VLDB 2026 Research / reviewers in the wild / expert
Daisuke Kotani
dblp:38/10847
· DBLP profile ↗
25ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0003-4305-8379ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 15 · 1 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 1 first-author · 9 since 2021Security and privacy · 4 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Generating Diverse Network Control Policies for Cyber Attack Response Support via Service Dependency Graph Exploration
Shinnosuke Kataoka, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2026 | Automated Attack Trace Generation: Investigating Coverage and Cleanup Resilience
Masahito Kumazaki, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2026 | Kubernetes-Based Transparent Orchestration of Heterogeneous IoT Devices Through Peripheral Abstraction with Webassembly
Soichiro Ueda, Ai Nozaki, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2025 | Operational Planning of a Home Energy Management System Using Regional Weekly Weather Forecasts to Mitigate Surplus ElectricityabstractPhotovoltaic (PV) systems often generate surplus electricity during daytime when production exceeds demand. To address this, existing studies optimize energy storage and heat-pump (HP) water heater operations but typically focus only on same-day forecasts. This study proposes using regional weekly weather forecasts to enhance PV surplus management. Solar irradiance is estimated via machine learning trained on historical data, using daily and weekly forecasts as inputs. Predicted irradiance informs PV generation forecasts, guiding optimal operational planning for battery storage and HP water heaters through linear programming. Plans are adjusted based on actual generation data. Results indicate that perfectly accurate weekly forecasts could reduce surplus electricity by 16% compared to same-day forecasts. Even with estimated irradiance, integrating next-day forecasts reduces surplus by 0.66% relative to same-day predictions alone. Hiroaki Aoyama, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2025 | Impact Evaluation of Attacks on Data Flows in Systems With Heterogeneous Redundant ResourcesabstractCyber-physical and IoT systems gather diverse real-world data through systems created by heterogeneous hardware, software resources, and communication technologies, which introduce various threats and countermeasures. Although protecting data transmitted over the system is critical, previous work has not shown how to model these threats and countermeasures to evaluate attack impacts in each threat category. We propose a framework to evaluate the attack impact on data flows in systems with heterogeneous resources by representing the threats existing in each node and the countermeasures applied to data flows in their respective categories. Our framework determines whether a dataflow is compromised or not for each threat category. We define a hierarchical model of resources and vulnerabilities, represent threats and countermeasures by vectors, and develop a metric to quantify attack impacts. To validate the framework, we assess a simple IoT sensor system combining ZigBee and LoRa, demonstrating how it captures protocol and device differences. As a result, our framework flags only threats with realistic attack risks as compromised. Kosei Shimoda, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2025 | Tiaccoon: Unified Access Control with Multiple Transports in Container NetworksabstractContainer orchestration tools use container overlay networks for communications between containers and enforcement of network access control policies to containers. Use of appropriate transports such as UNIX domain socket and RDMA for communications between containers provide higher throughput and lower latency than TCP/IP, although each transport have limitation on applicable scenarios. However, applications face challenges in flexibly selecting appropriate transports for each connection while container networks consistently apply unified network access control policies. To address this problem, we propose Tiaccoon, achieving unified access control and container communication regardless of transports by replacing the process of socket API. Tiaccoon hooks system calls related to socket API called by applications, applies access control for the connection, creates a socket with the fast transports available for communication with the destination containers, and replace the socket with the created one. Our evaluation shows Tiaccoon achieved throughput, round trip latency, and CPU time equivalent to host networks, which is better than container overlay networks. We also show Tiaccoon satisfies the requirements of container networks and can replace existing container overlay networks for connection-oriented protocols. Hiroya Onoe, Daisuke Kotani, Yasuo Okabe |
Middleware | 2 |
