EDBT 2026 Demo / reviewers in the wild / expert
Makoto Iwamura
dblp:33/6286
· DBLP profile ↗
18ranked-venue papers
5as first author
2since 2021 · last 2023
0009-0003-8640-7089ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 since 2021Artificial intelligence and machine learning · 7 · 4 first-authorSystems, architecture and hardware · 7 · 4 first-authorComputer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Xunpack: Cross-Architecture Unpacking for Linux IoT MalwareabstractAlthough the vast majority of malware used to be x86 architecture-based, the rapid rise of Internet of Things (IoT) malware in recent years has been forcing malware analysts to deal with binaries written for a wide range of architectures with little tooling support. Yuhei Kawakoya, Shu Akabane, Makoto Iwamura, Takeshi Okamoto |
RAID | 3 |
| 2022 | Script Tainting Was Doomed From The Start (By Type Conversion): Converting Script Engines into Dynamic Taint Analysis FrameworksabstractData flow analysis is an essential technique for understanding the complicated behavior of malicious scripts. For tracking the data flow in scripts, dynamic taint analysis has been widely adopted by existing studies. However, the existing taint analysis techniques have a problem that each script engine needs to be separately designed and implemented. Given the diversity of script languages that attackers can choose for their malicious scripts, it is unrealistic to prepare taint analysis tools for the various script languages and engines. Toshinori Usui, Yuto Otsuki, Yuhei Kawakoya, Makoto Iwamura, Kanta Matsuura |
RAID | 4 |
| 2020 | Security Threat Analysis of Automotive Infotainment SystemsabstractThis paper presents a security threat that can be induced by exploiting the vulnerabilities of In-Vehicle Infotainment (IVI) systems installed in connected vehicles. Recent IVI systems provide a remote control service that enables control from outside the car through an Internet connection. These systems also provide an in-vehicle Internet service that connects to the outside world. If IVI systems are inadequately implemented, they represent attack targets and the attacker may induce abnormal remote control of the car. In this paper, we analyze the security threat to IVI systems that may be a remote attack target in connected vehicles. We focus on (a) the remote control service that controls the car from the outside and (b) the in-vehicle network service that connects from inside the car to the outside. Regarding (a), we analyze the attack possibilities to verify whether or not previous countermeasures in the IVI system are sufficient to protect against attacks. Analysis results show that an attacker can remotely perform abnormal body control such as unlocking of a door by bypassing previous countermeasures embedded in the remote control service. Regarding (b), we analyze the in-vehicle network service from the aspect of a Denial of Service (DoS) attack, which has not been previously reported. Analysis results show that users are prevented from connecting to the Internet in the car by exploiting the improper implementation of the in-vehicle Wi-Fi service in an attack that has not been previously considered. Furthermore, for advanced attack techniques, (c) we analyze the IVI module itself and gain a root password through development interfaces to compromise the IVI module. We believe that this paper will contribute to the construction of improved secure designs and implementations in IVI systems. Junko Takahashi, Makoto Iwamura, Masashi Tanaka |
VTC Fall | 2 |
| 2019 | EIGER: automated IOC generation for accurate and interpretable endpoint malware detectionabstractA malware signature including behavioral artifacts, namely Indicator of Compromise (IOC) plays an important role in security operations, such as endpoint detection and incident response. While building IOC enables us to detect malware efficiently and perform the incident analysis in a timely manner, it has not been fully-automated yet. To address this issue, there are two lines of promising approaches: regular expression-based signature generation and machine learning. However, each approach has a limitation in accuracy or interpretability, respectively. Yuma Kurogome, Yuto Otsuki, Yuhei Kawakoya, Makoto Iwamura, Syogo Hayashi, Tatsuya Mori 0003, Koushik Sen |
ACSAC | 4 |
| 2019 | My script engines know what you did in the dark: converting engines into script API tracersabstractMalicious scripts have been crucial attack vectors in recent attacks such as malware spam (malspam) and fileless malware. Since malicious scripts are generally obfuscated, statically analyzing them is difficult due to reflections. Therefore, dynamic analysis, which is not affected by obfuscation, is used for malicious script analysis. However, despite its wide adoption, some problems remain unsolved. Current designs of script analysis tools do not fulfill the following three requirements important for malicious script analysis. (1) Universally applicable to various script languages, (2) capable of outputting analysis logs that can precisely recover the behavior of malicious scripts, and (3) applicable to proprietary script engines. Toshinori Usui, Yuto Otsuki, Yuhei Kawakoya, Makoto Iwamura, Jun Miyoshi, Kanta Matsuura |
ACSAC | 4 |
