VLDB 2026 Research / reviewers in the wild / expert
Daishi Kondo
dblp:122/3531
· DBLP profile ↗
16ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0003-1482-6148ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 4 first-author · 7 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Assessing the Adoption of Email Security Measures After Google's New Sender Guidelines
Daishi Kondo, Yuya Shibuya, Rie Shigetomi Yamaguchi, Tomohiro Ishihara, Yuji Sekiya, Toshiyuki Nakata 0001, Tohru Asami |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | TATA: Benchmark NIDS Test Sets Assessment and Targeted Augmentation
Omar Anser, Jérôme François, Isabelle Chrisment, Daishi Kondo |
ESORICS (1) | 4 |
| 2025 | Demo: SweetsPot: A Distributed Honeypot Federation PlatformabstractNetworks of honeypots, similar to network telescopes, enable the monitoring of Internet threat activity. Honeypots can collect service-specific information about threat behavior and capabilities, depending on their configuration. This demonstration paper presents SweetsPot, a distributed honeypot data collection system. SweetsPot aims to facilitate threat research to model attacker behavior and characterize emerging threats. Additionally, SweetsPot supports live-streaming of event data, enabling rapid analysis, visualization, and timely threat response. Tillmann Angeli, Frédéric Beck, Daishi Kondo, Isabelle Chrisment, Hideki Tode, Hans D. Schotten |
LCN | 3 |
| 2024 | Impact of DANE on Webpage Load TimeabstractAn authentication technique based on the domain name system (DNS), called DNS-based authentication of named entities (DANE), has been used to support the simple mail transfer protocol. However, DANE has not been extensively used for hypertext transfer protocol secure. This is possibly attributed to the increase in latency caused by DNS security extensions, which are essential for DANE. Unlike email services, web-service access is negatively impacted by latency which considerably affects the quality of experience for end users. This study assessed the extent to which DANE affects webpage load time. To investigate the load time, we developed DANEWebPerf, a tool—comprising a web browser, DNS cache server, and proxy that enables DANE use—to measure the webpage load time. Our experiments showed that using DANE increased the average webpage load time by at most 1190.9 ms. Therefore, DANE for the web does not significantly impact the quality of experience of end users. Kota Yagi, Katsuki Isobe, Daishi Kondo, Hideki Tode |
CNSM | 3 |
| 2024 | Resource Breadcrumbs: Discovering Edge Computing Resources Over Named Data NetworkingabstractEdge computing over Named Data Networking (NDN) is expected to be a promising approach for the deployment of applications such as connected cars and virtual or augmented reality. In conventional edge computing frameworks over NDN, computing request packets are not forwarded based on the resource availability status of the edge execution nodes (e.g., CPU and memory utilization). This may result in requests reaching fully loaded nodes that cannot handle these requests. To address this issue, this paper proposes a resource discovery scheme for edge computing over NDN. In this scheme, each execution node distributes its own resource availability status within its vicinity via scoped-flooding. Using this information, requests are guided toward available nodes that can satisfy the requirements of the requests. Moreover, the nodes attach their status to the computed response packets and distribute the status to each node along the response paths. Our extensive simulations show that the proposed scheme helps request packets to effectively discover available edge execution nodes. Daishi Kondo, Thomas Ansquer, Yosuke Tanigawa, Hideki Tode |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Computing Node Selection Method Based on Proactive Grasping of Computational Performance in End Cloud EnvironmentsabstractTechnologies such as volunteer computing, which use computing resources of nodes in the neighborhood of people, have been attracting attention. When using a large number of end nodes with computing power in the neighborhood of people as an “End Cloud,” main problems in selecting an appropriate group of computing nodes that communicate with each other from among the End Cloud include the long physical distances between the computing nodes and the large amount of messages required to precisely grasp the amount of computing resources. In this paper, we propose an algorithm for selecting an appropriate set of computing nodes from the End Cloud taking these problems into account. Tatsuya Ueda, Daishi Kondo, Yosuke Tanigawa, Hideki Tode |
CCNC | 2 |
