Yong Jin 0001

dblp:89/6327-1 · DBLP profile ↗
← Back
23ranked-venue papers
14as first author
7since 2021 · last 2024
0000-0003-2967-5557ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 12 · 7 first-author · 4 since 2021Software engineering, systems software and programming languages · 11 · 6 first-author · 4 since 2021Computer networks · 3 · 2 first-author · 1 since 2021Security and privacy · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2024 Privacy Preserved Achievement Method for OCSP Status and Supported Protocols in Full-DoH Architecture
abstract
Currently, efforts to protect privacy information through encrypted DNS communications are becoming increasingly active. The encryption of DNS, standardized by the IETF, predominantly uses TLS. However, the use of TLS for encrypting DNS communications results in the leakage of privacy information during the certificate revocation process. This paper proposes a new method for certificate revocation verification in encrypted DNS communications, presents a way to enhance the protection of privacy information, and outlines a research plan for further investigation.
Satoru Sunahara, Yong Jin 0001, Katsuyoshi Iida, Nariyoshi Yamai, Yoshiaki Takai
COMPSAC2
2023 Detection of DGA-based Malware Communications from DoH Traffic Using Machine Learning Analysis
abstract
Encrypted domain name resolution can reduce the risk of privacy leakage for Internet users, but it may also prevent network administrators from detecting suspicious communications. Since operating systems supporting DNS over HTTPS (DoH) have increased in recent years, malware that uses Domain Generation Algorithm (DGA) can exploit it to hide the generated domain names. In this paper, we propose a system that detects DGA-based malware communications from DoH traffic. Based on the concept of hierarchical machine learning analysis, the proposed system classifies network traffic with Gradient Boosting Decision Tree (GBDT) and tree-ensemble models. The evaluation confirmed that the system was able to detect DoH traffic generated by PadCrypt, Sisron, Tinba, and Zloader with 99.12% accuracy. The results indicate that the system has the ability to detect different DGA-based malware communications from DoH traffic with sufficient accuracy to support network administrators.
Rikima Mitsuhashi, Yong Jin 0001, Katsuyoshi Iida, Takahiro Shinagawa, Yoshiaki Takai
CCNC2
2023 A Named-Entity-based TTP-free Authentication and Authorization Architecture for IoT Systems
abstract
Authentication and authorization are essential functionalities in Internet of Things (IoT) systems in the areas of device monitoring, access control, data sharing, and privacy preservation. The current authentication and authorization technologies are mainly based on ID/Password (credential), public key cryptography collaborating with multi-factor approaches, and manual basis static access control for data resources. However, they have disadvantages in terms of identity/credential management, privacy preservation, and the mandatory requirement of Trusted Third Party (TTP) Certificate Authorities (which are not cryptographically secure) for certificate verifications. The objective of this fast abstract is to present a novel idea for named-entity-based TTP-free authentication and authorization architecture in IoT systems. The proposed architecture is based on the collaboration of blockchain technology and DNS-based Authentication of Named Entity (DANE) protocol to provide secure and privacy-preserved authentication and authorization functionalities with considering effective device identity management and secure data access control in IoT systems.
Yong Jin 0001, Masahiko Tomoishi
COMPSAC1
2023 Trustworthy Name Resolution Using TLS Certificates with DoT-enabled Authoritative DNS Servers
abstract
The Domain Name System (DNS) plays an important and indispensable role in supporting the modern Internet. Meanwhile, if the DNS message is not encrypted anyway, malicious third parties can exploit the communication channel and cause phishing scams and malware infection. Several countermeasures against this issue already exist, such as Domain Name System Security Extensions (DNSSEC), which guarantees the validity of DNS resource records by adding digital signatures to the DNS messages, and DNS over TLS (DoT), which encrypts a part of the communication channel of domain name resolution process. However, each of these solutions has its own merit and demerit, and neither of them has been implemented on a global scale. Therefore, in this paper, a trustworthy domain name resolution method using TLS certificates with DoT-enabled authoritative DNS servers is proposed. Specifically, the DoT-based name resolution is extended to authoritative DNS servers and the certificate validation is allowed on the end terminals. Moreover, the domain name resolution process is accelerated by obtaining the certificates on the end terminal via the DNS full-service resolver. The evaluation results confirmed that the prototype system worked as designed and it is expected to provide trustworthy domain name resolution service with privacy preservation.