| 2025 | PiCoP: Service Mesh for Sharing Microservices in Multiple Environments Using Protocol-Independent Context PropagationabstractContinuous integration and continuous delivery require many production-like environments in a cluster for testing, staging, debugging, and previewing. In applications built on microservice architecture, sharing common microservices in multiple environments is an effective way to reduce resource consumption. Previous methods extend application layer protocols like HTTP and gRPC to propagate contexts including environment identifiers and to route requests. However, microservices also use other protocols such as MySQL, Redis, Memcached, and AMQP, and extending each protocol requires lots of effort to implement the extensions. This paper proposes PiCoP, a framework to share microservices in multiple environments by propagating contexts and routing requests independently of application layer protocols. PiCoP provides a protocol that propagates contexts by appending them to the front of each TCP byte stream and constructs a service mesh that uses the protocol to route requests. We design the protocol to make it easy to instrument into a system. We demonstrate that PiCoP can reduce resource usage and that it applies to a real-world application, enabling the sharing of microservices in multiple environments using any application layer protocol. Hiroya Onoe, Daisuke Kotani, Yasuo Okabe |
IEEE Trans. Cloud Comput. | 2 |
| 2024 | DDoS Attack Information Sharing Among CDNs Interconnected Through CDNIabstractAs CDNs facing DDoS attacks targeting some content every day, CDNI, which is designed to allow multiple CDNs to cooperate each other to distribute content more broadly, will also be targeted if CDNI distributes such content, but for small CDNs owned by ISPs or NSPs in CDNI, it is hard to mitigate large DDoS attacks continuously because of financial limitations. Considering that each CDN in CDNI is operated autonomously in terms of system, security, etc., countermeasures against DDoS attacks should be implemented autonomously in each CDN, so that one of possible countermeasures against DDoS attacks in CDNI is to share information among CDNs to cope with DDoS attacks cooperatively. However, there is no previous research about what an architecture are required or what information should be shared through them to handle DDoS attacks. In this study, we propose a system that handles DDoS attacks through information exchange with leveraging capabilities of CDNI, and we show that, through several use cases of this system, information for requesting CDNI operations and information representing the attacks are essential. Especially, in order for the CDNI to effectively respond to attacks and gain the cooperation of more CDNs, two key types of information are needed: the volume of the attack and information that helps mitigate the attack. Finally, we briefly show an example implementation approach of the architecture and a format for sharing this information by using DOTS. Kazuki Takashima, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2024 | Putting Authorization Servers on User-Owned Devices in User-Managed Access
Masato Hirai, Daisuke Kotani, Yasuo Okabe |
SEC | 2 |
| 2023 | Partial Outsourcing of Malware Dynamic Analysis Without Disclosing File ContentsabstractDynamic analysis is one of the methods to analyze malware. However, if the file to be analyzed contains confidential information, disclosing it to the analyst outside the organization is undesirable. Previous works proposed classifying malware while preserving privacy or outsourcing dynamic analysis, but it is challenging to outsource dynamic analysis without disclosing file contents. The proposed method builds the Local Environment for users and the Remote Environment for analysts outside the organization. We proposed partial outsourcing, which opens a file in the Local Environment, reproduces its behavior in the Remote Environment, and conducts dynamic analysis based on this information. The Local Environment hooks an API call and retrieves information on the function name and arguments. Then, the Local Environment sends the information to the Remote Environment to reproduce file behavior. Our method could reproduce most operations on files and registries but could not reproduce some operations on files. Keisuke Hamajima, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2023 | Efficient Container Image Updating in Low-bandwidth Networks with Delta EncodingabstractContainers are the technology for Linux to isolate execution environments. By distributing a container image, which is a collection of files contained in the container, users can use an execution environment that includes the necessary files and libraries. However, container images are tens to hundreds of megabytes in size and require many network resources to be transferred. Especially in low-bandwidth network