EDBT 2026 Demo / reviewers in the wild / expert
Yuhei Kawakoya
dblp:91/1382
· DBLP profile ↗
9ranked-venue papers
3as first author
3since 2021 · last 2024
0009-0005-9310-0493ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | SmmPack: Obfuscation for SMM Modules with TPM Sealed Key
Kazuki Matsuo, Satoshi Tanda, Kuniyasu Suzaki, Yuhei Kawakoya, Tatsuya Mori 0003 |
DIMVA | 4 |
| 2023 | Xunpack: Cross-Architecture Unpacking for Linux IoT MalwareabstractAlthough the vast majority of malware used to be x86 architecture-based, the rapid rise of Internet of Things (IoT) malware in recent years has been forcing malware analysts to deal with binaries written for a wide range of architectures with little tooling support. Yuhei Kawakoya, Shu Akabane, Makoto Iwamura, Takeshi Okamoto |
RAID | 1 |
| 2022 | Script Tainting Was Doomed From The Start (By Type Conversion): Converting Script Engines into Dynamic Taint Analysis FrameworksabstractData flow analysis is an essential technique for understanding the complicated behavior of malicious scripts. For tracking the data flow in scripts, dynamic taint analysis has been widely adopted by existing studies. However, the existing taint analysis techniques have a problem that each script engine needs to be separately designed and implemented. Given the diversity of script languages that attackers can choose for their malicious scripts, it is unrealistic to prepare taint analysis tools for the various script languages and engines. Toshinori Usui, Yuto Otsuki, Yuhei Kawakoya, Makoto Iwamura, Kanta Matsuura |
RAID | 3 |
| 2020 | Is stateful packrat parsing really linear in practice? a counter-example, an improved grammar, and its parsing algorithmsabstractStateful packrat parsing is an algorithm for parsing syntaxes that have context-sensitive features. It is a well-known knowledge among researchers that the running time of stateful packrat parsing is linear for real-world grammars, as demonstrated in existing studies. However, we have found the cases in real-world grammars and tools that lead its running time to become exponential. Nariyoshi Chida, Yuhei Kawakoya, Dai Ikarashi, Kenji Takahashi, Koushik Sen |
CC | 2 |
| 2019 | EIGER: automated IOC generation for accurate and interpretable endpoint malware detectionabstractA malware signature including behavioral artifacts, namely Indicator of Compromise (IOC) plays an important role in security operations, such as endpoint detection and incident response. While building IOC enables us to detect malware efficiently and perform the incident analysis in a timely manner, it has not been fully-automated yet. To address this issue, there are two lines of promising approaches: regular expression-based signature generation and machine learning. However, each approach has a limitation in accuracy or interpretability, respectively. Yuma Kurogome, Yuto Otsuki, Yuhei Kawakoya, Makoto Iwamura, Syogo Hayashi, Tatsuya Mori 0003, Koushik Sen |
ACSAC | 3 |
| 2019 | My script engines know what you did in the dark: converting engines into script API tracersabstractMalicious scripts have been crucial attack vectors in recent attacks such as malware spam (malspam) and fileless malware. Since malicious scripts are generally obfuscated, statically analyzing them is difficult due to reflections. Therefore, dynamic analysis, which is not affected by obfuscation, is used for malicious script analysis. However, despite its wide adoption, some problems remain unsolved. Current designs of script analysis tools do not fulfill the following three requirements important for malicious script analysis. (1) Universally applicable to various script languages, (2) capable of outputting analysis logs that can precisely recover the behavior of malicious scripts, and (3) applicable to proprietary script engines. Toshinori Usui, Yuto Otsuki, Yuhei Kawakoya, Makoto Iwamura, Jun Miyoshi, Kanta Matsuura |
ACSAC | 3 |
| 2017 | Stealth Loader: Trace-Free Program Loading for API Obfuscation
Yuhei Kawakoya, Eitaro Shioji, Yuto Otsuki, Makoto Iwamura, Takeshi Yada |
RAID | 1 |
| 2013 | API Chaser: Anti-analysis Resistant Malware Analyzer
Yuhei Kawakoya, Makoto Iwamura, Eitaro Shioji, Takeo Hariu |
RAID | 1 |
| 2012 | Code shredding: byte-granular randomization of program layout for detecting code-reuse attacksabstractCode-reuse attacks by corrupting memory address pointers have been a major threat of software for many years. There have been numerous defenses proposed for countering this threat, but majority of them impose strict restrictions on software deployment such as requiring recompilation with a custom compiler, or causing integrity problems due to program modification. One notable exception is ASLR(address space layout randomization) which is a widespread defense free of such burdens, but is also known to be penetrated by a class of attacks that takes advantage of its coarse randomization granularity. Focusing on minimizing randomization granularity while also possessing these advantages of ASLR to the greatest extent, we propose a novel defensive approach called code shredding: a defensive scheme based on the idea of embedding the checksum value of a memory address as a part of itself. This simple yet effective approach hinders designation of specific address used in code-reuse attacks, by giving attackers an illusion of program code shredded into pieces at byte granularity and dispersed randomly over memory space. We show our design and implementation of a proof-of-concept prototype system for the Windows platform and the results from several experiments conducted to confirm its feasibility and performance overheads. Eitaro Shioji, Yuhei Kawakoya, Makoto Iwamura, Takeo Hariu |
ACSAC | 2 |