EDBT 2026 Demo / reviewers in the wild / expert
Kenji Kono
dblp:57/3958
· DBLP profile ↗
47ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0002-8650-9822ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 17 · 2 first-author · 3 since 2021Security and privacy · 9 · 1 first-authorComputer networks · 6Software engineering, systems software and programming languages · 6 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Revisiting Memory Swapping for Big-Memory Applications
Shun Kida, Satoshi Imamura, Kenji Kono |
HPC Asia | 3 |
| 2024 | PvCC: A vCPU Scheduling Policy for DPDK-applied Systems at Multi-Tenant Edge Data CentersabstractThis paper explores a practical means to employ Data Plane Development Kit (DPDK), a kernel-bypassing framework for packet processing, in resource-limited multi-tenant edge data centers. The problem is that the traditional virtual CPU (vCPU) schedulers are not well compatible with the event detection model of DPDK, which needs to monopolize a physical CPU (pCPU) for NIC register polling. Consequently, DPDK-applied systems running on consolidated Virtual Machines (VMs), a common setup at edges, fail to achieve low serving latencies regardless of the use of DPDK. Toward edge data center providers, this work presents a new vCPU scheduling policy named Polling vCPU Consolidation (PvCC) which runs DPDK-applied systems on dedicated pCPUs adopting microsecond-scale time slices. Along with this, we introduce a mechanism to determine an appropriate number of dedicated pCPUs according to customers' demands represented through a newly introduced vCPU scaling API enabling customers to scale up/down the vCPUs of their VMs at runtime. Our experiments show that PvCC allows DPDK-applied systems running on consolidated VMs to achieve low serving latencies, and our vCPU scaling API enables customers to adjust CPU resource assignment according to the incoming request rate and providers to effectively assign spare pCPUs to VMs executing non-latency-sensitive best-effort tasks. Yuki Tsujimoto, Kenichi Yasukata, Kenta Ishiguro, Kenji Kono |
Middleware | 5 |
| 2024 | Balancing Analysis Time and Bug Detection: Daily Development-friendly Bug Detection in Linux
Keita Suzuki, Kenta Ishiguro, Kenji Kono |
USENIX ATC | 3 |
| 2023 | Accelerating Multilingual Applications with In-memory Array SharingabstractData analysis applications are recently developed by combining multiple programming languages to utilize the advantage of each of them. Such applications are called multilingual applications and can accelerate data-intensive tasks such as data preprocessing and machine learning. However, multilingual applications require time-consuming serialization and deserialization (S/D) processes to exchange data between different programming languages. Although state-of-the-art mechanisms have developed to reduce the time overheads of S/D processes, the overheads are still not trivial due to memory copy of shared data. In this paper, for multilingual applications combining Python and Julia, we propose an in-memory array sharing method that serializes/deserializes only lightweight metadata and directly shares heavy data arrays in a shared memory space. It completely eliminates memory copy of numeric arrays by using a common in-memory metadata format between Python and Julia. Our evaluation shows that the proposed method reduces the execution times of three multilingual machine learning applications by 40.8% to 44.5% compated to a state-of-the-art S/D mechanism. Consequently, it brings the benefit of combining Python and Julia to develop machine learning applications. In addition, we demonstrate that the proposed method has a high scalability to the larger amount of data. Masanobu Nozawa, Satoshi Imamura, Kenji Kono |
IEEE Big Data | 3 |
| 2023 | Revisiting VM-Agnostic KVM vCPU Scheduler for Mitigating Excessive vCPU SpinningabstractIn virtualized environments, virtual CPUs (vCPUs) are commonly oversubscribed on physical CPUs (pCPUs) to utilize CPU resources efficiently. However, excessive vCPU spinning, which occurs when a vCPU is waiting in a spin loop for an event from a descheduled vCPU, greatly degrades application performance in virtualized environments. VM-agnostic hypervisors aim to prevent excessive vCPU spinning by rescheduling vCPUs when an excessive spin is detected by hardware support for virtualization. We investigate the effectiveness of the KVM vCPU scheduler and show that it fails to avoid excessive vCPU spinning under various situations. We identify three problems: 1) scheduler mismatch, 2) aggressive limitation of candidate vCPUs, and 3) IPI context misuse. The first problem stems from the mismatch between the KVM vCPU scheduler and the Linux scheduler. The second and third problems come from failures in choosing candidate vCPUs to be scheduled next. Our in-depth analysis reveals simple modification to KVM (89 LoC) can mitigate excessive vCPU spinning. Our simple modification reduces excessive vCPU spinning by up to 96% and improves benchmark performance by up to 2.6×. Part of the proposed mitigation has been integrated with KVM from Linux KVM v5.13 onward. Kenta Ishiguro, Naoki Yasuno, Pierre-Louis Aublin, Kenji Kono |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2021 | Mitigating excessive vCPU spinning in VM-agnostic KVMabstractIn virtualized environments, oversubscribing virtual CPUs (vCPUs) on physical CPUs (pCPUs) is common to utilize CPU resources efficiently. Unfortunately, excessive vCPU spinning, which occurs when a vCPU is waiting in a spin loop for an event from a descheduled vCPU, causes serious performance degradation. Usually, the VM-agnostic hypervisor tries to prevent excessive vCPU spinning by rescheduling vCPUs when an excessive spin is detected by hardware support for virtualization. Kenta Ishiguro, Naoki Yasuno, Pierre-Louis Aublin, Kenji Kono |
VEE | 4 |
| 2020 | Poster: No More Slow Messages: Programmable Packet Handling in Hard IRQabstractTail latency in packet handling can easily occur in today's huge distributed systems. Serious failure can happen if a packet experiences tail latency, especially if that packet is used to manage distributed systems. For example, the delay in heartbeat packets results in unnecessary invocation of recovery procedures, and degrades the overall availability of the system. This poster presents a mechanism that handles critical management packets without any tail latency. It handles critical packets inside hard interrupt request (IRQ) contexts to avoid unexpected delay of packet handling due to resource contention. The code for handling management packets is programmable. To allow the installation of user-defined code, it also provides programmable but safe execution environments. Our experimental results demonstrate our system can reduce 99.9 percentile latency up to 74.7% compared to XDP, a state-of-the-art packet handling system. Ko Natori, Takafumi Kikuchi, Kenji Kono |