Toshio Murakami, Kenta Shimabukuro, Nao Sato, Rei Nakagawa, Yong Jin 0001, Nariyoshi Yamai
COMPSAC5
2023 Verification Method of Associated Domain Names Using Certificates by Applying DNS over TLS to Authoritative Servers
abstract
DNS over Transport Layer Security (DoT) has been standardized in the Domain Name System (DNS) to protect the confidentiality of communications between stub resolvers and recursive resolvers. In addition, the standardization for introducing encrypted communication between recursive resolvers and authoritative servers is in progress in IETF. In this paper, we assume that authoritative servers have X.509 certificates to support DoT and propose a mechanism that enables users to determine whether or not a domain name that is similar to or closely associated with a legitimate domain name (possibly a "cousin domain") is actually associated with it.
Nariyoshi Yamai, Yong Jin 0001, Toshio Murakami, Rei Nakagawa
COMPSAC2
2023 Malicious DNS Tunnel Tool Recognition Using Persistent DoH Traffic Analysis
abstract
DNS over HTTPS (Do) can mitigate the risk of privacy breaches but makes it difficult to control network security services due to the DNS traffic encryption. However, since malicious DNS tunnel tools for the DoH protocol pose network security threats, network administrators need to recognize malicious communications even after the DNS traffic encryption has become widespread. In this paper, we propose a malicious DNS tunnel tool recognition system using persistent DoH traffic analysis based on machine learning. The proposed system can accomplish continuous knowledge updates for emerging malicious DNS tunnel tools on the machine learning model. The system is based on hierarchical machine learning classification and focuses on DoH traffic analysis. The evaluation results confirm that the proposed system is able to recognize the six malicious DNS tunnel tools in total, not only well-known ones, including dns2tcp, dnscat2, and iodine, but also the emerging ones such as dnstt, tcp-over-dns, and tuns with 98.02% classification accuracy.
Rikima Mitsuhashi, Yong Jin 0001, Katsuyoshi Iida, Takahiro Shinagawa, Yoshiaki Takai
IEEE Trans. Netw. Serv. Manag.2
2021 Identifying Malicious DNS Tunnel Tools from DoH Traffic Using Hierarchical Machine Learning Classification
Rikima Mitsuhashi, Akihiro Satoh, Yong Jin 0001, Katsuyoshi Iida, Takahiro Shinagawa, Yoshiaki Takai
ISC3
2020 A Study of Classification of Texts into Categories of Cybersecurity Incident and Attack with Topic Models
Masahiro Ishii 0002, Satoshi Matsuura, Kento Mori, Masahiko Tomoishi, Yong Jin 0001, Yoshiaki Kitaguchi
ICISSP5
2020 A Detour Strategy for Visiting Phishing URLs Based on Dynamic DNS Response Policy Zone
abstract
Email based Uniform Resource Locator (URL) distribution is one of the popular ways for starting phishing attacks. Conventional anti-phishing solutions rely on security facilities and investigate all incoming emails. This makes the security facilities get overloaded and cause consequences of upgrades or new deployments even with no better options. This paper presents a novel detour strategy for the traffic of visiting potential phishing URLs based on dynamic Domain Name System (DNS) Response Policy Zone (RPZ) in order to mitigate the overloads on security facilities. In the strategy, the URLs included in the incoming emails will be extracted and the corresponding Fully Qualified Domain Name (FQDN) will be registered in the RPZ of the local DNS cache server with mapping the IP address of a special Hypertext Transfer Protocol (HTTP) proxy. The contribution of the approach is to avoid heavy investigations on all incoming emails and mitigate the overloads on security facilities by directing the traffic to phishing URLs to the special HTTP proxy connected with a set of security facilities conducting various inspections. The evaluation results on the prototype system showed that the URL extraction and FQDN registration were finished before the emails had been delivered and accesses to the URLs were successfully directed to the special HTTP proxy. The results of overhead measurements also confirmed that the proposed strategy only affected the internal email server with 11% of performance decrease on the prototype system.
