EDBT 2026 Demo / reviewers in the wild / expert
Takahiro Kasama
dblp:119/1132
· DBLP profile ↗
8ranked-venue papers
0as first author
5since 2021 · last 2026
0009-0008-6556-1358ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Influence or Deception? Evaluating Social Suggestions with Persuasive Statements for Security and Privacy SettingsabstractConfiguring security and privacy (S&P) settings can be challenging for non-expert users, resulting in excessive dependence on persuasive cues, such as social proofs or expert suggestions. Although such suggestions can promote protective user choices, they can be misused as deceptive patterns that steer users toward less-protective settings. This study examines (1) how source-based suggestions (public vs. experts), when combined with logical persuasive statements, influence decision-making in S&P settings under honest or deceptive conditions and (2) how users evaluate these approaches once deception is revealed. An online experiment with 1,433 U.S. participants utilizing a 2 × 2 × 2 factorial design revealed that persuasive statements amplified the effect of social proof- and authority-based cues, which persisted even when promoting less-protective settings. These findings demonstrate the importance of persuasive S&P interfaces that follow transparent and rational design, as well as complementary interventions that foster users’ critical assessment and resilience against manipulation. Ayako Akiyama Hasegawa, Takahiro Kasama, Mitsuaki Akiyama |
CHI | 2 |
| 2024 | CIA-EBE: Class Imbalance-Aware Event-Based Embedding for SOC Log ScreeningabstractSecurity Operations Centers (SOCs) face significant challenges in processing large volumes of event logs. Traditional log screening methods frequently suffer from high false positive rates (FPR) and struggle to identify subtle, evolving threats such as reconnaissance attacks, which often precede more severe intrusions. This paper introduces a novel Class Imbalance-Aware Event-Based Embedding (CIA-EBE) approach designed to enhance SOC log screening by transforming individual security events into dense vector representations while emphasizing minority-class events. We evaluate the effectiveness of CIA-EBE using a dataset derived from Zeek logs and compare its performance against conventional embedding techniques like Word2Vec and Doc2Vec across multiple classifiers. CIA-EBE achieved 0% FPR and 100% recall with the Support Vector Machine classifier using stratified 5-fold cross-validation. Visualization techniques such as t-distributed Stochastic Neighbor Embedding and hierarchical clustering validated the separation between attack and benign events, demonstrating the robustness of CIA-EBE. This study illustrates the potential of AI-driven log screening approaches to enhance the accuracy and efficiency of SOC operations, equipping analysts with improved tools for early cyber threat detection. Samuel Ndichu, Tao Ban, Takeshi Takahashi 0001, Takahiro Kasama |
IEEE Big Data | 4 |
| 2024 | Customized Malware: Identifying Target Systems Using Personally Identifiable InformationabstractGiven the increasing popularity of sandbox analysis, malware authors have adapted sandbox evasion functionalities into modern malware. In addition, attackers can create Customized Malware that hide their malicious payload until the identifier of the target-specific system can be verified. In this paper, we propose an attack scenario in which adversaries can leverage publicly available personally identifiable information present in the target system as specific identifiers. The proposed attack scenario can be used in targeted attacks, especially against hosts that store business email addresses on personal computers (PCs). We investigated a set of desktop applications and specified 18 popular applications that store email addresses in their related files or directories. We also implemented a survey tool to access these applications and record whether email addresses were found. We then asked nine laboratory members and staff if the target-specific email address was found and if we could extract the same email address from each PC with 16 applications. Finally, we implemented a dummy malware sample that searches for the target host's email address from the executing environment and denies unpacking the malicious payload if the mark does not exist. The experiment results demonstrate that two modern mal ware security appliances did not detect the prototype sample. To defend against the proposed attack, we discuss countermeasures from both the sandbox and user perspective. We contacted security vendors to allow them to prepare for such attacks and provided POC programs. Rui Tanabe, Yuta Inoue, Daigo Ichikawa, Takahiro Kasama, Katsunari Yoshioka, Tsutomu Matsumoto |
COMPSAC | 4 |
| 2023 | Internet Service Providers' and Individuals' Attitudes, Barriers, and Incentives to Secure IoT
