Tatsuya Mori 0003

dblp:62/6630-3 · DBLP profile ↗
← Back
67ranked-venue papers
3as first author
18since 2021 · last 2026
0000-0003-1583-4174ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 29 · 12 since 2021Computer networks · 26 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 since 2021Software engineering, systems software and programming languages · 4Systems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Cross-Lingual Vulnerabilities of Text-to-Image Models: Evaluating Data Poisoning Attacks Across Ten Languages
Ryohei Kakebayashi, Tatsuya Mori 0003
ICPR (9)2
2026 Action Required: A Mixed-Methods Study of Security Practices in GitHub Actions
Yusuke Kubo, Fumihiro Kanei, Mitsuaki Akiyama, Takuro Wakai, Tatsuya Mori 0003
NDSS5
2026 N-Choice Game: Building a Smart Contract for Accurate Pseudo-Random Number Generation
abstract
We propose N-choice game (NCG), a decentralized method for generating pseudo-random numbers for smart contracts. NCG involves multiple participants, each of whom chooses a value between 0 and \(N-1\) and whose collective choices determine the generation of a pseudo-random number. The design of NCG has three key objectives: incentivizing participants to make random choices, assessing randomness in a decentralized environment, and achieving high operational performance. Implemented in Solidity and rigorously tested, NCG has shown remarkable effectiveness. Our results show that the randomness of the numbers generated by NCG is high and consistent, even under a strict NIST randomness test, provided that there is no collusion between the majority of participants. Not only is it impossible to customize the outputs generated by NCG, but it is also impractical to make them non-random. Therefore, it is rational to engage NCG for the purpose of rewards rather than the output values it produces. Selecting values in a way that is not predicted by other nodes yields the highest expected value, and NCG incentivizes random selection. Furthermore, NCG demonstrates a significant performance advantage, being up to 158 times faster at generating random numbers than the existing Random Bit Generator framework [ 3 ]. This efficiency underscores NCG’s potential to enhance blockchain applications.
Kentaro Sako, Shin'ichiro Matsuo, Tatsuya Mori 0003
Distributed Ledger Technol. Res. Pract.3
2026 Software and Hardware Implementations of a Cyber-Physical Firewall
abstract
This study evaluates software and hardware implementations based on the Cyber-Physical Firewall (CPFW) framework, which provides a flexible and generic access control mechanism for regulating malicious analog signals targeting cyber-physical systems. We describe the CPFW framework design and the implementation strategies for both software and hardware. The software implementation was performed on a Raspberry Pi, whereas the hardware implementation was performed on a Zybo Z7-10 SoC board. We evaluate the characteristics of each implementation, particularly for audio signals, and discuss the differences that arise between software and hardware implementations, along with the selection of an appropriate approach based on specific requirements. The evaluation results demonstrate that the software implementation of the CPFW framework has an overhead of 3.219 ms, whereas the hardware implementation has an overhead of 310 ns, indicating a difference in overhead of \(10^{4}\) . The hardware implementation resulted in only a 5.88% increase in resource utilization owing to the addition of CPFW circuits, indicating that the added circuit size is practical for real-world applications.
Ryo Iijima, Tatsuya Takehisa, Tatsuya Mori 0003
ACM Trans. Cyber Phys. Syst.3
2026 Adversarial Beats: Feasibility Study of Spoofed Arrhythmia in Automated Electrocardiogram Diagnosis
abstract
This study aims to assess the feasibility of applying adversarial examples to attack cardiac diagnosis systems powered by machine learning algorithms. To achieve this, we introduce “ adversarial beats ,” which are adversarial perturbations that are tailored specifically against classification systems designed to diagnose electrocardiograms (ECGs). We first formulated an algorithm to generate adversarial examples for multiple neural network models for ECG classification and studied their attack success rates. Next, to evaluate their feasibility in a physical environment, we mounted a hardware attack by designing a malicious signal generator that injects adversarial beats into ECG sensor readings using commercial off-the-shelf hardware. To the best of our knowledge, our research is the first to evaluate the proficiency of adversarial examples for ECGs in a physical setup. Our real-world experiments demonstrate that, against an automated ECG diagnosis apparatus, our attack method can fake the presence of potential signs of cardiomyopathy with approximately 42.1% chance of success and the attacker can repeat the attack until a fraudulent insurance claim or other health care fraud is established. Based on the comprehensive feasibility study of attacks using adversarial beats, we conclude that the attacks have a sufficient chance to succeed such that an attacker may be incentivized to fake the presence of cardiomyopathy, potentially leading to unnecessary medication prescriptions and fraudulent medical insurance claims.
Taiga Ono, Takeshi Sugawara 0001, Jun Sakuma, Tatsuya Mori 0003
ACM Trans. Cyber Phys. Syst.4
2025 Adversarial Fog: Exploiting the Vulnerabilities of LiDAR Point Cloud Preprocessing Filters
Yuna Tanaka, Kazuki Nomoto, Ryunosuke Kobayashi, Go Tsuruoka, Tatsuya Mori 0003
AsiaCCS5
2025 Invisible but Detected: Physical Adversarial Shadow Attack and Defense on LiDAR Object Detection
Ryunosuke Kobayashi, Kazuki Nomoto, Yuna Tanaka, Go Tsuruoka, Tatsuya Mori 0003
USENIX Security Symposium5
2024 The Catcher in the Eye: Recognizing Users by their Blinks
abstract
In this paper, we develop a novel behavioral biometric recognition framework, BlinkAuth, that takes advantage of a user's blinking. BlinkAuth utilizes electrooculogram (EOG) data, (i.e., the electric potential difference between the corneal and retinal sides of the eye), and applies a machine-learning model to achieve user recognition. BlinkAuth works with devices like smart glasses and VR headsets and can be used simultaneously in activities such as driving or cooking. Using JINS MEME, a glasses-type wearable device that can measure EOG, we collected EOG data from 31 participants under various conditions and evaluated the recognition accuracy of BlinkAuth. The results demonstrate that BlinkAuth can achieve high accuracy as a behavioral biometric recognition with an average AUC of 95.8% and an average EER of 9.28%. We developed a system for implementing BlinkAuth for real-time recognition and evaluated the time required for the recognition process and the system's usability with the System Usability Scale (SUS). The results show an overall processing time of approximately 0.6 seconds, including the data measurement time, and an average SUS score of 82.50, which indicates high usability equivalent to rank A in the standard criteria for interpreting SUS scores. Six extensive user experiments and 17 evaluation perspectives reveal that BlinkAuth is highly robust to environmental changes, such as skin moisture and makeup, participant actions, and eye strain conditions, as well as to attacks that imitate the target's blinking.
Ryo Iijima, Tatsuya Takehisa, Tetsushi Ohki, Tatsuya Mori 0003
AsiaCCS4
2024 Poster: YFuzz: Data-Driven Fuzzing
abstract
Code coverage is an effective objective for guiding fuzzers to explore code and identify bugs, and it has been a key factor in the success of greybox fuzzing. However, code coverage has a critical limitation: coverage-guided fuzzers can miss bugs even when the associated code is covered. This limitation arises because merely executing the associated code is often insufficient to trigger a bug; specific conditions are usually also required. These conditions are not fully captured by code coverage, which focuses only on whether the code was executed.
