VLDB 2026 Research / reviewers in the wild / expert
Katsunari Yoshioka
dblp:66/3013
· DBLP profile ↗
33ranked-venue papers
1as first author
17since 2021 · last 2026
0000-0003-0964-8631ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 1 first-author · 12 since 2021Computer networks · 5 · 2 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The End of Anarchy? Understanding the Life of HTTP Exploits Used in IoT Malware Infections
Ryu Kuki, Takayuki Sasaki, Arwa Abdulkarim Al Alsadi, Carlos Gañán, Katsunari Yoshioka |
AsiaCCS | 5 |
| 2026 | CIC-YNU-IoTMal: A comprehensive multilayer dataset for static and dynamic analysis of IoT malware behaviorabstractMalware continues to pose a critical security threat to the Internet of Things (IoT) ecosystem, driven by the diversity and dynamics of network environments. These conditions introduce significant vulnerabilities, rendering IoT devices prime targets for sophisticated malware attacks. Honeypots have been employed to emulate IoT devices and generate comprehensive malware datasets, enabling the development of adaptive defense systems. However, existing approaches often rely solely on static or dynamic analysis, which fails to keep pace with the evolving nature of malware. Moreover, rigorous detection requires high-fidelity datasets that reflect real-world threats, yet publicly available, multi-architecture IoT malware datasets with recent signatures remain scarce. To address this gap, we present CIC-YNU-IoTMal, a well-researched dataset integrating static and dynamic malware behaviors. Leveraging IoTPOT data and simulated IoT devices, we captured raw network packets, system calls, and system activity logs. Specifically, 10,000 malware binaries were executed on simulated IoT devices within Docker containers and sandbox environments tailored to each architecture. The pipeline processes ARM, MIPS, MIPSEL, and x86 architectures, collecting network traffic (PCAP), system traces (STRACE), and system statistics (SAR). These files were converted to CSV, analyzed, and used to train machine learning algorithms for malware classification. CIC-YNU-IoTMal comprises 2.4M PCAP, 1.8M SAR, and 105M STRACE samples across architectures, representing families such as Mirai, Bashlite (Gafgyt), DarkNexus, Rudedevil, Agent, Generic, and Tsunami. Experimental validation demonstrates that dynamic malware behaviors can be effectively tracked and detected. CIC-YNU-IoTMal2026 is publicly available, advancing research toward a more secure IoT environment. Sajjad Dadkhah, Ogobuchi Daniel Okey, Sebin Abraham Maret, Yen-Wu Lo, Amir Firouzi, Ryu Kuki, Takayuki Sasaki, Katsunari Yoshioka, Tao Ban, Seiichi Ozawa, Ali A. Ghorbani 0001 |
Inf. Syst. | 8 |
| 2025 | Bits and Pieces: Piecing Together Factors of IoT Vulnerability Exploitation
Arwa Abdulkarim Al Alsadi, Mathew Vermeer, Takayuki Sasaki, Katsunari Yoshioka, Michel van Eeten, Carlos Gañán |
AsiaCCS | 4 |
| 2025 | Uncovering Suspicious Posts on Abandoned BlogsabstractAs the Internet evolves, the diversification of information dissemination has led to the growth of various social media platforms and an increase in abandoned blogs. These abandoned blogs, if not properly managed, present a significant security risk. In this study, we introduce “Zombified Blogs,” defined as blogs deserted by their administrators and targeted for continuous submissions of unsolicited malicious content. We explore the causes and effects of this global phenomenon on a large scale, using data from multiple blog services over the past 18 years for the first time. To this end, we propose an innovative method for the continuous identification and collection of Zombified Blogs using a search engine. We analyzed data spanning 18 years, encompassing approximately 1.5 million blog posts, including 258, 547 malicious posts, across 1,141 Zombified Blogs on six different blog services. Our findings show a significant rise in malicious posts, primarily social engineering attacks, over the past four years on previously active blogs. We identify the email posting function as a critical area exploited by attackers, leading to the unintended posting of content. Finally, we provide an overview of the current challenges facing blog services and administrators, and discuss potential content management solutions. Hiroki Nakano, Takashi Koide, Daiki Chiba 0001, Katsunari Yoshioka, Tsutomu Matsumoto |
ICC | 4 |
