Theodore Tryfonas

dblp:03/4038 · also Theo Tryfonas · DBLP profile ↗
← Back
51ranked-venue papers
5as first author
8since 2021 · last 2025
0000-0003-4024-8003ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 5 first-authorComputer networks · 10 · 1 since 2021Human-computer interaction and ubiquitous computing · 7 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6Artificial intelligence and machine learning · 4Systems, architecture and hardware · 3 · 3 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Digital Twins in the Built Environment for Indoor Air Quality Management
abstract
Indoor air quality (IAQ) is a crucial aspect of the performance of the built environment that influences the health and wellbeing of occupants. A digital twin (DT) is an emerging technology that enables mirroring of real-world conditions to optimize building operations in anticipation of improvements of the occupant experience. However, existing studies and applications lack a holistic approach using digital twin technologies to quantitatively analyze the interactions between factors affecting indoor air quality. To fill this gap, two cases in a university building in Bristol were selected for in-depth study. IAQ was measured with sensors and simulated using computational fluid dynamics (CFD) in four scenarios. The results show that air temperature and humidity were not significantly affected across different scenarios, whereas CO₂ concentration varied distinctly under different conditions. In the four scenarios, the deviations of the CFD-simulated CO₂ outcomes from real-world measurements were 0.9%, 6.4%, 2.6%, and 2.8% respectively, demonstrating that the CFD simulation can predict and manage indoor air quality with high accuracy. This research reveals the extent to which IAQ factors (e.g., temperature, humidity, CO₂) are affected by window or door operation, room size and occupant distribution. Accordingly, measures for applying multi-functional sensors to monitor building conditions, simulating indoor air quality and optimizing building operations are proposed with the support of digital twin technologies.
Jinhai Tang, Theodore Tryfonas
ETFA3
2025 Transforming Open Urban Data into Infrastructure Supporting Air Quality Interventions
abstract
Urbanisation has led to urban population growth affecting the economy and the environment, including degrading air quality via pollution. Air pollution has been linked to a variety of conditions and health risks including heart disease, stroke, asthma, Alzheimer's and neurodevelopmental disorders. However, it is difficult for a citizen to find precise air pollution data at a particular location. Smart City strategies usually stipulate that city councils should focus on delivering platforms for active citizen participation using existing technology. Existing civic data hubs such as the London Datastore, Open Data Bristol etc., provide air pollution data but lack elaborate representations for user-defined locations. Existing air quality initiatives such as the Smart Citizen platform and Sensor.Community provide more advanced graphical representations. However, they restrict themselves to showing data coming from their respective devices. The paper presents the Open City Air Quality Platform (OpenCAQP), a development that merges a wide range of data sources and air pollution parameters into a single platform. The OpenCAQP allows citizens, environmentalists, data analysts, and developers to access and visualise data. The proposed solution contributes to two key objectives: i) analysis of the air pollution data sources available in a city; ii) a replicable scalable, modular open source capability aggregating and visualising air pollution data from multiple sources. Its effectiveness has been evaluated by measuring quality, usability and increased awareness of users through a feedback questionnaire.
Kévin Jolly, Sam Gunner, Maria Pregnolato, Patrick Tully, Theodore Tryfonas
HPCC6
2025 The Spacecraft Early Analysis Model: An MBSE Framework for Early Analysis of Spacecraft Behavior
abstract
Model-based systems engineering (MBSE) represents a move away from the traditional approach to systems engineering. MBSE has the potential to promote consistency, communication, clarity and maintainability within systems engineering projects. MBSE also has the potential to address one of the well-known issues of the systems engineering process—the late discovery of errors or design faults. In this article, the development of the “Spacecraft early analysis model” (SEAM) is detailed and the current version is presented. The SEAM is a model-based framework developed by the authors to define, execute and analyze spacecraft structure and behavior during preliminary design. The SEAM comprises multiple modules (Project, Requirements, Mission, System, Operations) that enable the definition of the spacecraft and its supporting systems, and enables each to be updated independently. The SEAM incorporates a novel behavioral pattern that structures the modes and functions of the spacecraft using state machines and activities. Using this pattern, the behavior itself is not prescribed, as is common in similar model-based representations of spacecraft. The user defines individual functions and modes, and the user then simulates the behavior of the spacecraft in response to a concept of operations (ConOps). In this article, the need for the SEAM, the development approach, the SEAM composition and the limitations of the SEAM are presented and discussed.
Joe Gregory, Lucy Berthoud, Theodore Tryfonas, Ludovic Faure, Antonio Prezzavento
IEEE Trans. Syst. Man Cybern. Syst.3
2024 Unweaving the Definitions of Complexity
abstract
The definition of complexity is contentious. The lack of a univocal definition for complexity is leading to a cacophony of different views and lexicons, limiting the collective ability to handle complexity effectively. This article aims to resolve this impasse by identifying or developing a useful and acceptable definition of complexity by focusing on how this term is used in practice, and hence determine which definition resonates with the broadest possible community. To understand how the term is being used, several popular complexity-definitions have been identified and de-constructed into component definitional elements. These elements are then compared to the descriptions of complexity in a range of key community documents to infer which definitions most align with the document authors usage of the complex term. The results indicate that new emergent definitions are far more popular than the established dictionary and complexity theory definitions, supporting previous surveys. These usage insights are then analyzed to develop a definition that can unify, as much as possible, the different complexity perspectives. The proposed definition establishes that complex(ity) is when relationships between elements are weaved together such that they are not fully comprehended, leading to insufficient certainty between cause and effect. This definition was tested at a series of international workshops and accepted as the most useful definition.