SRDS | 3 |
| 2019 | To unify or not to unify: a case study on unified builds (in WebKit)abstractUnified builds are a simple but effective technique to reduce the build time of large software projects. Unified builds generate large compiler tasks by bundling multiple source files into one, resulting in a significant reduction in build time through removal of redundant work incurred by shared headers. However, unified builds have a negative effect on incremental builds because each compiler task gets larger. An ad-hoc unification strategy causes an excessive slowdown in incremental builds. A rough report from WebKit says the worst slowdown is 20% (6s → 7s), but our investigation shows it is as high as 479% (19s → 110s). Takafumi Kubota, Yusuke Suzuki, Kenji Kono |
CC | 3 |
| 2019 | A Framework for Building Linux-Based Single-Purpose Appliances Optimized for the CloudabstractCloud-specialized OSes improve performance and efficiency of cloud applications by specializing their kernels to their target applications. Existing cloud-specialized OSes such as OSv and Unikernels are developed from the ground up and requires substantial porting efforts, resulting in the following drawbacks: 1) their functionalities are not as rich as general-purpose OSes, 2) some features are not optimized well, 3) the API compatibility with general-purpose OSes is limited, and 4) maintenance independent of existing development communities is required. To mitigate these drawbacks, we propose a Linux-based execution environment that can be specialized in the cloud but keeps the functionalities of Linux. The proposed environment enables "in-kernel" execution of existing applications, and the compile-time "whole-system" optimization beyond the application/kernel boundary. Memcached, running in our environment, shows 10% better throughput than the OSv version. Atsutoshi Osuka, Kenji Kono |
CloudCom | 2 |
| 2019 | Detecting and Analyzing Year 2038 Problem Bugs in User-Level ApplicationsabstractThe year 2038 problem is a well-known year problem that might cause severe damage to many existing software systems. However, no current tool can detect the bugs since it requires the understandings of the problem unique encoding semantics. In this paper, we analyze real-world applications and raise the alarm over the fact that the Year 2038 problem is a real threat. We target all of the C based projects uploaded on GitHub in the years 2012 to 2018 (32,921 in total), between the dates July 1 to July 10. Our analysis shows that 7.35% of the compiled projects have bugs. Some of the bugs trigger undefined behavior and are dangerous enough to crash the software systems. Our bug fixing patches sent to six projects have been confirmed and approved, including large-scale, real-world projects such as the Amazon Web Service support tools and the Linux Test Project. Keita Suzuki, Takafumi Kubota, Kenji Kono |
PRDC | 3 |
| 2018 | An Application Framework for Migrating GPGPU Cloud ApplicationsabstractGraphics Processing Units (GPUs) have become a common computing resource for general-purpose computing (GPGPU). GPU usage has also spread to high-throughput server applications, taking advantage of its massively parallel nature and wide availability at various cloud platforms. Although various methods currently exist to share a single GPU among multiple applications, migrating GPGPU server applications across different machines is challenging due to lack of hardware mechanisms, such as programmable preemption and access to GPU context. This paper presents an event-driven framework for GPGPU server applications, which enables us to implement a software based approach for migration which overcomes current hardware limitations. Sho Yuhara, Yusuke Suzuki, Kenji Kono |
CloudCom | 3 |
| 2017 | Nioh: Hardening The Hypervisor by Filtering Illegal I/O Requests to Virtual DevicesabstractVulnerabilities in hypervisors are crucial in multi-tenant clouds since they can undermine the security of all virtual machines (VMs) consolidated on a vulnerable hypervisor. Unfortunately, 107 vulnerabilitiesin KVM+QEMU and 38 vulnerabilities in Xen have been reported in 2016. The device-emulation layer in hypervisors is a hotbed of vulnerabilities because the code for virtualizing devices is complicated and requires knowledge on the device internals. We propose a "device request filter", called Nioh, that raises the bar for attackers to exploit the vulnerabilities in hypervisors. The key insight behind Nioh is that malicious I/O requests attempt to exploit vulnerabilities and violate device specifications in many cases. Nioh inspects I/O requests from VMs and rejects those that do not conform to a device specification. A device specification is modeled as a device automaton in Nioh, an extended automaton to facilitate the description of device specifications. The software framework is also provided to encapsulate the interactions between the device request filter and the underlying hypervisors. The results of our attack evaluation suggests that Nioh can defend against attacks that exploit vulnerabilities in device emulation, i.e., CVE-2015-5158, CVE-2016-1568, CVE-2016-4439, and CVE-2016-7909. This paper shows that the notorious VENOM attack can be detected and rejected by using Nioh. Junya Ogasawara, Kenji Kono |
ACSAC | 2 |
| 2017 | GLoop: an event-driven runtime for consolidating GPGPU applicationsabstractGraphics processing units (GPUs) have become an attractive platform for general-purpose computing (GPGPU) in various domains. Making GPUs a time-multiplexing resource is a key to consolidating GPGPU applications (apps) in multi-tenant cloud platforms. However, advanced GPGPU apps pose a new challenge for consolidation. Such highly functional GPGPU apps, referred to as GPU eaters, can easily monopolize a shared GPU and starve collocated GPGPU apps. This paper presents GLoop, which is a software runtime that enables us to consolidate GPGPU apps including GPU eaters. GLoop offers an event-driven programming model, which allows GLoop-based apps to inherit the GPU eaters' high functionality while proportionally scheduling them on a shared GPU in an isolated manner. We implemented a prototype of GLoop and ported eight GPU eaters on it. The experimental results demonstrate that our prototype successfully schedules the consolidated GPGPU apps on the basis of its scheduling policy and isolates resources among them. Yusuke Suzuki, Shinpei Kato, Kenji Kono |