| 2025 | A Longitudinal Analysis of LockBit 3.0's Extortion Lifecycle and Response to Law EnforcementabstractIn this study, we present a 532-day longitudinal analysis of LockBit 3.0’s leak site. We track 1,856 victims across multiple states-countdown, data publication, deletion, and relisting-and reconstruct a structured, three-stage extortion lifecycle: (1) pre-listing negotiation, (2) countdown negotiation, and (3) post-leak monetization. We find that $8.5 \%$ of countdownstate victims are deleted before their data is published, suggesting private settlements. In the post-leak phase, victims with price tags exhibit significantly more variable deletion timing compared to those without, despite sharing the same median exposure. This indicates that LockBit actively manages some listings after data publication, potentially extending monetization or negotiation efforts.We also measure the operational impact of law enforcement actions-including Operation Cronos and affiliate arrests-on LockBit’s infrastructure and victim activity. While the group rapidly restored services after takedowns, we observe a sustained decline in new victim onboarding, reduced infrastructure redundancy, and delayed payment behavior, suggesting long-term weakening.To our knowledge, this is the first empirical study to model a ransomware extortion lifecycle based on continuous monitoring of leak site behavior. Our findings provide actionable insights into ransomware monetization tactics, negotiation patterns, and post-takedown adaptation. Yin Minn Pa Pa, Yuji Sekine, Yamato Kawaguchi, Tatsuki Yogo, Kelvin Lubbertsen, Rolf van Wegberg, Michel van Eeten, Katsunari Yoshioka |
RAID | 8 |
| 2025 | Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic Service
Takayuki Sasaki, Tomoya Inazawa, Youhei Yamaguchi, Simon Edward Parkin, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
USENIX Security Symposium | 6 |
| 2024 | Customized Malware: Identifying Target Systems Using Personally Identifiable InformationabstractGiven the increasing popularity of sandbox analysis, malware authors have adapted sandbox evasion functionalities into modern malware. In addition, attackers can create Customized Malware that hide their malicious payload until the identifier of the target-specific system can be verified. In this paper, we propose an attack scenario in which adversaries can leverage publicly available personally identifiable information present in the target system as specific identifiers. The proposed attack scenario can be used in targeted attacks, especially against hosts that store business email addresses on personal computers (PCs). We investigated a set of desktop applications and specified 18 popular applications that store email addresses in their related files or directories. We also implemented a survey tool to access these applications and record whether email addresses were found. We then asked nine laboratory members and staff if the target-specific email address was found and if we could extract the same email address from each PC with 16 applications. Finally, we implemented a dummy malware sample that searches for the target host's email address from the executing environment and denies unpacking the malicious payload if the mark does not exist. The experiment results demonstrate that two modern mal ware security appliances did not detect the prototype sample. To defend against the proposed attack, we discuss countermeasures from both the sandbox and user perspective. We contacted security vendors to allow them to prepare for such attacks and provided POC programs. Rui Tanabe, Yuta Inoue, Daigo Ichikawa, Takahiro Kasama, Katsunari Yoshioka, Tsutomu Matsumoto |
COMPSAC | 6 |
| 2024 | VT-SOS: A Cost-effective URL Warning utilizing VirusTotal as a Second Opinion ServiceabstractThe menace of malicious websites, such as online scams or phishing, has exhibited a noteworthy surge. While URL-based blocklists are still used as the primary security solution, previous studies show that the range of protection provided by these lists has little overlap, and the demand to have a second opinion is growing. In this paper, we design a system that aggregates information from multiple security engines in VirusTotal and warns users with malicious URLs that a single antivirus product would dismiss. We introduce VT-SOS, a system utilizing VirusTotal to provide a Second Opinion. Using 47 days of web access logs of real users, we implemented VT-SOS and evaluated effectiveness, affordability, and usability. By simulation, we show that VT-SOS could warn more than 100 users/day and provide a second opinion for more than 30 URLs/day even under a tight budget. We compared VT-SOS with three popular security services and confirmed that it could cover a wider range of malicious websites than those services. By investigating the worst-case user with the most access and warning, we demonstrate that VT-SOS will not deeply affect user experience in practice. Kyohei Takao, Chika Hiraishi, Rui Tanabe, Kazuki Takada, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
NOMS | 9 |