Dean Beale, Francesco Dazzi, Theodore Tryfonas
IEEE Trans. Syst. Man Cybern. Syst.3
2023 A Conceptual Architecture for Scalable Multi-Application Support in Blockchain-based IoT Environments
abstract
Existing proposals that merge IoT with blockchain technologies have been efficient but often limited to a single application scenario. They require specific hardware setups, thus in case of switching to a new application scenario, they may become ineffective and require a new hardware setup. In this paper, we present a new blockchain-based architecture for IoT environments that addresses one of the fundamental challenges in the area which is the capability of supporting multiple application scenarios. The proposed architecture enables transitioning between various application scenarios via smart contracts and configuration files stored on blockchain. The architecture, additionally, addresses scalability concerns of the blockchain-based IoT systems through a cluster-based approach which provides a more flexible and secure solution.
Akin Eker, Theodore Tryfonas, George C. Oikonomou
INDIN2
2023 Blockchain-based Zero Trust Cybersecurity in the Internet of Things
abstract
Blockchain-based Zero Trust Cybersecurity in the Internet of Things 1 INTRODUCTIONThe Internet of Things (IoT) connects a massive number of smart devices to the Internet, in which all data, applications, devices, and users require connectivity, security, and trust.Traditional security approaches assume that all participants within the network perimeter are trustworthy.However, in IoT environment data, applications, devices, and users are gradually moving outside the traditional trusted defence perimeter and have become a source of security risks.Unlike traditional security approaches, which are initially designed for the optimum protection and only act if a process is malicious, the zero-trust security framework upholds the "verify and never trust" principle.Zero trust-based approaches assume that everything within the system is untrustworthy and needs to be verified to prevent threats.Meanwhile, the blockchain technology shows promises on cyber security and several blockchain security mechanisms have been developed, including access management, user authentication, and transaction security.Due to its prowess in enhancing cyber security, blockchain can provide zero trust security framework with highly accessible and transparent security mechanisms via a visible blockchain, in which all transactions are visible to restricted operators.Zero-trust models can be secured further by a blockchain due to its sheer immutable nature and blockchain technology is expected to recognise them, authenticate their trust, and allow them access.Blockchain-enabled zero trust security can detect suspicious online transaction, isolate connection, and restrict access to the user.This special issue received in total 37 high-quality submissions.Per journal policy, it was ensured that handling editors did not have any potential conflict of interest with authors of submitted papers.All submitted papers were reviewed by at least three independent potential referees.The papers were evaluated for their rigor and quality, and also for their relevance to the theme of our special issue.After evaluating the overall scores, seven papers were selected by the guest editors and approved by the Editor-in-Chief for inclusion in this special issue.We will now briefly introduce the accepted papers. THE PAPERSThe paper entitled "Three-tier storage framework based on TBchain and IPFS for protecting IoT security and privacy" by authors Li et al. proposed to use a three-tier blockchain to split
Shancang Li, Surya Nepal, Theodore Tryfonas, Hongwei Li 0001
ACM Trans. Internet Techn.3
2021 A Reference Implemenation for RPL Attacks Using Contiki-NG and COOJA
abstract
RPL-based IoT networks are vulnerable to routing attacks as well as flooding attacks. Developing security countermeasures requires knowledge of possible attacks, their timing, and combinations. Most implementations of RPL related attacks only consider individual attacks triggered when their simulation starts. Furthermore, nodes which to be compromised are preselected before a simulation starts and cannot later be changed. In this paper, we present a Contiki-NG implementation of most known RPL attacks all of which is shared on a public Github repository. In addition, we designed a framework in COOJA to facilitate simulating hybrid RPL attacks with different settings in terms of duration and severity.
Faya Algahtani, Theodore Tryfonas, George C. Oikonomou
DCOSS2
2021 Investigating the Flexibility of the MBSE Approach to the Biomass Mission
abstract
Model-based systems engineering (MBSE) represents a move away from the traditional approach of document-based systems engineering (DBSE), and is used to promote consistency, communication, clarity, and maintainability within systems engineering projects. MBSE offers approaches that can address issues associated with cost, complexity, and safety. One way that this can be achieved is by performing early functional validation of the high-level spacecraft functional avionics system. The use case discussed in this article focusses on the Biomass model, a systems modeling language-based representation of the Biomass Earth-observation mission. The MBSE approach is used to calculate the required size of the data handling unit onboard the Biomass spacecraft. The functional response of the system in terms of the onboard memory usage throughout the mission is simulated. Traditionally, this level of analysis would not be available at this early stage. The approach aims to replace ad hoc, spreadsheet-based calculations with a formal representation of the system that can be executed, interrogated and quantified. The flexibility of this MBSE approach is demonstrated by applying changes to the Biomass project and assessing the time required to implement these changes in the Biomass model and propagate them through to the results of the simulation. The changes have been made independently of each other and include: changes to the logical architecture, changes to the functional definition, changes to the mission profile, and changes to the requirements. Potential areas for improvement regarding the structure of the Biomass model are highlighted and discussed.