| 2023 | Strictly Prioritized Multihop Transmission of High-Priority Data Composed of Multiple Frames in Wireless Sensor NetworksabstractWireless sensor networks and their applications are becoming more diverse, and as an important future challenge, urgent high-priority data must be transferred with minimum delay and loss in a prioritized manner. This paper proposes strictly prioritized multihop transmission of high-priority data, composed of not only single frame but also multiple frames, by reserving the channel and exploiting medium access control coordination among sensor nodes on the route. Its effectiveness is shown through computer simulation. Keita Yoshitomi, Yosuke Tanigawa, Daishi Kondo, Hideki Tode |
CCNC | 3 |
| 2023 | Collaborative Defense Framework Using FQDN-Based Allowlist Filter Against DNS Water Torture AttackabstractIn 2016, Dyn Inc., a managed Domain Name System (DNS) service provider, experienced a DNS water torture attack. The attackers created several unique and unresolvable fully qualified domain names (FQDNs) with random labels and sent malicious DNS queries to the authoritative DNS server via DNS cache servers. This attack eventually caused the authoritative DNS server to become unserviceable. We propose a collaborative defense framework that minimizes the damage by quickly detecting the attack on the victim side and effectively defending against it on the attack source side. In this framework, the DNS cache servers (attack source) create FQDN-based allowlist filters to eliminate malicious DNS queries; the attacked authoritative DNS server (victim) sends a signal to activate filters on cache servers upon detection. Trace-driven simulations show that the proposed framework effectively detects and protects against stealthy attacks circumventing conventional countermeasures. Further, we find that disposable domains, which are designed for one-time use to send signals from DNS clients to authoritative DNS servers, have similar characteristics to FQDNs created for the attack. Moreover, the operation of disposable domains is found to be a key vulnerability to such attacks. Keita Hasegawa, Daishi Kondo, Masato Osumi, Hideki Tode |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | A first look at the name resolution latency on handshakeabstractThe domain name system (DNS) has been an important base of the Internet; however, it faces various issues, including DNS server attacks. Blockchain-based DNS services have recently emerged to solve these DNS issues. Among them, Handshake provides a decentralized root zone and supports state-of-the-art features. However, few studies have investigated the performance evaluations of Handshake. We measure the name resolution latency on Handshake to assess its suitability as an alternative to the current DNS root servers and reveal that it has a practical drawback compared to current root servers at the current early stage. Katsuki Isobe, Daishi Kondo, Hideki Tode |
IMC | 2 |
| 2021 | Resource Discovery for Edge Computing over Named Data NetworkingabstractEdge computing over Named Data Networking (NDN) is expected to be a promising approach for the deployment of applications such as connected cars and virtual/augmented reality. In conventional edge computing frameworks, computing request packets are not forwarded based on the resource availability statuses of edge execution nodes (e.g., CPU and memory utilization). This makes it possible for the requests to reach fully loaded nodes that cannot deal with these requests. To address this issue, this paper proposes a resource discovery scheme for edge computing over NDN. In this scheme, each execution node distributes its own resource availability status in its vicinity by scoped-flooding. This information guides the requests toward available nodes that meet the requirements of the requests. Our extensive simulations show that the proposed scheme helps request packets to discover available execution nodes effectively. Daishi Kondo, Thomas Ansquer, Yosuke Tanigawa, Hideki Tode |
COMPSAC | 1 |
| 2021 | FQDN-Based Whitelist Filter on a DNS Cache Server Against the DNS Water Torture Attack
Keita Hasegawa, Daishi Kondo, Hideki Tode |
IM | 2 |