Yong Jin 0001, Masahiko Tomoishi, Nariyoshi Yamai
ISNCC1
2019 Detection of Hijacked Authoritative DNS Servers by Name Resolution Traffic Classification
abstract
Authoritative DNS server hijacking has been a critical threat which can be hardly prevented by DNSSEC. In this work, we propose a machine learning based detection method against DNS responses replied from hijacked external authoritative DNS servers by DNS traffic data classification and heuristic analysis. The proposed method consists of header, answer, authority and additional section analysis each of which is combined with the corresponding question section. The decision maker decides if a DNS query-response pair has been related to a hijacked external authoritative DNS server by conducting heuristic analysis on the classified DNS traffic data with comparing with old cached DNS data. We have setup a local experimental network and achieved DNS traffic data (A records) of the top 500 FQDNs listed on Alexa web site for about one month and confirmed that the required features can be attracted from the DNS traffic data. Accordingly, we confirmed that it was expectable to conduct the DNS traffic classification and heuristic analysis in order to detect DNS responses replied from hijacked external authoritative DNS servers. The future work includes the DNS traffic data training and the evaluations on a local experimental network as well as in a large scale real network environment.
Yong Jin 0001, Masahiko Tomoishi, Satoshi Matsuura
IEEE BigData1
2019 A Lightweight and Secure IoT Remote Monitoring Mechanism Using DNS with Privacy Preservation
abstract
IoT remote control is faced with scalability, secure communication and privacy preservation issues and conventional solutions (HTTPS) have disclosed poor scaling problem and privacy concerns. In this paper, we propose a novel lightweight and secure IoT remote monitoring mechanism using DNS with privacy preservation. Basically, the communication between IoT devices and gateways uses the conventional protocols as usual such as CoAP and MQTT while only the remote monitoring uses DNS protocol. That is, encrypted IoT data, after being encoded with base64, is stored as a DNS TXT record of the domain name of the IoT device and only the designated users are allowed to query and decrypt the data based on TSIG authentication of DNS protocol and asymmetric cryptography. We implemented a prototype system over name-bound virtual networks (NBVNs) in which all virtual nodes are registered in DNS automatically and the network traffic is restricted within each NBVN. Through the preliminary evaluations we confirmed the effectiveness of secure communication and privacy preservation in IoT remote monitoring in the proposed mechanism.
Yong Jin 0001, Masahiko Tomoishi, Kenji Fujikawa, Ved P. Kafle
CCNC1
2019 Encrypted QR Code Based Optical Challenge-Response Authentication by Mobile Devices for Mounting Concealed File System
abstract
Nowadays mobile devices have become the majority terminals used by people for social activities so that carrying business data and private information in them have become normal. Accordingly, the risk of data related cyber attacks has become one of the most critical security concerns. The main purpose of this work is to mitigate the risk of data breaches and damages caused by malware and the lost of mobile devices. In this paper, we propose an encrypted QR code based optical challenge-response authentication by mobile devices for mounting concealed file systems. The concealed file system is basically invisible to the users unless being successfully mounted. The proposed authentication scheme practically applies cryptography and QR code technologies to challenge-response scheme in order to secure the concealed file system. The key contribution of this work is to clarify a possibility of a mounting authentication scheme involving two mobile devices using a special optical communication way (QR code exchanges) which can be realizable without involving any network accesses. We implemented a prototype system and based on the preliminary feature evaluations results we confirmed that encrypted QR code based optical challenge-response is possible between a laptop and a smart phone and it can be applied to authentication for mounting concealed file systems.