Joe Gregory, Lucy Berthoud, Theodore Tryfonas, Antonio Prezzavento, Ludovic Faure
IEEE Trans. Syst. Man Cybern. Syst.3
2020 The long and winding road: MBSE adoption for functional avionics of spacecraft
abstract
Model-Based Systems Engineering (MBSE) represents a move away from the traditional approach of Document-Based Systems Engineering (DBSE). It is claimed that MBSE promotes consistency, communication, clarity and maintainability within systems engineering projects and addresses issues associated with cost, complexity and safety. While these potential benefits of MBSE are generally agreed upon by would-be practitioners, its implementation is challenging and many organisations struggle to overcome the cultural and technical hurdles along the long and winding road to MBSE adoption. In this paper, we aim to ease the process of implementation by investigating where the current issues with the existing systems engineering processes lie, and where a model-based approach may be able to help, from the perspective of engineers working on spacecraft functional avionics in Airbus. A repeatable process has been developed to elicit this information. Semi-structured interviews have been conducted with 25 Airbus engineers working in Operations, Software and Failure, Detection, Isolation and Recovery. The acquired data has been thematically analysed to extract common themes from the responses. The results presented in this paper have yielded four recommended application areas to consider when applying MBSE to Functional Avionics: organisation modelling; early functional validation; communication and consistency; template model framework development.
Joe Gregory, Lucy Berthoud, Theodore Tryfonas, Alain Rossignol, Ludovic Faure
J. Syst. Softw.3
2019 Towards Asthma Self-Management: An Integrated Ontology Model for Asthma Action Plan
abstract
Asthma is a chronic disease that cannot be cured but however it can be managed. There are different ways for Asthma management and the Asthma Action Plan is one of the self-management methods used for managing and monitoring a patient's condition. In this paper, we use an ontology-based method to identify and classify Asthma Action Plan terminologies and integrate respective models with demographics of asthma patients for the purpose of personalisation. We propose a personalised Asthma Patients Profile Model and integrate it with an Action Plan Model and Asthma Disease Model. These can be subsequently used for the development of software applications integrating patient records and contextual data from wearables and sensors, in order to provide personalised disease management plans per patient.
Fatmah Bamashmoos, Theodore Tryfonas
BIBM2
2019 A Proactive Genotype for Cybernetic Systems
abstract
This paper details a concept model for proactive competence, that provides a bridge between Situational Awareness (SA) and Operational Agility (OA) models. The model addresses a gap within the literature for an end-to-end view of the functions required for effective awareness and proactive action. A set of common concepts from different SA-domains are defined to provide a consistent approach and improve the interface of models implemented across different domains. An abstract OA model is developed and the concepts defined, as there lacks an underpinning theory within agility literature. Cybernetic principles are applied to ensure the viability of the model as a potential blueprint for the design of system architecture and provide a measure of underpinning theory to SA and OA models that has been lacking from existing approaches. The Viable System Model (VSM) provides the framework upon which to develop the concept model and demonstrate how a cybernetic approach may contribute to SA and OA literature.
Richard Craig, Theodore Tryfonas, John May
SMC2
2019 Special issue on security of IoT-enabled infrastructures in smart cities
Ali Ismail Awad, Steven Furnell, Abbas M. Hassan, Theodore Tryfonas
Ad Hoc Networks4
2019 Efficient DCT-based secret key generation for the Internet of Things
abstract
Cryptography is one of the most widely employed means to ensure confidentiality in the Internet of Things (IoT). Establishing cryptographically secure links between IoT devices requires the prior consensus to a secret encryption key. Yet, IoT devices are resource-constrained and cannot employ traditional key distribution schemes. As a result, there is a growing interest in generating secret random keys locally, using the shared randomness of the communicating channel. This article presents a secret key generation scheme, named SKYGlow, which is targeted at resource-constrained IoT platforms and tested on devices that employ IEEE 802.15.4 radios. We first examine the practical upper bounds of the number of secret bits that can be extracted from a message exchange. We contrast these upper bounds with the current state-of-the-art, and elaborate on the workings of the proposed scheme. SKYGlow applies the Discrete Cosine Transform (DCT) on channel observations of exchanged messages to reduce mismatches and increase correlation between the generated secret bits. We validate the performance of SKYGlow in both indoor and outdoor scenarios, at 2.4 GHz and 868 MHz respectively. The results suggest that SKYGlow can create secret 128-bit keys of 0.9978 bits entropy with just 65 packet exchanges, outperforming the state-of-the-art in terms of energy efficiency.