SoCC | 4 |
| 2016 | Containers or Hypervisors: Which Is Better for Database Consolidation?abstractDatabase management systems (DBMS) is a common service in clouds. Cloud platforms use virtualization to consolidate servers for efficient resource utilization and to isolate collocated users' workloads. The underlying virtualization technologies have critical impact on the performance and isolation, especially in disk I/O, in DBMS. There are two major virtualization approaches: the hypervisor-based (virtual machines) and the operating-system-level virtualization (containers). Containers are widely believed to outperform virtual machines because of negligible virtualization overheads, while virtual machines are expected to provide stronger performance isolation. This paper argues against the above beliefs by investigating MySQL I/O performance and isolation in KVM and LXC. Contrary to the general belief, our results show that KVM outperforms LXC by up to 86% without compromising the isolation. Our analysis reveals that file system journaling has negative impact on both the performance and isolation in LXC. Since containers share a journaling mechanism unlike virtual machines, journaling activities are serialized and bundled with each other, resulting in inferior performance and isolation. Asraa Abdulrazak Ali Mardan, Kenji Kono |
CloudCom | 2 |
| 2016 | GPUvm: GPU Virtualization at the HypervisorabstractGraphic processing units (GPUs) provide a massively-parallel computational power and encourage the use of general-purpose computing on GPUs (GPGPU). The distinguished design ofdiscrete GPUshelps them to provide the high throughput, scalability, and energy efficiency needed for GPGPU applications. Despite the previous study on GPU virtualization, the tradeoffs between the virtualization approaches remain unclear, because of a lack of designs for or quantitative evaluations of the hypervisor-level virtualization for discrete GPUs. Shedding light on these tradeoffs and the technical requirements for the hypervisor-level virtualization would facilitate the development of an appropriate GPU virtualization solution.$\sf{GPUvm}$, which is an open architecture for hypervisor-level GPU virtualization with a particular emphasis on using the Xen hypervisor, is presented in this paper.$\sf{GPUvm}$offers three virtualization modes: the full-, naive para-, and high-performance para-virtualization.$\sf{GPUvm}$exposes low- and high-level interfaces such as memory-mapped I/O and DRM APIs to the guest virtual machines (VMs). Our experiments using a relevant commodity GPU showed that$\sf{GPUvm}$incurs different overheads as the level of the exposed interfaces is changed. The results also showed that a coarse-grained fairness on the GPU among multiple VMs can be achieved using GPU scheduling. Yusuke Suzuki, Shinpei Kato, Kenji Kono |
IEEE Trans. Computers | 4 |
| 2014 | Minimizing WAN Communications in Inter-datacenter Key-Value StoresabstractCloud-federations have emerged as popular platforms for Internet-scale services. Cloud-federations are running over multiple datacenters, because a cloud-federation is an aggregate of cloud services each of which runs in a single datacenter. In such inter-datacenter environments, distributed key-value stores (DKVSs) are attractive databases in terms of scalability. However, inter-datacenter communications degrade the performance of these DKVSs because of their large latency and narrow bandwidth. In this paper, we demonstrate how to reduce and hide the weak points of inter-datacenter communications for DKVSs. To solve the problems we introduce two techniques called multi-layered DHT (ML-DHT) and local-first data rebuilding (LDR). ML-DHT provides a global and consistent index of key-value pairs with the efficient expandability of the storage capacity. It employs a routing protocol which reduces routing hops that pass through interdatacenter connections. LDR reduces data transfer on interdatacenter connections by using erasure coding techniques. It enables KVS administrators to flexibly make trade-offs between expandability of storage capacity and the performance of data transfer. Experimental results demonstrate that our techniques improve the latency up to 74 % compared with a Chord-based system and enable us to balance the amount of storage usage and remote data transfer. Hikaru Horie, Masato Asahara, Kenji Kono |
IEEE CLOUD | 4 |
| 2014 | A Guideline for Selecting Live Migration Policies and Implementations in CloudsabstractLive migration of virtual machines (VMs) is widely used for managing cloud computing platforms. However, live migration causes performance interference on cloud services running on migrated VMs or other VMs collocating with the services during or after migration. Although migration time and downtime are mainly for measuring live migration performance, cloud administrators must take live migration-performance interference into consideration. Since many live migration policies and implementations have been proposed recently, cloud administrators are required to choose an appropriate migration policy and/or implementation. For this study, we conducted several experiments and compared several migration methods quantitatively. According to our experimental results, we reveal the trade-offs of each migration policy and implementation that are not just related to downtime and migration time and present guidelines for selecting appropriate policies and implementations. Akane Koto, Kenji Kono |
CloudCom | 2 |
| 2014 | FoxyFeed: Forging Device-Level Asynchronous Events for Kernel DevelopmentabstractEnhancing source code quality of operating systems (OSes) is an essential and endless task in communities of commodity OSes. Unfortunately, improving the quality of the kernel code is not trivial because the kernel is large and complex. In particular, asynchronous events from peripheral devices such as interrupts make the improvement quite hard due to their low reproducibility. This paper presents Foxy Feed, a mechanism based on virtual machine monitors that helps to fix bugs caused by asynchronous device-level events. Foxy Feed forges device-level events and injects them to a debuggee kernel at the timing specified in advance, and allows us to control the timing at which asynchronous events occur for the debugging purpose. Using our prototype implementation of Foxy Feed, which is based on Xen 4.1.0, we demonstrate that Foxy Feed reproduces failures caused by device-triggered bugs in Linux and gives significant clues to the root causes. Kenji Kono, Shunsuke Miyahara, Takeshi Yoshimura |