environments like edge computing, frequent image updating can be difficult and affect other services’ communication. In this paper, we propose a method to reduce the data size required for image updates using delta encoding. We use delta encoding to reduce data size and finish updating quickly, but generating and applying deltas is a time-consuming operation. Our method proposes DeltaMerging which enables faster delta generation by merging existing deltas, and Di3FS which applies deltas lazily. The proposed method reduces the data size required to update container images from 5 to 40% of that of existing methods. Also, the time required to generate and apply deltas is greatly reduced with DeltaMerging and Di3FS. Furthermore, the performance degradation of the application in the container was almost negligible. Naoki Matsumoto, Daisuke Kotani, Yasuo Okabe |
IC2E | 2 |
| 2023 | Protocol-Independent Context Propagation for Sharing Microservices in Multiple EnvironmentsabstractIn systems designed based on microservice architecture, many production-like environments should be deployed for testing, staging, debugging, and previewing. One way to reduce resource consumption while deploying many environments is to allow sharing of common microservices in multiple environments, and current mechanisms extend application layer protocols like HTTP and gRPC to propagate contexts including environment identifiers and to route requests. However, microservices also use other protocols such as MySQL, Redis, Memcached, and AMQP, and extending each protocol requires lots of effort to implement the extensions. This paper proposes PiCoP, a framework to propagate contexts and route requests independently of application layer protocols. PiCoP consists of a protocol that propagates contexts without interpreting application layer protocols by adding contexts to the front of each TCP byte stream and a proxy that uses the protocol to route requests. We design the protocol to make instrumentation into a system as easy as possible. We showed that PiCoP could reduce resource usage, that the proxy's communication delay is within a practical range, and that it makes sharing microservices in multiple environments with any application layer protocols possible. Hiroya Onoe, Daisuke Kotani, Yasuo Okabe |
IC2E | 2 |
| 2023 | Key Management Based on Ownership of Multiple Authenticators in Public Key Authentication
Koudai Hatakeyama, Daisuke Kotani, Yasuo Okabe |
SEC | 2 |
| 2023 | Visibility of Scan Traffic Trends in Sparsely Populated Darknets
Kodai Mizutani, Daisuke Kotani, Yasuo Okabe |
SecureComm (2) | 2 |
| 2021 | QoS Network Control for Elderly Support ServicesabstractA variety of traffic flows will be generated by various IoT devices in the home in auxiliary services for an aging society. In this study, a network control system was developed to control the Quality of Service (QoS) of its traffic according to the characteristics of devices, services, and users. Assuming a relatively small network environment such as a home network, a mechanism to easily realize QoS through centralized control using SDN and a REST API to specify QoS from applications were designed and implemented. Daisuke Kotani, Taku Tanaka, Yasuo Okabe |
COMPSAC | 1 |
| 2021 | Analysis of Inter-regional Relationship among Regional Tier-1 ASes in the InternetabstractThe ASes on the Internet are considered to be in a hierarchical structure and are called Tier 1, Tier 2 and Tier 3 from the upper level. ASes ranked at the same Tier are believed to be in an equal relationship (a peering relationship). A subset of Tier 2 is generally regarded as Regional Tier 1 which can obtain almost all route information in a specific region without receiving them from Tier-1 ASes. The scale and the target customers of Regional Tier-1 ASes are different by the region, and such factors may result in an unequal relationship when Regional Tier-1 ASes in two countries are connected. In this paper, we analyze the connection between ASes considered as Regional Tier 1 in two countries, assuming that the target region of Regional Tier 1 is one country. Firstly, we proposed the method to identify the Regional Tier-1 ASes in each country. Next, we examined the relationships between Regional Tier-1 ASes in six countries, the top five countries with the largest number of ASes and Japan, and we confirmed that there were some connections in the transit relationships. We also found that an AS becomes a provider of many foreign Regional Tier-1 ASes, and that an AS peers with small ASes but provides transit to larger ASes in foreign countries. Takuya Urimoto, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2020 | Improving Attack Detection Performance in NIDS Using GANabstractNowadays, various methods are proposed to build effective anomaly-based Network Intrusion Detection System (NIDS). However, malicious packets are extremely less than normal packets and this class imbalance problem will result in low performance of attack detection. In this study, we have proposed a new hybrid oversampling model using GAN to improve attack detection performance in anomaly-based NIDS. It contains three main steps: feature extraction by Information Gain and PCA, data clustering by DBSCAN and data generation by WGAN-DIV. For performance evaluation, three HTTP only datasets: NSL-KDD-HTTP, UNSW-NB15-HTTP and Kyoto2006-Plus-HTTP are used. Six machine learning methods are utilized as anomaly-based NIDS and SMOTE is also used for comparison. Our model with XGBoost has achieved best F1-score in these three datasets from the results. Daisuke Kotani, Yasuo Okabe |
