Yutaka Miyake

dblp:22/993 · DBLP profile ↗
← Back
39ranked-venue papers
3as first author
5since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 1 since 2021Computer networks · 11 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
YearPublicationVenuePosition
2023 Combining Stochastic and Deterministic Modeling of IPFIX Records to Infer Connected IoT Devices in Residential ISP Networks
abstract
Residential Internet service providers (ISPs) today have limited device-level visibility into subscriber houses, primarily due to the network address translation (NAT) technology. The continuous growth of “unmanaged” consumer Internet of Things (IoT) devices combined with the rise of work-from-home makes home networks attractive targets to sophisticated cyber attackers. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This article explains how ISPs can employ IP Flow Information eXport (IPFIX), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: 1) we analyze more than nine million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 flow features pertinent to their network activity that characterize the network behavior of IoT devices—we release our IPFIX records as open data to the public; 2) we train a multiclass classifier on stochastic attributes of IPFIX flows to infer the presence of certain IoT device types in a home network with an average accuracy of 96%. On top of the machine learning (ML) model, we develop a trust metric to track network activity of detected devices over time; and 3) finally, we develop deterministic models (DTs) of specific and shared cloud services consumed by IoTs, yielding an average accuracy of 92%. We show a combination of stochastic and DTs mitigates false positives in 75% of incidents at the expense of an average 7% reduction in true positives.
Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili
IEEE Internet Things J.3
2022 Identification of an IoT Device Model in the Home Domain Using IPFIX Records
abstract
With the widespread adoption of the Internet of Things (loT), a large number of diverse devices are now con-nected to the internet, and the number and variety of these devices are expected to increase in the future. Various manu-facturers have entered the consumer loT (home loT) market, and users can purchase a wide variety of devices such as smart speakers, network cameras, and home appliances. Some loT devices with security vulnerabilities have been reported, and the number of cyberattacks targeting loT devices is increasing, so the use of loT devices may involve security risks. One way to protect users and networks from such security risks to loT devices is to identify and manage loT devices connected to the network. This allows us to detect devices that pose a security risk. This research discusses development and evaluation of a method to estimate the models of loT devices connected to a home gateway using communication data sent from the devices. With regard to traffic data, IPFIX, a standard for flow information, is used for communication packets captured on the home gateway. By using IPFIX, the number of data records was reduced to approximately 11% compared to the number of traffic packets. Since IPFIX does not have information on the application layer in the TCP/IP model, the information available from IPFIX records is limited compared to traffic packets. Our method was evaluated using the traffic data of 25 different loT devices released by 19 vendors and obtained 98.48% precision.
Norihiro Okui, Masataka Nakahara, Yutaka Miyake, Ayumu Kubota
COMPSAC3
2021 Malware Detection for IoT Devices using Automatically Generated White List and Isolation Forest
Masataka Nakahara, Norihiro Okui, Yasuaki Kobayashi, Yutaka Miyake
IoTBDS4
2021 Inferring Connected IoT Devices from IPFIX Records in Residential ISP Networks
abstract
Residential ISPs today have limited device-level visibility into subscriber houses, primarily due to network address translation (NAT) technology. The continuous growth of "unmanaged" consumer IoT devices combined with the rise of work-from-home makes home networks attractive targets for cyber-attacks. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This paper explains how ISPs can employ IPFIX (IP Flow Information eXport), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: (1) We analyze near three million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 features, pertinent to their network activity and services, that characterize the network behavior of IoT devices – we release our IPFIX records as open data to the public; (2) We develop a multi-class classifier to infer the presence of certain IoT device types in a home network from NATed IPFIX records. We also develop a Trust metric to track network activity of detected devices over time; and, (3) We evaluate the efficacy of our inferencing method by applying the trained classifier to IPFIX traces which yields an average accuracy of 96% in detecting device types. By computing a temporal measure of trust per each device, we highlight (on our testbed) a permanent behavioral change in third of devices as well as some intermittent behavioral changes in others.
Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili
LCN3
2021 Automatic Security Inspection Framework for Trustworthy Supply Chain
abstract
Threats and risks against supply chains are increasing and a framework to add the trustworthiness of supply chain has been considered. In this framework, organisations in the supply chain validate the conformance to the pre-defined requirements. The results of validations are linked each other to achieve the trustworthiness of the entire supply chain. In this paper, we further consider this framework for data supply chains. First, we implement the framework and evaluate the performance. The evaluation shows 500 digital evidences (logs) can be checked in 0.28 second. We also propose five methods to improve the performance as well as five new functionalities to improve usability. With these functionalities, the framework also supports maintaining the certificate chain.