Yong Jin 0001, Masahiko Tomoishi
COMPSAC (2)1
2019 A Detection Method Against DNS Cache Poisoning Attacks Using Machine Learning Techniques: Work in Progress
abstract
DNS based domain name resolution has been known as one of the most fundamental Internet services. In the meanwhile, DNS cache poisoning attacks also have become a critical threat in the cyber world. In addition to Kaminsky attacks, the falsified data from the compromised authoritative DNS servers also have become the threats nowadays. Several solutions have been proposed in order to prevent DNS cache poisoning attacks in the literature for the former case such as DNSSEC (DNS Security Extensions), however no effective solutions have been proposed for the later case. Moreover, due to the performance issue and significant workload increase on DNS cache servers, DNSSEC has not been deployed widely yet. In this work, we propose an advanced detection method against DNS cache poisoning attacks using machine learning techniques. In the proposed method, in addition to the basic 5-tuple information of a DNS packet, we intend to add a lot of special features extracted based on the standard DNS protocols as well as the heuristic aspects such as “time related features”, “GeoIP related features” and “trigger of cached DNS data”, etc., in order to identify the DNS response packets used for cache poisoning attacks especially those from compromised authoritative DNS servers. In this paper, as a work in progress, we describe the basic idea and concept of our proposed method as well as the intended network topology of the experimental environment while the prototype implementation, training data preparation and model creation as well as the evaluations will belong to the future work.
Yong Jin 0001, Masahiko Tomoishi, Satoshi Matsuura
NCA1
2018 Message from the ADMNET 2018 Workshop Organizers
abstract
Presents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record.
Takashi Yamanoue, Hiroki Kashiwazaki, Yong Jin 0001, Ruediger Gad
COMPSAC (2)3
2018 A Client Based Anomaly Traffic Detection and Blocking Mechanism by Monitoring DNS Name Resolution with User Alerting Feature
abstract
Malware has become one of the most critical targets of network security solutions nowadays. Many types of malware receive further instructions from the C&C servers and the attack targets may be instructed by IP addresses which causes direct attacks without DNS name resolution from the malware-infected computers. In the meanwhile, several programs that are hidden from the users (e.g. malware, virus, etc.) may perform DNS name resolutions for cyber attacks or other communications. In this paper, we propose a client based anomaly traffic detection and blocking mechanism by monitoring DNS name resolution per application program. In the proposed mechanism, by the collaboration of DNS proxy and packet filter, DNS traffic is monitored on the client and the traffic destined to the IP addresses obtained without DNS name resolution or the traffic from unrecognized programs will be detected and blocked. In addition, in order to mitigate false positive detection, an alert-window will be shown to let the users decide whether to allow the traffic or not. We implemented a prototype system on a Windows 7 client and confirmed that the proposed mechanism worked as expected.
Yong Jin 0001, Kunitaka Kakoi, Nariyoshi Yamai, Naoya Kitagawa, Masahiko Tomoishi
CW1
2017 An In-depth Concealed File System with GPS Authentication Adaptable for Multiple Locations
abstract
Security threats from cyber attacks never stop threatening human's social activities. Even though, carrying mobile devices with confidential data is still popular among people without constraint due to business needs and usability. In this paper, we propose an in-depth concealed file system with GPS authentication adaptable for multiple locations in order to mitigate data breaches and file destructions on mobile devices. The proposed file system has in-depth layout and is mountable only when the mobile device is in the designated areas using GPS authentication. Different security policies can be set for each layer and data can be separately stored in each layer based on the confidentiality. Moreover, usability is considered as high priority and an automatic mounting feature is also introduced since people cannot be bordered to run the program a lot times. We implemented a 2-layer prototype system with combination of GPS only authentication (lightweight) and collaborated authentication (mobile device and smart phone). According to the preliminary evaluation results, we confirmed that the proposed in-depth concealed file system can contribute to mitigate the risk of data breaches and destructions on mobile devices.
