VLDB 2026 Research / reviewers in the wild / expert
Kotaro Kataoka
dblp:31/4385
· DBLP profile ↗
22ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0003-0545-3415ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 1 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HRL-D3: High resolution and lightweight defective data detection for IoT data integrity
Suparna Kar, Kaif Ali Khan Parigi, Ravi Surendra Nalawade, Vanga Aravind Shounik, Vikas Ravi Patil, Kotaro Kataoka |
Future Gener. Comput. Syst. | 6 |
| 2026 | Enhancing Security and Achievability of PBFT-Based Consensus Development for Connected Vehicles With Location-Based TrustabstractIn Intelligent Transportation Systems (ITS), permissioned blockchains have been adopted to record location specific traffic contexts among legitimate vehicles. This paper aims to address two challenges in using a permissioned blockchain for ITS: 1) ensuring the legitimacy and timeliness of vehicles together to join the permissioned blockchain and 2) maintaining the availability of contextually relevant, fast-moving vehicles to serve as endorsers for reliable consensus on traffic event verification at road junctions. This paper introduces V-Trust, an integrated system for a location specific PBFT-based blockchain network enhanced with Location Certificate, Fast Joining Protocol, Network Prefetch, Dynamic Endorsers Management, and Delayed Endorsement. These components ensure 1) the legitimacy and quickness of vehicles to join a permissioned blockchain, 2) the selection of contextually relevant vehicles for endorsing a traffic event, and 3) the improvement of endorser availability by allowing legitimate and contextually relevant vehicles to participate in the consensus even after leaving the junction. The V-Trust was simulated and evaluated using ns-3 with a 4G LTE setup. The evaluation results confirmed that V-Trust enables a vehicle to join a PBFT network with one bidirectional message exchange (virtually 1 RTT using a persistent TCP connection) between a vehicle and a Roadside Unit (RSU) and the communication overhead of O(1). Reshu Verma, Kotaro Kataoka |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | FlowMeterLite: Real-time General Purpose Flow Metering as a Module for SDN ApplicationsabstractExisting flow feature extraction techniques depend on packet traces or are limited in terms of the number of flow features as well as easiness to enable. This paper proposes FlowMeterLite as a general purpose solution that extracts the flow features using OpenFlow messages and its counter without depending on full scale packet traces. FlowMeterLite can extract 63 flow features with more than 93% accuracy compared to CICFlowMeter as our benchmark. FlowMeterLite works with very less computational overhead and network overhead than the benchmark because full scale packet capturing is not used, and our system takes the advantage of calculations performed in OpenFlow switches. Vanga Aravind Shounik, Jeevan Sammeswar Siddaboena, Kotaro Kataoka |
GLOBECOM | 3 |
| 2024 | Revocable TACO: Revocable Threshold based Anonymous Credentials over BlockchainsabstractThe anonymity, multi-show unlinkability, and selective disclosure property of anonymous credentials enables users to access third-party services without revealing unnecessary details or being profiled. Threshold-based anonymous credentials provide a distributed framework to issue these credentials. While all of this enhances privacy, anonymity can also be misused and some schemes, therefore, have an opening mechanism, which enables the authorities to trace a user's identity. Nevertheless, relying solely on this measure is inadequate as the users can continue to use their previously issued anonymous credentials to authenticate themselves successfully with the service providers. To address this issue, we propose a revocation mechanism for such schemes using dynamic threshold accumulators (DTA) (Helminger et al. 2021). We first formally define a generic threshold-based anonymous credentials with an opening scheme (TACO) and subsequently propose an extension of TACO, "Revocable TACO (RTACO)" - revocable threshold-based credentials over blockchains - that integrates a revocation mechanism based on DTAs to the TACO system. In RTACO, we integrate a revocation handle into the credential as an extra attribute, allowing the disclosure of this attribute during the opening phase, which is then used to blocklist the credential, preventing its further use. We formally prove the security of this scheme in the universal composability (UC) framework. We also give a proof-of-concept implementation of RTACO over the Ethereum blockchain. Kanchan Bisht, Neel Yogendra Kansagra, Reisha Ali, Mohammed Sayeed Shaik, Maria Francis, Kotaro Kataoka |
AsiaCCS | 6 |
| 2024 | Off-Chaining Approaches for Cost-Efficiency in Threshold-Based Elliptic Curve Systems over Blockchains