PRDC | 1 |
| 2014 | Clickjuggler: Checking for incomplete defenses against clickjackingabstractClickjacking is a new attack which exploits a vulnerability in web applications. It tricks victims into clicking on something different from what they perceive they are clicking on. The victims may reveal confidential information or start unintended online transactions. Clickjacking can be prevented if appropriate countermeasures such as frame busting are implemented in web applications. However, the correct implementation is not easy. A trivial mistake in the implementation leads to evasion of the countermeasures. For the correct implementation, web developers must have intimate knowledge on evasion techniques of the countermeasures. In this paper, we propose Clickjuggler, an automated tool for checking for defenses against clickjacking during the development. Clickjuggler generates clickjacking attacks, performs those attacks on web applications, and checks whether the attacks are successful or not. By automating the process of checking for the clickjacking vulnerabilities, web developers are released from the burden of checking the correctness of their implementation. Unskillful developers can benefit from Clickjuggler since no special knowledge on clickjacking is needed to use Clickjuggler. Our experimental results demonstrate that Clickjuggler can check for the clickjacking vulnerabilities in 4 real-world web applications. Yusuke Takamatsu, Kenji Kono |
PST | 2 |
| 2014 | GPUvm: Why Not Virtualizing GPUs at the Hypervisor?
Yusuke Suzuki, Shinpei Kato, Kenji Kono |
USENIX ATC | 4 |
| 2013 | Pangaea: A Single Key Space, Inter-datacenter Key-Value StoreabstractThis paper presents Pangaea, an inter-data center key-value store that keeps reasonable expandability of storage capacity, data lookup latency and data transfer speed. Pangaea uses two techniques called multi-layered DHT (ML-DHT) and local-first data rebuilding (LDR). ML-DHT provides a global and consistent index of key-value pairs with efficient routings in inter-data center environments. LDR reduces inter-data center data transfer by using erasure coding techniques. Hikaru Horie, Masato Asahara, Kenji Kono |
ICPADS | 4 |
| 2013 | Traveling forward in time to newer operating systems using ShadowRebootabstractOperating system (OS) reboots are an essential part of updating kernels and applications on laptops and desktop PCs. Long downtime during OS reboots severely disrupts users' computational activities. This long disruption discourages the users from conducting OS reboots, failing to enforce them to conduct software updates. This paper presents ShadowReboot, a virtual machine monitor (VMM)-based approach that shortens downtime of OS reboots in software updates. ShadowReboot conceals OS reboot activities from user's applications by spawning a VM dedicated to an OS reboot and systematically producing the rebooted state where the updated kernel and applications are ready for use. ShadowReboot provides an illusion to the users that the guest OS travels forward in time to the rebooted state. ShadowReboot offers the following advantages. It can be used to apply patches to the kernels and even system configuration updates. Next, it does not require any special patch requiring detailed knowledge about the target kernels. Lastly, it does not require any target kernel modification. We implemented a prototype in VirtualBox 4.0.10 OSE. Our experimental results show that ShadowReboot successfully updated software on unmodified commodity OS kernels and shortened the downtime of commodity OS reboots on five Linux distributions (Fedora, Ubuntu, Gentoo, Cent, and SUSE) by 91 to 98%. Kenji Kono |
VEE | 2 |
| 2012 | Energy-Price-Driven Request Dispatching for Cloud Data CentersabstractCloud services make use of data center resources so that hosted applications can utilize them as needed. To offer a large amount of computational resources, cloud service providers manage tens of geographically distributed data centers. Since each data center is made up of hundreds of thousands of physical machines, energy consumption is a major concern for cloud service providers. The electric cost imposes significant financial overheads on those companies and pushes up the price for the cloud users. This paper presents an energy-price-driven request dispatcher that forwards client requests to data centers in an electric-cost-saving way. In our technique, mapping nodes, which are used as authoritative DNS servers, forward client requests to data centers in which the electric price is relatively lower. We additionally develop a policy that gradually shifts client requests to electrically cheaper data centers, taking into account application latency requirements and data center loads. Our simulation-based results show that our technique can reduce electric cost by 15% more than randomly dispatching client requests. Takumi Sakamoto, Hikaru Horie, Kenji Kono |
IEEE CLOUD | 4 |
| 2012 | Honeyguide: A VM migration-aware network topology for saving energy consumption in data center networksabstractNetwork elements consume 10-20% of the total power in data centers. Today's network elements are not energy-proportional and consume constant energy1regardless of the traffic amounts. Thus, turning off unused network switches is the most efficient way of saving energy consumption of data center networks. This paper presents Honeyguide, an energy optimizer for data center networks that not only turns off inactive switches but also increases the number of inactive switches for energy-efficiency. To this end, Honeyguide combines two techniques: (1) virtual machine (VM) and traffic consolidation, and (2) a slight extension to existing tree-based topologies. Honeyguide has the following advantages. VM consolidation, which is gracefully combined with traffic consolidation, can handle severe requirements on fault tolerance. It can be introduced into existing data centers without replacing already-deployed tree-based topologies. Our simulation results demonstrate that Honeyguide can save more energy consumption of network elements than conventional VM migration schemes, and the savings are up to 7.8% in a fat tree with k = 12. Hiroki Shirayanagi, Kenji Kono |
ISCC | 3 |