George Margelis, Xenofon Fafoutis, George C. Oikonomou, Robert J. Piechocki, Theodore Tryfonas
Ad Hoc Networks5
2018 Exploring Potential 6LoWPAN Traffic Side Channels
Yan Yan 0018, Elisabeth Oswald, Theodore Tryfonas
EWSN3
2018 Popularity and Geospatial Spread of Trends on Twitter: A Middle Eastern Case Study
Nabeel Albishry, Tom Crick, Tesleem Fagade, Theodore Tryfonas
ICCCI (1)4
2017 Physical layer secret-key generation with discreet cosine transform for the Internet of Things
abstract
The confidentiality of communications in the Internet of Things (IoT) is critical, with cryptography currently being the most widely employed method of ensuring it. Establishing cryptographically secure communication links between two transceivers requires the pre-agreement on some key, unknown to an external attacker. In recent years there has been growing attention in techniques that generate a shared random key through observation of the channel and its effects on the exchanged messages. In this work we present SKYGlow, a novel scheme for secret-key generation, designed for IoT devices, such as IEEE 802.15.4 and Bluetooth Low Energy (BLE) transceivers. SKYGlow employs the Discreet Cosine Transform (DCT) of channel observations and Slepian-Wolf coding for information reconciliation. Real-life experiments have resulted in the creation of 128-bit secret keys with only 65 packet exchanges and with an entropy of 0.9978 bits, making our scheme much more energy-efficient compared with others in the existing literature.
George Margelis, Xenofon Fafoutis, George C. Oikonomou, Robert J. Piechocki, Theodore Tryfonas
ICC5
2017 "Come Together!": Interactions of Language Networks and Multilingual Communities on Twitter
Nabeel Albishry, Tom Crick, Theodore Tryfonas
ICCCI (2)3
2017 Link quality and path based clustering in IEEE 802.15.4-2015 TSCH networks
abstract
Advance clustering techniques have been widely used in Wireless Sensor Networks (WSNs) since they can potentially reduce latency, improve scheduling, decrease end-to-end delay and optimise energy consumption within a dense network topology. In this paper, we present a novel clustering algorithm for high density IEEE 802.15.4-2015 Time-Slotted Channel Hopping (TSCH). In particular, the proposed methodology merges a variety of solutions into an integrated clustering design. Assuming an homogeneous network distribution, the proposed configuration deploys a hierarchical down-top approach of equally numbered sub-groups, in which the formation of the separate sub-groups is adapted to the network density and the node selection metric is based on the link quality indicator. The presented algorithm is implemented in Contiki Operating System (OS) and several test vectors have been designed in order to evaluate the performance of the proposed algorithm in a COOJA simulation environment. Performance results demonstrate the capability of the clustering structure since compared to the default scheme it significantly improves the energy efficiency up to 35%, packet drops more than 40% as well the packet retransmission rate. Last but not least, the outcome of this study indicates a major increase in the network lifetime, i.e., up to 50%.
Alexandros Mavromatis, Georgios Z. Papadopoulos, Xenofon Fafoutis, Angelos A. Goulianos, George C. Oikonomou, Periklis Chatzimisios, Theodore Tryfonas
ISCC7
2017 Optimized Certificate Revocation List Distribution for Secure V2X Communications
abstract
The successful deployment of safe and trustworthy Connected and Autonomous Vehicles (CAVs) will highly depend on the ability to devise robust and effective security solutions to resist sophisticated cyber attacks and patch up critical vulnerabilities. Pseudonym Public Key Infrastructure (PPKI) is a promising approach to secure vehicular networks as well as ensure data and location privacy, concealing the vehicles' real identities. Nevertheless, pseudonym distribution and management affect PPKI scalability due to the significant number of digital certificates required by a single vehicle. In this paper, we focus on the certificate revocation process and propose a versatile and low- complexity framework to facilitate the distribution of the Certificate Revocation Lists (CRL) issued by the Certification Authority (CA). CRL compression is achieved through optimized Bloom filters, which guarantee a considerable overhead reduction with a configurable rate of false positives. Our results show that the distribution of compressed CRLs can significantly enhance the system scalability without increasing the complexity of the revocation process.
Giovanni Rigazzi, Andrea Tassi, Robert J. Piechocki, Theodore Tryfonas, Andrew R. Nix
VTC Fall4
2017 Privacy Leakage of Physical Activity Levels in Wireless Embedded Wearable Systems
abstract
With the ubiquity of sensing technologies in our personal spaces, the protection of our privacy and the confidentiality of sensitive data becomes a major concern. In this letter, we focus on wearable embedded systems that communicate data periodically over the wireless medium. In this context, we demonstrate that private information about the physical activity levels of the wearer can leak to an eavesdropper through the physical layer. Indeed, we show that the physical activity levels strongly correlate with changes in the wireless channel that can be captured by measuring the signal strength of the eavesdropped frames. We practically validate this correlation in several scenarios in a real residential environment, using data collected by our prototype wearable accelerometer-based sensor. Finally, we propose a privacy enhancement algorithm that mitigates the leakage of this private information.
