VLDB 2026 Research / reviewers in the wild / expert
Hiroki Takakura
dblp:99/4054
· DBLP profile ↗
36ranked-venue papers
3as first author
14since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 13 · 3 since 2021Software engineering, systems software and programming languages · 12 · 3 since 2021Computer networks · 9 · 8 since 2021Security and privacy · 7 · 3 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-authorArtificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lightweight and Stateless PUF-based Authentication Key Exchange Protocol for IoT Devices
Koki Mizoguchi, Rizka Reza Pahlevi, Hajime Shimada, Hirokazu Hasegawa, Hiroki Takakura |
COMPSAC | 5 |
| 2026 | Cybersecurity Exercise Generation System Using LLMs with Real Attack Datasets
Hirokazu Hasegawa, Hiroki Takakura |
ICISSP (1) | 2 |
| 2025 | Sleeping Multi-Armed Bandit-Based Path Selection in Space-Ground Semantic Communication NetworksabstractSemantic communication, an emerging AI-driven communication paradigm, offers great potential for multimodal data delivery in space-ground integrated networks (SGINs). However, the dynamic nature of SGINs presents severe challenges for path selection, making it difficult to ensure the quality of service (QoS) at the semantic level. To this end, we propose in this paper a novel path selection scheme in space-ground multimodal semantic communication networks based on the sleeping multi-armed bandit (MAB) approach. Specifically, we first model the approximate semantic entropy and semantic rate, formulating an optimal path selection problem that integrates link state information and semantic data transmission volume. Then, we convert the path selection problem into a sleeping MAB problem and meticulously design an upper confidence bound (UCB)-based algorithm to solve it, called Periodic Probability Sleeping Path Selection (PPSPS), which copes with the dynamic feature of SGINs. We further theoretically verify the bounded regret of the PPSPS algorithm, indicating that it can ensure good semantic communication QoS. Simulation results demonstrate the superiority of the proposed path selection scheme compared to traditional reinforcement learning methods. Hanlu Wu, Yang Xu 0012, Shouxin Cao, Jia Liu 0009, Hiroki Takakura, Norio Shiratori |
WCNC | 5 |
| 2024 | Multi-Armed Bandit-Based Secure Routing in Air-Ground Integrated NetworksabstractAir-ground integrated networks (AGINs) are promising to provide wide-coverage, high-capacity, and low-latency communication services, and thus have been attracting increasing attention from industry and academia recently. However, the open and dynamic nature of AGINs makes them vulnerable to eavesdropping attacks, posing a major challenge in ensuring end-to-end information transmission security. To this end, we propose in this paper a secure routing scheme in AGINs based on the multi-armed bandit (MAB) approach. Specifically, we first model the secrecy transmission performance for the ground-to-ground links and ground-to-air links. Based on this, we then formulate the end-to-end secure route selection problem and convert it into a budget-constrained MAB problem, where each arm is associated with a corresponding reward and cost. We further design a Secure Route Upper Confidence Bound (SRUCB) algorithm to solve the MAB problem, which copes with the scenario where the locations of eavesdroppers and jammers are unknown, and can be proven to have a bounded regret. Numerical results demonstrate the superiority of the proposed routing scheme compared to several online learning algorithms. Yang Xu 0012, Jia Liu 0009, Hiroki Takakura, Xiaoying Liu 0001, Kechen Zheng, Norio Shiratori |
WCNC | 4 |
| 2023 | Security Operation Support by Estimating Cyber Attacks Without Traffic DecryptionabstractThe use of encrypted communications has become common and now majority on Internet traffic. Taking advantage of this trend, attackers also use encrypted communications for cyber attacks. In addition, the shift to cloud environments is in progress, and the effectiveness of measures of traffic analysis with decryption and re-encryption is becoming less and less. Installing software to monitor decrypted traffic on endpoints is also very costly. Therefore, many organizations require a method to narrow down the number of encrypted traffic candidates in a monitoring operation to a number that analysts can investigate to see if it is an attack without decryption. In this paper, we propose a method to estimate cyber attacks without traffic decryption to support the monitoring operation of encrypted traffic. The proposed method consists of a following two-step process where session information of encrypted traffic is used for the estimation: 1. A method to narrow down to encrypted traffic that behaves similarly to attacks from a large number of encrypted traffic. 2. A method to determine whether the narrowed-down encrypted traffic requires further investigation by analysts. By extracting and analyzing 17 million encrypted traffic from a 40 Gbps network, narrowed down to 194 encrypted traffic that can be analyzed in detail in the human operation. Additionally, 49 of those encrypted traffic were determined to be threats and 72 of those were determined to be scans by the detailed analysis. Shohei Hiruta, Itaru Hosomi, Hirokazu Hasegawa, Hiroki Takakura |