| 2012 | Automated detection of session management vulnerabilities in web applicationsabstractMany web applications employ session management to keep track of visitors' activities across pages and over periods of time. A session is a period of time linked to a visitor, which is initiated when he/she arrives at a web application and it ends when his/her browser is closed or after a certain time of inactivity. Attackers can hijack a user's session by exploiting session management vulnerabilities by means of session fixation and cross-site request forgery attacks. Even though such session management vulnerabilities can be eliminated in the development phase of web applications, the test operator is required to have detailed knowledge on the attacks and to set up a test environment each time he/she attempts to detect vulnerabilities. We propose a technique that automatically detects session management vulnerabilities in web applications by simulating real attacks. Our technique requires the test operator to only enter a few pieces of basic information about the web application, without requiring a test environment to be set up or detailed knowledge on the web application. Our experiments demonstrated that our technique could detect vulnerabilities in five web applications deployed in the real world. Yusuke Takamatsu, Yuji Kosuga, Kenji Kono |
PST | 3 |
| 2011 | Efficiently Synchronizing Virtual Machines in Cloud Computing EnvironmentsabstractInfrastructure as a Service (IaaS), a form of cloud computing, is gaining attention for its ability to enable efficient server administration in dynamic workload environments. In such environments, however, updating the software stack or content files of virtual machines (VMs) is a time-consuming task, discouraging administrators from frequently enhancing their services and fixing security holes. This is because the administrator has to upload the whole new disk image to the cloud platform via the Internet, which is not yet fast enough that large amounts of data can be transferred smoothly. Although the administrator can apply only incremental updates directly to the running VMs, he or she has to carefully consider the type of update and perform operations on all the running VMs, such as application restarts and operating system reboots. This is a tedious and error-prone task. This paper presents a technique for synchronizing VMs with less time and lower administrative burden. We introduce the Virtual Disk Image Repository, which runs on the cloud platform and automatically updates the virtual disk image and the running VMs with only the incremental update information. We also show a mechanism that performs necessary operations on the running VM such as restarting server processes, based on the types of files that are updated. We implemented a prototype on Linux 2.6.31.14 and Amazon Elastic Compute Cloud. The experimental results show that our technique can synchronize VMs in an order-of-magnitude shorter time than the conventional disk-image-based VM cloning method. Although our system imposes about 30% overhead on the developer's environment, it imposes no observable overhead on public servers and correctly performs necessary operations to put updates into effect. Shuntaro Tonosaki, Kenji Kono |
CloudCom | 3 |
| 2011 | Phase-based reboot: Reusing operating system execution phases for cheap reboot-based recoveryabstractAlthough operating systems (OSes) are crucial to achieving high availability of computer systems, modern OSes are far from bug-free. Rebooting the OS is simple, powerful, and sometimes the only remedy for kernel failures. Once we accept reboot-based recovery as a fact of life, we should try to ensure that the downtime caused by reboots is as short as possible. This paper presents “phase-based” reboots that shorten the downtime caused by reboot-based recovery. The key idea is to divide a boot sequence into phases. The phase-based reboot reuses a system state in the previous boot if the next boot reproduces the same state. A prototype of the phase-based reboot was implemented on Xen 3.4.1 running para-virtualized Linux 2.6.18. Experiments with the prototype show that it successfully recovered from kernel transient failures inserted by a fault injector, and its downtime was 34.3 to 93.6% shorter than that of the normal reboot-based recovery. Kazuya Yamakita, Kenji Kono |
DSN | 3 |
| 2010 | AspFuzz: A state-aware protocol fuzzer based on application-layer protocolsabstractIn the face of constant malicious attacks to network-connected software systems, software vulnerabilities need to be discovered early in the development phase. In this paper, we present AspFuzz, a state-aware protocol fuzzer based on the specifications of application-layer protocols. AspFuzz automatically generates anomalous messages that exploit possible vulnerabilities. The key observation behind AspFuzz is that most of the previously reported attack messages violate the strict specifications of application-layer protocols. For example, they do not conform to the rigid format or syntax required of each message. In addition, some attack messages ignore the protocol states and have incorrect orders of messages. AspFuzz automatically generates a large number of anomalous messages that deliberately violate the specifications of application-layer protocols. It then sends the generated messages in both anomalous orders and correct orders. To demonstrate the effectiveness of AspFuzz, we conducted experiments with POP3 and HTTP servers. With AspFuzz, we can discover 20 reported and 1 previously unknown vulnerabilities for POP3 servers and 25 reported vulnerabilities for HTTP servers. Takahisa Kitagawa, Miyuki Hanaoka, Kenji Kono |
ISCC | 3 |
| 2010 | Automated detection of session fixation vulnerabilitiesabstractSession fixation is a technique for obtaining the visitor's session identifier (SID) by forcing the visitor to use the SID supplied by the attacker. The attacker who obtains the victim's SID can masquerade as the visitor. In this paper, we propose a technique to automatically detect session fixation vulnerabilities in web applications. Our technique uses attack simulator that executes a real session fixation attack and check whether it is successful or not. In the experiment, our system successfully detected vulnerabilities in our original test cases and in a real world web application. Yusuke Takamatsu, Yuji Kosuga, Kenji Kono |
WWW | 3 |
| 2009 | Yataglass: Network-Level Code Emulation for Analyzing Memory-Scanning Attacks
Makoto Shimamura, Kenji Kono |
DIMVA | 2 |