Yuto Nakano, Toru Nakamura, Yasuaki Kobayashi, Takashi Ozu, Masahito Ishizaka, Masayuki Hashimoto, Hiroyuki Yokoyama, Yutaka Miyake, Shinsaku Kiyomoto
SERA8
2020 Machine Learning based Malware Traffic Detection on IoT Devices using Summarized Packet Data
Masataka Nakahara, Norihiro Okui, Yasuaki Kobayashi, Yutaka Miyake
IoTBDS4
2018 Message from the NETSAP 2018 Workshop Organizers
abstract
Presents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record.
Masaki Hashimoto, Yoshiaki Hori, Yutaka Miyake
COMPSAC (2)3
2015 Practical Private One-way Anonymous Message Routing
abstract
Opinions from people can either be biased or reflect low participation due to legitimate concerns about privacy and anonymity. To alleviate those concerns, the identity of a message sender should be disassociated from the message while the contents of the actual message should be hidden from any relaying nodes. We propose a novel message routing scheme based on probabilistic forwarding that guarantees message privacy and sender anonymity through additively homomorphic public-key encryption. Our scheme is applicable to anonymous surveys and microblogging.
Anirban Basu 0001, Juan Camilo Corena, Jaideep Vaidya, Jon Crowcroft, Shinsaku Kiyomoto, Yung Shin Van Der Sype, Yutaka Miyake
AsiaCCS7
2014 XOR network coding pollution prevention without homomorphic functions
abstract
Network coding is a way of transmitting information where nodes in a network combine incoming packets into a single one to increase throughput in some scenarios, nodes wishing to get the original information can perform decoding when enough packets have been received. Given its efficiency, the exclusive or (XOR) operation is very popular for network coding. One security concern for networks using network coding is the so called “pollution attack”, where an adversary introduces packets that are not combinations of the original ones. In this paper, we present a construction to prevent pollution attacks in XOR network coding that is suitable for networks where nodes must perform fast verifications. Unlike existing constructions in the literature which are based on XOR-homomorphic authentication functions, our construction can be instantiated with existing cryptographic primitives that are not related to the XOR operation. The core insight of our proposal is a carefully selected set of authenticated packets that are used to authenticate the network coding stream. We show that our proposal is computationally efficient at the intermediate nodes and that can be computed efficiently at the nodes which are generating the content.
Juan Camilo Corena, Anirban Basu 0001, Shinsaku Kiyomoto, Yutaka Miyake, Tomoaki Ohtsuki
CCNC4
2014 CF-inspired Privacy-Preserving Prediction of Next Location in the Cloud
abstract
Mobility data gathered from location sensors such as Global Positioning System (GPS) enabled phones and vehicles is valuable for spatio-temporal data mining for various location-based services (LBS). Such data is often considered sensitive and there exist many a mechanism for privacy preserving analyses of the data. Through various anonymisation mechanisms, it can be ensured with a high probability that a particular individual cannot be identified when mobility data is outsourced to third parties for analysis. However, challenges remain with the privacy of the queries on outsourced analysis results, especially when the queries are sent directly to third parties by end-users. Drawing inspiration from our earlier work in privacy preserving collaborative filtering (CF) and next location prediction, in this exploratory work, we propose a novel representation of trajectory data in the CF domain and experiment with a privacy preserving Slope One CF predictor. We present evaluations for the accuracy and the computational performance of our proposal using anonymised data gathered from real traffic data in the Italian cities of Pisa and Milan. One use-case is a third-party location-prediction-as-a-service deployed on a public cloud, which can respond to privacy-preserving queries while enabling data owners to build a rich predictor on the cloud.
