Masataka Nakahara

dblp:172/4453 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
9since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 5 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Digital Twin-Based Security Function in the Space Domain
abstract
Cybersecurity in the space domain is becoming increasingly critical because of rising satellite attacks. In this paper, leveraging digital twin technology as a novel security measure that is tailored for the space domain is proposed. The architecture aims to address key challenges such as remote management, long-term operation, and resource limitations that are inherent to space environments. By using local security digital twins for multiple devices, the proposed framework facilitates remote attack detection, security management, and simulation, all while significantly reducing communication costs. The ultimate goal is to enable early attack detection and response, thereby ensuring long-term resilience and security in space operations.
Masataka Nakahara, Keizo Sugiyama, Yasuaki Kobayashi, Ayumu Kubota
CCNC1
2025 WIP: Cyber Security Measurement Taking Physical Circumstances
abstract
This paper proposes an architecture that supports security measures by evaluating the impact of cyber attacks on physical spaces, utilizing information gathered from the neighborhoods of devices. The architecture includes digital twin (DT) models that represent the conditions of physical spaces in cyberspace and utilizes various types of information in both cyber and physical spaces, such as device location, speed, and vulnerability, for cyber-physical security measures. We summarize the challenges in translating security information into DT models and in implementing the overall architecture for security measurements.
Masataka Nakahara, Keizo Sugiyama, Norihiro Okui, Yasuaki Kobayashi, Ayumu Kubota, Shinsaku Kiyomoto
CCNC1
2025 Survey and Experimentation to Compare IoT Device Model Identification Methods
abstract
The widespread use of the Internet of Things (IoT) devices introduces a novel security threat due to the many vulnerable devices connected to the Internet. One effective countermeasure against such threats involves detecting vulnerable IoT devices by identifying the models of connected IoT devices. Several studies have concentrated on model identification methods that utilize flow and communication data to identify IoT device models. With the advances in machine learning and deep learning, high identification accuracy has been reported under certain conditions. However, when implementing these research findings, selecting the most suitable model for the application is crucial. This selection process presents challenges in terms of reproducibility and applicability. The issue of reproducibility lies in the difficulty of implementing a model that accurately reproduces the methods outlined in the paper. The applicability issue arises when attempting to select the best method based solely on the experimental results described in the papers, as difference studies have conducted these experiments on different datasets across various papers. This study focused on IoT device model identification using flow data. We surveyed existing studies and selected a method with high reproducibility. Additionally, we conducted experiments to evaluate the accuracy of the selected methods using multiple datasets under uniform conditions for feature values and dataset usage. Consequently, we identified the optimal method in terms of both reproducibility and applicability within the scope of our study.
Norihiro Okui, Masataka Nakahara, Ayumu Kubota
WoWMoM2
2023 Combining Stochastic and Deterministic Modeling of IPFIX Records to Infer Connected IoT Devices in Residential ISP Networks
abstract
Residential Internet service providers (ISPs) today have limited device-level visibility into subscriber houses, primarily due to the network address translation (NAT) technology. The continuous growth of “unmanaged” consumer Internet of Things (IoT) devices combined with the rise of work-from-home makes home networks attractive targets to sophisticated cyber attackers. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This article explains how ISPs can employ IP Flow Information eXport (IPFIX), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: 1) we analyze more than nine million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 flow features pertinent to their network activity that characterize the network behavior of IoT devices—we release our IPFIX records as open data to the public; 2) we train a multiclass classifier on stochastic attributes of IPFIX flows to infer the presence of certain IoT device types in a home network with an average accuracy of 96%. On top of the machine learning (ML) model, we develop a trust metric to track network activity of detected devices over time; and 3) finally, we develop deterministic models (DTs) of specific and shared cloud services consumed by IoTs, yielding an average accuracy of 92%. We show a combination of stochastic and DTs mitigates false positives in 75% of incidents at the expense of an average 7% reduction in true positives.
Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili
IEEE Internet Things J.4
2023 Dynamic Inference From IoT Traffic Flows Under Concept Drifts in Residential ISP Networks
abstract
Millions of vulnerable consumer IoT devices in home networks are the enabler for cyber crimes putting user privacy and Internet security at risk. Internet service providers (ISPs) are best poised to mitigate risks by automatically inferring active IoT devices per household and notifying users of vulnerable ones. Developing a scalable inference method that can perform robustly across thousands of home networks is a nontrivial task. This article focuses on the challenges of developing and applying data-driven inference models when labeled data of device behaviors is limited and the distribution of data changes across time and space domains (concept drifts). Our contributions are fourfold: 1) we collect and analyze more than six million network traffic flows of 24 types of consumer IoT devices from 12 real homes over six weeks to highlight the challenge of temporal and spatial concept drifts in network behaviors of IoT devices—we publicly release our training and testing instances data; 2) we analyze the performance of two inference strategies, namely global inference (a model trained on a combined set of all labeled data from training homes) and contextualized inference (several models each trained on the labeled data from a training home) in the presence of concept drifts; 3) to manage concept drifts, we develop a method that dynamically applies the “best” model (from a set) to network traffic of unseen homes during the testing phase, yielding better performance in a fifth of scenarios when the labels are available for the testing data (ideal but unrealistic settings); and 4) we develop a method to automatically select the best model without needing labels of unseen data (a realistic inference) and show that it can achieve 94% of the ideal model’s accuracy.
