Motoyuki Ohmori

dblp:76/3057 · DBLP profile ↗
← Back
10ranked-venue papers
8as first author
6since 2021 · last 2026
0000-0002-8769-4505ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 5 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 5 first-author · 5 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2026 Comparison of Congestion Controls for LEO Satellite Communications in the Wild
abstract
Low Earth Orbit (LEO) satellite constellation services are expected to be a part of next-generation communication infrastructure. In LEO satellite communications, handover is required to switch communications between satellites and ground stations or terminals, which causes communication breakdown. These communication disruptions affect congestion control in transport protocols, leading to degradation of their performance. To address this degradation, congestion controls tailored for LEO satellites, such as StarQUIC, SatPipe, and TCP LEO, have been proposed. However, comprehensive evaluations of these congestion controls on a real LEO satellite network cannot be found, and evaluations are desired. To this end, this paper compares these LEO satellite congestion controls with one of major LEO satellite communication services, Starlink, evaluating them based on throughput, retransmissions, latencies, and file download time. The evaluation results have shown that TCP LEO employing transmission freeze during handover has shown the best throughput, the minimum latencies, and the shortest download time. Regarding retransmissions, SatPipe has achieved the lowest number of retransmissions.
Motoyuki Ohmori, Kohichi Ogawa, Hiroki Kashiwazaki, Takeshi Ikenaga
CCNC1
2026 Vendor-Lock Free Security Policy Synchronization Between Redundant Firewalls
Motoyuki Ohmori
COMPSAC1
2026 CUBIC++: Empirical Fine-Tuned CUBIC
Motoyuki Ohmori, Kohichi Ogawa, Hiroki Kashiwazaki, Takeshi Ikenaga
COMPSAC1
2024 Transforming Security Policies in Firewalls Using the Shortest Editing Script Algorithm
abstract
In this paper, we propose a novel transformation of security policies of firewalls using the Shortest Edit Script (SES) algorithm that is employed in the widely known diff command. We here assume to configure a standby firewall in order to synchronize its security policies with one of an active firewall. Security policies in a standby firewall are transformed into those in an active firewall. We regard one security policy as a symbol, and entire security policies in a firewall are considered to be a sequence of these symbols. We have then attributed this transformation problem to the SES problem, and have solved it. Our prototype implementation has appeared to be able to transform security policies in a running firewall within 0.19 seconds where the number of security policies is about 500.
Motoyuki Ohmori
COMPSAC1
2023 Let's Block Encrypted Malicious Sites
abstract
Always-On SSL (AOSSL) is now becoming common even in malicious sites for phishing or malware. Most of these AOSSLed malicious sites employs Domain-Validated (DV) certificate. Many of these DV certificates are issued by Let’s encrypt, which is a major CA that is dedicated for DV certificate.This paper proposes to regard AOSSLed sites using Let’s Encrypt with additional factors as malicious, and block them on a firewall in the wild. For judging maliciousness, use of Transport Layer Security (TLS) 1.2 or less, malicious Top-Level Domain (TLD) found in a heuristic way and dynamic DNS (DDNS) are considered as criteria. We have then implemented an on-the-fly access prevention to malicious sites on a next-generation firewall running in the actual environment of authors’ university. We have implemented these by configuration changes only on the firewall developed by Palo Alto Networks, Inc., and keep operability and an access prevention. In the authors’ university, the proposal has appeared that TLD based detection could detect malicious sites by 38.3% accuracy while no malicious sites was detected by DDNS.
Motoyuki Ohmori
COMPSAC1
2022 A Novel Passive L1/L2 Edge Loop Detection Observing MAC addresses of L3 Core Switches
abstract
A L1 and/or L2 loop in a network may cause congestion and incur communication failures. It is, therefore, important to quickly and accurately detect a loop and locate its origin in order to eliminate the loop. To address this issue, this paper proposes a novel passive loop detection on edge ports of edge switches where end users' routers or terminals are accom-modated. The basic idea of the proposed detection is inspired by the nature that a MAC address of a L3 core switch should never be observed on an edge port. The MAC address is then observed by always-accepting MAC address authentication that can be easily deployed. The proposed detection can, therefore, accurately locate an edge port where a loop is formed, and avoid a failure to notify a network operator of a loop. In addition, the proposed detection can reduce a load on an edge switch more than the existing active detecting methods. Our evaluations in the real campus network have shown that the proposed method can detect the loop even where the existing methods cannot.
