Manabu Hirano

dblp:25/230 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0001-9780-6454ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2025 RanSMAP: Open dataset of Ransomware Storage and Memory Access Patterns for creating deep learning based ransomware detectors
abstract
Ransomware attacks have become significant cyber threats to enterprises and public sectors. Our previous RanSAP dataset, which contained only low-level storage access patterns collected using a thin hypervisor , was used to create behavioral-based ransomware detectors; it provides an additional protection layer when the OS-level ransomware detection systems are compromised. The previous ransomware detector, which used only low-level storage access patterns, could not detect ransomware when Office applications and web browsers were executed simultaneously. This paper presents a new open dataset named RanSMAP, which stands for Ransomware Storage and Memory Access Patterns . It contains low-level storage and memory access patterns collected using a thin hypervisor. We provide an overview of the open RanSMAP dataset, including directory structure and file formats , to guide researchers in using the dataset. We then present our data preprocessing method and deep-learning-based ransomware detector. The RanSMAP datasets consist of storage and memory access patterns of six ransomware samples and six benign applications , seven Conti ransomware variants, and simultaneous execution of ransomware with benign applications collected on the machines with various CPUs, RAM generations, RAM frequencies, and RAM capacities. The experimental results show that low-level memory access patterns improved ransomware detection performance by 2.3% compared to detectors using only storage access patterns. We confirmed that ransomware detectors trained using the RanSMAP dataset can detect ransomware when Office and web browser programs are executed simultaneously. We presented the survey on state-of-the-art ransomware detection research and the availability of open behavioral-feature datasets to discuss the advantages and limitations of our RanSMAP dataset.
Manabu Hirano, Ryotaro Kobayashi
Comput. Secur.1
2024 Motivation and Educational Effectiveness in Teaching Expert Development Project by an Educational Community
abstract
KOSEN, which emphasizes the acquisition of practical skills from the age of 15, is a good fit with the Cyber security body of knowledge. A cyber security education proj ect has occurred at KOSEN, and a project to develop cyber security teaching materials for further teacher training is also underway. In the course of examining the learning effectiveness in this project, we obtained the knowledge that a certain amount of motivation is a critical point to improve the learning effectiveness when using our teaching materials, when cyber security education is viewed from the perspective of gamification. In this study, to make this finding even more effective, we attempted to confirm whether or not Game Based Learning (GBL) enhances motivation and improves learning effectiveness, both in our teaching materials and in teaching materials developed by others, and to gain a foothold for examining the details of the effectiveness of GBL. The validation results show that prior learning in our materials, whether developed by us or not, works effectively in subsequent learning with materials, increasing motivation and positively correlating learning effects with motivation. As a next step, we will obtain further directions for future educational development by further examining which elements contributed to motivation and which were influenced by motivation.
Keiichi Yonemura, Hideyuki Kobayashi, Shinya Oyama, Tatsuki Fukuda, Manabu Hirano, Noriaki Hayashi, Keiichi Shiraishi, Satoru Yamada, Jun Sato, Hisashi Taketani, Yoshinobu Matsuno, Tomoharu Kaeriyama, Masaki Hashimoto, Ryotaro Nakata, Masao Maruyama, Shigenori Akamatsu, Routa Takahashi, Kentaro Noguchi, Seiichi Kishimoto
EDUCON5
2023 Motivation in Teaching Expert Development Project by KOSEN Security Educational Community
abstract
As cyber-attacks intensify, cyber security education in engineering education is becoming increasingly important, and KOSEN, which emphasizes the acquisition of practical skills from the age of 15, is a good fit with the cyber security body of knowledge. The cyber security education project has occurred at KOSEN, and a project to develop cyber security educational materials that also serve as teacher training has been carried out for the past several years, and the educational effects of the developed educational materials have been examined. Educational methods using educational materials can be expected to improve some skills. However, when cyber security education is viewed from the perspective of gamification, motivation for the concepts of attack and defense may contribute to educational effectiveness. In this study, we discussed the motivation that contributes to the effectiveness of skill improvement in practical exercises using educational materials developed through the project we have been working on. We also discussed whether it is possible to enhance life-work balance by considering the project itself as a Role Playing Game, and obtained suggestions on the effectiveness of motivation and how the project can enhance life-work balance.