COMPSAC | 2 |
| 2019 | An Architecture of a Network Controller for QoS Management in Home Networks with Lots of IoTDevices and ServicesabstractMore and more IoT services are introduced in home, and they will consume many network resources in home networks including an uplink to the Internet, but the resources are sometimes insufficient to host all services. Traditionally, QoS control is applied to handle such situation by prioritizing important traffic. However, in IoT at home, it is hard to find important traffic because it depends on the context that is greatly different among homes, such as services and the life of residents. In addition, administrators in home networks can rarely understand the context and configure the whole system including IoT devices and services. This paper proposes an architecture of the network controller that automatically estimates and prioritizes important traffic under such situation. The controller under the proposed architecture provides three interfaces to ask each party, IoT devices, service providers, and users, for input about its information. Then, the controller automatically estimates the important traffic based on the input and applies the estimated policy to the network in a centralized way. This paper also shows key points of designing each interface according to the information that each party knows. Daisuke Kotani |
CCNC | 1 |
| 2019 | Detecting Successful Attacks from IDS Alerts Based On Emulation of Remote ShellcodesabstractServer administrators and security operation center analysts receive alerts from an intrusion detection system and check whether attacks have succeeded. However, it is difficult to handle them quickly because a tremendous number of alerts is generated in a short period of time. We propose a method to identify important alerts that lead to security incidents automatically. The key idea is to determine the success or failure of an attack based on traffic logs and the network behaviors observed during shellcode emulation. We evaluated the proposed method in terms of accuracy and performance and found that it can handle more than 60% of remote shellcodes and cope with practical attack cases. Yo Kanemoto, Kazufumi Aoki, Makoto Iwamura, Jun Miyoshi, Daisuke Kotani, Hiroki Takakura, Yasuo Okabe |
COMPSAC (2) | 5 |
| 2018 | Detecting Emerging Large-Scale Vulnerability Scanning Activities by Correlating Low-Interaction Honeypots with DarknetabstractCyberattacks such as scanning by botnet worms, falsification of web pages, and security breaches happen on the Internet every day. To minimize damage caused by such attacks, early discovery of new attack trends and quick response to incidents are essential since detection delays and slow responses to incidents will cause further damage. Typical methods to detect new large-scale attacks are: (1) analyzing data collected by the darknet, (2) analyzing data collected by honeypots, and (3) summarizing alerts made by intrusion detection systems (IDSs). A darknet is a reachable and unused address space on the Internet, and we can figure out coarse-grained attack trends, such as volume of scans to each TCP/UDP port, by analyzing packets arrived at the darknet. However, darknet traffic usually cannot provide enough payloads to analyze attacks in detail although there are various scans to applications running on one TCP/UDP port, such as Web applications. A honeypot system can intentionally be attacked so that the attack codes and attacker behaviors can be observed after they are attracted to it. A drawback is that honeypots cannot be deployed so large because attackers are very likely to become aware of honeypots whey they are deployed on a network scale like darknet. IDS alerts provide information about attacks, but in recent years attacks the are resistant to be detected by IDS are increasing. In this paper, we present a system that automatically detects new scan activities and estimates the scale of each attack by correlating the data obtained by both low-interaction honeypots and the darknet. A low-interaction honeypot collects payload in TCP stream to find attacks without depending on a specific protocol and classify attack codes in the context of applications. By analyzing the cooccurrence of attacks observed at honeypots and darknet by various features, the system estimates the scale of attacks per each attack. The evaluation result suggests that many attacks can be observed at both honeypots and darknet, so it may be useful to correlate both data by observed time. Ryoh Akiyoshi, Daisuke Kotani, Yasuo Okabe |