Anirban Basu 0001, Juan Camilo Corena, Anna Monreale, Dino Pedreschi, Fosca Giannotti, Shinsaku Kiyomoto, Jaideep Vaidya, Yutaka Miyake
CloudCom8
2014 Data Storage on the Cloud under User Control
abstract
Cloud services provide advantages in terms of service scalability and availability of users' data, but increase concerns about the control that a user has over her own data. These concerns include not just issues related to access to the information itself, but issues about the effective deletion of the information by the cloud in compliance with the user's right to deletion. In this on-going work, we present a mechanism that allows users to control access to and deletion of their information stored on the cloud. Our construction separates the user's content into several encoded pieces most of which are stored by a cloud provider. The remaining encoded pieces are stored by the user and are served directly from the user's infrastructure to the persons interested in viewing the content. The encoding must satisfy the property that without the pieces stored in the user's infrastructure none of the data is revealed. This property is found in several constructions related to secret sharing. We evaluate the practical feasibility of our proposal by developing an image sharing mechanism and simulating the user infrastructure using a single-board computer connected to the home Internet connection of one of the authors.
Juan Camilo Corena, Anirban Basu 0001, Yuto Nakano, Shinsaku Kiyomoto, Yutaka Miyake
CloudCom5
2014 Key Extraction Attack Using Statistical Analysis of Memory Dump Data
Yuto Nakano, Anirban Basu 0001, Shinsaku Kiyomoto, Yutaka Miyake
CRiSIS4
2014 Beyond proofs of data possession: Finding defective blocks in outsourced storage
abstract
Proofs of Data Possession (PDPs) are protocols that allow a file owner to verify that a file stored at an outsourced server is stored entirely. From a security perspective, it must be difficult for the server to pass the verification protocol if the file is not available. Even though several efficient PDPs exist in the literature, to the best of our knowledge no special algorithms, besides the existing combinatorial approaches have been designed to find what exact blocks of the file are defective. In this article we present an efficient method to find what blocks are defective in a server, even when the server might lie; we show that by taking advantage of the homomorphic properties of existing PDPs, we can improve existing combinatorial methods to find the defective blocks. Our method involves a single invocation of the PDP's verification protocol and an additional communication overhead, which is never larger than the number of blocks of the file regardless of the number of missing blocks. For cases where few blocks have been corrupted, the transmission overhead is proportional to the the number of missing block times the logarithm of the length of the file. This is a significant improvement from existing combinatorial methods which exhibit worse performance than the naive approach (where the result of the PDP for each block is sent independently) as the number of corrupted blocks increases.
Juan Camilo Corena, Anirban Basu 0001, Shinsaku Kiyomoto, Yutaka Miyake, Tomoaki Ohtsuki
GLOBECOM4
2014 A Multiple-server Efficient Reusable Proof of Data Possesion from Private Information Retrieval Techniques
abstract
A proof of Data Possession (PDP) allows a client to verify that a remote server is still in possession of a file entrusted to it. One way to design a PDP, is to compute a function depending on a secret and the file. Then, during the verification stage, the client reveals the secret input to the server who recomputes the function and sends the output back to the client. The client can then compare both values to determine if the server is still in possession of the file. The problem with this approach is that once the server knows the secret, it is not useful anymore. In this article, we present two PDP schemes inspired in Multiple-Server Private Information Retrieval (MSPIR) protocols. In a traditional MSPIR protocol, the goal is to retrieve a given block of the file from a group of servers storing identical copies of it, without telling the servers what block was retrieved. In contrast, our goal is to let servers evaluate a function using an input that is not revealed to them. We show that our constructions are secure, practical and that they can complement existing approaches in storage architectures using multiple cloud providers. The amount of transmitted information during the verification stage of the protocols is proportional to the square root of the length of the file.