| 2019 | Detecting Successful Attacks from IDS Alerts Based On Emulation of Remote ShellcodesabstractServer administrators and security operation center analysts receive alerts from an intrusion detection system and check whether attacks have succeeded. However, it is difficult to handle them quickly because a tremendous number of alerts is generated in a short period of time. We propose a method to identify important alerts that lead to security incidents automatically. The key idea is to determine the success or failure of an attack based on traffic logs and the network behaviors observed during shellcode emulation. We evaluated the proposed method in terms of accuracy and performance and found that it can handle more than 60% of remote shellcodes and cope with practical attack cases. Yo Kanemoto, Kazufumi Aoki, Makoto Iwamura, Jun Miyoshi, Daisuke Kotani, Hiroki Takakura, Yasuo Okabe |
COMPSAC (2) | 3 |
| 2017 | Stealth Loader: Trace-Free Program Loading for API Obfuscation
Yuhei Kawakoya, Eitaro Shioji, Yuto Otsuki, Makoto Iwamura, Takeshi Yada |
RAID | 4 |
| 2016 | POSTER: Static ROP Chain Detection Based on Hidden Markov Model Considering ROP Chain IntegrityabstractReturn-oriented programming (ROP) has been crucial for attackers to evade the security mechanisms of operating systems. It is currently used in malicious documents that exploit viewer applications and cause malware infection. For inspecting a large number of commonly handled documents, high-performance and flexible-detection methods are required. However, current solutions are either time-consuming or less precise. In this paper, we propose a novel method for statically detecting ROP chains in malicious documents. Our method generates a hidden Markov model (HMM) of ROP chains as well as one of benign documents by learning known malicious and benign documents and libraries used for ROP gadgets. Detection is performed by calculating the likelihood ratio between malicious and benign HMMs. In addition, we reduce the number of false positives by ROP chain integrity checking, which confirms whether ROP gadgets link properly if they are executed. Experimental results showed that our method can detect ROP-based malicious documents with no false negatives and few false positives at high throughput. Toshinori Usui, Tomonori Ikuse, Makoto Iwamura, Takeshi Yada |
CCS | 3 |
| 2013 | API Chaser: Anti-analysis Resistant Malware Analyzer
Yuhei Kawakoya, Makoto Iwamura, Eitaro Shioji, Takeo Hariu |
RAID | 2 |
| 2012 | Code shredding: byte-granular randomization of program layout for detecting code-reuse attacksabstractCode-reuse attacks by corrupting memory address pointers have been a major threat of software for many years. There have been numerous defenses proposed for countering this threat, but majority of them impose strict restrictions on software deployment such as requiring recompilation with a custom compiler, or causing integrity problems due to program modification. One notable exception is ASLR(address space layout randomization) which is a widespread defense free of such burdens, but is also known to be penetrated by a class of attacks that takes advantage of its coarse randomization granularity. Focusing on minimizing randomization granularity while also possessing these advantages of ASLR to the greatest extent, we propose a novel defensive approach called code shredding: a defensive scheme based on the idea of embedding the checksum value of a memory address as a part of itself. This simple yet effective approach hinders designation of specific address used in code-reuse attacks, by giving attackers an illusion of program code shredded into pieces at byte granularity and dispersed randomly over memory space. We show our design and implementation of a proof-of-concept prototype system for the Windows platform and the results from several experiments conducted to confirm its feasibility and performance overheads. Eitaro Shioji, Yuhei Kawakoya, Makoto Iwamura, Takeo Hariu |
ACSAC | 3 |
| 2011 | Towards Efficient Analysis for Malware in the WildabstractWe propose two novel techniques for reducing the workload for malware analysis. The first technique is restricted instruction, which accelerates finding the longest common subsequence (LCS) between machine code instruction sequences of malware. The second technique is probabilistic disassembly, which can find the most probable disassembly result of a binary stream without a clue, such as debug symbols or the information of import functions. By combining the two proposals and our generic unpacker, we built an automatic malware classification system. Given an unknown malware program, the system enables malware analysts to find the most similar known malware program to this unknown one, and even estimate different/common instructions. In one of our experiments, we classified 3,233 malware samples in the wild and concluded that 75% of the samples belong to the seven largest clusters. As a result, only seven samples, one from each cluster, were required to be analyzed in order to reveal the functionality of the rest of the 75%, showing a great increase in efficiency of analysis. Makoto Iwamura, Mitsutaka Itoh, Yoichi Muraoka |
ICC | 1 |
| 2002 | Motion Planning of Under-Actuated Mechanical Systems: Convergence Analysis for Iterative MethodsabstractFor the motion planning problem, an iterative algorithm has been proposed as a general method. However, when we apply the algorithm to the problem of under-actuated mechanical systems, there are many cases when the convergence performance becomes too poor and we can not obtain the solution. We investigate the reason why the performance becomes poor and propose a method to improve the convergence performance. The effectiveness of the proposed method is shown by using an index that expresses the convergence performance. Makoto Iwamura, Hiroaki Ozaki, Akira Mohri |
ICRA | 1 |