| 2024 | Who Left the Door Open? Investigating the Causes of Exposed IoT Devices in an Academic NetworkabstractMany studies have discovered internet-facing systems exposing services that are vulnerable to attack. These are often assumed to be misconfigured systems that are not meant to expose these services to the network, especially not in an enterprise network. In this study, we clarify the causes of the presence of IoT devices exposing Telnet and FTP in a university enterprise network. This also helps us to understand who is responsible. We scanned the network and found 185 IoT devices consisting of 30 device models exposing Telnet and 49 models exposing FTP. We sent out a security notification and a survey to device owners. The survey demonstrated that 2 out of 21 and 8 out of 41 owners intentionally enabled Telnet and FTP, respectively, on all their devices. After receiving the notification, 38 out of 47 owners said they were willing to take measures on at least one of their IoT devices. All except one of the devices of these willing owners were successfully remediated. When we investigated the manuals of the devices, we were able to confirm that there was no disclosure whatsoever of the exposed service in 15 out of 30 manuals for models with Telnet and 10 out of 49 manuals for models with FTP. We also confirmed, by combining a survey of the manufacturers with the device manuals, that 22 out of 30 and 29 out of 49 devices enabled Telnet and FTP by default, respectively. From the above results, we conclude that the presence of misconfigured devices was less driven by human errors of the owners and more by the choices of the manufacturers. The majority of owners were motivated to remediate the security risks once made aware of them. Takayuki Sasaki, Takaya Noma, Yudai Morii, Toshiya Shimura, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
SP | 6 |
| 2023 | Canary in Twitter Mine: Collecting Phishing Reports from Experts and Non-expertsabstractThe rise in phishing attacks via e-mail and short message service (SMS) has not slowed down at all. The first thing we need to do to combat the ever-increasing number of phishing attacks is to collect and characterize more phishing cases that reach end users. Without understanding these characteristics, anti-phishing countermeasures cannot evolve. In this study, we propose an approach using Twitter as a new observation point to immediately collect and characterize phishing cases via e-mail and SMS that evade countermeasures and reach users. Specifically, we propose CrowdCanary, a system capable of structurally and accurately extracting phishing information (e.g., URLs and domains) from tweets about phishing by users who have actually discovered or encountered it. In our three months of live operation, CrowdCanary identified 35,432 phishing URLs out of 38,935 phishing reports, 31,960 (90.2%) of these phishing URLs were later detected by the anti-virus engine. We analyzed users who shared phishing threats by categorizing them into two groups: experts and non-experts. As a results, we discovered that CrowdCanary extracts non-expert report-specific information, like company brand name in tweets, phishing attack details from tweet images, and pre-redirect landing page information. Hiroki Nakano, Daiki Chiba 0001, Takashi Koide, Naoki Fukushi, Takeshi Yagi, Takeo Hariu, Katsunari Yoshioka, Tsutomu Matsumoto |
ARES | 7 |
| 2023 | Peering into the Darkness: The Use of UTRS in Combating DDoS Attacks
Radu Anghel, Swaathi Vetrivel, Elsa Turcios Rodriguez, Kaichi Sameshima, Daisuke Makita, Katsunari Yoshioka, Carlos Gañán, Yury Zhauniarovich |
ESORICS (2) | 6 |
| 2023 | Bin there, target that: Analyzing the target selection of IoT vulnerabilities in malware binariesabstractFor years, attackers have exploited vulnerabilities in Internet of Things (IoT) devices. Previous research has examined target selection in cybercrime, but there has been little investigation into the factors that influence target selection in attacks on IoT. This study aims to better understand how attackers choose their targets by analyzing the frequency of specific exploits in 11,893 IoT malware binaries that were distributed between 2018–2021. Our findings indicate that 78% of these binary files did not specifically target IoT vulnerabilities but rather scanned the Internet for devices with weak authentication. To understand the usage of exploits in the remaining 2,629 binaries, we develop a theoretical model from relevant literature to examine the impact of four latent variables, i.e. exposure, vulnerability, exploitability, and patchability. We collect indicators to measure these variables and find that they can explain to a significant extent (R2=0.38) why some vulnerabilities are more frequently exploited than others. The severity of vulnerabilities does not significantly increase the frequency with which they are targeted, while the presence of Proof-of-Concept exploit code does increase it. We also observe that the availability of a patch reduces the frequency of being targeted, yet that more complex patches are associated with higher frequency. In terms of exposure, more widespread device models are more likely to be targeted by exploits. We end with recommendations to disincentivize attackers from targeting vulnerabilities. Arwa Abdulkarim Al Alsadi, Kaichi Sameshima, Katsunari Yoshioka, Michel van Eeten, Carlos Gañán |