Chun-Chia Huang, Tatsuya Mori 0003, Hsu-Chun Hsiao
CCS3
2024 SmmPack: Obfuscation for SMM Modules with TPM Sealed Key
Kazuki Matsuo, Satoshi Tanda, Kuniyasu Suzaki, Yuhei Kawakoya, Tatsuya Mori 0003
DIMVA5
2024 DeGhost: Unmasking Phantom Intrusions in Autonomous Recognition Systems
abstract
Autonomous systems that rely on object recognition are susceptible to the unique vulnerability of phantom attacks. In these scenarios, adversaries exploit the system by projecting sophisticated deceptive illusions that cause confusion between real objects and their virtual shadows. Despite the growing consensus on the importance of this threat, previous research has lacked comprehensive and quantitative assessments. In an effort to address this research gap, we first methodically investigated the success rates of attacks at various projection distances and angles. Following this baseline assessment, we conducted targeted experiments on two different setups: a black-box approach using the commercial DJI Mavic Air drone with its ActiveTrack feature, and a white-box approach using the open-source Tello drone integrated with YOLOv3 object recognition. These real-world evaluations clearly demonstrated the effectiveness of the phantom attacks. Considering the identified vulnerabilities, we developed DeGhost, a deep learning framework capable of distinguishing real entities from their projected counterparts. To ensure a holistic understanding of its performance, we projected phantoms using different types of projectors onto various surfaces such as concrete, screens, white cloth, white walls, whiteboards, and wooden boards. DeGhost was then evaluated against a range of SoTA object detectors, including the YOLO series, Faster R-CNN, and CenterNet. Our results underscored the ability of DeGhost to detect these phantom attacks with high accuracy, as evidenced by an AUC of 0.998, an FNR of 0.013, and an FPR of 0.018. In addition, the incorporation of an advanced Fourier technique enhanced the robustness of the model. This study not only illuminates the feasibility of the attack but also offers practical security countermeasures for emerging autonomous technologies.
Hotaka Oyama, Ryo Iijima, Tatsuya Mori 0003
EuroS&P3
2023 Browser Permission Mechanisms Demystified
Kazuki Nomoto, Takuya Watanabe 0001, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya Mori 0003
NDSS5
2023 A First Look at Brand Indicators for Message Identification (BIMI)
abstract
Abstract As promising approaches to thwarting the damage caused by phishing emails, DNS-based email security mechanisms, such as the Sender Policy Framework (SPF), Domain-based Message Authentication, Reporting & Conformance (DMARC) and DNS-based Authentication of Named Entities (DANE), have been proposed and widely adopted. Nevertheless, the number of victims of phishing emails continues to increase, suggesting that there should be a mechanism for supporting end-users in correctly distinguishing such emails from legitimate emails. To address this problem, the standardization of Brand Indicators for Message Identification (BIMI) is underway. BIMI is a mechanism that helps an email recipient visually distinguish between legitimate and phishing emails. With Google officially supporting BIMI in July 2021, the approach shows signs of spreading worldwide. With these backgrounds, we conduct an extensive measurement of the adoption of BIMI and its configuration. The results of our measurement study revealed that, as of November 2022, 3,538 out of the one million most popular domain names have a set BIMI record, whereas only 396 (11%) of the BIMI-enabled domain names had valid logo images and verified mark certificates. The study also revealed the existence of several misconfigurations in such logo images and certificates.
Masanori Yajima, Daiki Chiba 0001, Yoshiro Yoneya, Tatsuya Mori 0003
PAM4
2022 Cyber-physical firewall: monitoring and controlling the threats caused by malicious analog signals
abstract
This work developed a new security framework named Cyber-Physical Firewall (CPFW), which provides a generic and flexible access control mechanism for regulating the malicious analog signals that target cyber-physical system (CPS) devices. This framework enables the defeat of various attacks that make use of malicious analog signals against CPS devices; e.g., stealth voice command injection attack using ultrasonic waves or adversarial examples, or attacks to crash drones in flight using malicious sound waves.
Ryo Iijima, Tatsuya Takehisa, Tatsuya Mori 0003
CF3
2022 Understanding the Behavior Transparency of Voice Assistant Applications Using the ChatterBox Framework
abstract
A voice assistant (VA) is a platform that provides users with a wide range of services via interaction with a voice application using verbal commands. Since the VA application is deployed in the cloud, its behavior is not transparent to the user, which raises privacy concerns. In this study, we developed a framework called ChatterBox, which attempts to analyze VA applications via extensive continuous interaction, to understand their behavior. ChatterBox is capable of parsing and generating dialogues by utilizing natural language processing approach. It can also parse application-level messages to understand how a VA app acquires personal information. ChatterBox supports English and Japanese, which are completely different languages, and can extract more than twice as many dialogues from VA applications compared to SkillExplorer, a state-of-the-art VA dialogue analysis system. Based on analyses of English and Japanese VA applications using ChatterBox, we revealed that 5–15% of VA applications collect personal information or recorded user identifiers in a non-transparent manner, and 76–94% applications collected personal information without providing appropriate privacy policies. In light of these findings, we discuss the implementation of a highly transparent VA application platform.
Atsuko Natatsuka, Ryo Iijima, Takuya Watanabe 0001, Mitsuaki Akiyama, Tetsuya Sakai, Tatsuya Mori 0003
RAID6
2022 On the Feasibility of Linking Attack to Google/Apple Exposure Notification Framework
abstract
Digital contact-tracing (DCT) applications have been installed on more than 188 M smartphones worldwide as an effective mechanism for monitoring contact with COVID-19 infected individuals. DCT is promising not only for COVID-19, but also for preparing for a possible future large-scale pandemic. The DCT framework is unique in that it combines Bluetooth Low Energy (BLE) communications with cryptography techniques to track exposure on a large scale while protecting user privacy. The objective of this study is to assess the risk of the linking attack to the DCT frameworks; i.e., linking individuals to the identifiers contained in BLE broadcast frames that are supposed to be anonymized. Specifically, we target Google/Apple’s Exposure Notification (GAEN), which is the representative implementation of DCT. Our extensive experiments demonstrate that passively collected rolling proximity identifiers (RPIs) contained in the BLE frames can be linked to face photos which could lead to the exposure of privacy information with high accuracy, including infection status. We also demonstrate that an attacker with a few number of devices can correctly link RPIs and the images of the target person with a success rate of 86% at a rate of 5,000 users per hour. Based on these results, we propose countermeasures to reduce the inherent privacy risk of the GAEN framework.
Kazuki Nomoto, Mitsuaki Akiyama, Masashi Eto, Atsuo Inomata, Tatsuya Mori 0003
Proc. Priv. Enhancing Technol.5
2021 Measuring Adoption of DNS Security Mechanisms with Cross-Sectional Approach
abstract
The threat of attacks targeting a DNS, such as DNS cache poisoning attacks and DNS amplification attacks, continues unabated. In addition, attacks that exploit the difficulty in deter-mining the authenticity of domain names, such as phishing sites and fraudulent emails, continue to be a significant threat. Various DNS security mechanisms have been proposed, standardized, and implemented as effective countermeasures against DNS-related attacks. However, it is not clear how widespread these security mechanisms are in the DNS ecosystem and how effectively they work in the wild. With this background, this study targets the major DNS security mechanisms deployed for the DNS name servers, DNSSEC, DNS Cookies, CAA, SPF, DMARC, MTA-STS, DANE, and TLSRPT, and a large-scale measurement analysis of their deployment is conducted. Our results quantitatively reveal that, as of 2021, the adoption rate of most DNS security mechanisms, except SPF, remains low, and the adoption rate is lower for mechanisms that are more difficult to configure. These findings suggest the importance of developing easy-to-deploy tools to promote the adoption of security mechanisms.