Arman Pashamokhtari, Norihiro Okui, Masataka Nakahara, Ayumu Kubota, Gustavo Batista, Hassan Habibi Gharakheili
IEEE Internet Things J.3
2022 Identification of an IoT Device Model in the Home Domain Using IPFIX Records
abstract
With the widespread adoption of the Internet of Things (loT), a large number of diverse devices are now con-nected to the internet, and the number and variety of these devices are expected to increase in the future. Various manu-facturers have entered the consumer loT (home loT) market, and users can purchase a wide variety of devices such as smart speakers, network cameras, and home appliances. Some loT devices with security vulnerabilities have been reported, and the number of cyberattacks targeting loT devices is increasing, so the use of loT devices may involve security risks. One way to protect users and networks from such security risks to loT devices is to identify and manage loT devices connected to the network. This allows us to detect devices that pose a security risk. This research discusses development and evaluation of a method to estimate the models of loT devices connected to a home gateway using communication data sent from the devices. With regard to traffic data, IPFIX, a standard for flow information, is used for communication packets captured on the home gateway. By using IPFIX, the number of data records was reduced to approximately 11% compared to the number of traffic packets. Since IPFIX does not have information on the application layer in the TCP/IP model, the information available from IPFIX records is limited compared to traffic packets. Our method was evaluated using the traffic data of 25 different loT devices released by 19 vendors and obtained 98.48% precision.
Norihiro Okui, Masataka Nakahara, Yutaka Miyake, Ayumu Kubota
COMPSAC2
2022 Anomaly Traffic Detection with Federated Learning toward Network-based Malware Detection in IoT
abstract
To mitigate cyberattacks, detecting anomalies in network traffic is of key importance. In this paper, we propose a model training method for detection of Internet of Things (IoT) anomalous traffic that is robust against the contamination of anomalous samples in the training set. The key idea is to focus on the nature of IoT malware infections (i.e., only a limited number of IoT networks contain infected devices) and employ federated learning (FL) to mitigate the impact of anomalous samples on model training. The simulation evaluation using IoT traffic data obtained from residences and malware traffic data collected from sandbox experiments demonstrates that the proposed method does not cause accuracy degradation even when the anomalous samples are contaminated, in contrast with the detection accuracy of baseline methods, which does degrade.
Takayuki Nishio, Masataka Nakahara, Norihiro Okui, Ayumu Kubota, Yasuaki Kobayashi, Keizo Sugiyama, Ryoichi Shinkuma
GLOBECOM2
2021 Malware Detection for IoT Devices using Automatically Generated White List and Isolation Forest
Masataka Nakahara, Norihiro Okui, Yasuaki Kobayashi, Yutaka Miyake
IoTBDS1
2021 Inferring Connected IoT Devices from IPFIX Records in Residential ISP Networks
abstract
Residential ISPs today have limited device-level visibility into subscriber houses, primarily due to network address translation (NAT) technology. The continuous growth of "unmanaged" consumer IoT devices combined with the rise of work-from-home makes home networks attractive targets for cyber-attacks. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This paper explains how ISPs can employ IPFIX (IP Flow Information eXport), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: (1) We analyze near three million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 features, pertinent to their network activity and services, that characterize the network behavior of IoT devices – we release our IPFIX records as open data to the public; (2) We develop a multi-class classifier to infer the presence of certain IoT device types in a home network from NATed IPFIX records. We also develop a Trust metric to track network activity of detected devices over time; and, (3) We evaluate the efficacy of our inferencing method by applying the trained classifier to IPFIX traces which yields an average accuracy of 96% in detecting device types. By computing a temporal measure of trust per each device, we highlight (on our testbed) a permanent behavioral change in third of devices as well as some intermittent behavioral changes in others.
Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili
LCN4
2020 Machine Learning based Malware Traffic Detection on IoT Devices using Summarized Packet Data
Masataka Nakahara, Norihiro Okui, Yasuaki Kobayashi, Yutaka Miyake
IoTBDS1
2015 Tradeoff between privacy protection and network resource in community associated network virtualization
abstract
These days, people have shifted from global services to social services. However, it is common that privacy-sensitive data is exchanged in such social services and the conventional privacy control function is built just on the application level. Therefore, to consider privacy control in the network level, this paper proposes a framework for community associated networks enabled by the network virtualization technique. A community associated network is defined as a logical information space in which people who are socially connected with each other exchange and share their data including privacy sensitive data. In the proposed framework, community networks are created for each community and physical network resources are assigned to each community network. However, as the number of communities increases, the more physical network resources are needed. Therefore, this paper discusses the tradeoff between the number of community and network resource and shows numerical results obtained from the model.
Masataka Nakahara, Ryoichi Shinkuma, Kohei Yamaguchi, Kazuhiro Yamaguchi
PIMRC1