access control for the IoT devices, there are several approaches utilizing OAuth have been proposed. However, OAuth is an authorization protocol which designed for use in web services, and the users need to perform pre-configuration and re-configuration tasks when utilizing OAuth in the IoT environment. Since previous access control approaches have not shown effective solutions to reduce these configuration tasks, it becomes burdens to the users and would be a barrier to introduce proper access management in the IoT environment. In this paper, we present an access control and management model for the IoT environment including automated configuration to solve the issues of conventional studies. The automated configuration registers devices and issues authentication information at the first time of connection instead of the user. In addition, the evaluation results show that our model has feasibility and reasonable resource consumption even when managing a large number of devices.
Kenta Yokogi, Naoya Kitagawa, Nariyoshi Yamai
COMPSAC (2)3
2018 A Client Based Anomaly Traffic Detection and Blocking Mechanism by Monitoring DNS Name Resolution with User Alerting Feature
abstract
Malware has become one of the most critical targets of network security solutions nowadays. Many types of malware receive further instructions from the C&C servers and the attack targets may be instructed by IP addresses which causes direct attacks without DNS name resolution from the malware-infected computers. In the meanwhile, several programs that are hidden from the users (e.g. malware, virus, etc.) may perform DNS name resolutions for cyber attacks or other communications. In this paper, we propose a client based anomaly traffic detection and blocking mechanism by monitoring DNS name resolution per application program. In the proposed mechanism, by the collaboration of DNS proxy and packet filter, DNS traffic is monitored on the client and the traffic destined to the IP addresses obtained without DNS name resolution or the traffic from unrecognized programs will be detected and blocked. In addition, in order to mitigate false positive detection, an alert-window will be shown to let the users decide whether to allow the traffic or not. We implemented a prototype system on a Windows 7 client and confirmed that the proposed mechanism worked as expected.
Yong Jin 0001, Kunitaka Kakoi, Nariyoshi Yamai, Naoya Kitagawa, Masahiko Tomoishi
CW3
2017 A Secure and Lightweight IoT Device Remote Monitoring and Control Mechanism Using DNS
abstract
Many reports predicted that the number of connected IoT (Internet of Things) devices will reach to billions in the next several years, accordingly, how to securely and effectively manage, monitor and control them becomes a critical problem. In conventional IoT solutions, direct SSL/TLS based HTTP connections to IoT devices with high overhead are required and encryption is not considered due to low computing capability and memory capacity of IoT devices. In this paper, we propose an integrated mechanism using DNS (Domain Name System) to accomplish the objective. In the proposed mechanism, names or IDs of IoT devices are managed by DNS server and the monitoring and control are conducted by the collaboration of DNS name resolution, DNS dynamic update and DNS zone transfer. Considering the security and privacy protection, the status and control command for IoT devices described in the corresponding DNS TXT records will be encrypted and TSIG (Transaction SIGnatures) will be used for authentication to restrict the clients allowed to monitor and control the IoT devices.
Yong Jin 0001, Masahiko Tomoishi, Nariyoshi Yamai
COMPSAC (2)3
2017 Cache Function Activation on a Client Based DNSSEC Validation and Alert System by Multithreading
abstract
Domain Name System (DNS) is one of the most important services of the Internet since most communications normally begin with domain name resolutions provided by DNS. However, DNS has vulnerability against some kind of attacks such as DNS spoofing, DNS cache poisoning, and so on. DNSSEC is an security extension of DNS to provide secure name resolution services by using digital signature based on public key cryptography. However, there are several problems with DNSSEC such as failing resolution in case of validation failure, increasing the load of DNS full resolver, and so on. To mitigate these problems, we proposed a Client Based DNSSEC Validation System. This system performs DNSSEC validation on the client, and in case of validation failure, it forwards the failed response and alerts the user to the fact. However, this system has a problem that it inactivates the cache function of validation library so that it always performs DNSSEC validation even for the same query. In this paper, we report how to solve this problem by multithreading of DNSSEC validation system.
Kunitaka Kakoi, Yong Jin 0001, Nariyoshi Yamai, Naoya Kitagawa, Masahiko Tomoishi
COMPSAC (2)3
2016 Joint bandwidth scheduling and routing method for large file transfer with time constraint
abstract
In recent years, the number of requests to transfer large files via large high-speed computer networks has been increasing rapidly. Typically, these requests are handled in the “best effort” manner and resulting in unpredictable completion times. In this paper, we consider a model where a transfer request either must be completed by a user-specified deadline or must be rejected if its deadline cannot be satisfied. We propose a bandwidth scheduling method and a routing method for reducing the call-blocking probability in a bandwidth-guaranteed network. Finally, we show their excellent performance by simulation experiments.