Masanori Yajima, Daiki Chiba 0001, Yoshiro Yoneya, Tatsuya Mori 0003
GLOBECOM4
2021 A First Look at COVID-19 Domain Names: Origin and Implications
Ryo Kawaoka, Daiki Chiba 0001, Takuya Watanabe 0001, Mitsuaki Akiyama, Tatsuya Mori 0003
PAM5
2020 Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost Websites
Takuya Watanabe 0001, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya Mori 0003
NDSS4
2019 EIGER: automated IOC generation for accurate and interpretable endpoint malware detection
abstract
A malware signature including behavioral artifacts, namely Indicator of Compromise (IOC) plays an important role in security operations, such as endpoint detection and incident response. While building IOC enables us to detect malware efficiently and perform the incident analysis in a timely manner, it has not been fully-automated yet. To address this issue, there are two lines of promising approaches: regular expression-based signature generation and machine learning. However, each approach has a limitation in accuracy or interpretability, respectively.
Yuma Kurogome, Yuto Otsuki, Yuhei Kawakoya, Makoto Iwamura, Syogo Hayashi, Tatsuya Mori 0003, Koushik Sen
ACSAC6
2019 Poster: A First Look at the Privacy Risks of Voice Assistant Apps
abstract
In this study, we conduct the first study on the analysis of voice assistant (VA) apps. We first collect the metadata of VA apps from the VA app directory and analyze them. Next, we call VA apps by the corresponding voice commands and examine how they identify users by analyzing the responses from the apps. We found that roughly half of the VA apps performed user identification by some means. We also found that several apps aim to acquire personal information such as birth date, age, or the blood type through voice conversations. As such data will be stored in the cloud, we need to have a mechanism to ensure that an end-user can check/control the data in a usable way.
Atsuko Natatsuka, Ryo Iijima, Takuya Watanabe 0001, Mitsuaki Akiyama, Tetsuya Sakai, Tatsuya Mori 0003
CCS6
2019 Understanding the Responsiveness of Mobile App Developers to Software Library Updates
abstract
This paper reports a longitudinal measurement study aiming to understand how mobile app developers are responsive to updates of software libraries over time. To quantify their responsiveness to library updates, we collected 21,046 Android apps, which equated 142,611 unique application package kit (APK) files, each corresponding to a different version of an app. The release dates of these APK files spanned across 9 years. The key findings we derived from our analysis are as follows. (1) We observed an undesirable level of responsiveness of app developers; 50% of library update adoptions by app developers were performed for more than 3 months after the release date of the library, and 50% of outdated libraries used in apps were retained for over 10 months. (2) Deploying a security fix campaign in the app distribution market effectively reduced the number of apps with unfixed vulnerabilities; however, CVE-numbered vulnerabilities (without a campaign) were prone to remain unfixed. (3) The responsiveness of app developers varied and depended on multiple factors, for example, popular apps with a high number of installations had a better response to library updates and, while it took 77 days on average for app developers to adopt version updates for advertising libraries, it took 237 days for updates of utility libraries to be adopted. We discuss practical ways to eliminate libraries with vulnerabilities and to improve the responsiveness of app developers to library updates.
Tatsuhiko Yasumatsu, Takuya Watanabe 0001, Fumihiro Kanei, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya Mori 0003
CODASPY6
2019 ShamFinder: An Automated Framework for Detecting IDN Homographs
abstract
The internationalized domain name (IDN) is a mechanism that enables us to use Unicode characters in domain names. The set of Unicode characters contains several pairs of characters that are visually identical with each other; e.g., the Latin character 'a' (U+0061) and Cyrillic character 'a' (U+0430). Visually identical characters such as these are generally known as homoglyphs. IDN homograph attacks, which are widely known, abuse Unicode homoglyphs to create lookalike URLs. Although the threat posed by IDN homograph attacks is not new, the recent rise of IDN adoption in both domain name registries and web browsers has resulted in the threat of these attacks becoming increasingly widespread, leading to large-scale phishing attacks such as those targeting cryptocurrency exchange companies. In this work, we developed a framework named "ShamFinder," which is an automated scheme to detect IDN homographs. Our key contribution is the automatic construction of a homoglyph database, which can be used for direct countermeasures against the attack and to inform users about the context of an IDN homograph. Using the ShamFinder framework, we perform a large-scale measurement study that aims to understand the IDN homographs that exist in the wild. On the basis of our approach, we provide insights into an effective countermeasure against the threats caused by the IDN homograph attack.
Hiroaki Suzuki, Daiki Chiba 0001, Yoshiro Yoneya, Tatsuya Mori 0003, Shigeki Goto
Internet Measurement Conference4
2019 Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone Touchscreens
abstract
We present a novel attack named "Tap 'n Ghost", which aims to attack the touchscreens of NFC-enabled mobile devices such as smartphones. Tap 'n Ghost consists of two striking attack techniques - "Tag-based Adaptive Ploy (TAP)" and "Ghost Touch Generator." First, using a NFC card emulator embedded in a common object such as table, a TAP system performs tailored attacks on the victim's smartphone by employing device fingerprinting; e.g., popping up a customized dialogue box asking whether or not to connect to an attacker's Bluetooth mouse. Further, Ghost Touch Generator forces the victim to connect to the mouse even if she or he aimed to cancel the dialogue by touching the "cancel" button; i.e., it alters the selection of a button on a screen. After the connection is established, the attacker can remotely take control of the smartphone, with the knowledge about the layout of the screen derived from the device fingerprinting. To evaluate the reality of the attack, we perform an online survey with 300 respondents and a user study involving 16 participants. The results demonstrate that the attack is realistic. We additionally discuss the possible countermeasures against the threats posed by Tap 'n Ghost.
Seita Maruyama, Satohiro Wakabayashi, Tatsuya Mori 0003
IEEE Symposium on Security and Privacy3
2018 Audio Hotspot Attack: An Attack on Voice Assistance Systems Using Directional Sound Beams
abstract
We propose a novel attack named "Audio Hotspot Attack'', which performs an inaudible malicious voice command attack, targeting voice assistance systems, e.g., smart speakers or in-car navigation systems. This attack leverages directional sound beams generated from parametric loudspeakers, which emit AM-modulated ultrasounds that will be self-demodulated in the air. It can succeed in the attack on a long distance (2--4 meters in a small room and 10+ meter in a long hallway). To evaluate the feasibility of the attack, we performed extensive in-lab experiments and a user study involving 20 participants. The results demonstrate that the attack is feasible in a real-world setting.
Ryo Iijima, Shota Minami, Yunao Zhou, Tatsuya Takehisa, Takeshi Takahashi 0001, Yasuhiro Oikawa, Tatsuya Mori 0003
CCS7
2018 Don't throw me away: Threats Caused by the Abandoned Internet Resources Used by Android Apps
abstract
This study aims to understand the threats caused by abandoned Internet resources used by Android apps. By abandoned, we mean Internet resources that support apps that were published and are still available on the mobile app marketplace, but have not been maintained and hence are at risk for abuse by an outsider. Internet resources include domain names and hard-coded IP addresses, which could be used for nefarious purposes, e.g., stealing sensitive private information, scamming and phishing, click fraud, and injecting malware distribution URL. As a result of the analysis of 1.1 M Android apps published in the official marketplace, we uncovered 3,628 of abandoned Internet resources associated with 7,331 available mobile apps. These resources are subject to hijack by outsiders. Of these apps, 13 apps have been installed more than a million of times, a measure of the breadth of the threat. Based on the findings of empirical experiments, we discuss potential threats caused by abandoned Internet resources and propose countermeasures against these threats.