Yong Jin 0001, Masahiko Tomoishi, Satoshi Matsuura
COMPSAC (1)1
2017 A Secure and Lightweight IoT Device Remote Monitoring and Control Mechanism Using DNS
abstract
Many reports predicted that the number of connected IoT (Internet of Things) devices will reach to billions in the next several years, accordingly, how to securely and effectively manage, monitor and control them becomes a critical problem. In conventional IoT solutions, direct SSL/TLS based HTTP connections to IoT devices with high overhead are required and encryption is not considered due to low computing capability and memory capacity of IoT devices. In this paper, we propose an integrated mechanism using DNS (Domain Name System) to accomplish the objective. In the proposed mechanism, names or IDs of IoT devices are managed by DNS server and the monitoring and control are conducted by the collaboration of DNS name resolution, DNS dynamic update and DNS zone transfer. Considering the security and privacy protection, the status and control command for IoT devices described in the corresponding DNS TXT records will be encrypted and TSIG (Transaction SIGnatures) will be used for authentication to restrict the clients allowed to monitor and control the IoT devices.
Yong Jin 0001, Masahiko Tomoishi, Nariyoshi Yamai
COMPSAC (2)1
2017 Cache Function Activation on a Client Based DNSSEC Validation and Alert System by Multithreading
abstract
Domain Name System (DNS) is one of the most important services of the Internet since most communications normally begin with domain name resolutions provided by DNS. However, DNS has vulnerability against some kind of attacks such as DNS spoofing, DNS cache poisoning, and so on. DNSSEC is an security extension of DNS to provide secure name resolution services by using digital signature based on public key cryptography. However, there are several problems with DNSSEC such as failing resolution in case of validation failure, increasing the load of DNS full resolver, and so on. To mitigate these problems, we proposed a Client Based DNSSEC Validation System. This system performs DNSSEC validation on the client, and in case of validation failure, it forwards the failed response and alerts the user to the fact. However, this system has a problem that it inactivates the cache function of validation library so that it always performs DNSSEC validation even for the same query. In this paper, we report how to solve this problem by multithreading of DNSSEC validation system.
Kunitaka Kakoi, Yong Jin 0001, Nariyoshi Yamai, Naoya Kitagawa, Masahiko Tomoishi
COMPSAC (2)2
2016 Design of a Concealed File System Adapted for Mobile Devices Based on GPS Information
abstract
The Internet Security Threat Report by Symantec announced that the number of data breaches increased 23 percent in 2014 and the causes by theft or loss of devices reached to 21 percent. Carrying mobile devices with business data and private information is indispensable for human's social activities nowadays and unexpected data breach is one of the severe ongoing issues in cyber security. In this paper, we propose a concealed file system adapted for mobile devices based on GPS (Global Positioning System) information which is only mountable in the designated area. Differs from conventional encryption technologies, the proposed file system can be completely isolated from the viruses and attacks outside the designated area. Moreover, instead of the GPS information of the designated area, the encrypted hash value will be stored in mobile devices for the privacy concerns. We statistically analyzed the GPS information logged in our lab and defined an algorithm for deciding the designated area without leaking the GPS information. Based on the algorithm, we evaluated the proposed file system using Veracrypt by adding the hash of GPS information indicating the designated area as one of the attributes for mounting authentication. As a result, we confirmed that the proposed file system was mounted with about 91% success rate within average in the designated area even with noise interference.
Yong Jin 0001, Masahiko Tomoishi, Satoshi Matsuura
COMPSAC1
2016 Enhancement of VPN Authentication Using GPS Information with Geo-Privacy Protection
abstract
VPN (Virtual Private Network) technology is well used for remote access to the internal server in order to mitigate intrusion attacks and data breaches. In the current VPN technologies, PKI (Public Key Infrastructure) based certificate authentication and user ID/Password authentication are well used. However, in case of password leakage and lost of mobile devices, those authentication methods cannot effectively prevent the malicious accesses. In this paper, we propose an enhancement method of VPN authentication using GPS (Global Positioning System) information with geo-privacy protection. In this method, the GPS information of the client is used for VPN authentication without leaking the raw GPS coordinates of the client. Specifically, the hash values of GPS coordinate ranges will be registered on the VPN authentication server in order to protect the user geo-privacy. By using the proposed method, the remote access via VPN tunnel can be controlled within all designated areas so that the risk of intrusion attacks can be mitigated significantly. We achieved the GPS coordinates in our lab for one month and checked their hit rates in the GPS coordinate ranges achieved from the Google Maps. The results showed about 99.29% and 92.96% hit rates in the latitude and longitude respectively which are acceptable for real operation.