RAID | 3 |
| 2022 | An Internet-Wide View of Connected Cars: Discovery of Exposed Automotive DevicesabstractAs the number of connected cars increases, cyber-attacks targeting them become significant risks. Especially, On-Board Equipment (OBE) that is directly accessible from the Internet can be an immediate target. However, it is not known what kind of and how many connected automotive devices can be remotely accessed from the Internet and, if compromised, become an entry point for further attacks on in-vehicle networks. In this study, we investigate the prevalence of such exposed vehicular devices. We propose a discovery method that utilizes an Internet-wide scan engine and a regular web search engine to find Internet-facing OBE. Using the proposed method, we discovered 2,532 devices of 12 different OBE products across 27 countries. We also investigated the potential cyber-attack risks against the discovered devices. 11 out of the 12 products have security concerns for remote compromises, such as running Telnet or outdated server programs. Moreover, we found that nine products have the capability to connect to the in-vehicle network. We could confirm from the information displayed in their user interface that at least two of them indeed connected to the in-vehicle network. Additionally, we noticed three products expose privacy-sensitive information such as GPS location. We believe this result provides a lower bound of the security risk of Internet-facing vehicular devices. Takahiro Ueda, Takayuki Sasaki, Katsunari Yoshioka, Tsutomu Matsumoto |
ARES | 3 |
| 2022 | No Spring Chicken: Quantifying the Lifespan of Exploits in IoT Malware Using Static and Dynamic AnalysisabstractThe Internet of things (IoT) is composed by a wide variety of software and hardware components that inherently contain vulnerabilities. Previous research has shown that it takes only a few minutes from the moment an IoT device is connected to the Internet to the first infection attempts. Still, we know little about the evolution of exploit vectors: Which vulnerabilities are being targeted in the wild, how has the functionality changed over time, and for how long are vulnerabilities being targeted? Understanding these questions can help in the secure development, and deployment of IoT networks. Arwa Abdulkarim Al Alsadi, Kaichi Sameshima, Jakob Bleier, Katsunari Yoshioka, Martina Lindorfer, Michel van Eeten, Carlos Gañán |
AsiaCCS | 4 |
| 2022 | Amplification Chamber: Dissecting the Attack Infrastructure of Memcached DRDoS Attacks
Mizuki Kondo, Rui Tanabe, Natsuo Shintani, Daisuke Makita, Katsunari Yoshioka, Tsutomu Matsumoto |
DIMVA | 5 |
| 2022 | Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesabstractGeographically distributed infrastructures, such as buildings, dams, and solar power plants, are commonly maintained via Internet-connected remote management devices. Previous studies on detecting and securing industrial control systems (ICS) have overlooked these remote management devices, as they do not expose ICS-specific services like Modbus and BACnet and thus do not show up in Internet-wide scans for such services. In this paper, we implement and validate a discovery method for these devices via their Web User Interface (WebUI) and detect 890 devices in Japan alone. We also show that many of these devices are highly insecure. Many allow access to the status or even the control over industrial systems without proper authentication. Taking a closer look at three prevalent remote management devices, we discovered 13 0-day vulnerabilities, several of which were rated as medium or high severity. They have been responsibly disclosed to the manufacturers. By using honeypots that imitate these systems, we show that over time, only a small number of attackers enter these systems, but some do change critical parameters. Attackers appear to interact more with the system when more facility information is displayed on the WebUI. Finally, we notified operators of 317 vulnerable remote management devices by email and telephone. We reached 212 persons in charge of the devices and received confirmation that our method had correctly identified the device. 50% of the persons in charge of the devices stated that they mitigated or will mitigate the problem. We confirmed their actions via a followup scan for vulnerable devices and found that measures were taken for 58% of the devices when we could reach the persons in charge of the device. Takayuki Sasaki, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
SP | 5 |
| 2021 | Adaptive Observation of Emerging Cyber Attacks targeting Various IoT Devices
Seiya Kato, Rui Tanabe, Katsunari Yoshioka, Tsutomu Matsumoto |
IM | 3 |