COMPSAC | 4 |
| 2023 | Bandwidth Allocation for Low-Latency Wireless Federated Learning: An Evolutionary Game ApproachabstractAs a new distributed data training framework, federated learning (FL) has attracted increasing attention owing to its advantages of preserving data privacy and low communication cost. However, in a wireless FL network, due to the limited bandwidth resources, when a large number of clients participate in FL, the communication burden is too heavy. Therefore, efficient bandwidth allocation is critical to facilitate the application of wireless FL. In this paper, we investigate bandwidth allocation in wireless FL networks with the objective of minimizing the latency of FL services. We first analyze and formulate the latency minimization problem. Then, considering that the computing and transmitting capabilities of each client cannot be completely and truly acquired, we develop an evolutionary game (EG) framework to model the dynamic process of bandwidth allocation in wireless FL. We further show the optimal bandwidth allocation solution is equivalent to the evolutionary equilibrium (EE) obtained by the replicator dynamics in the EG model, and prove the EE is asymptotically stable. With the help of these results, we propose the EG-based bandwidth allocation algorithm, which enables the latency of FL services to be reduced by performing the replicator dynamics iteratively. Numerical simulations are provided to demonstrate the evolutionary behaviors in the EG-based bandwidth allocation Algorithm. Yang Xu 0012, Jia Liu 0009, Hiroki Takakura, Norio Shiratori |
ICC | 4 |
| 2023 | Double-Sided Auction based Data-Energy Trading Architecture in Internet of VehiclesabstractIn the era of big data, the unprecedented growth of data has spawned the commercial application of data trading markets in the Internet of Vehicles (IoV), while also posing challenges to their economic feasibility. In this paper, we propose a data-energy trading architecture in IoV consisting of a market operator, electric vehicles (EVs), and roadside units (RSUs), where RSUs exchange energy for data collected by EVs, and the market operator solves the data/energy allocation problem to maximize social welfare. However, due to the information asymmetry and fragmentation in the market, it is difficult to determine the optimal data and energy trading amount. To this end, we design an iterative double-sided auction (IDA) mechanism to regulate the interactive behaviors among the trading entities, where the market operator gathers local information from RSUs and EVs, and gradually adjusts the submitted bids of two sides to reach the desired payment and reward rules. The proposed IDA-based data-energy trading algorithm is convergent and satisfies the economic properties of efficiency, incentive compatibility, individual rationality, and budget balance. Numerical results demonstrate the performance of the proposed IDA-based data-energy trading architecture in IoV. Honggang He, Yang Xu 0012, Jia Liu 0009, Hiroki Takakura, Zhao Li 0005, Norio Shiratori |
WCNC | 4 |
| 2022 | Incentive Routing Design for Covert Communication in Multi-hop Decentralized Wireless NetworksabstractIn this paper, we focus on a multi-hop decentralized wireless network consisting of legitimate nodes, adversary wardens, and friendly but selfish jammers, and investigate the routing design for achieving covert communication. For a pair of source and destination nodes, we first provide theoretical analysis for a given route between them to reveal how the covertness performance is related to the jamming power of jammers in the network. Then, we design an incentive mechanism that stimulates selfish jammers to supply artificial jamming to protect communication covertness, by granting them rewards from the source. A two-stage Stackelberg game framework is developed to analyze the strategic interactions between the source and jammers, and so as to determine the optimal settings of rewards and jamming power. Based on these results, we formulate a shortest weighted path-finding problem to identify the optimal route for covert communication between the source and destination, which can be solved efficiently by employing Dijkstra's algorithm. Simulation results demonstrate the performance of the proposed incentive routing scheme. Meng Xie, Jia Liu 0009, Hiroki Takakura, Yang Xu 0012, Zhao Li 0005, Norio Shiratori |