Yong Jin 0001, Masahiko Tomoishi, Satoshi Matsuura
ICCCN1
2015 Web server performance enhancement by suppressing network traffic for high performance client
abstract
In a high performance computer network system especially that has high-speed networks, an imbalance problem occurs in terms of that network performance is significantly higher than computer capacity. The problem deteriorates performance of the entire system by ineffectively overloading application servers by few high performance clients. In this paper, we present performance analysis and validation of a web server and confirm the possibility of transparent performance enhancement for a high performance computer network system by only changing the configuration of network facilities such as switches and routers. We constructed a local experimental web system and reproduced several cases in which the problem occurred and confirmed that it is possible to solve the problem by only suppressing network traffic on the communication lines for high performance clients. By practically using the network traffic control method it is expectable to provide best performance of application systems in a high-speed network environment in the future.
Yong Jin 0001, Masahiko Tomoishi
APNOMS1
2015 Secure Glue: A Cache and Zone Transfer Considering Automatic Renumbering
abstract
Domain Name System (DNS) is the most widely used name resolution system for computers and services in the Internet. The number of domain name registrations is reaching 276 million across all top level domains (TLDs) today and the DNS query count is increasing year over year. The main reason of the high DNS query count is the increase of out-of-bailiwick domain name delegation since it (NS without glue A record) makes the client send extra DNS queries for the glue A record. On the other hand, the master/slave model is not compatible with address renumbering in DNS since the master is indicated by its IP address in the slave. Thus it is necessary to redesign the current DNS protocol considering lower name resolution latency as well as the enhancement of automatic convergence after the address renumbering for the effective and sustained name resolution service. In this paper, we propose two mechanisms: one is the secure glue A cache and update to reduce the name resolution latency by cutting the DNS query count with low security risk, the other is the automatic zone transfer which automatically recovers the DNS based on FQDN (Fully Qualified Domain Name) after address renumbering. We successfully implemented the prototype in Linux as an extended form of BIND (Berkeley Internet Name Domain). The evaluation results confirmed approximately 25% down of the DNS query count and the successful automatic DNS recovery after address renumbering.
Yong Jin 0001, Kenji Fujikawa, Hiroaki Harai, Masataka Ohta
COMPSAC1
2015 Design of Detecting Botnet Communication by Monitoring Direct Outbound DNS Queries
abstract
Domain Name System is the most widely used protocol for domain name resolution in the Internet. Domain name resolution is necessary for most of Internet services and it is usually provided by DNS full resolvers. Unfortunately, many reports indicated that DNS protocol was also used in botnet communication recently. Botnet communications between bot-infected computers and Command and Control (C&C) servers are indispensable in botnet attacks and the involved DNS traffic may not use DNS full resolvers. More importantly, due to the popularity of DNS protocol it is difficult to simply block the DNS traffic from internal computers. Several related works have been launched but they only focus on DNS full resolvers. In this paper, we focus on monitoring direct outbound DNS queries and propose a new botnet communication detection method by collecting authoritative NS (Name Server) record and its IP address. We monitored all DNS traffic for about three months in our university and checked the destination IP addresses of direct outbound DNS queries in a third party security site to confirm the effectiveness of the proposed method. The results confirmed that about 19% IP addresses in average have hits per day which indicates that our proposed method is effective and the hit rate is acceptable for detailed investigation in real operation.
Yong Jin 0001, Hikaru Ichise, Katsuyoshi Iida
CSCloud1