| 2009 | Efficient Update Propagation by Speculating Replica Locations on Peer-to-Peer NetworksabstractAs demand for high fidelity multimedia content has soared, content distribution has emerged as a critical application. Large multimedia files require effective content distribution services such as content distribution networks (CDNs). A recent trend in CDN development is the use of peer-to-peer (P2P) techniques to enhance scalability, fault resilience, and cost-effectiveness. Unfortunately, P2P-based content distribution poses a crucial problem in that update propagation is quite difficult to accomplish. This is because peers cannot obtain a global view of replica locations on the network. In this paper, we propose speculative update, which quickly propagates an update to all replicas in a pure P2P fashion. Each server attempts to determine the directions in which there will be replicas with high probability based on server's local state used for replica repositioning. Then, it relays update messages speculatively in those directions. Simulation results demonstrate that our mechanism propagates an update to all replicas faster than the current pure P2P-based approaches. Ai Hayakawa, Masato Asahara, Kenji Kono, Toshinori Kojima |
ICPADS | 3 |
| 2009 | Embedding Network Coordinates into the Heart of Distributed Hash TablesabstractNetwork coordinates (NCs) construct a logical space which enables efficient and accurate estimation of network latency. Although many researchers have proposed NC-based strategies to reduce the lookup latency of distributed hash tables (DHTs), these strategies are limited in the improvement of the lookup latency; the nearest node to which a query should be forwarded is not always included in the consideration scope of a node. This is because conventional DHTs assign node IDs independent of the underlying physical network. In this paper, we propose an NC-based method of constructing a topology-aware DHT by Proximity Identifier Selection strategy (PIS/NC). PIS/NC assigns an ID to each node based on NC of the node. This paper presents Canary, a PIS/NC-based CAN whose d-dimensional logical space corresponds to that of Vivaldi. Our simulation results suggest that PIS/NC has the possibility of dramatically improving the lookup latency of DHTs. Whereas DHash++ is only able to reduce the median lookup latency by 15% of the original Chord, Canary reduces it by 70% of the original CAN. Toshinori Kojima, Masato Asahara, Kenji Kono, Ai Hayakawa |
Peer-to-Peer Computing | 3 |
| 2009 | BitVisor: a thin hypervisor for enforcing i/o device securityabstractVirtual machine monitors (VMMs), including hypervisors, are a popular platform for implementing various security functionalities. However, traditional VMMs require numerous components for providing virtual hardware devices and for sharing and protecting system resources among virtual machines (VMs), enlarging the code size of and reducing the reliability of the VMMs.This paper introduces a hypervisor architecture, called parapass-through, designed to minimize the code size of hypervisors by allowing most of the I/O access from the guest operating system (OS) to pass-through the hypervisor, while the minimum access necessary to implement security functionalities is completely mediated by the hypervisor. This architecture uses device drivers of the guest OS to handle devices, thereby reducing the size of components in the hypervisor to provide virtual devices. This architecture also allows to run only single VM on it, eliminating the components for sharing and protecting system resources among VMs.We implemented a hypervisor called BitVisor and a parapass-through driver for enforcing storage encryption of ATA devices based on the parapass-through architecture. The experimental result reveals that the hypervisor and ATA driver require approximately 20 kilo lines of code (KLOC) and 1.4 KLOC respectively. Takahiro Shinagawa, Hideki Eiraku, Kouichi Tanimoto, Kazumasa Omote, Shoichi Hasegawa, Takashi Horie, Manabu Hirano, Kenichi Kourai, Yoshihiro Oyama, Eiji Kawai, Kenji Kono, Shigeru Chiba, Yasushi Shinjo, Kazuhiko Kato |
VEE | 11 |
| 2008 | Enforcing appropriate process execution for exploiting idle resources from outside operating systemsabstractIdle resources can be exploited not only to run important local tasks such as data replication and virus checking, but also to make contributions to society by participating in open computing projects like SETI@home [2]. When executing background processes to utilize such valuable idle resources, we need to explicitly control them so that the user will not be discouraged from exploiting idle resources by foreground performance degradation. Unfortunately, common priority-based schedulers lack such explicit execution control. In addition, to encourage active use of idle resources, a mechanism for controlling background processes should not require modifications to the underlying operating system or user applications. If such modifications are required, the user may be reluctant to employ the mechanism. In this paper, we argue that we can reasonably detect resource contention between foreground and background processes and properly control background process execution at the user level. We infer the existence of resource contention from the approximated resource shares of background processes. Our approach takes advantage of dynamically instrumented probes, which are becoming increasingly popular, in estimating the resource shares. Also, it considers different resource types in combination and can handle varied workloads, including multiple background processes. We show that our system effectively avoids the performance degradation of foreground activities by suspending background processes in an appropriate fashion. Our system keeps the increase in foreground execution time due to background processes below 16.9%, or much lower in most of our experiments. Also, we extend our approach to address undesirable resource allocations to CPU-intensive processes that can occur in multiprocessor environments. Yoshihisa Abe, Kenji Kono |
EuroSys | 3 |
| 2008 | FlexBox: Sandboxing internet servers based on layer-7 contextsabstractInternet servers are constantly exposed to malicious attacks launched remotely. Sandbox is a promising approach to reducing the damage caused by malicious attacks. A sandbox system provides a restricted environment for executing programs/codes from an Internet server, in which the accessible resources are limited to those required for legal execution. However, traditional sandbox systems are not suitable for preventing sensitive files, legally accessed by Internet servers, from being leaked or tampered. A sandbox system must permit access to sensitive files if the sandboxed server requires access to them. This paper presents FlexBox, a novel sandbox system that reduces the possibility of leaking or tampering with sensitive files accessed by Internet servers. The key observation is that Internet servers typically have several execution states, each of which requires different access rights to resources such as files, especially sensitive files that are usually accessed only in a few execution states. Therefore, if FlexBox dynamically changes a set of accessible files according to servers’ execution states, it is expected to dramatically reduce the possibility of information leakage/tampering. To obtain the execution states of Internet servers, FlexBox exploits the layer-7 contexts of Internet servers, i.e., it monitors the network messages exchanged between the server and clients. We demonstrate that FlexBox can be applied to several real Internet servers and the overhead from FlexBox is reasonably low. A. Tanoue, Makoto Shimamura, Miyuki Hanaoka, Kenji Kono |