Elkana Pariwono, Daiki Chiba 0001, Mitsuaki Akiyama, Tatsuya Mori 0003
AsiaCCS4
2018 Understanding the Origins of Weak Cryptographic Algorithms Used for Signing Android Apps
abstract
Android applications are digitally signed using developers' signing keys. As each key is associated with a developer, it can be used to establish trust between applications published by the author (that is, apps signed with the same key are allowed to update themselves if package names are identical, or access each other's resources). However, if a digital signature is generated using a weak algorithm such as MD5, then apps signed with the corresponding key are exposed to several risks (such as hijacking apps with fake updates or granting permissions to a malicious app). In this work, we analyze several Android apps to identify the threats caused using weak algorithms. Our study uncovered the following findings: Of the more than one million apps collected from Google Play, 223 and 52,866 were digitally signed using the weak algorithms of 512-bit RSA key and MD5, respectively. We identified the causal mechanisms of generating certificates that employ weak algorithms, and that they can be attributed to app-building frameworks and online app-building services. Based on these findings, we provide guidelines for stakeholders of the Android app distribution ecosystem.
Kanae Yoshida, Hironori Imai, Nana Serizawa, Tatsuya Mori 0003, Akira Kanaoka
COMPSAC (2)4
2018 Stay On-Topic: Generating Context-Specific Fake Restaurant Reviews
Mika Juuti, Tatsuya Mori 0003, N. Asokan
ESORICS (1)3
2018 User Blocking Considered Harmful? An Attacker-Controllable Side Channel to Identify Social Accounts
abstract
This paper presents a practical side-channel attack that identifies the social web service account of a visitor to an attacker's website. Our attack leverages the widely adopted user-blocking mechanism, abusing its inherent property that certain pages return different web content depending on whether a user is blocked from another user. Our key insight is that an account prepared by an attacker can hold an attackercontrollable binary state of blocking/non-blocking with respect to an arbitrary user on the same service; provided that the user is logged in to the service, this state can be retrieved as one-bit data through the conventional cross-site timing attack when a user visits the attacker's website. We generalize and refer to such a property as visibility control, which we consider as the fundamental assumption of our attack. Building on this primitive, we show that an attacker with a set of controlled accounts can gain a complete and flexible control over the data leaked through the side channel. Using this mechanism, we show that it is possible to design and implement a robust, largescale user identification attack on a wide variety of social web services. To verify the feasibility of our attack, we perform an extensive empirical study using 16 popular social web services and demonstrate that at least 12 of these are vulnerable to our attack. Vulnerable services include not only popular social networking sites such as Twitter and Facebook, but also other types of web services that provide social features, e.g., eBay and Xbox Live. We also demonstrate that the attack can achieve nearly 100% accuracy and can finish within a sufficiently short time in a practical setting. We discuss the fundamental principles, practical aspects, and limitations of the attack as well as possible defenses.
Takuya Watanabe 0001, Eitaro Shioji, Mitsuaki Akiyama, Keito Sasaoka, Takeshi Yagi, Tatsuya Mori 0003
EuroS&P6
2018 DomainChroma: Building actionable threat intelligence from malicious domain names
abstract
Since the 1980s, domain names and the domain name system (DNS) have been used and abused. Although legitimate Internet users rely on domain names as indispensable infrastructures for using the Internet, attackers use or abuse them as reliable, instantaneous, and distributed attack infrastructures. However, there is a lack of complete understanding of such domain-name abuses and methods for coping with them. In this study, we designed and implemented a unified analysis system combining current defense solutions to build actionable threat intelligence from malicious domain names. The basic concept underlying our system is malicious domain name chromatography. Our analysis system can distinguish among mixtures of malicious domain names for websites. On the basis of this concept, we do not create a hodgepodge of current solutions but design separation of abused domain names and offer actionable threat intelligence or defense information by considering the characteristics of malicious domain names as well as the possible defense solutions and points of defense. Finally, we evaluated our analysis system and defense-information output using a large real dataset to show the effectiveness and validity of our system.
Daiki Chiba 0001, Mitsuaki Akiyama, Takeshi Yagi, Kunio Hato, Tatsuya Mori 0003, Shigeki Goto
Comput. Secur.5
2017 POSTER: TOUCHFLOOD: A Novel Class of Attacks against Capacitive Touchscreens
abstract
We present a novel class of attacks against capacitive touchscreens, which are common in devices such as smartphones and tablet computers. The attack we named TOUCHFLOOD aims to scatter touch events, alternating the selection of buttons on a screen. The key idea of TOUCHFLOOD is to intentionally cause a malfunction by injecting intentional noise signals from an external source. This paper describes the attack as well as the experimental results that clarify the conditions for successful attacks. The demo videos of the experiments using a smartphone are available at https://goo.gl/56G79e.
Seita Maruyama, Satohiro Wakabayashi, Tatsuya Mori 0003
CCS3
2017 POSTER: Is Active Electromagnetic Side-channel Attack Practical?
abstract
Radio-frequency (RF) retroreflector attack (RFRA) is an {\em active} electromagnetic side-channel attack that aims to leak the target's internal signals by irradiating the targeted device with a radio wave, where an attacker has embedded a malicious circuit (RF retroreflector) in the device in advance. As the retroreflector consists of small and cheap electrical elements such as a field-effect transistor (FET) chip and a wire that can work as a dipole antenna, the reflector can be embedded into various kinds of electric devices that carry unencrypted, sensitive information; e.g., keyboard, display monitor, microphone, speaker, USB, and so on. Only a few studies have addressed the basic mechanism of RFRA and demonstrated the success of the attack. The conditions for a successful attack have not been adequately explored before, and therefore, assessing the feasibility of the attack remains an open issue. In the present study, we aim to investigate empirically the conditions for a successful RFRA through field experiments. Understanding attack limitations should help to develop effective countermeasures against it. In particular, with regard to the conditions for a successful attack, we studied the distance between the attacker and the target, and the target signal frequencies. Through the extensive experiments using off-the-shelf hardware including software-defined radio (SDR) equipment, we revealed that the required conditions for a successful attack are (1) up to a 10-Mbps of target signal and (2) up to a distance of 10 meters. These results demonstrate the importance of the RFRA threat in the real world.
Satohiro Wakabayashi, Seita Maruyama, Tatsuya Mori 0003, Shigeki Goto, Masahiro Kinugawa, Yuichi Hayashi
CCS3
2017 DomainChroma: Providing Optimal Countermeasures against Malicious Domain Names
abstract
Domain names and domain name system (DNS) have been used and abused for over 30 years since the 1980s. Although legitimate Internet users rely on domain names as their indispensable infrastructures for using the Internet, attackers use or abuse them as reliable, instantaneous, and distributed attack infrastructure. However, there is a lack of complete understanding of such domain name abuses and the methods for coping with them. In this paper, we design and implement a unified and objective analysis pipeline combining the existing defense solutions to realize practical and optimal defenses against today's malicious domain names. The basic concept underlying our novel analytical approach is malicious domain names' chromatography. Our new analysis pipeline can distinguish among mixtures of malicious domain names for websites. On the basis of this concept, we do not create a hodgepodge of existing solutions but design separation of abused domain names and offer defense information by considering the characteristics of malicious domain names as well as the possible defense solutions and points of defense. Finally, we evaluate our analysis pipeline and output defense information using a large and real dataset to show the effectiveness and validity of our proposed approach.
Daiki Chiba 0001, Mitsuaki Akiyama, Takeshi Yagi, Takeshi Yada, Tatsuya Mori 0003, Shigeki Goto
COMPSAC (1)5
2017 Detecting and Classifying Android PUAs by Similarity of DNS queries
abstract
This work develops a method of detecting and classifying “potentially unwanted applications” (PUAs) such as adware or remote monitoring tools. Our approach leverages DNS queries made by apps. Using a large sample of Android apps from third-party marketplaces, we first reveal that DNS queries can provide useful information for the detection and classification of PUAs. Next, we show that existing DNS blacklists are ineffective to perform these tasks. Finally, we demonstrate that our methodology performed with high accuracy.