| 2001 | Sub-Optimal Trajectory Planning of Mobile ManipulatorabstractA trajectory planning method of a mobile manipulator is presented. We derive the dynamics of the mobile manipulator considering it as the combined system of the manipulator and the mobile platform. The planning problem is formulated as an optimal control problem. To solve the problem, we use the concept of the order of priority. A gradient-based iterative algorithm which synthesize the gradient function in a hierarchical manner based on the order of priority is used. The simulation results of the 2-link planar nonholonomic mobile manipulator are given to show the effectiveness of the proposed algorithm. Akira Mohri, Seiji Furuno, Makoto Iwamura, Motoji Yamamoto |
ICRA | 3 |
| 2000 | Near-Optimal Motion Planning for Nonholonomic Systems Using Time-Axis Transformation and Gradient MethodabstractIn this paper, an optimal motion planning scheme using time-axis transformation and gradient method is proposed for nonholonomic systems. The motion planning of nonholonomic systems can be formulated as a nonlinear optimal control problem. However, the optimal control problem is too difficult to solve due to peculiar difficulty in the control of the nonholonomic systems. To alleviate the difficulty, we first convert the optimal control problem to a bidirectional, fixed-domain optimal control problem by using quasi-time variable. Then, a numerical algorithm which is based on the gradient method is developed for the optimal control problem and its convergence property with respect to final state error is proved. The optimal motion planning scheme is also applied to a 2-link planar free-joint manipulator. The simulation results show the effectiveness of the proposed optimal motion planning scheme. Makoto Iwamura, Motoji Yamamoto, Akira Mohri |
ICRA | 1 |
| 2000 | A gradient-based approach to collision-free quasi-optimal trajectory planning of nonholonomic systemsabstractThis paper discusses the optimal trajectory planning problem of nonholonomic systems in the presence of obstacles. The problem can be formulated as an optimal control problem by incorporating final state errors and obstacle avoidance conditions in the cost function. To solve the highly nonlinear optimal control problem, we introduce the concept of the order of priority into the trajectory generation procedure. We place the first priority on the convergence of the state to a desired state. The second priority is given to obstacle avoidance and the third priority is given to trajectory optimization. Then, a gradient-based iterative algorithm which synthesizes the gradient function in a hierarchical manner considering the order of priority is proposed. The simulation results of the 3-link planar free-joint manipulator are given to show the effectiveness of the proposed algorithm. Makoto Iwamura, Motoji Yamamoto, Akira Mohri |
IROS | 1 |
| 1999 | Quasi-Time-Optimal Motion Planning of Mobile Platforms in the Presence of ObstaclesabstractThis paper addresses a problem of optimal motion planning of mobile platforms amidst obstacles, considering the mobile platform dynamics. Due to nonholonomic constraints, actuator constraints, and state constraints by obstacle avoidance, the planning problem of mobile platform with two independently driven wheels is a complicated one. In this study, a dynamical model for the mobile platform is presented, including nonholonomic kinematic constraints. The idea of a path parameter is introduced to simplify the planning problem by considering the dynamics and nonholonomic constraints. Using the path parameter, the optimal motion planning problem is divided into two sub-problems: 1) time-optimization of trajectory along specified path, and 2) search for optimal path. Then two methods are proposed the solve the problems using the path parameter and parametrization by B-spline function. Finally, quasi-time-optimal solution for the original problem are planned by combining the two methods. Numerical examples show effectiveness of the motion planner. Motoji Yamamoto, Makoto Iwamura, Akira Mohri |
ICRA | 2 |
| 1999 | Near-optimal trajectory planning for nonholonomic Caplygin systemsabstractDiscusses the optimal trajectory planning problem of classical nonholonomic systems. Most conventional studies have discussed the nonholonomic motion planning problem considering only kinematics. However, when a trajectory is required to minimize the traveling time or the energy used in performing tasks, the dynamics must be taken into consideration. In this paper, a trajectory planning method that considers the full nonlinear dynamics of the system is proposed. This method is based on the concept of geometric phase and the minimum cost trajectory planning algorithm which were previously developed for motion planning of robotic manipulators. Simulation results show the effectiveness of the proposed method. Makoto Iwamura, Motoji Yamamoto, Akira Mohri |
IROS | 1 |
| 1998 | Time-optimal motion planning of skid-steer mobile robots in the presence of obstaclesabstractAddresses a problem of time-optimal motion planning of skid-steer mobile robots amidst obstacles. Due to nonholonomic constraints, actuator constraints, and state constraints by obstacle avoidance, the planning problem is a complicated one. In this study, the problem is divided into two sub-problems: (1) time-optimization of trajectory along specified path, (2) search for the optimal path, to alleviate the difficulties of the original problem. Then two methods to solve the problems are proposed, using an idea of path parameter and parametrization by B-spline function. Finally, quasi-optimal solutions for the original problem are obtained by combining the two algorithms. A simulation result shows an effectiveness of the proposed motion planner. Motoji Yamamoto, Makoto Iwamura, Akira Mohri |
IROS | 2 |