GLOBECOM | 3 |
| 2022 | Stackelberg Game-based Secure Communication in SWIPT-enabled Relaying SystemsabstractThis paper investigates secure communication in a two-hop relaying system based on physical layer security. The relay employs time-switching simultaneous wireless information and power transfer (SWIPT) to harvest energy and receive information from the source, and then transmits the source’s information and its own information to the destination. A passive eavesdropper exists and wiretaps information transmission over both hops. Under the general system configuration, we first provide performance modeling to reveal the secrecy rate of source and relay as well as identify their utilities. Then, we analyze the hierarchical competition behaviors between the source and relay from a game-theoretic perspective. In particular, we develop a Stackelberg game-based analytical framework to determine the optimal strategies for the source and relay by deriving the Stackelberg equilibrium. Furthermore, we summarize the feasible conditions of utilizing SWIPT-enabled relaying for secure communication and propose the end-to-end transmission scheme accordingly. Extensive numerical results are presented to demonstrate the performance of the proposed SWIPT-enabled relaying system. Yang Xu 0012, Jia Liu 0009, Hiroki Takakura, Zhao Li 0005, Yusheng Ji, Norio Shiratori |
ICC | 3 |
| 2022 | Cyber Attack Stage Tracing System based on Attack Scenario Comparison
Masahito Kumazaki, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura |
ICISSP | 5 |
| 2022 | Buffer Space Management in Intermittently Connected Internet of Things: Sharing or Allocation?abstractThe efficient buffer space management in intermittently connected Internet of Things (IC-IoT) is of great importance for data delivery performance guarantee in such networks. This article considers two typical buffer space management policies for IC-IoT, i.e., buffer-space sharing (BS) and buffer-space allocation (BA). The BS policy allows the buffer space of each device to be fully shared by the exogenous packets and the packets from other devices, while the BA policy divides the buffer space into the source buffer and relay buffer for storing the two kinds of packets separately. With the help of the queueing theory and Markov chain theory, we develop a theoretical framework to capture the sophisticated queueing processes for the buffer space under either BS or BA policy, which enables the limiting distribution of the buffer occupation state to be determined. We then provide theoretical modeling for throughput and expected end-to-end delay to evaluate the fundamental performance of the IC-IoT under the BS and BA policies. Finally, extensive simulation and numerical results are presented to validate theoretical models and to demonstrate the effects of BS and BA policies on the IC-IoT performance. Jia Liu 0009, Yang Xu 0012, Yulong Shen 0001, Hiroki Takakura, Xiaohong Jiang 0001, Tarik Taleb |
IEEE Internet Things J. | 4 |
| 2021 | An Evaluation of Stochastic Quantitative Resilience Index Based on SLAs of Communication LinesabstractA wide-area distributed application is affected by network failure due to natural disasters because the servers on which the application operates are distributed geographically in a wide area. Failure Injection Testing (FIT) is a method for verifying fault tolerance of widely distributed applications. In this paper, by limiting network failures only to the connection line, whole FIT scenarios are generated, and exhaustive evaluation of fault tolerance is performed. The authors propose a method to evaluate the resilience quantitatively by specifications of the distributed application and their service level agreements (SLAs) that consist of the distributed network. The authors compare the resilience of several distributed applications in several topologies and show returns of investigation (ROI) in each application and topology. Hiroki Kashiwazaki, Hiroki Takakura, Shinji Shimojo |
COMPSAC | 2 |
| 2021 | On Strategic Interactions in Blockchain Markets: A Three-stage Stackelberg Game ApproachabstractBlockchain technology is a promising approach for solving the security and personal privacy problems in Internet applications. The successful commercial deployment of Blockchain markets relies on a comprehensive understanding of the economic and strategic interactions among different entities involved. In this paper, we focus on a blockchain market consisting of a blockchain platform (BP), multiple miners, and blockchain users (BUs), and formulate their interactions as a three-stage Stackelberg game. In Stage I, the BP strategizes the rewards granted to the miners, so as to attract the miners to contribute more computing power used for improving the security