Mitsuhiro Hatada, Tatsuya Mori 0003
COMPSAC (2)2
2017 BotDetector: A robust and scalable approach toward detecting malware-infected devices
abstract
Damage caused by malware is a serious problem that needs to be addressed. The recent rise in the spread of evasive malware has made it difficult to detect it at the pre-infection timing. Malware detection at post-infection timing is a promising approach that fulfills this gap. Given this background, this work aims to identify likely malware-infected devices from the measurement of Internet traffic. The advantage of the traffic-measurement-based approach is that it enables us to monitor a large number of clients. If we find a client as a source of malicious traffic, the client is likely a malware-infected device. Since the majority of malware today makes use of the web as a means to communicate with the C&C servers that reside on the external network, we leverage information recorded in the HTTP headers to discriminate between malicious and legitimate traffic. To make our approach scalable and robust, we develop the automatic template generation scheme that drastically reduces the amount of information to be kept while achieving the high accuracy of classification; since it does not make use of any domain knowledge, the approach should be robust against changes of malware. We apply several classifiers, which include machine learning algorithms, to the extracted templates and classify traffic into two categories: malicious and legitimate. Our extensive experiments demonstrate that our approach discriminates between malicious and legitimate traffic with up to 97.1% precision while maintaining the false positive below 1.0%.
Sho Mizuno, Mitsuhiro Hatada, Tatsuya Mori 0003, Shigeki Goto
ICC3
2017 Understanding the origins of mobile app vulnerabilities: a large-scale measurement study of free and paid apps
abstract
This paper reports a large-scale study that aims to understand how mobile application (app) vulnerabilities are associated with software libraries. We analyze both free and paid apps. Studying paid apps was quite meaningful because it helped us understand how differences in app development/maintenance affect the vulnerabilities associated with libraries. We analyzed 30k free and paid apps collected from the official Android marketplace. Our extensive analyses revealed that approximately 70%/50% of vulnerabilities of free/paid apps stem from software libraries, particularly from third-party libraries. Somewhat paradoxically, we found that more expensive/popular paid apps tend to have more vulnerabilities. This comes from the fact that more expensive/popular paid apps tend to have more functionality, i.e., more code and libraries, which increases the probability of vulnerabilities. Based on our findings, we provide suggestions to stakeholders of mobile app distribution ecosystems.
Takuya Watanabe 0001, Mitsuaki Akiyama, Fumihiro Kanei, Eitaro Shioji, Yuta Takata, Yuta Ishii, Toshiki Shibahara, Takeshi Yagi, Tatsuya Mori 0003
MSR10
2017 Analyzing the ecosystem of malicious URL redirection through longitudinal observation from honeypots
abstract
Today, websites are exposed to various threats that exploit their vulnerabilities. A compromised website will be used as a stepping-stone and will serve attackers' evil purposes. For instance, URL redirection mechanisms have been widely used as a means to perform web-based attacks covertly; i.e., an attacker injects a redirect code into a compromised website so that a victim who visits the site will be automatically navigated to a malware distribution site. Although many defense operations against malicious websites have been developed, we still encounter many active malicious websites today. As we will show in the paper, we infer that the reason is associated with the evolution of the ecosystem of malicious redirection . Given this background, we aim to understand the evolution of the ecosystem through long-term measurement. To this end, we developed a honeypot-based monitoring system, which specializes in monitoring the behavior of URL redirections. We deployed the monitoring system across four years and collected more than 100K malicious redirect URLs, which were extracted from 776 distinct websites. Our chief findings can be summarized as follows: (1) Click-fraud has become another motivation for attackers to employ URL redirection, (2) The use of web-based domain generation algorithms (DGAs) has become popular as a means to increase the entropy of redirect URLs to thwart URL blacklisting, and (3) Both domain-flux and IP-flux are concurrently used for deploying the intermediate sites of redirect chains to ensure robustness of redirection. Based on the results, we also present practical countermeasures against malicious URL redirections. Security/network operators can leverage useful information obtained from the honeypot-based monitoring system. For instance, they can disrupt infrastructures of web-based attack by taking down domain names extracted from the monitoring system. They can also collect web advertising/tracking IDs, which can be used to identify the criminals behind attacks.
Mitsuaki Akiyama, Takeshi Yagi, Takeshi Yada, Tatsuya Mori 0003, Youki Kadobayashi
Comput. Secur.4
2016 POSTER: Toward Automating the Generation of Malware Analysis Reports Using the Sandbox Logs
abstract
In recent years, the number of new examples of malware has continued to increase. To create effective countermeasures, security specialists often must manually inspect vast sandbox logs produced by the dynamic analysis method. Conversely, antivirus vendors usually publish malware analysis reports on their website. Because malware analysis reports and sandbox logs do not have direct connections, when analyzing sandbox logs, security specialists can not benefit from the information described in such expert reports. To address this issue, we developed a system called ReGenerator that automates the generation of reports related to sandbox logs by making use of existing reports published by antivirus vendors. Our system combines several techniques, including the Jaccard similarity, Natural Language Processing (NLP), and Generation (NLG), to produce concise human-readable reports describing malicious behavior for security specialists.
Akinori Fujino, Tatsuya Mori 0003
CCS3
2016 DomainProfiler: Discovering Domain Names Abused in Future
abstract
Cyber attackers abuse the domain name system (DNS) to mystify their attack ecosystems, they systematically generate a huge volume of distinct domain names to make it infeasible for blacklisting approaches to keep up with newly generated malicious domain names. As a solution to this problem, we propose a system for discovering malicious domain names that will likely be abused in future. The key idea with our system is to exploit temporal variation patterns (TVPs) of domain names. The TVPs of domain names include information about how and when a domain name has been listed in legitimate/popular and/or malicious domain name lists. On the basis of this idea, our system actively collects DNS logs, analyzes their TVPs, and predicts whether a given domain name will be used for malicious purposes. Our evaluation revealed that our system can predict malicious domain names 220 days beforehand with a true positive rate of 0.985.
Daiki Chiba 0001, Takeshi Yagi, Mitsuaki Akiyama, Toshiki Shibahara, Takeshi Yada, Tatsuya Mori 0003, Shigeki Goto
DSN6
2016 Statistical estimation of the names of HTTPS servers with domain name graphs
Tatsuya Mori 0003, Takeru Inoue, Akihiro Shimoda, Kazumichi Sato, Shigeaki Harada, Keisuke Ishibashi, Shigeki Goto
Comput. Commun.1
2015 Discovering similar malware samples using API call topics
abstract
To automate malware analysis, dynamic malware analysis systems have attracted increasing attention from both the industry and research communities. Of the various logs collected by such systems, the API call is a very promising source of information for characterizing malware behavior. This work aims to extract similar malware samples automatically using the concept of “API call topics,” which represents a set of API calls that are intrinsic to a specific group of malware samples. We first convert Win32 API calls into “API words.” We then apply non-negative matrix factorization (NMF) clustering analysis to the corpus of the extracted API words. NMF automatically generates the API call topics from the API words. The contributions of this work can be summarized as follows. We present an unsupervised approach to extract API call topics from a large corpus of API calls. Through analysis of the API call logs collected from thousands of malware samples, we demonstrate that the extracted API call topics can detect similar malware samples. The proposed approach is expected to be useful for automating the process of analyzing a huge volume of logs collected from dynamic malware analysis systems.
