EDBT 2026 Demo / reviewers in the wild / expert
Akira Fujita
dblp:97/3642
· DBLP profile ↗
10ranked-venue papers
2as first author
4since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 2 first-authorSecurity and privacy · 3 · 2 since 2021Systems, architecture and hardware · 2Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | VT-SOS: A Cost-effective URL Warning utilizing VirusTotal as a Second Opinion ServiceabstractThe menace of malicious websites, such as online scams or phishing, has exhibited a noteworthy surge. While URL-based blocklists are still used as the primary security solution, previous studies show that the range of protection provided by these lists has little overlap, and the demand to have a second opinion is growing. In this paper, we design a system that aggregates information from multiple security engines in VirusTotal and warns users with malicious URLs that a single antivirus product would dismiss. We introduce VT-SOS, a system utilizing VirusTotal to provide a Second Opinion. Using 47 days of web access logs of real users, we implemented VT-SOS and evaluated effectiveness, affordability, and usability. By simulation, we show that VT-SOS could warn more than 100 users/day and provide a second opinion for more than 30 URLs/day even under a tight budget. We compared VT-SOS with three popular security services and confirmed that it could cover a wider range of malicious websites than those services. By investigating the worst-case user with the most access and warning, we demonstrate that VT-SOS will not deeply affect user experience in practice. Kyohei Takao, Chika Hiraishi, Rui Tanabe, Kazuki Takada, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
NOMS | 5 |
| 2023 | Internet Service Providers' and Individuals' Attitudes, Barriers, and Incentives to Secure IoT
Nissy Sombatruang, Tristan Caulfield, Ingolf Becker, Akira Fujita, Takahiro Kasama, Koji Nakao |
USENIX Security Symposium | 4 |
| 2022 | Understanding the Characteristics of Public Blocklist ProvidersabstractWebsites can spread malware and phishing scams, and this represents a significant risk to users. To block such malicious websites, various organizations and individuals, e.g., security vendors, analyze URLs and create blocklists. Some blocklists are paid and some are free public blocklists; however, the effectiveness of public blocklists is generally not guaranteed. Thus, many studies have attempted to verify their effectiveness. To the best of our knowledge, public blocklist providers (PBP) have not been studied as rigorously as blocklists, and it is still unclear how blocklists should be operated and how PBP websites should be designed to maintain the effectiveness. Therefore, to unveil more characteristics of the PBP, we designed a measurement study to analyze PBPs in terms of lifespan, update frequency, entry bias, and user interface metrics. In this paper, we describe the results of measuring seven PBPs according to these four metrics. Mitsuhiro Umizaki, Tomohiro Morikawa, Akira Fujita, Takeshi Takahashi 0001, Tsungnan Lin |
ISCC | 3 |
| 2022 | Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesabstractGeographically distributed infrastructures, such as buildings, dams, and solar power plants, are commonly maintained via Internet-connected remote management devices. Previous studies on detecting and securing industrial control systems (ICS) have overlooked these remote management devices, as they do not expose ICS-specific services like Modbus and BACnet and thus do not show up in Internet-wide scans for such services. In this paper, we implement and validate a discovery method for these devices via their Web User Interface (WebUI) and detect 890 devices in Japan alone. We also show that many of these devices are highly insecure. Many allow access to the status or even the control over industrial systems without proper authentication. Taking a closer look at three prevalent remote management devices, we discovered 13 0-day vulnerabilities, several of which were rated as medium or high severity. They have been responsibly disclosed to the manufacturers. By using honeypots that imitate these systems, we show that over time, only a small number of attackers enter these systems, but some do change critical parameters. Attackers appear to interact more with the system when more facility information is displayed on the WebUI. Finally, we notified operators of 317 vulnerable remote management devices by email and telephone. We reached 212 persons in charge of the devices and received confirmation that our method had correctly identified the device. 50% of the persons in charge of the devices stated that they mitigated or will mitigate the problem. We confirmed their actions via a followup scan for vulnerable devices and found that measures were taken for 58% of the devices when we could reach the persons in charge of the device. Takayuki Sasaki, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