Xenofon Fafoutis, Letizia Marchegiani, Georgios Z. Papadopoulos, Robert J. Piechocki, Theodore Tryfonas, George C. Oikonomou
IEEE Signal Process. Lett.5
2016 Smart Attacks on the Integrity of the Internet of Things: Avoiding Detection by Employing Game Theory
abstract
The Internet of Things (IoT) is expected to connect billions of devices, that will interact with their physical environment through sensors or actuators. The measurements created from these sensors have varying levels of precision, leading to measurements that follow a distribution, whose variance presents an additional challenge for the employed security schemes. In this work we assume a smart attacker would attempt to mask his attack in the inherent uncertainty of the measurements, and attempt to manipulate the distribution of measurements as covertly as possible to affect the final meaningful value that the system would result in. We employ Game Theory to examine the best strategies to slowly corrupt the integrity of an IoT network, similar to ETSI's Low Throughput Networks (LTN). We examine the extent of the changes that can be made to the distribution without assuming a priori knowledge of it by the attacker, for different scenarios and compromisation patterns. To the best of our knowledge this is the first attempt to examine the limits of the compromise that could be applied by a smart attacker on an IoT/LTN-type network without triggering outlier-alarms, and can be applied in the design of better targeted defensive measures.
George Margelis, Robert J. Piechocki, Theodore Tryfonas
GLOBECOM3
2016 A Mobility-Supporting MAC Scheme for Bursty Traffic in IoT and WSNs
abstract
Recent boom of mobile applications has become an essential class of mobile Internet of Things (IoT), whereby large amounts of sensed data are collected and shared by mobile sensing devices for observing phenomena such as traffic or the environmental. Currently, most of the proposed Medium Access Control (MAC) protocols mainly focus on static networks. However, mobile sensor nodes may pose many communication challenges during the design and development of a MAC protocol. These difficulties first require an efficient connection establishment between a mobile and static node, and then an efficient data packet transmissions. In this study, we propose MobIQ, an advanced mobility-handling MAC scheme for low-power MAC protocols, which achieves for efficient neighbour(hood) discovery and low-delay communication. Our thorough performance evaluation, conducted on top of Contiki OS, shows that MobIQ outperforms state-of-the-art solutions such as MoX-MAC, MOBINET and ME-ContikiMAC, in terms of significantly reducing delay, contention to the medium and energy consumption.
Georgios Z. Papadopoulos, Vasileios Kotsiou, Antoine Gallais, George C. Oikonomou, Periklis Chatzimisios, Theodore Tryfonas, Thomas Noël
GLOBECOM6
2016 Optimizing Short Message Text Sentiment Analysis for Mobile Device Forensics
Oluwapelumi Aboluwarin, Panagiotis Andriotis, Atsuhiro Takasu, Theodore Tryfonas
IFIP Int. Conf. Digital Forensics4
2016 Impact of User Data Privacy Management Controls on Mobile Device Investigations
Panagiotis Andriotis, Theodore Tryfonas
IFIP Int. Conf. Digital Forensics2
2016 Impact of Guard Time Length on IEEE 802.15.4e TSCH Energy Consumption
abstract
The IEEE 802.15.4-2015 standard defines a number of Medium Access Control (MAC) layer protocols for low-power wireless communications in the IoT. Originally defined in the IEEE 802.15.4e amendment, TSCH (Time Slotted Channel Hopping) is among the proposed mechanisms. TSCH is a scheme aiming to guarantee network reliability by keeping nodes time-synchronised at the MAC layer. In order to ensure successful communication between a sender and a receiver, the latter starts listening shortly before the expected time of a MAC layer frame's arrival. The offset between the time a node starts listening and the estimated time of frame arrival is called guard time and it aims to reduce the probability of missed frames due to clock drift. In this poster, we investigate the effect of the guard time duration on energy consumption. We identify that, when using the 6tisch minimal schedule, the most significant cause of energy consumption is idle listening during guard time. Therefore, the energy-efficiency of TSCH can be significantly improved by guard time optimisation. Our performance evaluation results, conducted using the Contiki operating system, show that an efficient configuration of guard time may reduce energy consumption by up to 30%, without compromising network reliability.
Alexandros Mavromatis, Georgios Z. Papadopoulos, Xenofon Fafoutis, Atis Elsts, George C. Oikonomou, Theodore Tryfonas
SECON6
2016 A study on usability and security features of the Android pattern lock screen
abstract
Purpose – The Android pattern lock screen (or graphical password) is a popular user authentication method that relies on the advantages provided by the visual representation of a password, which enhance its memorability. Graphical passwords are vulnerable to attacks (e.g. shoulder surfing); thus, the need for more complex passwords becomes apparent. This paper aims to focus on the features that constitute a usable and secure pattern and investigate the existence of heuristic and physical rules that possibly dictate the formation of a pattern. Design/methodology/approach – The authors conducted a survey to study the users’ understanding of the security and usability of the pattern lock screen. The authors developed an Android application that collects graphical passwords, by simulating user authentication in a mobile device. This avoids any potential bias that is introduced when the survey participants are not interacting with a mobile device while forming graphical passwords (e.g. in Web or hard-copy surveys). Findings – The findings verify and enrich previous knowledge for graphical passwords, namely, that users mostly prefer usability than security. Using the survey results, the authors demonstrate how biased input impairs security by shrinking the available password space. Research limitations/implications – The sample’s demographics may affect our findings. Therefore, future work can focus on the replication of our work in a sample with different demographics. Originality/value – The authors define metrics that measure the usability of a pattern (handedness, directionality and symmetry) and investigate their impact to its formation. The authors propose a security assessment scheme using features in a pattern (e.g. the existence of knight moves or overlapping nodes) to evaluate its security strengths.
