Yu Tsuda

dblp:215/7237 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
2since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Security and privacy · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Threat and Risk Analysis for Human-Augmentation Robots: Use-cases from Robots Working in the Real Society
Daiya Kato, Yu Tsuda, Hideki Sunahara, Masaaki Sato
COMPSAC2
2022 NEMIANA: Cross-Platform Execution Migration for Debugging
abstract
Many IoT devices are compromised by exploiting their software vulnerabilities in these devices. A technique during a development phase to fix such vulnerabilities efficiently is leveraging advantages of various platforms (e.g., single-board computers, emulators, and FPGA (Field Programmable Gate Array) boards). As a debugging scenario, developers discover some vulnerability-candidates of software under test on an emulator like QEMU with rich debugging plugins. They then check those candidates in detail on a single-board computer (i.e., a real device) with GDB. To efficiently conduct this kind of debugging, we propose NEMIANA (Noncomplex Execution Migration Integrated Architecture for Nonstop Analyses), an architecture for automatically conducting cross-platform execution migration. It can migrate execution-state of software at any execution points (e.g., 500 steps after the beginning) from a platform (e.g., a single-board computer) to another platform (e.g., a FPGA board). Developers then seamlessly continue debugging at that execution point on the destination platform. A key idea for cross-platform migration is an abstraction model of execution-state (e.g., CPU register/memory values), which can be applied to various platforms (if they have CPUs of the same ISA (Instruction Set of Architecture)). Another key idea is to trace all instructions executed by software. This incurs a system performance overhead; however, it enables developers to choose any execution points, which we hope is very helpful for debugging. In the evaluation, a prototype system of NEMIANA demonstrates three case studies: a typical debugging with GDB, benchmarking, and vulnerability discovery. It shows developers can use NEMIANA for their debugging purposes.
Nobuyuki Kanaya, Yu Tsuda, Yuuki Takano, Yoshitada Fujiwara, Ryoichi Isawa
AST2
2020 Continuous and Multiregional Monitoring of Malicious Hosts
abstract
The number of cybersecurity threats has been increasing, and these threats have become more sophisticated year after year. Malicious hosts play a large role in modern cyberattacks, e.g., as a launcher of remote-control attacks or as a receiver of stolen information. In such circumstances, continuous monitoring of malicious hosts (URL/IP addresses) is indispensable to reveal cyberattack activities, and many studies have been conducted on that. However, many of them have limitations: they help only in the short-term or they help only a few regions and/or a few organizations. Therefore, we cannot effectively monitor attacks that are active for only a short time or that change their behavior depending on where the victims are from (e.g., country/organization). In this paper, we propose Stargazer, a program that monitors malicious hosts from multiple points on a long-term basis. Multiregional monitoring sensors and inter-organizational collaboration are conducted to achieve this surveillance. In this paper, we describe an implementation of the Stargazer prototype and how monitoring was carried out using multiregional sensors starting in Dec. 2018 of 1,050 malicious hosts; 10,929,418 measurements were obtained. Case studies on (1) revived hosts, (2) hosts that only respond to specific regions, and (3) the behavior of attack preparation were created.
Shota Fujii, Takayuki Sato, Sho Aoki, Yu Tsuda, Yusuke Okano, Tomohiro Shigemoto, Nobutaka Kawaguchi, Masato Terada
CCS4
2019 Byakko: Automatic Whitelist Generation based on Occurrence Distribution of Features of Network Traffic
abstract
In security operations such as incident response and malware analysis, a large number of logs are gathered from a monitoring network. These logs include security appliance alerts and network communications. Security operators must then find remarkable logs from all these logs. To filter out benign logs from all the logs, security operators commonly use a whitelist, which is a set of benign hosts decided upon by the security operators. When creating a whitelist, security operators typically refer to website-ranking services, the features of a monitoring network topology, their knowledge and expertise about the monitoring network, etc. In contrast, a whitelist should be continuously and manually updated by the security operators; thus, maintaining the whitelist places a higher burden on them. Therefore, in this paper, we propose Byakko, which is a method for automatically generating a whitelist based on statistical features, that is, occurrence distribution and its standard deviation. These features describe the stationarity of communications in a monitoring network. If a host has stationary communications, Byakko decides that the host must be benign. To evaluate Byakko, we conduct a performance evaluation and two case studies, which are for incident responses on an office network and for malware analysis on an analysis network. Our results show that Byakko is a practical method and can be applied to other cases as well.
Nobuyuki Kanaya, Yu Tsuda, Yuuki Takano
IEEE BigData2