Keiichi Yonemura, Ryotaro Nakata, Hideyuki Kobayashi, Masaki Hashimoto, Shinya Oyama, Jun Sato, Tatsuki Fukuda, Hisashi Taketani, Manabu Hirano, Satoru Yamada, Keiichi Shiraishi, Satoru Izumi, Noriaki Hayashi, Hiroyuki Okamoto, Hideaki Moriyama, Youichi Fujimoto, Shingo Okamura, Yoshinori Sakamoto, Shigeo Doi, Masao Maruyama, Tomoharu Kaeriyama, Kentaro Noguchi, Seiichi Kishimoto
EDUCON9
2022 Teaching Expert Development Project by KOSEN Security Educational Community
abstract
Cyber-attacks are on the rise, and the advent of COVID-19 has changed work styles, leading to an increase in cyber-attacks targeting remote workers. This situation is the same in the world and in Japan, and the development of cyber security personnel and their training to face the attackers who can respond to the social situation is desired all over the world. The National Institute of Technology (KOSEN) is known not only in Japan but also in the world as the only institution of higher learning in the world where students can freely study engineering for five years from the age of 15. The technical framework of cybersecurity and the KOSEN education, which is based on the acquisition of practical skills, go hand in hand, and KOSEN is an important higher education institution that plays a part in the cybersecurity human resource development strategy in Japan. In 2015, KOSEN launched the KOSEN Security Educational Community (K-SEC) to initiate cybersecurity education for KOSEN students. This project has two objectives: one is to develop excellent cyber security personnel for qualitative improvement. The second is to develop a large number of KOSEN students who have systematically acquired security knowledge for the purpose of quantitative expansion. In 2019, a new project, Highly Advanced Cybersecurity for KOSEN (HACK), was launched within K-SEC to accelerate the achievement of the two objectives of K-SEC. HACK is a project based on a simple idea: to strengthen KOSEN faculty in order to develop strong students with practical cybersecurity skills. Participating faculty members will develop cyber range materials. The development of the cyber range will contribute to the understanding of both attacker and defender scenarios and the acquisition of advanced security knowledge and skills. In the previous paper, we reported on the results of the first year of HACK (2019). The faculty development plan, which mainly focused on cyber range development, contributed to the motivation and skill development of the faculty. The cyber range as a deliverable was also obtained. This paper reports on the outcomes of the second year (2020) of HACK activities. Within the faculty development plan, which mainly focused on cyber range development as in the first year, we used the deliverables of the first year to give lectures to KOSEN students to measure the educational effects. During the cyber range development, there were some knowledge and skills that the faculty intended to have the KOSEN students improve their skills. Therefore, the focus of the study was to see if the faculty members’ intended skills would be improved when they gave lectures to the KOSEN students using the teaching materials. As it turned out, we were able to achieve this goal, and we were able to improve the skills of the KOSEN students as intended by the faculty. Furthermore, it was not only possible to control the skills to be improved by the content of the teaching materials, but also by the way the lectures were delivered. In addition, by selecting the theme of the cyber range development, we were able to achieve the intended skill improvement for the faculty. Through the implementation of HACK until the second year, we were able to identify many factors for skill improvement. In the third and fourth years of the program, we will continue to look for factors that can be used to further improve specific skills, and at the same time, we will explore the relationship with motivation, which is expected to contribute greatly to educational effectiveness.
Keiichi Yonemura, Shinya Oyama, Hideyuki Kobayashi, Satoru Yamada, Keiichi Shiraishi, Satoru Izumi, Tatsuki Fukuda, Hiroyuki Okamoto, Manabu Hirano, Youichi Fujimoto, Hideaki Moriyama, Yoshinori Sakamoto, Jun Sato, Kentaro Noguchi, Hisashi Taketani, Seiichi Kishimoto
EDUCON9
2016 A Log-Structured Block Preservation and Restoration System for Proactive Forensic Data Collection in the Cloud
abstract
Preservation and data collection in cloud environments are difficult because forensic data are volatile and they are scattered in many servers. This paper describes a novel surveillance mechanism for virtual block devices on IaaS cloud environments. We first describe some related work on backup applications, versioning file systems, and virtual machine introspection systems that can be applied to cloud forensics. The proposed log-structured block preservation and restoration system can be used for recording cloud consumers' write operations on virtual block devices and for restoring the state of a virtual block device at an arbitrary point in time. This paper presents a design and an implementation of the proposed system by using Xen hypervisor. The prototype implementation achieved better read and write performance compared to the baseline driver provided by Xen when we ran four or more virtual machines simultaneously. This paper shows two forensic applications for preserved data blocks: a file tracking application and a novel diff command that supports time travel.