Visakh K. Vijayan, Maria Francis, Kotaro Kataoka |
ICISSP | 3 |
| 2023 | Verifiable and Robust Monitoring and Alerting System for Road Safety by AI based Consensus Development on BlockchainabstractThe integration of AI and the Blockchain has been explored by existing solutions that cooperatively detect and alert a dangerous situation for road safety purposes. However, most such solutions endorse a transaction without considering the context conveyed. Alternatively, their concept has not been implemented as a deployable system for a trial in the field. Considering a use case to be the safety of a pedestrian in a traffic junction, this paper proposes a novel approach, the VErifiable and Robust Monitoring and Alerting (VERMA) system, that 1) detects a potentially dangerous situation (like a fallen pedestrian on the road), 2) immediately alerts the other stakeholders, the driver, and the driving assistance system in the proximity, and 3) records the detected danger in the Blockchain with auditable evidence. The key feature of the proposed system is the multi-AI PBFT-based voting mechanism that enables the other participating nodes to verify the context of the reported dangerous situation using their own AI from different angles and locations in the junction. The VERMA system was implemented by emulating a pseudo vehicle using a smartphone and a GPU-enabled laptop computer that satisfies the requirement to be tested in the field. The evaluation results through the field trial confirm the end-to-end integration of the proposed system with the fast consensus development. This paper also organizes the lessons that should be considered for real-world deployment. Reshu Verma, Vishnu V. S, Kotaro Kataoka |
IV | 3 |
| 2023 | Scaling IoT MUD Enforcement using Programmable Data PlanesabstractIoT-based intrusions and network attacks are becoming ever more concerning. As a mitigatory measure, the IETF standardized Manufacturer Usage Description (MUD) which allows IoT device vendors to specify the legitimate communication patterns (as a MUD profile) of an IoT device. A MUD profile allows the validation of the actual communication pattern of an IoT device with the intended behavior at runtime. However, as the number of IoT devices increases, validation at runtime has scalability challenges in terms of the number of switch resources (e.g., TCAM) required to maintain MUD profiles.In this work, we propose a scalable data plane primitive and a system on top of the primitive, which together enforce MUD profiles of thousands of IoT devices in a P4 programmable switch data plane. Our main idea is to avoid inefficiencies because of the repetition of header values while representing MUD profile-based ACL rules. Further, we exploit the characteristics of header values in ACL rules of real IoT devices and carefully partition the rules across multiple hash-based exact match-action tables in the switch data plane. Since hash-based data structures can be implemented using SRAM which is cheap and abundantly available (order of MBs) in commodity programmable switches, our approach scales well for a large IoT network. Harish S. A, Suvrima Datta, Hemanth Kothapalli, Praveen Tammana, Achmad Basuki, Kotaro Kataoka, Selvakumar Manickam, U. Venkanna 0001, Yung-Wey Chong |
NOMS | 6 |
| 2022 | ResiConnect - Fault Detection and Resilience for Multi-Stage AWGR-based Optical NetworksabstractArrayed Waveguide Grating Router (AWGR) based optical networks are emerging as a promising solution for handling modern data centers due to their wide bandwidth, scalability, high data rates, and lower latency. However, link failures in AWGR based optical networks can significantly impact the network performance and lead to the loss of reachability due to the rigid, passive wavelength routing. In this paper, we present ResiConnect, a scalable, and resilient optical network architecture. ResiConnect is a 3-stage Clos network of AWGR, space switches, and AWGR (ASA) which is managed by a centralized controller. ResiConnect introduces an alternative path to redirect the affected traffic by vertically connecting transmitters, and incorporates an active link fault detection and the failover traffic steering. The evaluation results on various performance metrics confirm that ResiConnect is 1) resilient and scalable against multiple link faults, 2) efficient in detecting any link fault with minimum resource overhead, and 3) efficient in handling uneven traffic demand during link failure. Anish Hirwe, Nikita Makharia, Tanmay Renugunta, Kotaro Kataoka |
APNOMS | 4 |