Akinori Fujino, Junichi Murakami, Tatsuya Mori 0003
CCNC3
2015 Increasing the Darkness of Darknet Traffic
abstract
A Darknet is a passive sensor system that monitors traffic routed to unused IP address space. Darknets have been widely used as tools to detect malicious activities such as propagating worms, thanks to the useful feature that most packets observed by a darknet can be assumed to have originated from non-legitimate hosts. Recent commoditization of Internet-scale survey traffic originating from legitimate hosts could overwhelm the traffic that was originally supposed to be monitored with a darknet. Based on this observation, we posed the following research question: "Can the Internet-scale survey traffic become noise when we analyze darknet traffic?" To answer this question, we propose a novel framework, ID2, to increase the darkness of darknet traffic, i.e., ID2 discriminates between Internet-scale survey traffic originating from legitimate hosts and other traffic potentially associated with malicious activities. It leverages two inrinsic characteristics of Internet-scale survey traffic: a network- level property and some form of footprint explicitly indicated by surveyors. When we analyzed darknet traffic using ID2, we saw that Internet-scale traffic can be noise. We also demonstrated that the discrimination of survey traffic exposes hidden traffic anomalies, which are invisible without using our technique.
Yumehisa Haga, Akira Saso, Tatsuya Mori 0003, Shigeki Goto
GLOBECOM3
2015 Inferring Popularity of Domain Names with DNS Traffic: Exploiting Cache Timeout Heuristics
abstract
Popularity ranking of Internet services is an important metric for network operators, because it enables mid- to-long term planning of their network facilities and root cause analysis for unexpected traffic. The service-oriented traffic monitoring is much helpful to infer the popularity, hence it has been gathering much attention from both researchers and practitioners. Lately, service identification of a given flow has become very difficult due to the rapid growth of CDNs and/or encrypted traffic, while some research works employed preceding DNS traffic as a hint. However, because of its cache mechanism, the DNS message count deviates from the actual number of flows, which can greatly degrade the ranking reliability. We propose a theoretical model for inferring the user's number of accesses per domain name by exploiting the characteristics of the DNS message count. To the best of our knowledge, this paper is the first attempt to formulate the effect of user's stub resolvers; previous studies were focused on analyzing the effect of cache servers. We evaluated the precision of our model with a real dataset of traffic of thousands of users. By analyzing the top-50 domain names by the number of users, we can infer the number of flows within a 24% error rate on average in 42 out of 50 FQDNs.
Akihiro Shimoda, Keisuke Ishibashi, Kazumichi Sato, Masayuki Tsujino, Takeru Inoue, Masaki Shimura, Takanori Takebe, Kazuki Takahashi, Tatsuya Mori 0003, Shigeki Goto
GLOBECOM9
2015 AutoBLG: Automatic URL blacklist generator using search space expansion and filters
abstract
Modern web users are exposed to a browser security threat called drive-by-download attacks that occur by simply visiting a malicious Uniform Resource Locator (URL) that embeds code to exploit web browser vulnerabilities. Many web users tend to click such URLs without considering the underlying threats. URL blacklists are an effective countermeasure to such browser-targeted attacks. URLs are frequently updated; therefore, collecting fresh malicious URLs is essential to ensure the effectiveness of a URL blacklist. We propose a framework called automatic blacklist generator (AutoBLG) that automatically identifies new malicious URLs using a given existing URL blacklist. The key idea of AutoBLG is expanding the search space of web pages while reducing the amount of URLs to be analyzed by applying several pre-filters to accelerate the process of generating blacklists. Auto-BLG comprises three primary primitives: URL expansion, URL filtration, and URL verification. Through extensive analysis using a high-performance web client honeypot, we demonstrate that AutoBLG can successfully extract new and previously unknown drive-by-download URLs.
Mitsuaki Akiyama, Takeshi Yagi, Mitsuhiro Hatada, Tatsuya Mori 0003
ISCC5
2015 Understanding the Inconsistencies between Text Descriptions and the Use of Privacy-sensitive Resources of Mobile Apps
Takuya Watanabe 0001, Mitsuaki Akiyama, Tetsuya Sakai, Tatsuya Mori 0003
SOUPS4
2014 POSTER: Seven Years in MWS: Experiences of Sharing Datasets with Anti-malware Research Community in Japan
abstract
In 2008, the anti-Malware engineering WorkShop (MWS) was organized in Japan. The main objective of MWS is to accelerate and expand the activities of anti-malware research. To this end, MWS aims to attract new researchers and stimulate new research by lowering the technical obstacles associated with collecting the datasets that are crucial for addressing recent cyber threats. Moreover, MWS hosts intimate research workshops where researchers can freely discuss their results obtained using MWS and other datasets. This paper presents a quantitative accounting of the effectiveness of the MWS community by tracking the number of papers and new researchers that have arisen from the use of our datasets. In addition, we share the lessons learned from our experiences over the past seven years of sharing datasets with the community.
Mitsuhiro Hatada, Masato Terada, Tatsuya Mori 0003
CCS3
2014 Spatio-temporal factorization of log data for understanding network events
abstract
Understanding the impacts and patterns of network events such as link flaps or hardware errors is crucial for diagnosing network anomalies. In large production networks, analyzing the log messages that record network events has become a challenging task due to the following two reasons. First, the log messages are composed of unstructured text messages generated by vendor-specific rules. Second, network equipment such as routers, switches, and RADIUS severs generate various log messages induced by network events that span across several geographical locations, network layers, protocols, and services. In this paper, we have tackled these obstacles by building two novel techniques: statistical template extraction (STE) and log tensor factorization (LTF). STE leverages a statistical clustering technique to automatically extract primary templates from unstructured log messages. LTF aims to build a statistical model that captures spatial-temporal patterns of log messages. Such spatial-temporal patterns provide useful insights into understanding the impacts and root cause of hidden network events. This paper first formulates our problem in a mathematical way. We then validate our techniques using massive amount of network log messages collected from a large operating network. We also demonstrate several case studies that validate the usefulness of our technique.
Tatsuaki Kimura, Keisuke Ishibashi, Tatsuya Mori 0003, Hiroshi Sawada, Tsuyoshi Toyono, Ken Nishimatsu, Akio Watanabe, Akihiro Shimoda, Kohei Shiomoto
INFOCOM3
2013 Autonomic load balancing of flow monitors
Noriaki Kamiyama, Tatsuya Mori 0003, Ryoichi Kawahara
Comput. Networks2
2013 Mean-variance relationship of the number of flows in traffic aggregation and its application to traffic management
Ryoichi Kawahara, Tetsuya Takine, Tatsuya Mori 0003, Noriaki Kamiyama, Keisuke Ishibashi
Comput. Networks3
2012 Autonomic load balancing for flow monitoring
abstract
Monitoring flows at routers for flow analysis or deep packet inspection requires the monitors to update monitored flow information at the transmission line rate and needs to use highspeed memory such as SRAM. Therefore, it is difficult to measure all flows, and the monitors need to limit the monitoring target to a part of the flows. However, if monitoring targets are randomly selected, an identical flow will be monitored at multiple routers on its route, or a flow will not be monitored at any routers on its route. To maximize the number of flows monitored in the entire network, the monitors are required to select the monitoring targets while maintaining a balanced load among the monitors. In this paper, we propose an autonomous load balancing method where monitors exchange monitor load information with only adjacent monitors.