and privacy of the blockchain. In Stage II, each miner strategizes its computing power individually for winning the mining compe-tition, which is modeled as a non-cooperative game. In Stage III, the BUs strategize the transaction fee to acquire a corresponding service experience. With the objective of utility maximization, we develop a theoretical framework to analyze the hierarchical interactive behaviors among the entities in a backward inductive way. By solving the Stackelberg equilibrium, we determine the optimal strategies of entities in closed-form. Numerical results are provided to demonstrate the performance of the strategic interactions in the blockchain market. Jianbo Shao, Yang Xu 0012, Jia Liu 0009, Hiroki Takakura, Zhao Li 0005, Xuewen Dong |
GLOBECOM | 4 |
| 2021 | A Dynamic Access Control System based on Situations of UsersabstractRecently, cyber attacks have been sophisticated and cause serious damages. As one of the solutions for mitigating the damages, the network separation and fine granularity of access controls are effective against attacks. However, the COVID-19 changes human work style, and telecommuting comes to be generally. It may give many chances to attackers for invading the organization's internal network by infecting user's vulnerable home terminals, which are out of control by the organization. To ensure the security of organizations, we propose a dynamic access control system based on the situations of users. The system evaluates communications based on the user's risk and the importance of resources in destination terminals. When a user connects to the organization network from the outside, the system dynamically changes the access controls according to the evaluation results. The such situation requires stricter access controls than usual ones. For example, the communication by the high-risk user and the communication to servers storing important resources are restricted. By applying such dynamic access controls, the system enables us to ensure our network security with maintaining the convenience of users telecommuting. Hirokazu Hasegawa, Hiroki Takakura |
ICISSP | 2 |
| 2020 | A Quantitative Evaluation of a Wide-Area Distributed System with SDN-FITabstractA wide-area distributed application is affected by network failure due to natural disasters because the servers on which the application operates are distributed geographically in a wide area. Failure Injection Testing (FIT) is a method for verifying fault tolerance of widely distributed applications. In this paper, by limiting network failures only to the connection line, whole FIT scenarios are generated, and exhaustive evaluation of fault tolerance is performed. The authors propose a method to omit the evaluations from the aspect of topological constraint conditions. And they evaluate the visualization method of performance data obtained from this evaluation and the reduction of the fault tolerance evaluation cost by the proposed method. Hiroki Kashiwazaki, Hiroki Takakura, Shinji Shimojo |
COMPSAC | 2 |
| 2019 | Detecting Successful Attacks from IDS Alerts Based On Emulation of Remote ShellcodesabstractServer administrators and security operation center analysts receive alerts from an intrusion detection system and check whether attacks have succeeded. However, it is difficult to handle them quickly because a tremendous number of alerts is generated in a short period of time. We propose a method to identify important alerts that lead to security incidents automatically. The key idea is to determine the success or failure of an attack based on traffic logs and the network behaviors observed during shellcode emulation. We evaluated the proposed method in terms of accuracy and performance and found that it can handle more than 60% of remote shellcodes and cope with practical attack cases. Yo Kanemoto, Kazufumi Aoki, Makoto Iwamura, Jun Miyoshi, Daisuke Kotani, Hiroki Takakura, Yasuo Okabe |
COMPSAC (2) | 6 |
| 2019 | Construction of Secure Internal Networks with Communication Classifying System
Yuya Sato, Hirokazu Hasegawa, Hiroki Takakura |
ICISSP | 3 |
| 2019 | Resilient Mechanisms for Reliable Digital Health ServicesabstractSummary form only given. The complete presentation was not made available for publication as part of the conference proceedings. cyberattacks on specific personal’s services can be possible and might lead to medical malpractice. Therefore, it is necessary to understand the balance between their merits and risks of custom-made services and to take some measures to avoid the risks. An attacker who tries to falsify the health data of a specific person is required to keep consistency among all data, because we can expect the correlation among data from services used by the person and similarity among data of all users of each service. Such manipulation is almost