| 2022 | Topology Poisoning Attacks and Prevention in Hybrid Software-Defined NetworksabstractThe hybrid software-defined networks (SDN) architectures are beneficial for a smooth transition and less costly SDN deployment. However, legacy switches and SDN switches coexistence brings new challenges of deployment inconsistency management and security. Security is not well studied for hybrid SDN architecture. In this paper, we study the topology poisoning attacks in hybrid SDN for the first time. We propose new attack vectors for link fabrication in hybrid SDN. The new attack is named “multi-hop link fabrication,” in which an adversary successfully injects a fake multi-hop link (MHL) by exploiting the link discovery protocols. We presented the Hybrid-Shield, a link verification framework for hybrid SDN link discovery. Hybrid-Shield introduces a novel verification technique that includes: i) monitoring legacy switch and host generated traffic at MHL and ii) validating the existence of legacy switches contained in an MHL. This paper presents the prototype implementation of Hybrid-Shield over a real SDN controller. The experimental evaluation is performed with the mininet virtual network emulation. Our evaluation shows that Hybrid-Shield is capable of detecting MHL fabrication attacks in real-time with high accuracy. Hybrid-Shield’s performance evaluation shows that it is lightweight at the controller as it causes less overhead and requires no additional functionalities at the SDN controller for deployment. Pragati Shrivastava, Kotaro Kataoka |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | BO-RL: Buffer Optimization in Data Plane Using Reinforcement Learning
M. Sneha, Kotaro Kataoka, G. Shobha |
AINA (1) | 2 |
| 2021 | TRAQR: Trust aware End-to-End QoS routing in multi-domain SDN using Blockchain
Prashanth Podili, Kotaro Kataoka |
J. Netw. Comput. Appl. | 2 |
| 2020 | pSMART: A lightweight, privacy-aware service function chain orchestration in multi-domain NFV/SDNabstractService Function Chaining (SFC) has become an integral part of every emerging application to satisfy its specific demand. Due to the massive increase in such diverse applications, there is a need for an efficient solution for flexible SFC orchestration. In this context, deploying SFC across domains can be a promising way to provide the required network services through cost-effective resource utilization . However, the operation of Multi-Domain SFC (MD-SFC) mainly has a trade-off between privacy and performance. While sharing the detailed network information, such as topology and resource availability , is important for the efficient MD-SFC orchestration, the network operators are not willing to disclose such private and detailed network information about the domain network. As a result, there is always a higher demand for privacy preservation while employing efficient MD-SFC orchestration. In this paper, we present pSMART, a lightweight, privacy-aware service function chain orchestration in a multi-domain NFV/SDN scenario. The main purpose of pSMART is to utilize less sensitive information , to reduce privacy and security risks, and to employ learning based decision making for efficient MD-SFC mapping. We quantify and analyse the gain of the proposed pSMART approach in terms of privacy-preservation and response time . The simulation results show that the proposed pSMART approach achieves a higher level of privacy and optimizes the response time of MD-SFC orchestration. Kalpana D. Joshi, Kotaro Kataoka |
Comput. Networks | 2 |
| 2020 | EvilScout: Detection and Mitigation of Evil Twin Attack in SDN Enabled WiFiabstractSpoofing the identity of a WiFi access point (AP) is trivial. Consequently, an adversary can impersonate the legitimate AP (LAP) by mimicking its network name (SSID) and MAC address (BSSID). This fake AP is called the evil twin. An evil twin can perform multiple attacks such as man-in-the-middle (MITM) attack between the LAP and a wireless client as well as service blocking of LAP. Existing solutions rely on the collection and calculation of information with the AP and/or client for finding evidence of evil twins in the WiFi network. Some of them require additional hardware to acquire further information that cannot be provided by the AP/client. In this paper, we propose “EvilScout,” an evil twin detection and mitigation framework that utilizes the information of the IP-prefix distribution by the LAP. EvilScout exploits the SDN potential for detection of an evil twin without the need of any additional hardware or modifications at the AP or client. Additionally, the information that becomes available at the SDN controller enables simplified and more accurate evil twin detection. This paper presents the implementation of EvilScout over a real SDN WiFi testbed with an actual evil twin. We verify the successful detection of the evil twin with high accuracy and low processing cost at the SDN WiFi. We perform a rigorous analysis of the evil twin in different WiFi setups and discover a new “AP Service Blocking” attack by the evil twin adversary in the WPA2 protected WiFi for the first time. Pragati