Panagiotis Andriotis, George C. Oikonomou, Alexios Mylonas, Theodore Tryfonas
Inf. Comput. Secur.4
2016 Highlighting Relationships of a Smartphone's Social Ecosystem in Potentially Large Investigations
abstract
Social media networks are becoming increasingly popular because they can satisfy diverse needs of individuals (both personal and professional). Modern mobile devices are empowered with increased capabilities, taking advantage of the technological progress that makes them smarter than their predecessors. Thus, a smartphone user is not only the phone owner, but also an entity that may have different facets and roles in various social media networks. We believe that these roles can be aggregated in a single social ecosystem, which can be derived by the smartphone. In this paper, we present our concept of the social ecosystem in contemporary devices and we attempt to distinguish the different communities that occur from the integration of social networking in our lives. In addition, we propose techniques to highlight major actors within the ecosystem. Moreover, we demonstrate our suggested visualization scheme, which illustrates the linking of entities that live in separate communities using data taken from the smartphone. Finally, we extend our concept to include various parallel ecosystems during potentially large investigations and we link influential entities in a vertical fashion. We particularly examine cases where data aggregation is performed by specific applications, producing volumes of textual data that can be analyzed with text mining methods. Our analysis demonstrates the risks of the rising "bring your own device" trend in enterprise environments.
Panagiotis Andriotis, George C. Oikonomou, Theodore Tryfonas, Shancang Li
IEEE Trans. Cybern.3
2016 Risk Assessment for Mobile Systems Through a Multilayered Hierarchical Bayesian Network
abstract
Mobile systems are facing a number of application vulnerabilities that can be combined together and utilized to penetrate systems with devastating impact. When assessing the overall security of a mobile system, it is important to assess the security risks posed by each mobile applications (apps), thus gaining a stronger understanding of any vulnerabilities present. This paper aims at developing a three-layer framework that assesses the potential risks which apps introduce within the Android mobile systems. A Bayesian risk graphical model is proposed to evaluate risk propagation in a layered risk architecture. By integrating static analysis, dynamic analysis, and behavior analysis in a hierarchical framework, the risks and their propagation through each layer are well modeled by the Bayesian risk graph, which can quantitatively analyze risks faced to both apps and mobile systems. The proposed hierarchical Bayesian risk graph model offers a novel way to investigate the security risks in mobile environment and enables users and administrators to evaluate the potential risks. This strategy allows to strengthen both app security as well as the security of the entire system.
Shancang Li, Theodore Tryfonas, Gordon Russell 0001, Panagiotis Andriotis
IEEE Trans. Cybern.2
2015 A Framework for Describing Multimedia Circulation in a Smartphone Ecosystem
Panagiotis Andriotis, Theodore Tryfonas, George C. Oikonomou, Irwin King
IFIP Int. Conf. Digital Forensics2
2015 Application of a Game Theoretic Approach in Smart Sensor Data Trustworthiness Problems
Konstantinos Maraslis, Theodoros Spyridopoulos, George C. Oikonomou, Theodore Tryfonas, Mo Haghighi
SEC4
2015 Class Based Overall Priority Scheduling for M2M Communications over LTE Networks
abstract
The rapidly increasing demand of M2M (Machine to Machine) communications poses great challenges to the capacity of cellular networks. This paper proposes a new M2M scheduling algorithm, namely, Class Based Overall Priority (CBOP) scheduling, which is designed particularly to improve uplink scheduling for a massive number of MTCDs (Machine Type Communication Devices) in LTE networks. We compare the proposed algorithm with several existing scheduling algorithms via simulations and discuss its advantages and limitations.
Beichen Chen, Zhong Fan, Fengming Cao, George C. Oikonomou, Theodore Tryfonas
VTC Spring5
2014 Smartphone Message Sentiment Analysis
Panagiotis Andriotis, Atsuhiro Takasu, Theodore Tryfonas
IFIP Int. Conf. Digital Forensics3
2014 A Holistic Approach for Cyber Assurance of Critical Infrastructure with the Viable System Model
Theodoros Spyridopoulos, Ioanna-Aikaterini Topa, Theodore Tryfonas, Maria Karyda 0001
SEC3
2014 Soft systems methodology in net-centric cyber defence system development
abstract
Complexity is ever increasing within our information environment and organisations, as interdependent dynamic relationships within sociotechnical systems result in high variety and uncertainty from a lack of information or control. A net-centric approach is a strategy to improve information value, to enable stakeholders to extend their reach to additional data sources, share Situational Awareness (SA), synchronise effort and optimise resource use to deliver maximum (or proportionate) effect in support of goals. This paper takes a systems perspective to understand the dynamics within a net-centric information system. This paper presents the first stages of the Soft Systems Methodology (SSM), to develop a conceptual model of the human activity system and develop a system dynamics model to represent system behaviour, that will inform future research into a net-centric approach with information security. Our model supports the net-centric hypothesis that participation within a information sharing community extends information reach, improves organisation SA allowing proactive action to mitigate vulnerabilities and reduce overall risk within the community. The system dynamics model provides organisations with tools to better understand the value of a net-centric approach, a framework to determine their own maturity and evaluate strategic relationships with collaborative communities.