impossible, so that we can be aware of the sign of cyberattacks by detecting inconsistency among the data and eliminate negative effect by falsified data. Such concepts of bird's-eye view detection are generally deployed as the safety mechanisms of operational technologies, like plant control, but we should take care of unique aspect of the health services. Therefore, we need to develop cyberattack detection scheme under these conditions. It is also expected that the scheme solves the reliability issues of digital health services, because malfunction of one service/sensor can be detected and its negative effect can be mitigated. Furthermore, we can design the combination of health services which can compensate missing data. Hiroki Takakura |
SERVICES | 1 |
| 2018 | Message from the Fast Abstract Co-chairsabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Hossain Shahriar, Hiroki Takakura, Michiharu Takemoto, Dave Towey |
COMPSAC (1) | 2 |
| 2017 | SINET5: A low-latency and high-bandwidth backbone network for SDN/NFV EraabstractSINET5 is a new 100-Gbps-based academic backbone network, which started full-scale operations in April 2016. It uses multi-protocol label switching-transport profile (MPLS-TP) systems and reconfigurable optical add-drop multiplexers (ROADMs) to create a nationwide network and has more than 50 backbone IP routers to provide a wide range of services, such as several virtual private network (VPN) services. It provides end-to-end data communications up to 100 Gbps throughput, minimized-latency, and software-defined networking (SDN)-friendly functions to researchers in every Japanese prefecture. SINET5 is also a platform for dynamic inter-cloud connections and network functions visualization (NFV) services. This paper brief review of the network architecture, and describes new featured services, SDN-oriented layer-2 on-demand VPN services, and NFV functions. Field test results for SINET5 performance are also reported. Takashi Kurimoto, Shigeo Urushidani, Kenjiro Yamanaka, Motonori Nakamura, Shunji Abe, Kensuke Fukuda, Michihiro Koibuchi, Hiroki Takakura, Shigeki Yamada, Yusheng Ji |
ICC | 9 |
| 2016 | Evaluation on Malware Classification by Session Sequence of Common Protocols
Shohei Hiruta, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura, Takeshi Yagi, Mitsuaki Akiyama |
CANS | 4 |
| 2016 | Message from the SEPT Organizing CommitteeabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Bhavani Thuraisingham, Dianxiang Xu, Hiroki Takakura, Mohammad Zulkernine, Elisa Bertino |
COMPSAC | 3 |
| 2015 | Message from SEPT Symposium Organizing CommitteeabstractPresents a listing of the Symposium organizing committee. Bhavani Thuraisingham, Dianxiang Xu, Hiroki Takakura, Mohammad Zulkernine, Elisa Bertino |
COMPSAC | 3 |
| 2015 | Detecting Malicious Inputs of Web Application Parameters Using Character Class SequencesabstractWeb attacks that exploit vulnerabilities of web applications are still major problems. The number of attacks that maliciously manipulate parameters of web applications such as SQL injections and command injections is increasing nowadays. Anomaly detection is effective for detecting these attacks, particularly in the case of unknown attacks. However, existing anomaly detection methods often raise false alarms with normal requests whose parameters differ slightly from those of learning data because they perform strict feature matching between characters appeared as parameter values and those of normal profiles. We propose a novel anomaly detection method using the abstract structure of parameter values as features of normal profiles in this paper. The results of experiments show that our approach reduced the false positive rate more than existing methods with a comparable detection rate. Hiroshi Asakura, Hiroki Takakura, Yoshihito Oshima |
COMPSAC | 3 |
| 2015 | Malware Classification Method Based on Sequence of Traffic FlowabstractNetwork-based malware classification plays an important role in improving system security than system-based malware classification. The vast majority of malware needs a network activity in order to accomplish its purpose (e.g., downloading malware, connecting to a C&C server, etc.). Many malware classification approaches based on network behavior have thus been proposed. Nevertheless, they merely rely on either a request URL or payload for signature matching. To classify the network activity of malware, the patterns of network behavior must be understood and the changes in behavior observed. Therefore, the sequence of flows and their correlation caused by the malware should be analysed. In this paper, we present a novel malware classification method based on clustering of flow features and sequence alignment algorithms for computing sequence similarity, which represents network behavior of malware. We focus on analysing the sequence similarity between the sequence patterns of malware traffic flow generated by executing malware on the dynamic analysing system. We also performed an evaluation by using malware traffic collected from a real environment. On the basis of our experimental results, we identified the most appropriate method for classifying malware by similarity of network activity. Hyoyoung Lim, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura |
