VLDB 2026 Research / reviewers in the wild / expert
Atsushi Kanai
dblp:90/5569
· DBLP profile ↗
16ranked-venue papers
0as first author
3since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 2 since 2021Artificial intelligence and machine learning · 5Applied, interdisciplinary, general and emerging computing · 5 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Operation Management Method of Software Defined Perimeter for Promoting Zero-Trust ModelabstractTelework has been on the rise since the advent of COVID-19, and concerns have arisen about issues such as information leakage due to internal fraud. The zero-trust model is attracting attention as a countermeasure. This model reduces risk by constantly performing authentication and authorization, thus leading to improved security levels and safer operation. However, currently less than 40% of the companies in Japan have introduced zero trust into their security policies, mainly due to the lack of specific guidelines for operational management. We have therefore developed a security policy (service authorization conditions) for the software defined perimeter (SDP) zero-trust model as a universal operational management method to promote zero-trust implementation. Specifically, we simplify the time/place/occasion (TPO) conditions of users as T (inside/outside working hours), P (inside/outside the company, telework), and O (with/without visitors), resulting in 12 patterns, and for each of these TPO conditions, we propose detailed new service authorization conditions for SDP. The results of qualitative evaluation demonstrated the effectiveness of the proposed method. Our findings will contribute to the introduction of the zero-trust model and pave the way for safer and more secure corporate networks. Shigeaki Tanimoto, Sogen Hori, Hiroyuki Sato 0002, Atsushi Kanai |
SERA | 4 |
| 2022 | Two-Tier Trust Structure Model for Dynamic Supply Chain Formulation
Shigeaki Tanimoto, Yudai Watanabe, Hiroyuki Sato 0002, Atsushi Kanai |
AINA (3) | 4 |
| 2021 | Utilizing obfuscation information in deep learning-based Android malware detectionabstractWith the large number of Android applications being released, reliable Android malware classifier is required. In recent years, machine learning as well as deep learning have played important roles in Android malware detection, and various static and dynamic features have been extracted and combined with both machine learning algorithms and deep learning algorithms. Studies have shown that these models can detect malware that is not included in the training set, indicating potential abilities to capture zero-day malware samples. However, the use of obfuscation technology, which is originally aimed at optimizing code and protecting intellectual property, has become a kind of threat in this type of detection method because both static features and dynamic features might be influenced by obfuscation, which has a negative impact on efficacy of models based on these features. As a result, the trained models might be overfit. In this work, we propose a deep learning based Android malware detection method that uses obfuscation labels in training to force the deep learning model to learn features of obfuscation technologies and malware simultaneously from part of the input. The experimental results demonstrate that our method achieved 96.2%-99.6% accuracy on different datasets and suppressed overfitting compared to method that doesn’t use obfuscation labels. Junji Wu, Atsushi Kanai |
COMPSAC | 2 |
| 2019 | Communication Robot for Elderly Based on Robotic Process AutomationabstractCurrently, a communication robot like an AI speaker has become popular as one of consumer services. As realized high functions seen in cooperation of network and home appliances by them, hurdles for the elderly in operating such advanced IT devices are still high. On the other hand, RPA (Robotic Process Automation) attracts attention for productivity improvement of business processing. However, there are few examples that applied RPA to consumer services. It is caused that there is not common sense about an application method of RPA for consumer services. Therefore, if we could define the application method of RPA for consumer services, we could develop consumer services familiar with the elderly. This paper gives some examples of our developed consumer services for the elderly by communication robots after summarizing requirements for applying RPA to consumer services. Then, we inspect the effectiveness of the consumer services based on RPA. Finally, we make clear a RPA basic model for consumer services. Toru Kobayashi, Kenichi Arai, Tetsuo Imai, Shigeaki Tanimoto, Hiroyuki Sato 0002, Atsushi Kanai |
COMPSAC (2) | 6 |