Richard Craig, Theodoros Spyridopoulos, Theodore Tryfonas, John May
SMC3
2014 A viable systems approach towards cyber situational awareness
abstract
There is a gap in the ability to gain sufficient Situational Awareness (SA) of the cyber domain at the strategic level, leading nations and organisations to rapidly develop this capability. Through various cyber strategies, nations are seeking to encourage multi-organisation collaboration and information infrastructures between government, military, critical national infrastructure and engaging with the public and private sectors to secure cyberspace and its dependencies. This paper discusses the benefits of a systems approach to the complex sociotechnical problem of collaboration towards a cyber defence capability, and how challenges can be managed through the perspective of a viable system. The Viable Systems Model (VSM) provides a perspective for understanding system behaviour and anticipating, planning, and implementing large scale organisational change. The output from focus group sessions with stakeholders across national infrastructure, are placed in context to the VSM to provide a framework to better understand the challenges from the cyber domain, points of intervention, and requirements for a viable collaborative cyber defence system. Without a holistic, efficient information infrastructure supporting a cyber SA capability, the ability for a whole system response to take a proactive posture to threats or put in place effective mitigation and resilience measures is severely reduced, leading to even greater vulnerability. Relevance to industry This paper presents the outputs from a number of focus groups with stakeholders drawn from national infrastructure and business sectors, that are place within the context of the VSM. The VSM is presented as a framework to identify requirements and intervention points for future research towards a collaborative information system architecture.
Richard Craig, Theodore Tryfonas, John May
SMC2
2014 A Distributed Consensus Algorithm for Decision Making in Service-Oriented Internet of Things
abstract
In a service-oriented Internet of things (IoT) deployment, it is difficult to make consensus decisions for services at different IoT edge nodes where available information might be insufficient or overloaded. Existing statistical methods attempt to resolve the inconsistency, which requires adequate information to make decisions. Distributed consensus decision making (CDM) methods can provide an efficient and reliable means of synthesizing information by using a wider range of information than existing statistical methods. In this paper, we first discuss service composition for the IoT by minimizing the multi-parameter dependent matching value. Subsequently, a cluster-based distributed algorithm is proposed, whereby consensuses are first calculated locally and subsequently combined in an iterative fashion to reach global consensus. The distributed consensus method improves the robustness and trustiness of the decision process.
Shancang Li, George C. Oikonomou, Theodore Tryfonas, Thomas M. Chen
IEEE Trans. Ind. Informatics3
2013 Game Theoretic Approach for Cost-Benefit Analysis of Malware Proliferation Prevention
Theodoros Spyridopoulos, George C. Oikonomou, Theodore Tryfonas
SEC3
2013 A System Dynamics Model of Cyber Conflict
abstract
In this paper we try to determine whether a potential state-aggressor in a recent cyber attack can be identified through an understanding of shared international dependencies between nations. Combining the International Affairs and Systems Science disciplines, we put forth a system dynamics model of cyber conflict which may facilitate the identification of a culpable state or states in a cyber attack through publicly available information. Having identified 22 countries with military or civilian cyber capability, data on economic trade imports and diplomatic relationships were combined to identify dependencies, or countries upon which dependent countries rely for trade or military collaboration. The system dynamics model simulates diplomatic tension between two countries to estimate the probability of a cyber conflict. Nine case studies, in which the likely cyber combatant was identified, are used to test the model. Initial results yielded a number of prior indicators of cyber conflict, such as dips in trade imports from future cyber combatants up to 2 years before a launched cyber attack.
Dana Polatin-Reuben, Richard Craig, Theodoros Spyridopoulos, Theodore Tryfonas
SMC4
2013 A pilot study on the security of pattern screen-lock methods and soft side channel attacks
abstract
Graphical passwords that allow a user to unlock a smartphone's screen are one of the Android operating system's features and many users prefer them instead of traditional text-based codes. A variety of attacks has been proposed against this mechanism, of which notable are methods that recover the lock patterns using the oily residues left on screens when people move their fingers to reproduce the unlock code. In this paper we present a pilot study on user habits when setting a pattern lock and on their perceptions regarding what constitutes a secure pattern. We use our survey's results to establish a scheme, which combines a behaviour-based attack and a physical attack on graphical lock screen methods, aiming to reduce the search space of possible combinations forming a pattern, to make it partially or fully retrievable.
Panagiotis Andriotis, Theodore Tryfonas, George C. Oikonomou, Can Yildiz
WISEC2
2013 Cryptographic Key Exchange in IPv6-Based Low Power, Lossy Networks
Panagiotis Ilia, George C. Oikonomou, Theodore Tryfonas
WISTP3
2013 A game theoretic defence framework against DoS/DDoS cyber attacks
Theodoros Spyridopoulos, G. Karanikas, Theodore Tryfonas, George C. Oikonomou
Comput. Secur.3
2012 Life-logging in smart environments: Challenges and security threats
abstract
As the world becomes an interconnected network in which objects and humans interact, new challenges and threats appear. In this interconnected world, smart objects seam to have an important role in giving users the chance for life-logging in smart environments. However, the limitation of smart devices with regard to memory, resources and computation power, hinder the opportunity to apply well-established security algorithms and techniques for secure life-logging on the Internet of Things domain. As the need for secure and trustworthy life-logging in smart environments is vital, a lightweight approach has to be considered to overcome the constraints of smart objects. The purpose of this paper is to detail current topics of life-logging in smart environments while describing interconnection issues, security threats and suggesting a lightweight framework for ensuring security, privacy and trustworthy life-logging.