ISCC | 4 |
| 2008 | Tuning mechanisms for two major parameters of Apache web serversabstractAbstract Apache web servers are widely used as stand‐alone servers or front‐ends in multi‐tiered web servers. Despite the wide availability of software, it is quite difficult for many administrators to properly configure their web servers. In particular, setting the performance‐related parameters is an error‐prone and time‐consuming task because their values heavily depend on the server environment. In this paper, two mechanisms are described for automatically tuning two performance‐related parameters of Apache web servers:KeepAliveTimeoutandMaxClients. These mechanisms are easy to deploy because no modifications to the server or the operating system are required. Moreover, they are parameter specific. Although interference betweenKeepAliveTimeoutandMaxClientsis inevitable, the tuning mechanisms minimize the correlation by using almost completely independent metrics. Experimental results show that these mechanisms work well for two different workloads; the parameter values are close to optimal and can adapt to workload changes. Copyright © 2007 John Wiley & Sons, Ltd. Akiyoshi Sugiki, Kenji Kono, Hideya Iwasaki |
Softw. Pract. Exp. | 2 |
| 2007 | Sania: Syntactic and Semantic Analysis for Automated Testing against SQL InjectionabstractWith the recent rapid increase in interactive Web applications that employ back-end database services, an SQL injection attack has become one of the most serious security threats. The SQL injection attack allows an attacker to access the underlying database, execute arbitrary commands at intent, and receive a dynamically generated output, such as HTML Web pages. In this paper, we present our technique, Sania, for detecting SQL injection vulnerabilities in Web applications during the development and debugging phases. Sania intercepts the SQL queries between a Web application and a database, and automatically generates elaborate attacks according to the syntax and semantics of the potentially vulnerable spots in the SQL queries. In addition, Sania compares the parse trees of the intended SQL query and those resulting after an attack to assess the safety of these spots. We evaluated our technique using real-world Web applications and found that our solution is efficient in comparison with a popular Web application vulnerabilities scanner. We also found vulnerability in a product that was just about to be released. Yuji Kosuga, Kenji Kono, Miyuki Hanaoka, Miho Hishiyama, Yu Takahama |
ACSAC | 2 |
| 2007 | Finding candidate spots for replica servers based on demand fluctuationabstractMany service providers distribute various kinds of content over the Internet. They often use replica servers to provide stable service. To position them appropriately, service providers must predict the demands for their services and provide computing capacity sufficient for servicing the demands. Unfortunately, predicting demands is difficult because demand for a service usually fluctuates. Our research group is developing ExaPeer, an infrastructure that apportions computing capacity to services running on hundreds or thousands of trusted machines all over the Internet. In this paper, we describe ExaPeer’s approach to dynamically selecting candidate spots for replica servers. The runtime system in ExaPeer detects fluctuations in demand and then dynamically selects candidate spots on which replica servers should be placed to best meet the demand. Experimental results demonstrate that the candidate spots selected by ExaPeer work better than manually selected ones even if the scale of demand changes rapidly. Masato Asahara, Akio Shimada, Kenji Kono |
ICPADS | 4 |
| 2007 | An Efficient TCP Reassembler Mechanism for Layer7-aware Network Intrusion Detection/Prevention SystemsabstractExploiting layer/ context is an effective approach to improving the accuracy of detecting malicious messages in network intrusion detection/prevention systems (NIDS/NIPSs). Unfortunately layerl-aware NIDS/NIPSs pose crucial implementation issues because they require full TCP/IP reassembly without losing (1) complete prevention, (2) performance, (3) application transparency, or (4) transport transparency. To the best of our knowledge, none of the existing approaches meet all of these requirements. Our store-through does this by forwarding each out-of-order or IP-fragmented packet immediately after copying it even if it has not been checked yet. Although the forwarded packet might turn out to be a part of an attack, the store-through can successfully defend against the attack by blocking one of the subsequent packets. Testing of a prototype in linux kernel 2.4.30 demonstrated that the overhead of our mechanism is negligible compared with that of a simple IP forwarder even with the presence of out-of-order packets. Miyuki Hanaoka, Kenji Kono, Makoto Shimamura, Satoshi Yamaguchi |
ISCC | 2 |
| 2007 | FoxyTechnique: tricking operating system policies with a virtual machine monitorabstractIntegrating new resource management policies into operating systems (OSes) is an ongoing process. Despite innovative policy proposals being developed, it is quite difficult to deploy a new one widely because it is difficult, costly and often impractical endeavor to modify existing OSes to integrate a new policy. To address this problem, we explore the possibility of using virtual machine technology to incorporate a new policy into an existing OS without the need to make any changes to it. This paper describes FoxyTechnique, which virtualizes physical devices differently from real ones and tricks a guest OS into producing a behavior similar to a desired policy. FoxyTechnique offers several advantages. First, it allows us to implement a new policy without the need to make any changes to OS kernels. Second, Foxy-based policies are expected to be portable across different operating systems because they are isolated from guest OSes by stable virtual hardware interfaces. Finally, Foxy-based policies sometimes outperform guest OS policies because they can measure performance indicators more accurately than guest OSes. To demonstrate the usefulness of FoxyTechnique, we conducted two case studies, FoxyVegas and FoxyIdle, on the Xen virtual machine monitor. FoxyVegas and FoxyIdle tricked the original Linux and successfully mimicked TCP Vegas and Idletime scheduling, respectively. Kenji Kono |