COMPSAC (2) | 2 |
| 2018 | A Mixed Integer Programming Solution for Network Optimization Under Tunneling-Based Traffic Engineering SchemesabstractIn order to utilize the network resources efficiently, many traffic engineering schemes have been proposed to distribute the loads on links by controlling traffic routes. Traffic engineering based on tunneling can finely control traffic by setting a route of each flow explicitly. In the tunneling-based traffic engineering scheme, it is not easy to choose the best tunnel node pairs and the best flow allocation to the tunnels. In this paper, we propose a method to calculate an optimal solution in terms of the number of tunnels that can mitigate network congestion or the ratio of each flow on the links in a given network topology. We formulate the problems as mixed integer programming (MIP) and obtain optimal solutions using a high speed MIP solver. We have conducted experiments in the two kinds of problems on two network topologies. We calculate optimal solutions using a MIP solver, and evaluate the calculation time and improvement of network congestion by adding tunnels. Tsubasa Munemitsu, Daisuke Kotani, Yasuo Okabe |
COMPSAC (2) | 2 |
| 2018 | Xilara: An XSS Filter Based on HTML Template Restoration
Keitaro Yamazaki, Daisuke Kotani, Yasuo Okabe |
SecureComm (2) | 2 |
| 2017 | A Threshold-Based Authentication System Which Provides Attributes Using Secret SharingabstractIn identity federation, each service provider verifies the identity of a user based on authentication performed by an authentication server called an Identity Provider (IdP). When the IdP suffers from a trouble such that an unauthorized person has cracked into the IdP or the IdP is unreachable due to a network problem, all services in the federation may be stopped by the single trouble. Simple replication of servers for the IdP might cause privacy concern because plain attribute values of registered users are copied to multiple servers, including servers that may not necessarily be trusted. In order to maintain the function as an IdP even under such troubles, we propose a system in which servers of the IdP are distributed and cooperate using threshold-based authentication and secret sharing. Even when some of IdPs are not available, the proposed system can provide authentication and authorization to all services in the federation by performing authentication procedure with the rest IdPs. Since attribute values are distributed to IdPs using secret sharing, an attacker cannot know the attribute values even if he successfully usurps administrator-level privilege of an IdP. We also design and implement the proposed system. We measure the execution time and verify that the computation time is sufficiently small. Furthermore, we show that our system is robust with respect to both fault tolerance and security. Tomohiro Ito, Daisuke Kotani, Yasuo Okabe |
COMPSAC (2) | 2 |
| 2014 | A packet-in message filtering mechanism for protection of control plane in openflow networksabstractProtecting control planes in networking hardware from high rate packets is a critical issue for networks under operation. One common approach for conventional networking hardware is to offload expensive functions onto hard-wired offload engines as ASICs. OpenFlow networks are expected to provide greater network control flexibility by an open interface to the packet-forwarding plane and by centralized controllers. In OpenFlow networks, the approach for conventional networking hardware alone is inadequate because it restricts a certain amount of flexibility that OpenFlow is expected to provide. Therefore, we need a generic control plane protection mechanism in OpenFlow switches as a last resort. In this paper, we propose a mechanism to filter out Packet-In messages without dropping important ones for network control. Our proposed mechanism works simply. Switches record the values of packet header fields before sending Packet-In messages, which are specified by the controllers in advance, and filter out packets that have the same values as the recorded ones. We implemented and evaluated the proposed mechanism on a prototype software switch, concluding that it dramatically reduces CPU loads in the switches and passes important Packet-In messages for network control. Daisuke Kotani, Yasuo Okabe |
ANCS | 1 |
| 2011 | Supporting Sharing of Browsing Information and Search Results in Mobile Collaborative Searches
Daisuke Kotani, Satoshi Nakamura 0002, Katsumi Tanaka |
WISE | 1 |