Nikos Petroulakis, Ioannis G. Askoxylakis, Theodore Tryfonas
ICC3
2009 Using penetration testing feedback to cultivate an atmosphere of proactive security amongst end-users
abstract
Purpose The purpose of this case study paper is to demonstrate that, no matter how complex computer security systems are, effort should be concentrated and focused on employees to improve their security awareness. Each employee needs to become a “Security Deputy” to the company's computer security staff and he or she needs to take some responsibility for preventing security breaches – whether inside the workplace or not. It is easy to unwittingly spread a virus, or open security vulnerabilities, and such actions might damage a company's systems perhaps even more than malicious employees, through simple ignorance of security issues. Design/methodology/approach A series of surveys and questionnaires were designed along with practical exercises and security awareness training sessions. Findings Following their involvement in the exercises and awareness training, employees demonstrated improvement in security awareness. Users were made explicitly aware of the realities of IT security with pertinent questions asked in order to force them evaluate their own reactions to a situation which may escalate into a security incident. Research limitations/implications The research was undertaken in a typical medium‐large sized company within the energy business sector, but it is possible that results may be different in other sectors. Practical implications It is clear that security technologies alone cannot prevent incidents and therefore employees need good quality security awareness training in order to protect the organisation. Originality/value It is becoming increasingly important that employees are taken through a more rigorous security‐awareness training programme, in order to protect business computer systems and to “protect them from themselves”.
Martyn Styles, Theodore Tryfonas
Inf. Manag. Comput. Secur.2
2009 A lightweight web-based vulnerability scanner for small-scale computer network security assessment
Pete Davies, Theodore Tryfonas
J. Netw. Comput. Appl.2
2007 Hard-drive Disposal and Identity Fraud
abstract
A personal computer is often used to store personal information about the user. This information may be intentionally kept by the user or information maybe automatically stored as the result of the user’s activities. In this paper we investigate whether it is possible for identity fraud to occur as a result of post-disposal access to the residual data stored on a personal computer’s hard drive. We provide indicative types of information required to commit an identify fraud and examine the personal information contained in a series of second-hand personal computer hard disk drives, purchased as part of a wider research study.
Paula Thomas, Theodore Tryfonas
SEC2
2004 From risk analysis to effective security management: towards an automated approach
abstract
Effective and risk‐free operation of modern information systems relies heavily on security practices and overall information security management. Usually, organizations perform risk analysis in order to adjust their security practices and controls to an acceptable level of risk. One of the various outputs of a risk analysis is a set of recommended practices expressed in high‐level statements of a natural language. In order to be applied to the real world, it is necessary to technically implement those requirements tailored to the specific organizational context. This is usually performed by experienced individuals. For this technical implementation and the configuration of the information technology facilities, several formal policy languages exist, which define access control policies, roles and responsibilities. This paper describes requirements for a software tool that could assist in the transition from high‐level security requirements to a formal, well‐defined policy language. Such a tool would provide valuable assistance and support in both policy implementation and overall security management.
Vassilis Tsoumas, Theodore Tryfonas
Inf. Manag. Comput. Secur.2
2003 Perceptions of Security Contributing to the Implementation of Secure IS
Theodore Tryfonas, Evangelos A. Kiountouzis
SEC1
2002 Information Systems Security and the Information Systems Development Project: Towards a Framework for Their Integration
Theodore Tryfonas, Evangelos A. Kiountouzis
SEC1
2001 Security Concerns for Contemporary Development Practices: A Case Study
Theodore Tryfonas, Evangelos A. Kiountouzis
SEC1
2001 Embedding security practices in contemporary information systems development approaches
abstract
Abstract As information and communication technologies become a critical component of firms' infrastructures and information establishes itself as a key business resource as well as driver, people start to realise that there is more than the functionality of the new information systems that is significant. Business or organisational transactions over new media require stability, one factor of which is information security. Information systems development practices have changed in line with the evolution of technology offerings as well as the nature of systems developed. Nevertheless, as this paper establishes, most contemporary development practices do not accommodate sufficiently security concerns. Beyond the literature evidence, reports on empirical study results indicating that practitioners deal with security issues by applying conventional risk analysis practices after the system is developed. Addresses the lack of a defined discipline for security concerns integration in systems development by using field study results recording development practices that are currently in use to illustrate their deficiencies, to point to required enhancements of practice and to propose a list of desired features that contemporary development practices should incorporate to address security concerns.
Theodore Tryfonas, Evangelos A. Kiountouzis, Angeliki Poulymenakou
Inf. Manag. Comput. Secur.1
2000 A Qualitative Approach to Information Availability
Theodore Tryfonas, Dimitris Gritzalis, Spyros Kokolakis
SEC1