VEE | 2 |
| 2006 | Using Attack Information to Reduce False Positives in Network IDSabstractReducing the rate of false positives is of vital importance in enhancing the usefulness of signature-based network intrusion detection systems (NIDSs). To reduce false positives, a network administrator must throughly investigate a lengthy list of signatures and carefully disable the ones that detect attacks not harmful to the user’s environment. This is a daunting task; if some signatures are disabled by mistake, the NIDS fails to detect critical remote attacks. We designed a NIDS, TrueAlarm, to reduce the rate of false positives. Conventional NIDSs alert administrators to the detection of a malicious message, regardless of whether the message actually attempts to compromise the protected server. In contrast, TrueAlarm delays the alert until it confirms that an attempt has been made. In TrueAlarm, NIDS cooperates with a server-side monitor that observes the protected server’s behavior. TrueAlarm alerts administrators only when a server-side monitor detects deviant server behavior that must have been caused by a message detected by NIDS. Our experimental results show that TrueAlarm reduces the rate of false positives. Using real network traffic collected over 15 days, TrueAlarm produced no false positives, while a conventional NIDS produced 125. Makoto Shimamura, Kenji Kono |
ISCC | 2 |
| 2006 | User-level disk-bandwidth control for resource-borrowing network applicationsabstractThis paper presents the design and implementation of DiscNice, a mechanism for controlling disk bandwidth at the user-level. To throttle disk I/O at the user-level, DiscNice infers what the internal behavior of the underlying OS is and predicts the disk I/O size that is incurred by file I/O. To infer internal kernel behavior, we extensively used a concept called the graybox technology and elaborated it to predict the disk I/O behavior. In the graybox technology, the underlying OS is treated as a graybox, which means that we could exploit: 1) our knowledge of the OS, 2) the state information the OS exposes to us, and 3) how the OS reacts to various operations to predict the internal kernel behavior. By exploiting the graybox knowledge on Linux, we developed a graybox technique for predicting the disk I/O behavior. Our technique could also be applied to Windows XP with minor modifications because it does not rely on a detailed knowledge of Linux Kenji Kono |
NOMS | 2 |
| 2001 | YabAI: The First Rescue Simulation League Champion
Takeshi Morimoto, Kenji Kono, Ikuo Takeuchi |
RoboCup | 2 |
| 2000 | Efficient RMI: Dynamic Specialization of Object SerializationabstractThis paper describes a novel approach to object serialization in remote method invocation (RMI). Object serialization transforms objects' representations between heterogeneous platforms. Efficient serialization is primary concern in RMI because the conventional approaches incur large runtime overheads. The approach described specializes a serializing routine dynamically according to a receiver's platform, and this routine converts the sender's in-memory representations of objects directly into the receiver's in-memory representations. This approach simplifies the process of RMI: the receiver can access the passed objects immediately without any data copies and data conversions. A new platform can join the existing community of senders and receivers because a specialized routine for the platform is generated as needed. Experimental results show that significant performance gains are obtained by this approach. The prototype implementation of this approach was 1.9-3.0 times faster than Sun XDR, and the time needed for generating a specialized routine was only 0.6 msec. Kenji Kono, Takashi Masuda |
ICDCS | 1 |
| 1999 | Efficient Kernel Support of Fine-Grained Protection Domains for Mobile CodeabstractMobile code is an emerging paradigm of distributed computing. It roams over a network, is linked with an application, and runs as a part of an application. In the case of Web browsers, it is commonplace to download a mobile code, called a plug-in, from a truly open network such as the Internet. Owing to the anonymity of an open network, the mobile code may be malicious; thus, it is important to protect local computing resources from attacks by malicious code. We have developed a kernel that supports fine-grained protection domains that preclude mobile code from making unauthorized accesses to the local resources. The developed scheme provides a novel mechanism, called a multi-protection page table, of virtual memory for creating fine-grained protection domains. The multi-protection page table enables efficient cross-domain calls, whereas it provides protection. Experimental results show that the developed scheme incurs only a 5.9% execution overhead even if cross domain calls occur 30000 times per second. Masahiko Takahashi, Kenji Kono, Takashi Masuda |
ICDCS | 2 |
| 1996 | An Implementation Method of Migratable Distributed Objects Using an RPC Technique Integrated with Virtual Memory Management
Kenji Kono, Kazuhiko Kato, Takashi Masuda |
ECOOP | 1 |
| 1994 | Smart Remote Procedure Calls: Transparent Treatment of Remote PointersabstractRemote procedure call (RPC) systems have been proven to be a practical basis for building distributed applications. The RPC technique abstracts a typical communication pattern to an ordinary procedure call. Compared with an ordinary procedure call, however, the conventional RPC technique has one evident restriction; pointers (addresses) cannot be passed to remote procedures without the explicit and nontrivial programming effort. This paper presents a method that eliminates this restriction. The method enables transparent treatment of pointers in RPC by combining three key techniques: virtual memory manipulation, pointer swizzling, and coherency protocol. The experiments performed using an implementation of the method show that the method provides performance that is scalable to the access ratio of the remotely referenced data.> Kenji Kono, Kazuhiko Kato, Takashi Masuda |
ICDCS | 1 |