Noriaki Kamiyama, Tatsuya Mori 0003, Ryoichi Kawahara
ICC2
2011 Performance evaluation of peer-assisted content distribution
abstract
Peer-assisted content distribution technologies have been attracting attention. By using not only server resources but also the resources of end hosts (i.e., peers), we can reduce the offered load on servers as well as utilization of the access bandwidth of the servers. However, offered traffi to the network may increase because the traffi exchanged between peers passes across the network. Specificall, if individual peers send traffi disregarding underlay network topology and traffi conditions, the peer-assisted content distribution method may cause excessive traffi offered to the network and poor application performance. We thus investigated the impact of traffi caused by peer-assisted content distribution on the underlay network. We found that although peer-assisted content distribution disregarding underlay network topology causes 80-120% additional traffi compared with the optimal case, i.e., content distribution using cache servers allocated optimally in the network, using underlay network topology enables us to achieve almost the same efficien network resource utilization as the optimal case. We also found that the peer-assisted approach can adaptively cope with change in the traffi demand matrix because uploaders in the network are generated according to the demand matrix in a self-organizing manner. This is because peers that have downloaded the content become uploaders so many uploaders are generated in the area where a large number of content requests exist according to the traffi condition; therefore, the content delivery traffi can be localized.
Ryoichi Kawahara, Noriaki Kamiyama, Tatsuya Mori 0003, Haruhisa Hasegawa
CCNC3
2011 Traffic Engineering Using Overlay Network
abstract
Due to integrated high-speed networks accommodating various types of services and applications, the quality of service (QoS) requirements for those networks have also become diverse. The network resources are shared by the individual service traffic in the integrated network. Thus, the QoS of all the services may be degraded indiscriminately when the network becomes congested due to a sudden increase in traffic for a particular service if there is no traffic engineering taking into account each service's QoS requirement. To resolve this problem, we present a method of controlling individual service traffic by using an overlay network, which makes it possible to flexibly add various functionalities. The overlay network provides functionalities to control individual service traffic, such as constructing an overlay network topology for each service, calculating the optimal route for the service's QoS, and caching the content to reduce traffic. Specifically, we present a method of overlay routing that is based on the Hedge algorithm, an online learning algorithm to guarantee an upper bound in the difference from the optimal performance. We show the effectiveness of our overlay routing through simulation analysis for various network topologies.
Ryoichi Kawahara, Shigeaki Harada, Noriaki Kamiyama, Tatsuya Mori 0003, Haruhisa Hasegawa, Akihiro Nakao
ICC4
2011 Limiting pre-distribution and clustering users on multicast pre-distribution VoD
abstract
In Video on Demand (VoD) services, the demand for content items greatly changes daily, so reducing the server load at the peak time is an important issue for ISPs to reduce the server cost. To achieve this goal, we proposed to reduce the server load by multicasting popular content items to all users independently of actual requests as well as providing on-demand unicast delivery. In this solution, however, the hit ratio of pre-distributed content items is small, and a large-capacity storage is required at set-top box (STB). We might be able to cope with this problem by limiting the number of pre-distributed content items or clustering users based on the history of viewing. We evaluate the effect of these techniques using actual VoD access log data. We clarify that the required storage capacity at STB can be halved while keeping the effect of server load reduction to about 80% by limiting pre-distributed content items, and user clustering is effective only when the cluster count is about two.
Noriaki Kamiyama, Ryoichi Kawahara, Tatsuya Mori 0003, Haruhisa Hasegawa
Integrated Network Management3
2011 Optimally designing caches to reduce P2P traffic
Noriaki Kamiyama, Ryoichi Kawahara, Tatsuya Mori 0003, Shigeaki Harada, Haruhisa Hasegawa
Comput. Commun.3
2011 Parallel video streaming optimizing network throughput
Noriaki Kamiyama, Ryoichi Kawahara, Tatsuya Mori 0003, Shigeaki Harada, Haruhisa Hasegawa
Comput. Commun.3
2010 Optimally Designing Capacity and Location of Caches to Reduce P2P Traffic
abstract
Traffic caused by P2P services dominates a large part of traffic on the Internet and imposes significant loads on the Internet, so reducing P2P traffic within networks is an important issue for ISPs. In particular, a huge amount of traffic is transferred within backbone networks; therefore reducing P2P traffic is important for transit ISPs to improve the efficiency of network resource usage and reduce network capital cost. To reduce P2P traffic, it is effective for ISPs to implement cache devices at some router ports and reduce the hop length of P2P flows by delivering the required content from caches. However, the design problem of cache locations and capacities has not been well investigated, although the effect of caches strongly depends on the cache locations and capacities. We propose an optimum design method of cache capacity and location for minimizing the total amount of P2P traffic based on dynamic programming, assuming that transit ISPs provide caches at transit links to access ISP networks. We apply the proposed design method to 31 actual ISP backbone networks.
Noriaki Kamiyama, Ryoichi Kawahara, Tatsuya Mori 0003, Shigeaki Harada, Haruhisa Hasegawa
ICC3
2010 Impact of topology on parallel video streaming
abstract
Video streaming with HDTV or UHDV quality will be provided and widely demanded in the future. However, the transmission bit-rate of high-quality video streaming is quite large, so generated traffic flows will cause link congestion. Therefore, when providing streaming services of rich content, it is important to flatten the link utilization, i.e., reduce the maximum link utilization. To achieve this goal, parallel video streaming in which ISPs use multiple servers to deliver rich content is effective. However, the effect of parallel video streaming depends on the network topology and link capacities. In this paper, we investigate the impact of network topologies on the effect of parallel video streaming using 23 actual commercial ISP networks, when optimally designing server locations and optimally selecting servers.
Noriaki Kamiyama, Ryoichi Kawahara, Tatsuya Mori 0003, Shigeaki Harada, Haruhisa Hasegawa
NOMS3
2009 Improving Deployability of Peer-Assisted CDN Platform with Incentive
abstract
As a promising solution to manage the huge workload of large-scale VoD services, managed peer-assisted CDN systems, such as P4P has attracted attention. Although the approach works well in theory or in a controlled environment, to our best knowledge, there have been no general studies that address how actual peers can be incentivized in the wild Internet; thus, deployablity of the system with respect to incentives to users has been an open issue. With this background in mind, we propose a new business model that aims to make peer-assisted approaches more feasible. The key idea of the model is that users sell their idle resources back to ISPs. In other words, ISPs can leverage resources of cooperative users by giving them explicit incentives, e.g., virtual currency. We show the high-level framework of designing optimal incentive amount to users. We also analyze how incentives and other external factors affect the efficiency of the system through simulation. Finally, we discuss other fundamental factors that are essential for the deployability of managed peer-assisted model. We believe that the new business model and the insights obtained through this work are useful for assessing the practical design and deployment of managed peer-assisted CDNs.
Tatsuya Mori 0003, Noriaki Kamiyama, Shigeaki Harada, Haruhisa Hasegawa, Ryoichi Kawahara
GLOBECOM1
2009 Adaptive Bandwidth Control to Handle Long-Duration Large Flows
abstract
We describe a method of adaptively controlling bandwidth allocation to flows for reducing the file transfer time of short flows without decreasing throughput of long-duration large flows. According to the rapid increase in Internet traffic volume, effective traffic engineering is increasingly required. Specifically, the traffic of long-duration large flows due to the use of peer-to-peer applications, for example, is a problem. Most conventional QoS controls allocate a fair-share bandwidth to each flow regardless of its duration. Thus, a long-duration large flow (such as a P2P flow) is allocated the same bandwidth as a short- duration flow (such as data from a Web page) in which the user is more sensitive to response time, i.e., file transfer time. As a result, long-duration large flows consume bandwidth over a long period and increase response times of short-duration flows, and conventional QoS methods do nothing to prevent this. In this paper, we therefore investigate a different approach, that is, a new form of bandwidth control that enables us to achieve better performance when handling short-duration flows while maintaining performance when handling long-duration flows. The basic idea is to tag packets of long-duration large flows according to traffic conditions and to give temporarily higher priority to non-tagged packets during network congestion. We also show the effectiveness of our method through simulation.