| 2018 | Evaluation of the Effectiveness of Risk Assessment and Security Fatigue Visualization Model for Internal E-CrimeabstractAs the Internet has become ever more important infrastructure, the threat of electronic crime (e-crime) has increased. Thus, to counter threats to information security, many information security solutions have been introduced and security policies have been made stricter. However, the excessive strictness of these policies may lower the security consciousness of employees and cause the security policy to become a dead letter. The feeling caused by following such strict information security policies is called security fatigue. Security fatigue is gaining attention as a research issue; for example, a workshop was held at SOUPS, one of Usable Security's top conferences, and a report by NIST researchers was published. To contribute to this research, we have proposed a security condition matrix to visualize how IT users feel security fatigue with respect to security countermeasures. The security condition matrix is a two-dimensional model, with the security fatigue degree on the vertical axis and the security countermeasure implementation degree on the horizontal axis. By using this matrix, it becomes possible to visualize how dangerous a person is in terms of information security and facilitate security countermeasures in accordance with each condition on the matrix. In this paper, we evaluated the effectiveness of the proposed security fatigue model for internal e-crime. Takashi Hatashima, Keita Nagai, Asami Kishi, Hikaru Uekusa, Shigeaki Tanimoto, Atsushi Kanai, Hitoshi Fuji, Kazuhiko Ohkubo |
COMPSAC (2) | 6 |
| 2016 | Risk assessment quantification of social-media utilization in enterpriseabstractThe purpose of this study is to make social media utilization by enterprises safer, more secure, and more convenient. Enterprises use social media for marketing, but this presents a lot of risks. These risks were comprehensively extracted in our previous study, but it was only a qualitative study, so a quantitative evaluation is needed to make the risks' countermeasures more practical. Thus, in this paper, the risk factors identified in the previous study are analyzed and quantitatively evaluated. Specifically, the values of the risk factors were approximately calculated by using a risk formula used in the field of information security management systems (ISMS). In this way, it was found that the countermeasures in the previous study could reduce their corresponding risk factors by about 60%. The results herein can contribute to helping enterprises to utilize social media more safely, securely, and conveniently in the future. Shigeaki Tanimoto, Motoi Iwashita, Yoshiaki Seki, Hiroyuki Sato 0002, Atsushi Kanai |
ICIS | 5 |
| 2015 | An Approach to Selecting Cloud Services for Data Storage in Heterogneous-Multicloud Environment with High Availability and ConfidentialityabstractCloud services are becoming more popular and as their price has been decreasing, the opportunity to use them has been increasing. However, it has become difficult to select optimal cloud services from many services. This paper proposes an approach to dynamically selecting optimal cloud services to store data in heterogeneous-multi-cloud environments, which we evaluated by using a secret sharing scheme. The results indicated that it is possible to select the best services from the proposed model in heterogeneous multi-cloud environments. Yuuki Kajiura, Shohei Ueno, Atsushi Kanai, Shigeaki Tanimoto, Hiroyuki Sato 0002 |
ISADS | 3 |
| 2015 | Improvement of multiple CP/CPS based on level of assurance for campus PKI deploymentabstractThe ICT environment has been rapidly developed by ubiquitization, and cloud computing and has become far more convenient to use. On the other hand, the negative side also exists, such as threats of viruses and unlawful access, in which the use of the safe and secure ICT environment is threatened. Public key infrastructure (PKI) construction is desired to achieve the safe and secure use of the ICT environment at universities. However, PKI has not been widely constructed in universities because of its cost. A previous study proposed multiple policies for core PKI operation. However, a dynamic evaluation that considers actual operation is not sufficient. In this paper, first, as a result of reexamining the conventional multiple-policy proposal in detail, an improvement plan is proposed from a viewpoint of the ease of introduction. Next, in addition to the conventional evaluation, dynamic evaluation based on real operation is performed, and effectiveness of the improvement plan is clarified. Shigeaki Tanimoto, Toshihiko Moriya, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 4 |