Shrivastava, Mohd. Saalim Jamal, Kotaro Kataoka |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2019 | BEAM: BEhavior-Based Access Control Mechanism for SDN ApplicationsabstractSoftware-Defined Networking (SDN) allows applications to control and manage the network from the northbound interface. These network applications can be installed by a third party; that cannot be trusted blindly. A Misconfigured or compromised application is a severe threat to the SDN controller. Providing proper access control mechanism to SDN applications can prevent malicious activities. However, the existing access control mechanisms define the static access permissions, and cannot prevent the malicious activities of the application at runtime. Therefore, we propose "BEAM", a BEhavior-based Access control Mechanism which dynamically grants the permissions based on the analysis of network behavior. BEAM periodically upgrades/downgrades the assigned access permissions, verifies and builds trust for an application. Bhavesh Toshniwal, Kalpana D. Joshi, Pragati Shrivastava, Kotaro Kataoka |
ICCCN | 4 |
| 2019 | PRIME-Q: Privacy Aware End-to-End QoS Framework in Multi-Domain SDNabstractThis paper presents the privacy preserving End-to-End (E2E) Quality of Service (QoS) mechanism in multi-domain Software Defined Network (SDN). Guaranteed E2E QoS needs complete information about the network. But, in multi-domain SDN, information sharing among different operators mainly have privacy and security issues; thus, operators may not share such network information. Moreover, such information collection is not only computationally expensive but also it requires a lot of message exchange between the domain controllers. Hence, we propose PRIME-Q, a PRIvacy aware E2E QoS framework in Multi-domain SDN. In PRIME-Q, instead of collecting the required information about the network at a single location, the data is distributively processed, and only the binary decision is reported at a single point to take the final decision about E2E QoS. To quantify the gain of PRIME-Q, we define Privacy Index to measure the privacy of E2E QoS coordination in multidomain SDN. The results show that the learning approach of PRIME-Q can achieve the required E2E QoS with maximum privacy. Further, the numerical results for PRIME-Q show a significant reduction in the communication and computation overhead in the network. Kalpana D. Joshi, Kotaro Kataoka |
NetSoft | 2 |
| 2018 | Poster: Detection of Topology Poisoning by Silent Relay Attacker in SDNabstractTopology Poisoning can be easily performed by injecting a fake link between SDN switches using a silent relay attack. This attack is difficult to detect because 1) the attacker is a passive man-in-the-middle to relay control messages between the compromised ports on SDN switches, and 2) such messages are genuine for the SDN switches and controller. This poster proposes Silent Relay Detector (SRD) that tailor- makes the SDN control messages to be processed normally by authentic switches but to make the attacker malfunction. The SRD implementation and experiment reveal how the silent relay attack is detected and fake link injection is prohibited ingeniously. Pragati Shrivastava, Annanay Agarwal, Kotaro Kataoka |
MobiCom | 3 |
| 2018 | Effective resource provisioning for QoS-aware virtual networks in SDNabstractThe emergence of the IoT, 5G and different modes of computing has introduced a new demand to tailor-made networks to support a wide spectrum of applications. Even though virtualizing networks and applying QoS to these networks are crucial, it is always challenging to achieve QoS, high acceptance ratio, and cost effectiveness on provisioning virtual networks given the constrained resource of the underlying network. This paper introduces Delay Constraint Optimum Bandwidth Tree (DCOBT), which effectively satisfies the QoS requirement of virtual networks in terms of both end-to-end delay and bandwidth. We propose the QoS-aware Resource Provisioning (QRP) algorithm to determine DCOBT with less bandwidth consumption and superior load balancing. Using SDN as a key platform to implement QoS-aware virtual networks, this paper further proposes flow rule reduction using Destination Label Forwarding (DLF) to provision more virtual networks with less Ternary Content-Addressable Memory (TCAM) consumption. The evaluation results proved significant contribution on different aspects of resource provisioning for QoS-aware virtual networks with improved availability, scalability, and cost effectiveness. Prashanth Podili, Kotaro Kataoka |
NOMS | 2 |