Motoyuki Ohmori
COMPSAC1
2019 AXARPS: Scalable ARP Snooping Using Policy-Based Mirroring of Core Switches
Motoyuki Ohmori, Naoki Miyata, Ichiroh Suzuta
AINA1
2019 A Case Study of Captive-Portal Detection for Web Authentication on Wired LAN in a Campus Network
abstract
In order to quickly and properly handle a computer security incident or a network failure, it is necessary to identify a suspicious host and its user, and a network authentication is then necessary. Regarding wired LAN, web authentication can be feasible because a user does not need to configure his or her host in advance. There are, however, severe issues of web authentication that incurs very long delay. This paper reveals that the cause of this long delay is mainly by Windows update before an authentication. This paper then proposes the feasible web authentication using captive-portal detection that achieve simultaneous authentications of more than 40 clients.
Motoyuki Ohmori
APNOMS1
2009 A Proposal to Enhance and Control Continuous Communications in Proxy Mobile IPv6
abstract
In future mobile systems, various access networks will be used and the usability of a mobile node (MN) with the access networks will be higher. When a MN is connected to several access networks simultaneously, it may hand over from one access network to the other according to the connectivity to the access network. In order to keep communications even during handover, the mobility of MNs and the continuous communications have to be supported. In addition, IP mobility has to be supported as well. With the increase usage and mobility of MNs, it is highly required to control the traffic incurred by the communication of MNs. In the prospects of Network Service Provider (NSP) or Internet Service Provider (ISP), the overall aspect of traffic would be more dynamic due to the mobility of MNs. It is also more likely for the traffic to be concentrated. Therefore, it is necessary for Service Provider (SP) to have how to control the communication service provided to each MN in order to provide smooth communication. In this paper, we propose a method to support the continuous communications in Proxy Mobile IPv6 (PMIPv6) that provides IP mobility. In case that a MN is connected to a PMIPv6 domain through multiple interfaces, this method makes it possible to keep all the communications as long as some connecting interfaces remain supported when other interfaces are disconnected because of some problems such as the movement of the MN. And we propose a method for the SP to control the communication provided to MN. This paper suggests a new signaling procedure to provide more stable continuous communications and to control the communications efficiently. The new MN protocol stack model is designed to maximize the use of MN as well.
Joon-Suk Kang, Motoyuki Ohmori, Koji Okamura
AINA2
2006 MIS Protocol for Secure Connection and Fast Handover on Wireless LAN
abstract
MIS (mobile Internet services) architecture is designed for secure connection and fast handover with wireless LAN. This architecture consists of three protocols, MISP (mobile Internet services protocol), MISAUTHP (mobile Internet services authentication protocol) and MIS MobilelP, and two kinds of servers, authentication servers and home agent, base routers and mobile nodes. MISP is a protocol designed for authentication, IP address assignments, session key exchanges and various negotiations between mobile nodes and base routers with one-round-trip packet exchange after a mobile node receives beacons. MISP quickly establishes link between mobile nodes and base routers. MISAUTHP is a protocol for authentication between authentication servers and base routers. MISAUTHP can authenticate mobile nodes and base routers with single exchange of packets too, MIS MobilelP is a mobility support protocol for IPv4. This is a subset of RFC2002 MobileIP. We mainly describe about MISP, MISAUTHP and comparison between MISP with MISAUTHP and IEEE802.11 with IEEE802.1x
Hitoshi Morioka, Hiroshi Mano, Motoyuki Ohmori, Masataka Ohta
AINA (1)3