| 2015 | Risk assessment of social-media utilization in an enterpriseabstractThe purpose of this study contributes to safe improvement in consideration of security in addition to convenience by the social media utilization in the company. The company uses the marketing using social media, but a lot of risks exist. We contribute to safe improvement by performing an example investigation in this study, and doing risk assessment. In this study, in order to extract a risk event, the RBS method was used. And we divided it into next four risk classifications by risk matrix method, "Risk Mitigation", "Risk Avoidance", "Risk Transference", and "Risk Acceptance". As a result, it became clear that it was necessary for the company to take risk measures mainly on "recognition of cost effectiveness", "the countermeasure against blog flaming", and "information leakage measure of employee". It is necessary for the company to take these risks measures from this result with precedence. Based on this, it is believed that the company can utilize social media effectively if the company follows these measures. Shigeaki Tanimoto, Kenichi Ohata, Shoichi Yoneda, Motoi Iwashita, Hiroyuki Sato 0002, Yoshiaki Seki, Atsushi Kanai |
SNPD | 7 |
| 2014 | Risk assessment quantification in life log serviceabstractA Life Log Service that handles action records, such as an individual search logs and data on shoppers' browsing and buying habits, have attracted attention with the spread of the Internet. Life Log Service is thought to present various risks to private information, such as personal information. For this reason, countermeasures to these risks need to be investigated. We have already qualitatively analyzed the risks of life log services. To extract the specific risks of using a life log service comprehensively, we used a Risk Breakdown Structure (RBS), which is the typical risk-analysis method. Furthermore, after risks were analyzed, concrete countermeasures were proposed. However, these results need to be quantitatively evaluated from a more practical viewpoint. In this paper, the validity is visualized by performing quantitive risk assessment on the proposed countermeasures for risks in the life log obtained in our previous research. Specifically, the risk value based on a risk formula is computed to a risk factor and its proposed countermeasures. Thereby, the effects of the proposed countermeasures on risks of the life log service found in previous research are evaluated quantitatively, and this will contribute to spreading and promoting the life log service. Shigeaki Tanimoto, Ken Takahashi, Taro Yabuki, Kazuhiko Kato, Motoi Iwashita, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 7 |
| 2013 | A Study of Data Management in Hybrid Cloud ConfigurationabstractCloud computing is currently spreading with the further implementation of IT infrastructure. Clouds involve certain negative factors, however, which must be addressed to promote further cloud utilization. As a means of addressing some of these negative factors, a hybrid cloud configuration combining public and private clouds has attracted attention. This configuration stores personal and confidential information in a private cloud and other data in a public cloud. Unfortunately, no detailed classification of where various kinds of data should be stored has yet been fully established. Hence, this paper proposes an enterprise data management method for a hybrid cloud configuration. Specifically, enterprise data was subdivided into 28 categories through a work breakdown structure (WBS) method. Then, the subdivided data was classified in terms of whether it did or did not consist of personal or confidential information. The resulting data portfolio required storing only about 18% of data in a private cloud, with the remaining 82% in a public cloud. In accordance with this basic guideline, a fundamental data management proposal is developed for the hybrid cloud configuration. Shigeaki Tanimoto, Yorihiro Sakurada, Yosiaki Seki, Motoi Iwashita, Shinsuke Matsui, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 7 |
| 2012 | Risk Management to User Perception of Insecurity in Ambient ServiceabstractIn recent years, Ambient service has attracted attention as a ubiquitous, future intelligence infrastructure. The Ambient service provides service suitable for user needs automatically by making a sensor and a computer cooperate, and gathering and analyzing the information about each user. However, with the Ambient service, in order to manage personal information, various risks, such as an information leakage, are assumed. In this research, about a risk of being assumed with the Ambient service, it analyzes from a viewpoint by the side of service provision and service use, and clarifies the proposed measures. Specifically, risk breakdown structure and the risk matrix which are the typical risk management methods of project management were used. These results extracted 40 factors as a risk factor of the Ambient service. As the main feature of countermeasure, for Risk Transference, a countermeasure, such as preparing a third party's inspection on the service provision side, was proposed. Moreover, for Risk Mitigation, a countermeasure, such as a rule for a new specification corresponding to the Ambient service, was proposed. As mentioned above, the risk management of the Ambient service was proposed in this paper. A future subject is evaluating the effectiveness of the proposed countermeasure. Shigeaki Tanimoto, Daisuke Sakurai, Yosiaki Seki, Motoi Iwashita, Hiroyuki Sato 0002, Atsushi Kanai |