Ryoichi Kawahara, Tatsuya Mori 0003, Noriaki Kamiyama, Shigeaki Harada, Haruhisa Hasegawa
ICC2
2008 A Method of Detecting Network Anomalies in Cyclic Traffic
abstract
We present a method of detecting network anomalies, such as DDoS (distributed denial of service) attacks and flash crowds, automatically in real time. We evaluated this method using measured traffic data and found that it successfully differentiated suspicious traffic. In this paper, we focus on cyclic traffic, which has a daily and/or weekly cycle, and show that the differentiation accuracy is improved by utilizing such a cyclic tendency in anomaly detection. Our method differentiates suspicious traffic that has different statistical characteristics from normal traffic. At the same time, it learns about cyclic large- volume traffic, such as traffic for network operations, and finally considers it to be legitimate.
Shigeaki Harada, Ryoichi Kawahara, Tatsuya Mori 0003, Noriaki Kamiyama, Haruhisa Hasegawa, Hideaki Yoshino
GLOBECOM3
2007 Detection Accuracy of Network Anomalies Using Sampled Flow Statistics
abstract
We investigate the detection accuracy of network anomalies when we use flow statistics obtained through packet sampling. We have already shown, through a case study based on measurement data, that network anomalies generating a huge number of small flows, such as network scans or SYN flooding, become hard to detect when we perform packet sampling. In this paper, we first develop an analytical model that enables us to quantitatively evaluate the effect of packet sampling on the detection accuracy and then investigate why detection accuracy worsens when the packet sampling rate decreases. In addition, we show that, even with a low sampling rate, spatially partitioning the monitored traffic into groups makes it possible to increase the detection accuracy. We also develop a method of determining an appropriate number of partitioned groups and show its effectiveness.
Ryoichi Kawahara, Keisuke Ishibashi, Tatsuya Mori 0003, Noriaki Kamiyama, Shigeaki Harada, Shoichiro Asano
GLOBECOM3
2007 Efficient Timeout Checking Mechanism for Traffic Control
abstract
Traffic flow measurement is essential to implement QoS control in the Internet. Flow monitoring system collects and stores sampled flow states in a flow table (FT) and the entries are renewed at every packet sampling. Entries in the FT are checked and removed when no packets are sampled within a predetermined timeout. We propose an efficient timeout checking mechanism based on checking a small number of entries selected randomly from the FT. Our proposed method aims to reduce the number of memory accesses dramatically and keep the memory size small. We evaluate our method and compare with the conventional method that checks all flow entries of the FT periodically. Our simulation and comparison results show that our method is able to reduce the number of memory access at a factor of 1000 with a small increase in memory size of approximately 10 percent.
Noriaki Kamiyama, Tatsuya Mori 0003, Ryoichi Kawahara, Eng Keong Lua
ICCCN2
2007 Simple and Adaptive Identification of Superspreaders by Flow Sampling
abstract
Abusive traffic caused by worms is increasing severely in the Internet. In many cases, worm-infected hosts generate a huge number of flows of small size during a short time. To suppress the abusive traffic and prevent worms from spreading, identifying these "superspreaders" as soon as possible and coping with them, e.g, disconnecting them from the network, is important. This paper proposes a simple and adaptive method of identifying superspreaders by flow sampling. By satisfying the given memory size and the requirement for the processing time, the proposed method can adaptively optimize parameters according to changes in traffic patterns.
Noriaki Kamiyama, Tatsuya Mori 0003, Ryoichi Kawahara
INFOCOM2
2006 Estimating Flow Rate from Sampled Packet Streams for Detection of Performance Degradation at TCP Flow Level
abstract
A method of estimating TCP flow-rates of sampled flows through packet sampling is described in this paper. We use sequence numbers of sampled packets, which make it possible to improve markedly the accuracy of estimating the flow rates. Using an analytical model, we investigate how to set parameters such as packet sampling probability used in this method of estimation. As a remarkable result, we show that the estimation accuracy improves as the sampling probability decreases. Using measured data, we also show that this method gives accurate estimations. We also show that this estimation method enables us to detect performance degradation at the TCP flow level.
Ryoichi Kawahara, Tatsuya Mori 0003, Keisuke Ishibashi, Noriaki Kamiyama, Takeo Abe
GLOBECOM2
2006 QoS control to handle long-duration large flows and its performance evaluation
abstract
A method of controlling the rate of long-duration large flows and its performance evaluation is described in this paper. Most conventional QoS controls allocate a fair-share bandwidth to each flow regardless of its duration. Thus, a long-duration large flow (such as a P2P flow) is allocated the same bandwidth as a short-duration flow (such as data from a Web page) in which the user is more sensitive to response time. As a result, long-duration flows will occupy the bandwidth over the long period and worsen response times of short-duration flows, and the conventional QoS methods do nothing to prevent this. We have, therefore, proposed a new form of QoS control that takes flow duration into account and assigns higher priority to the acceptance of shorter-duration flows. In this paper, we show through simulation that our method achieves high performance for short-duration flows without degrading the performance of long-duration flows. We also explain how to set parameters used in our method. Furthermore, we discuss the applicability of a packet-sampling technique to improve the method's scalability.
Ryoichi Kawahara, Tatsuya Mori 0003, Takeo Abe
ICC2
2006 Simple and Accurate Identification of High-Rate Flows by Packet Sampling
abstract
Abstract — Unfairness among best-effort flows is a serious problem on the Internet. In particular, UDP flows or unresponsive flows that do not obey the TCP flow control mechanism can consume a large share of the available bandwidth. High-rate flows seriously affect other flows, so it is important to identify them and limit their throughput by selectively dropping their packets. As link transmission capacity increases and the number of active flows increases, however, capturing all packet information becomes more difficult. In this paper, we propose a novel method of identifying high-rate flows by using sampled packets. The proposed method simply identifies flows from which Y packets are sampled without timeout. The identification principle is very simple and the implementation is easy. We derive the identification probability for flows with arbitrary flow rates and obtain an identification curve that clearly demonstrates the accuracy of identification. The characteristics of this method are determined by three parameters: the identification threshold Y, the timeout coefficient K, and the sampling interval N. To match the experimental identification probability to the theoretical one and to simplify the identification mechanism, we should set K to the maximum allowable value. Although increasing Y improves the identification accuracy, both the required memory size and the processing power grow as Y increases. Numerical evaluation using an actual packet trace demonstrated that the proposed method achieves very high identification accuracy with a much simpler mechanism than that of previously proposed methods. I.
Noriaki Kamiyama, Tatsuya Mori 0003
INFOCOM2
2004 Identifying elephant flows through periodically sampled packets
abstract
Identifying elephant flows is very important in developing effective and efficient traffic engineering schemes. In addition, obtaining the statistics of these flows is also very useful for network operation and management. On the other hand, with the rapid growth of link speed in recent years, packet sampling has become a very attractive and scalable means to measure flow statistics; however, it also makes identifying elephant flows become much more difficult. Based on Bayes' theorem, this paper develops techniques and schemes to identify elephant flows in periodically sampled packets. We show that our basic framework is very flexible in making appropriate trade-offs between false positives (misidentified flows) and false negatives (missed elephant flows) with regard to a given sampling frequency. We further validate and evaluate our approach by using some publicly available traces. Our schemes are generic and require no per-packet processing; hence, they allow a very cost-effective implementation for being deployed in large-scale high-speed networks.
Tatsuya Mori 0003, Masato Uchida, Ryoichi Kawahara, Jianping Pan 0001, Shigeki Goto
Internet Measurement Conference1