| 2021 | DNS Tunneling Detection by Cache-Property-Aware FeaturesabstractMany enterprises are under threat of targeted attacks aiming at data exfiltration. To launch such attacks, in recent years, attackers with their malware have exploited a covert channel that abuses the domain name system (DNS) named DNS tunneling. Although several research efforts have been made to detect DNS tunneling, the existing methods rely on features that advanced tunneling techniques can easily obfuscate by mimicking legitimate DNS clients. Such obfuscation would result in data leakage. To tackle this problem, we focused on a “trace” left by DNS tunneling that cannot be easily hidden. In the context of data exfiltration by DNS tunneling, the malware connects directly to the DNS cache server and the generated DNS tunneling queries produce cache misses with absolute certainty. In this study, we propose a DNS tunneling detection method based on the cache-property-aware features. Our experiments show that one of the proposed features can efficiently characterize the DNS tunneling traffic. Furthermore, we introduce a rule-based filter and a long short-term memory (LSTM)-based filter using this proposed feature. The rule-based filter achieves a higher rate of DNS tunneling attack detection than the LSTM one, which instead detects the attack more quickly, while both maintain a low misdetection rate. Naotake Ishikura, Daishi Kondo, Vassilis Vassiliades, Iordan Iordanov, Hideki Tode |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | [Invited] NDN Based Participatory Crowdsensing Framework with Area-focused Interest ForwardingabstractMobile crowdsensing is gaining wide popularity, and its main aim is to collect significant amounts of data by leveraging mobile terminals such as smartphones that provide a ubiquitous communication environment. On the other hand, named data networking (NDN) has become one of the most popular information-centric networks. In this paper, as a new paradigm, we propose an advanced crowdsensing system using NDN. Unlike previous studies, data, including uncertain information such as people's notions, opinions, and knowledge, are gathered from the outer locations of NDN, thanks to the delay-tolerant feature, which opens up new possibilities for data collection. The request for the data is forwarded in an area-focused manner. In addition, with this approach, we expect to significantly reduce the redundant data responses. Hideki Tode, Ashish Man Singh Pradhan, Daishi Kondo, Yosuke Tanigawa |
MSN | 3 |
| 2020 | The named data networking flow filter: Towards improved security over information leakage attacks
Daishi Kondo, Vassilis Vassiliades, Thomas Silverston, Hideki Tode, Tohru Asami |
Comput. Networks | 1 |
| 2016 | Name anomaly detection for ICNabstractInformation leakages are one of the main security threats in today's Internet. As ICN is expected to become the core architecture for Future Internet, it is therefore mandatory to prevent this threat. This paper proves that some ICN configuration prevents information leakages via Data packets and shows that it is an open problem to prevent interest packets from carrying encoded crucial information in their names. Assuming that names in ICN will follow the current URL format commonly used in the Internet, we get the statistics of web URL based on extensive crawling experiments of main internet organizations. Then we propose a simple filtering technique based on these statistics for firewall to detect anomalous names in ICN. The experiment shows that our filtering technique recognizes 15% of names in our dataset as malicious. As the false positive rate is still high for this filter to be used in a real world operation, this work is an important step for detecting anomalous names and preventing information-leakage in ICN. Daishi Kondo, Thomas Silverston, Hideki Tode, Tohru Asami, Olivier Perrin 0001 |
LANMAN | 1 |
| 2015 | Content Piece Rarity Aware In-Network Caching for BitTorrentabstractBitTorrent causes redundant inter-AS traffic that increases the operational cost by constructing topology-agnostic overlay network. One promising way for eliminating the redundant traffic is to utilize the in-network cache. Even though LRU algorithm is widely used for cache eviction in practice and believed to result in good performance in most cases, we posit that LRU may lead to suboptimal performance in the context of BitTorrent. This is due to the fact that BitTorrent adopts so called rarest-first algorithm for exchanging content pieces. Thus, LRU is rendered suboptimal in BitTorrent since LRU exploits temporal locality. In this paper, we propose a method consisting of two steps: (1) inference of the pieces of content to be requested in near future and (2) content piece rarity aware caching strategy for BitTorrent. To be concrete, our network node infers rare pieces transparently to BitTorrent applications, inspecting HAVE/BITFIELD messages within network and setting high priority for caching rare pieces. Simulation results show that our approach increases the cache hit ratio from 6.9% up to 45.7% compared to LRU. In particular, the less the size of cache is, the more effective our proposed caching algorithm is compared to LRU. Daishi Kondo, HyunYong Lee, Akihiro Nakao |
GLOBECOM | 1 |