Juan Camilo Corena, Anirban Basu 0001, Yuto Nakano, Shinsaku Kiyomoto, Yutaka Miyake
SECRYPT5
2014 A Pre-processing Composition for Secret Key Recovery on Android Smartphone
Yuto Nakano, Youssef Souissi, Robert Nguyen, Laurent Sauvage, Jean-Luc Danger, Sylvain Guilley, Shinsaku Kiyomoto, Yutaka Miyake
WISTP8
2013 Run-Time Enforcement of Information-Flow Properties on Android - (Extended Abstract)
Limin Jia 0001, Jassim Aljuraidan, Elli Fragkaki, Lujo Bauer, Michael Stroucken, Kazuhide Fukushima, Shinsaku Kiyomoto, Yutaka Miyake
ESORICS8
2013 A Key-revocable Attribute-based Encryption for Mobile Cloud Environments
Tsukasa Ishiguro, Shinsaku Kiyomoto, Yutaka Miyake
SECRYPT3
2013 LMM - A Common Component for Software License Management on Cloud
Shinsaku Kiyomoto, Andre Rein, Yuto Nakano, Carsten Rudolph, Yutaka Miyake
SECRYPT5
2013 Implementation and evaluation of a remote authentication system using touchless palmprint recognition
Haruki Ota, Shoichiro Aoyama, Ryu Watanabe, Koichi Ito 0001, Yutaka Miyake, Takafumi Aoki
Multim. Syst.5
2012 Memory Access Pattern Protection for Resource-Constrained Devices
Yuto Nakano, Carlos Cid, Shinsaku Kiyomoto, Yutaka Miyake
CARDIS4
2012 On Designing Privacy-Aware Data Upload Mechanism - Towards Information-Gathering System for Disasters
abstract
A key issue for an organization that is responsible for disaster and emergency management becomes how to gather reliable and useful information during a major disaster. We consider an information-gathering platform for large-scale disasters and emergencies based on mobile terminals. A simple solution to realize an information-gathering system is to construct a server where information is uploaded and published. However, such a centralized approach is not flexible nor is it robust. For example, it is very hard to find an appropriate system to which the user can upload information during a disaster, and the centralized server may be down because of overload or has been physically destroyed. We must consider a distributed and dynamic architecture for the system. Security and privacy issues are another concern that should be addressed for providing information from user's mobile terminals. We focus on a design of a privacy preserving data upload mechanism for the information-gathering system. We design the mechanism that accommodates privacy requirements and present a feasibility analysis of the mechanism.
Shinsaku Kiyomoto, Yutaka Miyake, Toshiaki Tanaka
TrustCom2
2012 Privacy Preservation of User History Graph
Shinsaku Kiyomoto, Kazuhide Fukushima, Yutaka Miyake
WISTP3
2011 Privacy Frost: A User-Oriented Data Anonymization Tool
abstract
A challenging task in privacy protection for public data is to realize an algorithm that generalizes a table according to requirements of a data user. In this paper, we propose an anonymization scheme for generating a k-anonymous and l-diverse table, and show evaluation results using three different tables. Our scheme is based on both top-down and bottom-up approaches for full-domain and partial-domain generalization, and the requirements are automatically incorporated into the generated table. The generated table meets user's requirements and can be employed in the services provided by users without any modification or evaluation.
Shinsaku Kiyomoto, Yutaka Miyake, Toshiaki Tanaka
ARES2
2011 Latin Dances Revisited: New Analytic Results of Salsa20 and ChaCha
Tsukasa Ishiguro, Shinsaku Kiyomoto, Yutaka Miyake
ICICS3
2011 Automatic security verification for 3-party authentication and key exchange protocols
abstract
It is preferable for authentication and key exchange protocols to be verified automatically and rapidly in accordance with security requirements. In order to meet these requirements, we proposed a security verification method for 2-party authentication and key exchange protocols based on Bellare et al.'s model and showed the verification points of the security properties to verify their security efficiently. However, 3-party authentication and key exchange protocols have more security properties than 2-party protocols: key privacy and security against a malicious insider. In this paper, we describe the novel security properties for 3-party protocols and show the verification point of key privacy. We also show the validity of the proposed method by explaining how it verifies the 3-party protocols as two verification examples. Our method is the first automatic security verification method that can verify the aforementioned security properties.
Haruki Ota, Shinsaku Kiyomoto, Yutaka Miyake
NSS3
2011 Towards Optimal Revocation and Tracing Schemes - The Power of the Ternary Tree
Kazuhide Fukushima, Shinsaku Kiyomoto, Yutaka Miyake, Kouichi Sakurai
SECRYPT3
2010 LSM-Based Secure System Monitoring Using Kernel Protection Schemes
abstract
Monitoring a process and its file I/O behaviors is important for security inspection for a data center server against intrusions, malware infection and information leakage. In the case of the Linux kernel 2.6, a set of hook functions called the Linux Security Module (LSM) has been implemented in order to monitor and control the system calls. By using the LSM we can inspect the activity of unknown malicious processes. However, a sophisticated attacker could breach the kernel configurations using the rootkits. Furthermore since the monitoring results of the malicious process activity are stored as a file on Hard Disk Drive (HDD), it will be easily manipulated by the attacker. In this paper, we propose a secure monitoring scheme that addresses the attacks against the monitoring module and its result for security inspection of the data center server. The monitoring module is implemented as a LSM-based function and protected by the kernel protection technique. The integrity of the monitoring result is guaranteed by using a Mandatory Access Control (MAC) of the Linux kernel and a mechanism of the trusted process invocation. This mechanism can serve as an infrastrucuture of secure inspection platform for data center server because the integrity of the monitoring module and its result is guaranteed.