| 2020 | Disposable botnets: examining the anatomy of IoT botnet infrastructureabstractLarge botnets made up of Internet-of-Things (IoT) devices have been a steady presence in the threat landscape since 2016. Earlier research has found preliminary evidence that the IoT binaries and C&C infrastructure were only seen for very brief periods. It has not explained how attackers maintain control over their botnets. We present a more comprehensive analysis of the infrastructure of IoT botnets based on 23 months of data gathered via honeypots and the monitoring of botnet infrastructure. We collected 59,884 IoT malware samples, 35,494 download servers, and 2,747 C&C servers. We focuse on three dominant families: Bashlite, Mirai, and Tsunami. The picture that emerges is that of highly disposable botnets. IoT botnet are not so much maintained as reconstituted from scratch all the time. Not only are most binaries distributed for less than three days, the connection of bots to the rest of the botnet is also short-lived. To reach the C&C server, the binaries typically contain only a single hard-coded IP address or domain. The C&C servers themselves also have a short lifespan. Long-term dynamic analysis finds no mechanism for the attackers to migrate the bots to a new C&C server. In other words, bots are used only immediately after capture and then abandoned---perhaps to be recaptured again via the aggressive scanning practices that these botnets are known for. While IoT botnets appear less advanced than Windows-based botnets, the advantage of being disposable means that they are very resistant to blacklisting and C&C takedown. Most IP addresses are used only once and never seen again. The question that arises is how attackers source these addresses. We speculate that they might be abusing the IP address allocation practices of cloud providers. Rui Tanabe, Tatsuya Tamai, Akira Fujita, Ryoichi Isawa, Katsunari Yoshioka, Tsutomu Matsumoto, Carlos Gañán, Michel van Eeten |
ARES | 5 |
| 2020 | It Never Rains but It Pours: Analyzing and Detecting Fake Removal Information Advertisement Sites
Takashi Koide, Daiki Chiba 0001, Mitsuaki Akiyama, Katsunari Yoshioka, Tsutomu Matsumoto |
DIMVA | 4 |
| 2020 | On the Origin of Scanning: The Impact of Location on Internet-Wide ScansabstractFast IPv4 scanning has enabled researchers to answer a wealth of security and networking questions. Yet, despite widespread use, there has been little validation of the methodology's accuracy, including whether a single scan provides sufficient coverage. In this paper, we analyze how scan origin affects the results of Internet-wide scans by completing three HTTP, HTTPS, and SSH scans from seven geographically and topologically diverse networks. We find that individual origins miss an average 1.6-8.4% of HTTP, 1.5-4.6% of HTTPS, and 8.3-18.2% of SSH hosts. We analyze why origins see different hosts, and show how permanent and temporary blocking, packet loss, geographic biases, and transient outages affect scan results. We discuss the implications for scanning and provide recommendations for future studies. Gerry Wan, Liz Izhikevich, David Adrian, Katsunari Yoshioka, Ralph Holz, Christian Rossow, Zakir Durumeric |
Internet Measurement Conference | 4 |
| 2020 | Tracing and Analyzing Web Access Paths Based on User-Side Data Collection: How Do Users Reach Malicious URLs?
Takeshi Takahashi 0001, Christopher Krügel, Giovanni Vigna, Katsunari Yoshioka |
RAID | 4 |
| 2019 | Detect Me If You... Oh Wait. An Internet-Wide View of Self-Revealing Honeypots
Shun Morishita, Takuya Hoizumi, Wataru Ueno, Rui Tanabe, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
IM | 7 |
| 2019 | Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove Mirai
Orçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama, Kazuki Tamiya, Ying Tie, Katsunari Yoshioka, Michel van Eeten |
NDSS | 8 |
| 2018 | Evasive Malware via Identifier ImplantingabstractTo cope with the increasing number of malware attacks that organizations face, anti-malware appliances and sandboxes have become an integral security defense. In particular, appliances have become the de facto standard in the fight against targeted attacks. Yet recent incidents have demonstrated that malware can effectively detect and thus evade sandboxes, resulting in an ongoing arms race between sandbox developers and malware authors. We show how attackers can escape this arms race with what we call customized malware , i.e., malware that only exposes its malicious behavior on a targeted system. We present a web-based reconnaissance strategy, where an actor leaves marks on the target system such that the customized malware can recognize this particular system in a later stage, and only then exposes its malicious behavior. We propose to implant identifiers into the target system, such as unique entries in the browser history, cache, cookies, or the DNS stub resolver cache. We then prototype a customized malware that searches for these implants on the executing environment and denies execution if implants do not exist as expected. This way, sandboxes can be evaded without the need to detect artifacts that witness the existence of sandboxes or a real system environment. Our results show that this prototype remains undetected on commercial malware security appliances, while only exposing its real behavior on the targeted system. To defend against this novel attack, we discuss countermeasures and a responsible disclosure process to allow appliances vendors to prepare for such attacks. Rui Tanabe, Wataru Ueno, Kou Ishii, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Christian Rossow |