| 2015 | liteFlow: Lightweight and distributed flow monitoring platform for SDNabstractTraditional network monitoring involving packet capturing or flow sampling has many challenges such as scalability, accuracy and availability of processing resource when networks become large-scale, high-speed and heterogeneous. SDN is a promising approach to address these challenges, but each SDN switch has it's own capacity limitation, such as it's cache memory called TCAM, and thus it needs coordination of resources with other network nodes to monitor the network in a scalable manner. liteFlow introduces an intelligent framework for authority switch selection, which is in charge of monitoring all flows between an end-hosts pair, while the other path switches simply forward packets without any monitoring process. The proposed system distributes the load of monitoring flows among SDN switches, and makes the scalability and accuracy of network monitoring manageable. This paper also implements a few metrics for flow-based network monitoring as example applications of liteFlow. The proof of concept implementation has been done using SDN testbed partially involving campus network of IIT Hyderabad. Naman Grover, Kotaro Kataoka |
NetSoft | 3 |
| 2015 | Performance evaluation of wireless ad-hoc network for post-disaster recovery using Linux Live USB nodesabstractWireless ad-hoc networks are unplanned, quickly deployable, infrastructureless, and realistic for networking in emergency or restricted situations. They have actively been studied and proposed for post-disaster recovery. Our approach uses Linux Live USB nodes, which can be any available laptop computer at disaster-affected site, to boot the guest OS using USB flash drive with a variety of customized software packages demanded in post-disaster situations. Using an additional Wi-Fi USB adapter, Linux Live USB nodes help to easily form wireless ad-hoc network and serve user devices through Wi-Fi hotspot. While a lot of studies have been done over simulation, it is crucial to understand how wireless ad-hoc networks behave and their performance in the real field. In this paper, we examine different scenarios of wireless ad-hoc network deployment inside a building: 1) the assignment of frequency (Single Channel or Multi Channel), and 2) choice of mesh and routing protocol (OSLR or batman-adv). According to the results of field trials, our primary option of deployment will be Multi Channel batman-adv to cover multiple rooms inside the building expected to be evacuation shelter. Kotaro Kataoka, Siva Subramanya Rohith Talluri |
WiMob | 2 |
| 2014 | Scaling a broadcast domain of Ethernet: Extensible transparent filter using SDNabstractScalability of Ethernet is a known issue where communication is disturbed by broadcast traffic caused by a large number of nodes in a single broadcast domain. This paper proposes Extensible Transparent Filter (ETF) for Ethernet using SDN, that suppresses broadcast traffic in a broadcast domain by selecting an appropriate outgoing port of the switch through which the target host of broadcast packet is reachable. ETF maintains both consistent functionality and backward compatibility of the existing networking protocols such as Address Resolution Protocol, Dynamic Host Configuration Protocol, and other possible protocols that work with the broadcast of a packet. ETF was developed using Trema and Floodlight, which are open source SDN controller supporting OpenFlow. The number of flooding was significantly reduced in a broadcast domain where user clients connecting to the same VLAN across multiple production SDN switches successfully performed DHCP and ARP respectively. This paper also discusses the practical deployment and operation of SDN and ETF as a part of campus network in Indian Institute of Technology Hyderabad. The proposed approach improves scalability of a broadcast domain of Ethernet as an enhancement to the existing enterprise networks using SDN. Kotaro Kataoka, Aditya V. Kamath |
ICCCN | 1 |
| 2012 | A rapidly deployable disaster communications system for developing countriesabstractWe address the problem of designing a communication system for deploying under disaster situations where the pre-disaster communication infrastructure has been uprooted. The disaster communication system is required to aid in rescue effort by providing text, voice, and video communication links between the field worker and the operation center. It is also required to provide some communication services to the affected citizens so that the overwhelming demands made on the communication infrastructure during the times of disaster are mitigated to some extent. The other highlights of the design are its low-cost nature by exploiting the economies of scale and the fact that basic mobile phones with text-only features are widely available in developing countries. Devendra Jalihal, Ravinder David Koilpillai, P. Khawas, S. Sampoornam, Sree Hari Nagarajan, Keiji Takeda, Kotaro Kataoka |
ICC | 7 |
| 2011 | On Operational Scheme for Remote Lectures in Inter-university Distance Learning Project
Noriatsu Kudo, Kotaro Kataoka, Jun Murai |
CSEDU (2) | 2 |