Takamasa Isohara, Keisuke Takemori, Yutaka Miyake, Ning Qu, Adrian Perrig
ARES3
2010 Remote Attestation for HDD Files Using Kernel Protection Mechanism
abstract
A remote attestation that measures files on a hard disk drive (HDD) is important for intrusion detection on a data center server. When the server is infected by a rootkit or when a file measurement application is manipulated, the response of the kernel or the measurement application is not reliable. A trusted platform module (TPM) that achieves a chain of trust from BIOS to kernel upon booting is proposed to provide the remote attestation. However, as the data center server is rarely rebooted, the TPM is ill suited for file measurements of the running server. In this paper, we propose an on-demand remote attestation scheme for HDD files of the server. We designed and implemented a trust chain from the BIOS via the kernel and the file measurement application to the HDD files on a running server for secure integrity measurement. A memory virtualization technique is applied to guarantee the integrity of the running kernel, and the file measurement application is verified using a code signature. Also, we implement a mechanism that attaches the server's signature to a measurement result in a trusted kernel. Finally, our proposed scheme achieves a result whereby the remote verifier can measure the integrity of the server files securely at any time.
Keisuke Takemori, Adrian Perrig, Ning Qu, Yutaka Miyake
ICC4
2009 Anomaly Detection for DNS Servers Using Frequent Host Selection
abstract
DNS is one of the internet's fundamental building blocks, used by various applications such as web and mail transfer. Therefore, monitoring DNS traffic has potential to detect host anomalies such as spammers and infected hosts in a network. However, previous works assume a small number of hosts or target on domain name anomalies, so that they cannot be applied to a large-scale networks due to performance issues. A large number of hosts and long-term tracing consume computational resources and make real-time analysis difficult. In this paper, we propose anomaly detection for DNS servers using frequent host selection, which selects only potential hosts and does not depend on the number of hosts. We evaluate the proposed system using DNS traffic for 6 months of tracing, and show that the system can feasibly handle hosts in the dataset and detect anomalies, such as mail servers suffering from spam and DNS servers are configured incorrectly.
Akira Yamada 0001, Yutaka Miyake, Masahiro Terabe, Kazuo Hashimoto, Nei Kato
AINA2
2009 Visual similarity-based phishing detection without victim site information
abstract
Phishing attacks, which steal users' account information by fake Websites, have become a serious problem on theInternet. There are two major approaches in phishing detection: the blacklist- and the heuristics-based approach. Heuristics-based approaches employ common characteristics of phishing sites such as distinctive keywords used in Web pages or URLs in order to detect new phishing sites that are not yet listed in blacklists. However, these kinds of heuristics can be easily circumvented by phishers once their mechanism is revealed. In order to overcome this weakness, visual similarity-based detection techniques have been proposed. Because phishing sites have to mimic victim sites, visual similarity between phishing sites and their victim sites is supposed to be an inherent and not easily concealable characteristic. However, these techniques require images of real victim sites for detection. In this paper, we propose a phishing detection mechanism based on visual similarity among phishing sites that mimic the same victim site. Surprisingly, just by analyzing visual similarity among Web pages without a priori knowledge, our method automatically extracts 224 distinct Web page layouts mimicked by 2,262 phishing sites and achieves a detection rate of over 80% while keeping the false-positive rate to 17.5%. We also find that the false-positive rate can be reduced.
Masanoei Hara, Akira Yamada 0001, Yutaka Miyake
CICS3
2009 Public Key-Based Rendezvous Infrastructure for Secure and Flexible Private Networking
abstract
Secure private networking over the Internet is difficult especially when trying to form a new network with private servers and hosts that belong to different administrative domains. Although such form of private network is useful as a closed group communication environment, simply applying existing VPN technologies is not sufficient. Not to mention common problems such as NAT and firewall traversal, potential collision of private IP addresses among networks makes their interconnection extremely difficult. In addition, access control inside the private network is required in order to prevent inappropriate access to other users' network resources. In this paper, we propose a public key-based rendezvous infrastructure and user-side VPN agents that can instantly interconnect multiple private networks while automatically mediating address collision and enforcing appropriate access control on cross domain communication by utilizing Zeroconf technologies. We built the rendezvous infrastructure using DHT technologies in order to achieve good scalability and implemented the VPN agent for Linux-based embedded devices so that users can run it on their residential gateway or wireless router.