SNPD | 6 |
| 2011 | Building a Security Aware Cloud by Extending Internal Control to CloudabstractFaced with today's innovative blow-up of cloud technologies, we are forced to rebuild services in terms of cloud. In the rebuilding, considering a facet of cloud as social infrastructure, security is a critical problem. Most of insecurity against clouds can be summarized as insecurity of management, which is classified into the multiple stakeholder problem, and the open space security problem. As a solution to these problems, we extend ISMS internal control to cloud by implementing trust base of security on IAM and key management. Because ISMS internal control is a source of trust, its extension to cloud can be an essential solution of security. Moreover, by controlling levels of quality of service and security by contract, we can optimize cost on service and security delegated to a cloud. Hiroyuki Sato 0002, Atsushi Kanai, Shigeaki Tanimoto |
ISADS | 2 |
| 2010 | The Metric Model for Personal Information DisclosureabstractIn recent years, the protection of personal information has become a matter of growing importance, and many enterprises and universities are developing disclosure-prevention technologies, as well as solutions to prevent inadvertent disclosure of personal information by organizations. On the other hand, in the case of the so called Consumer Generated Media such as blogs and Social Networking Services, the majority of authors (i.e. bloggers) pay little attention to protecting their personal information and carelessly disclose such data on their blog pages. In this paper, we present a novel metric model for estimating the state of personal information disclosure that assumes a Privacy Search Oracle, and describe a quantification method for the degree of personal information disclosure. We also evaluate the proposed model using actual blog articles and show how the degree of personal information disclosure can be reasonably estimated by our model. Ryosuke Yasui, Atsushi Kanai, Takashi Hatashima, Keiichi Hirota |
ICDS | 2 |
| 2001 | Scenario-Based Service Composition Method in the Open Service EnvironmentabstractSince most services on the Internet are mutually independent, users have trouble accessing several services to achieve a single purpose. For example, if a user wants to travel to Paris and Berlin, he/she has to access several hotel reservation services and airline reservation services. Solving this problem requires service composition technology, which constructs a composite service called a one-stop service by combining several independent services. Essential for service composition are one-stop service provisioning and collaboration technologies. One-stop service provisioning technology identifies services on the net that satisfy a user's needs and combines those independent services into a single service, and collaboration technology controls the one-stop service flow. We propose a scenario based service composition method to achieve one-stop services on the Internet using distributed object oriented technology and workflow technology. Kazuhiro Kiwata, Atsushi Nakano, Shunsuke Yura, Tomotaka Uchihashi, Atsushi Kanai |
ISADS | 5 |
| 2001 | Service Matching and Collaboration for Electronic CommerceabstractWe propose a software architecture for one-stop services of electronic commerce (EC). Users currently have trouble using multiple EC services because they are provided independently. Therefore a mediator that combines EC services and provides one-stop services to users would be useful. Service matching and service collaboration are important issues in the mediator because they are the main difficulties for users. The proposed architecture provides solutions to these issues. Multiple service assignment provides suitable combinations of EC services, flow division enables efficient execution of the combined EC services, and dynamic alternative service assignment enables flexible failure avoidance during the execution of combined services. These features make the proposed architecture a suitable mediator for EC services. Shunsuke Yura, Kazuhiro Kiwata, Atsushi Nakano, Tomotaka Uchihashi, Atsushi Kanai |
ISADS | 5 |