SP | 2 |
| 2020 | Disposable botnets: examining the anatomy of IoT botnet infrastructureabstractLarge botnets made up of Internet-of-Things (IoT) devices have been a steady presence in the threat landscape since 2016. Earlier research has found preliminary evidence that the IoT binaries and C&C infrastructure were only seen for very brief periods. It has not explained how attackers maintain control over their botnets. We present a more comprehensive analysis of the infrastructure of IoT botnets based on 23 months of data gathered via honeypots and the monitoring of botnet infrastructure. We collected 59,884 IoT malware samples, 35,494 download servers, and 2,747 C&C servers. We focuse on three dominant families: Bashlite, Mirai, and Tsunami. The picture that emerges is that of highly disposable botnets. IoT botnet are not so much maintained as reconstituted from scratch all the time. Not only are most binaries distributed for less than three days, the connection of bots to the rest of the botnet is also short-lived. To reach the C&C server, the binaries typically contain only a single hard-coded IP address or domain. The C&C servers themselves also have a short lifespan. Long-term dynamic analysis finds no mechanism for the attackers to migrate the bots to a new C&C server. In other words, bots are used only immediately after capture and then abandoned---perhaps to be recaptured again via the aggressive scanning practices that these botnets are known for. While IoT botnets appear less advanced than Windows-based botnets, the advantage of being disposable means that they are very resistant to blacklisting and C&C takedown. Most IP addresses are used only once and never seen again. The question that arises is how attackers source these addresses. We speculate that they might be abusing the IP address allocation practices of cloud providers. Rui Tanabe, Tatsuya Tamai, Akira Fujita, Ryoichi Isawa, Katsunari Yoshioka, Tsutomu Matsumoto, Carlos Gañán, Michel van Eeten |
ARES | 3 |
| 2016 | Translation Errors and Incomprehensibility: a Case Study using Machine-Translated Second Language Proficiency Tests
Takuya Matsuzaki, Akira Fujita, Naoya Todo, Noriko H. Arai |
LREC | 2 |
| 2015 | Trend in power devices for electric and hybrid electric vehiclesabstractSince the very successful release of the world's first mass-produced HEV (hybrid electric vehicle) in 1997, the number of HEVs as well as EVs (electric vehicles) has been gradually increasing in major cities around the world. Reliable and efficient power devices transferring energy between the battery and the motor/generator represent the heart of the electric power-train that realizes the electric-mobility concept. The objective of this presentation is to give a quick preview of the early mass-produced power modules for EV/HEVs and to highlight the advancement achieved so far in addressing the automotive severe reliability and high performance requirements. The presentation will also cover some of the power devices trends in terms of the major pillars comprising automotive power modules: (1) power chip technology, (2) packaging technology, and (3) functional integration as shown in Fig. 1. Khalid Hussein, Akira Fujita, Katsumi Sato |
ASP-DAC | 2 |
| 2014 | Cognitive Model of Generic Skill: Cognitive Processes in Search and Editing
Akira Fujita, Masayuki Suzuki, Noriko H. Arai |
CogSci | 1 |
| 2014 | Overview of Todai Robot Project and Evaluation Framework of its NLP-based Problem Solving
Akira Fujita, Akihiro Kameda, Ai Kawazoe, Yusuke Miyao |
LREC | 1 |
| 2004 | Semi-autonomous Reconfiguration of Wheeled Mobile Robots in CoordinationabstractThis paper investigates multiple wheeled mobile manipulators coordinating with each other for a common task such as transporting a common object. In our previous work we derived kinematic and dynamic manipulability measures for multiple mobile manipulators transporting a common object and also developed a simulation environment. The main objective of this paper is to conduct experiments with two different real robot systems, arm-type and table-type, and compare them with simulation results. Collision avoidance is also considered, in which they maneuver to avoid a collision while maintaining support for the object. Yoshio Yamamoto, Yoshihisa Hiyama, Akira Fujita |
ICRA | 3 |