Masahiko Aihara, Shiori Kono, Kazuhiko Kinoshita, Nariyoshi Yamai, Takashi Watanabe 0001
NOMS4
2015 A distributed bandwidth assignment method for large file transfer with time constraints
abstract
As growing the size of digital contents, it is harder to predict the completion time of file transfer. This is an important problem particularly in a data migration at cloud computing. Therefore, some bandwidth assignment methods have been proposed in a model where a transfer request either must be completed by a specified deadline or must be rejected if the deadline cannot be satisfied. However, existing methods are not practical in a large scale network since they assume a centralized control. To overcome this problem, in this paper, we propose a distributed bandwidth assignment method without using global network information. Simulation results show that the proposed method achieves almost equal call-blocking probability to the existing centralized control method.
Kensuke Saito, Kazuhiko Kinoshita, Nariyoshi Yamai, Takashi Watanabe 0001
APNOMS3
2014 Performance Improvement of SCTP Communication Using Selective Bicasting on Lossy Multihoming Environment
abstract
In recent years, with proliferation of smart phones and tablet PCs, speedup of wireless LAN communication is required for dealing with increase of traffic in wireless networks. However, transmission speed through a wireless network often slows down in comparison with that through a wired network since packets of wireless networks frequently drop due to the influence of surrounding environment such as electromagnetic noise. In this paper, we propose a method to mitigate the impacts caused by packet loss by virtue of SCTP bicasting in lossy multihoming environment with two or more wireless networks. This method bicasts not all packets but only important packets concerning retransmission for efficiency since bicasting all packets would cause congestion. We also implemented a prototype system based on the proposed method. According to the result of performance evaluation experiment, we confirmed the effectiveness of the proposed method by the fact that the prototype system performed faster transmission than normal SCTP transmission even in high packet loss rate environment.
Koki Okamoto, Nariyoshi Yamai, Kiyohiko Okayama, Keita Kawano, Motonori Nakamura, Tokumi Yokohira
COMPSAC2
2009 A Cooperative Routing Method for Multiple Overlay Networks
abstract
When multiple overlay networks are constructed over the same underlying IP network, overlay paths on different overlay networks may share some links on the IP network. In general, however, because overlay networks do not recognize the existence of each other, they have no consideration on such shared physical links. In this paper, a cooperative routing method for multiple overlay networks is proposed to improve the throughput of all overlay networks.
Hiroki Okada 0003, Tran Nguyen Trung, Kazuhiko Kinoshita, Koso Murakami, Nariyoshi Yamai
CCNC5
2009 An efficient agent control method for information retrieval with time constraints
abstract
Multiagent systems for information retrieval over large-scale networks are considered an effective technology and have received much attention. In a typical case, such information retrieval has time constraints, since the network contains too much information. In this paper, we assume that each retrieval result can be scored and propose a method to control agent execution to improve the score of the result that each agent has acquired. This method terminates the agents that are less likely to be able to complete their tasks by a given deadline and/or to acquire the result of a higher score than that they have already obtained. Finally, simulation experiments show the excellent performance of the proposed method.
Yusuke Hara, Kazuhiko Kinoshita, Nariyoshi Yamai, Koso Murakami
ISADS3
2008 A distributed mobility management scheme for large-scale Mobile Networks
abstract
Recent advances in information and communication technology have let not only a single node but also an entire network (mobile network) move across the Internet. Many schemes providing route optimization function for mobile networks have already been proposed in recent years. A scheme using Hierarchical Mobile IPv6 (traditional scheme) is one of them. The traditional scheme, however, suffers from a significant number of simultaneous signaling messages as the number of Mobile Network Nodes (MNNs) and/or the number of their Correspondent Nodes (CNs) increase. This paper proposes a scheme to overcome this problem. The simulation results show that our scheme reduces the mean handover delay of MNNs compared to the traditional scheme.
Keita Kawano, Kazuhiko Kinoshita, Nariyoshi Yamai
LCN3
2001 A dynamic traffic sharing with minimal administration on multihomed networks
abstract
Multihomed network is one of the most efficient configuration to improve the response time of network services. However, it is hard to introduce or manage because the existing configuration methods have several problems in that they require much technical skill, involve administrative over-burden for the administrator and so on. In this paper, we propose a dynamic traffic sharing technique and suitable backbone selection metrics to address some of these problems. Using the proposed technique, an appropriate backbone can be selected per connection with minimal technical skill and low administrative cost. In addition, the proposed metrics performs more efficient traffic sharing as compared to others techniques that were investigated.
Nariyoshi Yamai, Kiyohiko Okayama, Hiroshi Shimamoto, Takuji Okamoto
ICC1