ICISSP | 4 |
| 2014 | A Countermeasure Recommendation System against Targeted Attacks with Preserving Continuity of Internal NetworksabstractRecently, the sophistication of targeted cyber attacks makes conventional countermeasures useless to defend our network. Proper network design, i.e., Moderate segmentation and adequate access control, is one of the most effective countermeasures to prevent stealth activities of the attacks inside the network. By paying attention to the violation of the control, we can be aware of the existence of the attacks. In case that suspicious activities are found, we should adopt more strict design for further analysis and mitigation of damage. However, an organization must assume that its network administrators have full knowledge of its business and enough information of its network structure for selecting the most suitable design. This paper discusses a recommendation system to enhance the ability of a semi-automatic network design system previously proposed by us. Our new system evaluates on the viewpoint of two criteria, the effectiveness against malicious activities and the impact on business. The former takes the infection probability and hazardousness of communication into account and the latter considers the impact of the countermeasure which affects the organization's activities. By reviewing the candidate of the countermeasures with these criteria, the most suitable one to the organization can be selected. Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura |
COMPSAC | 4 |
| 2014 | Development of a Secure Traffic Analysis System to Trace Malicious Activities on Internal NetworksabstractIn contrast to conventional cyber attacks such as mass infection malware, targeted attacks take a long time to complete their mission. By using a dedicated malware for evading detection at the initial attack, an attacker quietly succeeds in setting up a front-line base in the target organization. Communication between the attacker and the base adopts popular protocols to hide its existence. Because conventional countermeasures deployed on the boundary between the Internet and the internal network will not work adequately, monitoring on the internal network becomes indispensable. In this paper, we propose an integrated sandbox system that deploys a secure and transparent proxy to analyze internal malicious network traffic. The adoption of software defined networking technology makes it possible to redirect any internal traffic from/to a suspicious host to the system for an examination of its insidiousness. When our system finds malicious activity, the traffic is blocked. If the malicious traffic is regarded as mandatory, e.g., For controlled delivery, the system works as a transparent proxy to bypass it. For benign traffic, the system works as a transparent proxy, as well. If binary programs are found in traffic, they are automatically extracted and submitted to a malware analysis module of the sandbox. In this way, we can safely identify the intention of the attackers without making them aware of our surveillance. Soshi Hirono, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura |
COMPSAC | 4 |
| 2014 | Unknown Attack Detection by Multistage One-Class SVM Focusing on Communication Interval
Shohei Araki, Yukiko Yamaguchi, Hajime Shimada, Hiroki Takakura |
ICONIP (3) | 4 |
| 2014 | Estimation of cause of ice jam flooding in sub-arctic regions using PALSAR full polarimetry dataabstractPALSAR full polarimetry data were used to detect thaw/freeze conditions on the ground to try to determine the cause of a spring flood on a northern river in Russia. Full polarimetric data was used to identify the forest area, and the radar backscattering coefficient, σ0HV, was examined. The σ0HV over a frozen forest area was -19.9 dB, while that of a thawing forest area was -11.9 dB, and freeze/thaw events over the forest area were well represented by this parameter. Using this characteristic, together with optical sensor (AVNIR-2) data and microwave radiometer (AMSR-E) data, freeze/thaw conditions were examined for an area including Markha, where a large ice jam flood occurred in 2007, and compared it to 2009, when no flooding occurred. The results indicate that the thawing event proceeded more rapidly between March 29 and April 10, 2007 for the forest, and this rapid thawing may be one of the possible causes for the large ice jam flood in Markha in 2007. Manabu Watanabe, Hiroki Takakura, Chinatsu Yonezawa, Yasuhiro Yoshikawa, Masanobu Shimada |