Nissy Sombatruang, Tristan Caulfield, Ingolf Becker, Akira Fujita, Takahiro Kasama, Koji Nakao |
USENIX Security Symposium | 5 |
| 2021 | Can ISPs Help Mitigate IoT Malware? A Longitudinal Study of Broadband ISP Security EffortsabstractFor the mitigation of compromised Internet of Things (IoT) devices we rely on Internet Service Providers (ISPs) and their users. Given that devices are in the hands of their subscribers, what can ISPs realistically do? This study examines the effects of ISP countermeasures on infections caused by variants of the notorious Mirai family of IoT malware, still among the dominant families. We collect and analyze more than 4 years of longitudinal darknet data tracking Mirai-like infections in conjunction with threat intelligence data on various other IoT and non-IoT botnets across the globe from January 2016 to May 2020. We measure the effect of two ISP countermeasures on Mirai variant infection numbers: (i) reducing the attack surface (i.e., closing ports that are used by the malware for propagation) and (ii) ISPs increasing their general network hygiene and malware removal efforts (as observed by proxy of the remediation of infections of other families of IoT and non-IoT malware and reductions in the number of DDoS amplifiers in their networks). We map our infection data to 342 broadband providers that have the bulk of the broadband market share in their respective 83 countries. We find that the number of infections correlates strongly with the number of ISP subscribers ($R^{2}=0.55$). Yet, infection numbers can still vary by three orders of magnitude even for ISPs with comparable subscriber numbers. We observe that many ISPs, together with their subscribers, have reduced their attack surface for IoT compromise by blocking traffic to commonly-exploited infection vectors such as Telnet and FTP. We statistically estimate the impact of these reductions on infection levels and, counter-intuitively, find no significant impact. In contrast, we do find a significant impact for improving general network hygiene and best malware mitigation practices. ISPs that were more successful in reducing DDoS amplifiers and non-Mirai malware infections in their networks also end up with significantly lower Mirai infection rates. In other words, rather than investing in IoT-specific countermeasures like reducing the attack surface, our findings suggest that ISPs might be better off investing in general security efforts to improve network hygiene and clean up abuse. Arman Noroozian, Elsa Turcios Rodriguez, Elmer Lastdrager, Takahiro Kasama, Michel van Eeten, Carlos Gañán |
EuroS&P | 4 |
| 2019 | Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove Mirai
Orçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama, Kazuki Tamiya, Ying Tie, Katsunari Yoshioka, Michel van Eeten |
NDSS | 4 |
| 2018 | Evasive Malware via Identifier ImplantingabstractTo cope with the increasing number of malware attacks that organizations face, anti-malware appliances and sandboxes have become an integral security defense. In particular, appliances have become the de facto standard in the fight against targeted attacks. Yet recent incidents have demonstrated that malware can effectively detect and thus evade sandboxes, resulting in an ongoing arms race between sandbox developers and malware authors. We show how attackers can escape this arms race with what we call customized malware , i.e., malware that only exposes its malicious behavior on a targeted system. We present a web-based reconnaissance strategy, where an actor leaves marks on the target system such that the customized malware can recognize this particular system in a later stage, and only then exposes its malicious behavior. We propose to implant identifiers into the target system, such as unique entries in the browser history, cache, cookies, or the DNS stub resolver cache. We then prototype a customized malware that searches for these implants on the executing environment and denies execution if implants do not exist as expected. This way, sandboxes can be evaded without the need to detect artifacts that witness the existence of sandboxes or a real system environment. Our results show that this prototype remains undetected on commercial malware security appliances, while only exposing its real behavior on the targeted system. To defend against this novel attack, we discuss countermeasures and a responsible disclosure process to allow appliances vendors to prepare for such attacks. Rui Tanabe, Wataru Ueno, Kou Ishii, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Christian Rossow |
DIMVA | 6 |
| 2016 | SandPrint: Fingerprinting Malware Sandboxes to Provide Intelligence for Sandbox Evasion
Akira Yokoyama, Kou Ishii, Rui Tanabe, Yinmin Papa, Katsunari Yoshioka, Tsutomu Matsumoto, Takahiro Kasama, Michael Brengel, Michael Backes 0001, Christian Rossow |
RAID | 7 |