Ayumu Kubota, Yutaka Miyake
ICC2
2008 Detection of Bot Infected PCs Using Destination-Based IP and Domain Whitelists During a Non-Operating Term
abstract
Spam e-mails and distributed denial of service (DDoS) attacks have now become critical issues to the Internet. These attacks are considered to be sent from bot infected PCs. As a bot communicates with a malicious controller over an encrypted channel and updates its code frequently, it becomes difficult to detect infected personal computers (PCs) using pattern-based intrusion detection systems (IDSs) and antivirus systems (AVs). As sending attack and control packets from the bot process are independent of the user operation, a behavior monitor is effective to detect an anomaly communication. In this paper, we propose a bot detection technique that checks outbound packets with destination-based whitelists. If any outbound packets during the non-operating term do not match the whitelists, the PC is considered to be infected by the bot. The whitelists are a set of a destination IP address and/or domain names (DNs) that are listed by monitoring outbound packets from an un-infected PC. Because the many IPs and DNs are grouped into a few sub-networks and superior DNs, it is easier to maintain the destination-based whitelists than the pattern-based IDS/AV. We implement the proposal system as a host-based detector and evaluate false negative (FN) and false positive (FP) frequencies for detection of bot activities.
Keisuke Takemori, Masakatsu Nishigaki, Tomohiro Takami, Yutaka Miyake
GLOBECOM4
2007 Combating Against Attacks on Encrypted Protocols
abstract
Attacks against encrypted protocols are becoming increasingly popular. They pose a serious challenge to the conventional intrusion detection systems (IDSs) which heavily rely on inspecting the network packet fields and are consequently unable to monitor encrypted sessions. IDSs can be broadly categorized into two types: signature-based and anomaly-based IDSs. The signature-based IDSs rely on previous attack signatures but are often ineffective against new attacks. On the other hand, anomaly-based detection systems depend on detecting the change in the protocol behavior caused by an attack. The latter can be employed to detect novel attacks, and therefore are often preferred over their signature-based counterpart. In this paper, we envision an anomaly-based IDS which can detect attacks against popular encrypted protocols, such as SSH and SSL. The proposed system creates a normal behavior profile and uses non-parametric Cusum algorithm to detect deviation from the normal profile. Upon detecting an anomaly, the proposed mechanism generates an alert, sets a delay to the protocol response, and traces back the attacker. The effectiveness of the proposed detection scheme is verified via simulations.
Zubair Md Fadlullah, Tarik Taleb, Nirwan Ansari, Kazuo Hashimoto, Yutaka Miyake, Yoshiaki Nemoto, Nei Kato
ICC5
2007 A SOC Framework for ISP Federation and Attack Forecast by Learning Propagation Patterns
abstract
A security operation center (SOC), which monitors network traffic on each domain, has been established to detect cyber attacks. However, there have been ever increasing worms and distributed denial of service (DDoS) attacks on the Internet and the number of unknown attacks is increasing day by day. It is hard to defend network infrastructure via the SOC, which is operated by an internet service provider (ISP). It is thus important to predict new security threats and share incidents that occur with related ISPs. In the case of Japan, the Telecom Information Sharing and Analysis Center (Telecom-ISAC) Japan is established for a federation scheme with ISP operators against serious security incidents. In this research, we design a federation SOC framework that monitors wide-area networks and analyzes multi-point traffic using statistical approaches. It can suggest anomalous ISPs and traffic parameters automatically. Moreover, we propose an attack forecast technique to ensure a swift response to regular and new attacks. The technique depicts an attack map and learns attack propagation patterns by using the Bayesian inference. We implement the system and evaluate integrated scale of the ISPs and forecast correct rate.
