Toshihiro Yamauchi

dblp:06/8767 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
4since 2021 · last 2024
0000-0001-6226-5715ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author
YearPublicationVenuePosition
2024 RKPM: Restricted Kernel Page Mechanism to Mitigate Privilege Escalation Attacks
Hiroki Kuzuno, Toshihiro Yamauchi
NSS2
2023 KDRM: Kernel Data Relocation Mechanism to Mitigate Privilege Escalation Attack
Hiroki Kuzuno, Toshihiro Yamauchi
NSS2
2023 Seeing is not always believing: Insights on IoT manufacturing from firmware composition analysis and vendor survey
abstract
Attacks on Internet of Things (IoT) devices have become increasingly sophisticated. However, there exist few comprehensive security investigations of IoT devices. We conducted a large-scale systematic investigation by assessing IoT firmware and follow-up survey with professionals involved in IoT-device manufacturing to understand the factors that prevent software security of IoT devices. Consequently, we discovered that many IoT devices continue to use old processor architecture and operating systems that are unable to efficiently use existing attack-mitigation features. Furthermore, we demonstrated that software patches are sometimes implicitly applied without changing the software version number (implicit patching); this may generate false positives in existing vulnerability assessments relying on software versions. On the basis of a follow-up survey, we determined technical and contractual constraints to IoT security emanating from the supply chain in the IoT device manufacturing industry. Based on the results, we discuss challenges associated with secure IoT manufacturing in the IoT-device supply chain.
Mitsuaki Akiyama, Shugo Shiraishi, Akifumi Fukumoto, Ryota Yoshimoto, Eitaro Shioji, Toshihiro Yamauchi
Comput. Secur.6
2022 Malware Classification by Deep Learning Using Characteristics of Hash Functions
Takahiro Baba, Kensuke Baba, Toshihiro Yamauchi
AINA (2)3
2019 KMO: Kernel Memory Observer to Identify Memory Corruption by Secret Inspection Mechanism
Hiroki Kuzuno, Toshihiro Yamauchi
ISPEC2
2017 Access Control for Plugins in Cordova-Based Hybrid Applications
abstract
Hybrid application frameworks such as Cordova allow mobile application (app) developers to create platform-independent apps. The code is written in JavaScript, with special APIs to access device resources in a platform-agnostic way. In this paper, we present a novel app-repackaging attack that repackages hybrid apps with malicious code; this code can exploit Cordova's plugin interface to tamper with device resources. We further demonstrate a defense against this attack through the use of a novel runtime access control mechanism that restricts access based on the mobile user's judgement. Our mechanism is easy to introduce to existing Cordova apps, and allows developers to produce apps that are resistant to app-repackaging attacks.
Naoki Kudo, Toshihiro Yamauchi, Thomas H. Austin
AINA2
2016 HeapRevolver: Delaying and Randomizing Timing of Release of Freed Memory Area to Prevent Use-After-Free Attacks
Toshihiro Yamauchi, Yuta Ikegami
NSS1
2016 Evaluation and design of function for tracing diffusion of classified information for file operations with KVM
Shota Fujii, Masaya Sato, Toshihiro Yamauchi, Hideo Taniguchi
J. Supercomput.3
2013 A mechanism for achieving a bound on execution performance of process group to limit CPU abuse
Toshihiro Yamauchi, Takayuki Hara, Hideo Taniguchi
J. Supercomput.1
2011 VMBLS: Virtual Machine Based Logging Scheme for Prevention of Tampering and Loss
Masaya Sato, Toshihiro Yamauchi
ARES2