Manabu Hirano, Hiromu Ogawa
ARES1
2015 Evaluation of a Sector-Hash Based Rapid File Detection Method for Monitoring Infrastructure-as-a-Service Cloud Platforms
abstract
Current computer forensics tools have some limitations on anti-forensics attacks, cloud computing, and a large increase in the size of forensics targets. To solve these problems, this paper proposes a system that preserves storage data on virtual machines by acquiring all data sectors with time stamps. The proposed system can restore a previous state of a block device at any date and time that is specified by an investigator. The proposed system aims to monitor users' behavior in Infrastructure-as-a-Service (IaaS) cloud platforms. This paper also presents a rapid file detection system that finds a target file from a large collection of the acquired data sectors by using sector-hashes and parallel distributed processing. This system enables investigators to track and to find a target file that is related to incidents or crimes in the cloud. First, this paper reports the preliminary experiments of a sector-hash based file detection method on three major operating systems for evaluating its effectiveness. We present a design and an implementation of the proposed monitoring and target file detection system by using Xen hypervisor and MapReduce. We report results of its performance evaluation. Finally, we discuss possible methods to improve the performance and the limitations of the current proposed mechanism.
Manabu Hirano, Hayate Takase, Koki Yoshida
ARES1
2009 BitVisor: a thin hypervisor for enforcing i/o device security
abstract
Virtual machine monitors (VMMs), including hypervisors, are a popular platform for implementing various security functionalities. However, traditional VMMs require numerous components for providing virtual hardware devices and for sharing and protecting system resources among virtual machines (VMs), enlarging the code size of and reducing the reliability of the VMMs.This paper introduces a hypervisor architecture, called parapass-through, designed to minimize the code size of hypervisors by allowing most of the I/O access from the guest operating system (OS) to pass-through the hypervisor, while the minimum access necessary to implement security functionalities is completely mediated by the hypervisor. This architecture uses device drivers of the guest OS to handle devices, thereby reducing the size of components in the hypervisor to provide virtual devices. This architecture also allows to run only single VM on it, eliminating the components for sharing and protecting system resources among VMs.We implemented a hypervisor called BitVisor and a parapass-through driver for enforcing storage encryption of ATA devices based on the parapass-through architecture. The experimental result reveals that the hypervisor and ATA driver require approximately 20 kilo lines of code (KLOC) and 1.4 KLOC respectively.
Takahiro Shinagawa, Hideki Eiraku, Kouichi Tanimoto, Kazumasa Omote, Shoichi Hasegawa, Takashi Horie, Manabu Hirano, Kenichi Kourai, Yoshihiro Oyama, Eiji Kawai, Kenji Kono, Shigeru Chiba, Yasushi Shinjo, Kazuhiko Kato
VEE7
2008 Introducing Role-Based Access Control to a Secure Virtual Machine Monitor: Security Policy Enforcement Mechanism for Distributed Computers
abstract
In recent years, as the data processed by governmental or commercial organizations increases, cases involving information leak have risen. It is difficult to control information on many distributed end-point computers using conventional security mechanisms. Therefore, we have been proposed a novel secure VMM (Virtual Machine Monitor) architecture which is used as a foundation of security policy enforcement on distributed computers. This paper especially introduces Role-based Access Control (RBAC) to theID management framework in a secure VMM system. Our proposal will reduce costs for distributed policies updates. Proposed RBAC mechanism employs attribute certificates (ACs) to handle user’s roles. This paper shows design and prototype implementation based on PKI-based ID card and proven open source VMM software, QEMU.
Manabu Hirano, Takahiro Shinagawa, Hideki Eiraku, Shoichi Hasegawa, Kazumasa Omote, Kouichi Tanimoto, Takashi Horie, Kazuhiko Kato, Takeshi Okuda, Eiji Kawai, Suguru Yamaguchi
APSCC1