DIMVA | 4 |
| 2016 | Who Gets the Boot? Analyzing Victimization by DDoS-as-a-Service
Arman Noroozian, Maciej Korczynski, Carlos Gañán, Daisuke Makita, Katsunari Yoshioka, Michel van Eeten |
RAID | 5 |
| 2016 | SandPrint: Fingerprinting Malware Sandboxes to Provide Intelligence for Sandbox Evasion
Akira Yokoyama, Kou Ishii, Rui Tanabe, Yinmin Papa, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Michael Brengel, Michael Backes 0001, Christian Rossow |
RAID | 5 |
| 2015 | AmpPot: Monitoring and Defending Against Amplification DDoS Attacks
Lukas Krämer, Johannes Krupp, Daisuke Makita, Tomomi Nishizoe, Takashi Koide, Katsunari Yoshioka, Christian Rossow |
RAID | 6 |
| 2012 | A Method of Preventing Unauthorized Data Transmission in Controller Area NetworkabstractThere is a strong demand for the security of Controller Area Network (CAN), a major in-vehicle network. A number of methods to detect unauthorized data transmission, such as anomaly detection and misuse detection, have already been proposed. However, all of them have no capability of preventing unauthorized data transmission itself. In this paper, we propose a novel method that realizes the prevention as well as detection. Our method can be effectively implemented with minimal changes in the current architecture of Electronic Control Unit. The method works even in a CAN with multiple buses interconnected by gateways. Tsutomu Matsumoto, Masato Hata, Masato Tanabe, Katsunari Yoshioka, Kazuomi Oishi |
VTC Spring | 4 |
| 2009 | A Proposal of Malware Distinction Method Based on Scan Patterns Using Spectrum Analysis
Masashi Eto, Kotaro Sonoda, Katsunari Yoshioka, Koji Nakao |
ICONIP (2) | 4 |
| 2009 | DAEDALUS: Novel Application of Large-Scale Darknet Monitoring for Practical Protection of Live Networks
Mio Suzuki, Masashi Eto, Katsunari Yoshioka, Koji Nakao |
RAID | 4 |
| 2008 | Malware Behavior Analysis in Isolated Miniature Network for Revealing Malware's Network ActivityabstractMalware, such as computer viruses, worms, and bots, has been recognized as one of the major security threats in the Internet environment, and a large amount of research and development is taking place to find effective countermeasures. These countermeasures are mainly based on either macroscopic or microscopic analysis. Macroscopic analysis is based on monitoring the network in order to grasp the global trends of malware propagations while microscopic analysis investigates malware executables to identify the details of how they behave. We have been developing the network incident analysis center for tactical emergency response (NICTER), where both kinds of analysis are highly integrated. By integrating and correlating the results from the both two approaches, the nicter binds phenomena, i.e., scans observed by network monitoring with their root causes, i.e., malwares. Previous analysis of malware has mainly focused on their internal behavior in the system. However, in order to achieve such a goal, it is crucial that the microscopic analysis extracts a malware's external behavior towards the network. We propose a novel way to analyze malware behavior: focus closely on the malware's external behavior. A malware sample is executed on a real machine that is connected to a virtual Internet environment called a "miniature network". Since this analysis environment is totally isolated from the real Internet, the execution of the sample, unlike in previously proposed methods, causes no further unwanted propagation. Furthermore, the behavioral analysis is carried out in two passes. In the first pass, in order to extract a wider variety of network behaviors from the sample, the miniature network responds as interactively as possible. In the second pass, to make only suitable response that will enable us to concentrate on specific behavior, namely scan behaviors, the miniature network is configured on the basis of the first pass result. We also present concrete analysis results that are gained by using the proposed method. Katsunari Yoshioka, Masashi Eto, Yuji Hoshizawa, Koji Nakao |
ICC | 2 |
| 2008 | An Incident Analysis System NICTER and Its Analysis Engines Based on Data Mining Techniques
Katsunari Yoshioka, Masashi Eto, Masaya Yamagata, Eisuke Nishino, Jun'ichi Takeuchi, Kazuya Ohkouchi, Koji Nakao |
ICONIP (1) | 2 |
| 2003 | Systematic Treatment of Collusion Secure Codes: Security Definitions and Their Relations
Katsunari Yoshioka, Junji Shikata, Tsutomu Matsumoto |
ISC | 1 |