Keisuke Takemori, Yutaka Miyake, Chie Ishida, Iwao Sasase
ISI2
2006 L2VPN over Chord: Hosting Millions of Small Zeroconf Networks over DHT Nodes
abstract
Although there are variety of VPN products and software available today, it is still difficult for normal users to setup their own VPN server and configure their firewall and NAT so that they can allow remote access to their home network. In this paper, we propose a DHT-based L2VPN hosting infrastructure that allows millions of consumer users to easily create their own L2VPN server processes outside their home network, which can then bridge their home network and remote VPN clients. Because each L2VPN server acts like a virtual Ethernet switch, a user can use auto-configuration technologies like Zeroconf, which relies on layer-2 broadcast capability, among his or her networks and hosts bridged by the L2VPN server. This extends applicability of Zeroconf-like technologies from local are to wide area and greatly broaden their usefulness. A user can dynamically form a L2VPN with widely distributed hosts and use it as a secure plug & play networking platform for Zeroconf-enabled applications. We show that the proposed infrastructure can be easily implemented using an existing DHT technology while achieving great scalability and minimizing the operational cost of the infrastructure nodes.
Ayumu Kubota, Akira Yamada 0001, Yutaka Miyake
GLOBECOM3
2002 TCP gateway for satellite-based Internet service accommodating multiple subscribers
abstract
Satellite-based Internet is one of attractive access media because it can be deployed even in inconvenient locations. However, it is a problem that TCP throughput is degraded by the large propagation delay in the satellite link. We previously proposed to introduce an intermediate gateway only in the carrier side premises to accelerate TCP throughput and confirmed its effectiveness in case of no network congestion. In order to accommodate many subscribers, it is also required to avoid network congestion caused by the extremely asymmetry of the access link. We describe the new TCP gateway taking account of multiple subscribers accommodated by a shared satellite access link. We also confirmed that the new gateway can accelerate TCP throughput more than 8 times avoiding network congestion.
Teruyuki Hasegawa, Toru Hasegawa, Yutaka Miyake, Koji Nakao
WCNC3
2000 Acceleration of TCP Throughput over Satellite-Based Internet Access Using TCP Gateway
abstract
Satellite communication is able to provide wide bandwidth, and satellite-based Internet access is expected to be a high speed Internet access method of the next generation. However, the propagation delay of a satellite link degrades the TCP throughput. The reason for this problem is that TCP performs window based flow control and most communicating hosts use the default window size such as 8 kbytes through 24 kbytes. To deal with this problem, we propose a TCP gateway for satellite-based Internet access. The communication throughput of TCP is improved without any modifications to equipment and terminals of subscribers by introducing this system only at a satellite Earth station. In this paper, we describe the protocol architecture of the TCP gateway and its performance by comparing with conventional methods. The results of a performance evaluation show that the proposed TCP gateway can provide more than 20 times higher throughput than communication without it over a link with 6 Mbps bandwidth and 350 msec round trip time.
Yutaka Miyake, Teruyuki Hasegawa, Toru Hasegawa, Toshihiko Kato
ISCC1
1995 Implementation method of high speed protocol as transport library
abstract
Along with the rapid progress of optical technologies, the transmission speed of LANs and public networks has been increased significantly. As a result, it has become possible for computers distributed geographically to communicate with each other with high throughput. However, the current protocols such as TCP/IP have some problems, especially the performance through long distance and wide bandwidth networks. Therefore, new protocols with new data transfer algorithms are required. In this paper, we describe an implementation of a high speed transport protocol by a user level library which interfaces to UDP/IP. This method uses only functions commonly provided by UNIX operating systems, and therefore, allows a new protocol to be developed easily and to be ported to other UNIX workstations easily. Our library called the transport library realizes the coordination of buffer managements in the application and the library, and low overhead and prompt handling of receive and timer interrupts in order to achieve high performance. Our implementation results show 32 Mbits/sec over an ATM network whose effective transmission speed is 36 Mbits/sec, regardless of the propagation delay from 0 to 200 msec. These values of throughput are better than those of the in-kernel TCP programs.
Yutaka Miyake, Toshihiko Kato, Kenji Suzuki 0003
ICNP1
1989 A new timing extraction method and data interpolation for block demodulation
abstract
The conventional timing extraction method for block demodulation requires a large amount of calculation, a high-speed A/D (analog/digital) converter and a large memory size. A method that overcomes these disadvantages is proposed. It calculates accurate frequency and phase of symbol timing from only two extracted spectra by using a modified discrete Fourier transform (DFT). Thus it requires less calculation than the conventional method. In addition, interpolation of stored data is used to reduce the sampling rate. As a result the method can use a slower A/D converter and has a reduced memory requirement. The lower limit of the number of samples per symbol can be reduced to about 2.5.>
Yutaka Miyake, Masafumi Hagiwara, Masao Nakagawa
ICASSP1