IGARSS | 2 |
| 2013 | ARIGUMA Code Analyzer: Efficient Variant Detection by Identifying Common Instruction Sequences in Malware FamiliesabstractIt is required in the first step of malware analysis to determine whether a given malware program is a variant of known ones. If it is surely not a variant, manual analysis against it is required. However, it is impossible to perform manual analysis, the cost of which is very high, over all the enormous number of newly found malware programs. An automatic and accurate malware program classification method should contribute to this situation. Existing methods suffer from such problems as the cost of calculating similarity between every pair of malware programs in a database, and the disability to precisely present the similarity and the difference between programs. In our approach, known malware programs are classified into families. A given malware program is determined to be a variant if it is classified into an existing family. Incremental clustering is then performed for the new one and the family, which reduces the cost of re-training and similarity calculation. Accurate comparison between programs is enabled by evaluating the difference between programs using the longest common subsequences (LCSs) of instructions. To reduce the amount of the costly calculation of LCSs, the numeric features of codes, such as cyclomatic complexity, the number of function calls and so on, are used to filter out dissimilar codes. Subsequences in the LCS of two codes are presented to malware analysts as the similarity between them, while those out of it are given as the difference. Experimental results show that this method can detect the name of APIs used in a malware which existing methods cannot, that it is useful to determine inserted codes which is used for generating variants to avoid pattern detection by anti-virus, and that it actually reduces the time to process malware programs without deteriorating the accuracy of classification. Hirofumi Yamaki, Yukiko Yamaguchi, Hiroki Takakura |
COMPSAC | 4 |
| 2013 | Toward a more practical unsupervised anomaly detection system
Hiroki Takakura, Yasuo Okabe, Koji Nakao |
Inf. Sci. | 2 |
| 2011 | A grid-based clustering for low-overhead anomaly intrusion detectionabstractTo defend a network system from security risks, intrusion detection systems (IDSs) have been playing an important role in recent years. There are two types of detection algorithms of IDSs: misuse detection and anomaly detection. Because misuse detection is based on a signature which is created from the features of attack traffic by security experts, it can achieve accurate and stable detection. However, its weakness is the difficulty of detecting new attacks (i.e., 0-day attack), and the cost of maintaining the latest signature version. Thinking of the increase of the skillful intrusion, e.g., intrusion showing similar access behavior to normal, misuse detection cannot handle these critical attacks, which results in a large number of false alarms. To cope with these problems, we present a clustering algorithm based on an unsupervised anomaly detection. We evaluated our system using Kyoto2006+ data set and KDD Cup 1999 data set. Evaluation results show that our approach achieved a higher detection rate in the region of very low false positive rate and real-time preprocessing capability. Hirofumi Yamaki, Hiroki Takakura |
NSS | 3 |
| 2007 | A Robust Feature Normalization Scheme and an Optimized Clustering Method for Anomaly-Based Intrusion Detection System
Hiroki Takakura, Yasuo Okabe, Yongjin Kwon |
DASFAA | 2 |
| 1993 | A Design of a Transparent Backup System Using a Main Memory Database
Hiroki Takakura, Yahiko Kambayashi |
DASFAA | 1 |
| 1993 | Continuous Backup Systems Utilizing Flash MemoryabstractA continuous-backup mechanism for main-memory databases that transmits data to archive storage during utilization of main memory without any software assistance is described. It is suggested that flash memory-based storage can improve the efficiency of conventional disk systems since it can realize faster read and write operations. As sequential access is performed by a series of direct accesses, the overhead caused by scheduling to utilize sequential access is not required. One serious drawback of flash memory is the limit of the number of rewrite operations. Mechanisms that have a five-year lifetime have been developed using existing technology. Results of a performance evaluation of the backup system are presented.> Hiroki Takakura, Yahiko Kambayashi |
ICDE | 1 |
| 1991 | Realization of Continuously Backed-up RAMs for High-Speed Database Recovery
Yahiko Kambayashi, Hiroki Takakura |
DASFAA | 2 |