VLDB 2026 Research / reviewers in the wild / expert
Christos Xenakis
dblp:11/3573 · also Christos K. Xenakis
· DBLP profile ↗
65ranked-venue papers
9as first author
29since 2021 · last 2026
0000-0001-6718-122XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 43 · 4 first-author · 21 since 2021Computer networks · 11 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptive DeSeTra: Adaptive deformable-span self-attention transformer for LLM securityabstractLarge Language Models (LLMs) remain vulnerable to prompt-based attacks such as jailbreaks and prompt injection, highlighting the need for security mechanisms that not only detect malicious intent but also determine whether an attack actually succeeds. In this paper, we introduce Adaptive DeSeTra, a novel security-centric Transformer model designed for deployment that mirrors the real-world attack pipeline through two layers: intent detection via multi-class prompt classification into Benign , Jailbreak and Prompt Injection ; and impact assessment via response-level classification into Compliant or Refusal . Prompt-level intent identification enables low-latency routing to appropriate guardrails, policies, and monitoring controls before a malicious prompt reaches the target Large Language Model (LLM). Conversely, response-level evaluation quantifies whether the adversarial attempt resulted in compliance or refusal, providing an outcome-based measure of attack effectiveness that supports risk assessment and enables more informative security benchmarking than intent detection alone. Experiments demonstrate strong performance across both layers: 99.35% Accuracy/F1/Precision/Recall with 99.85% AUC for prompt classification, and 99.80% for the same metrics with 99.98% AUC for impact assessment, positioning Adaptive DeSeTra as a strong candidate for deployment-oriented LLM security monitoring and evaluation. Konstantinos Giapantzis, Panagiotis Bountakas, Apostolis Zarras, Aristeidis Farao, Vaios Bolgouras, Christos Xenakis |
Inf. Sci. | 6 |
| 2025 | Game on: a performance comparison of interpolation techniques applied to Shamir's secret sharingabstractAbstract Public-key encryption is typically managed through a public key infrastructure. However, it relies on a central control point, the certification authority, which acts as a single point of failure. Recent technological advancements have led to the need for decentralized cryptographic protocols. This paper presents a comprehensive study on enhancing public-key encryption via threshold cryptography and multiparty computation to ensure robust security in decentralized systems. The focus lies in exploring various polynomial interpolation techniques within Shamir’s secret sharing scheme, particularly addressing the efficiency and practicality of Newton interpolation, fast Fourier transformation (FFT), and advanced versions of Lagrange’s method. Utilizing SageMath for a dedicated testing environment, the research investigates the swiftest interpolation methods for secret recovery, introducing new shares into the system, and evaluating the impact of optimizations on performance. The findings highlight FFT as the most effective interpolation method in speed and efficiency, albeit with limitations on the number of shares that can be processed. This paper critically evaluates these interpolation techniques against practical constraints and aims to answer pivotal research questions regarding the optimal approach for large-scale scenarios, challenging existing notions on the efficiency of Newton’s method and providing experimental evidence to support the superiority of FFT in specific contexts. Anastassis Voudouris, Aristomenis Tressos, Apostolis Zarras, Christos Xenakis |
Comput. J. | 4 |
| 2025 | EAP-FIDO: A novel EAP method for using FIDO2 credentials for network authenticationabstractThe adoption of FIDO2 authentication by major tech companies in web applications has grown significantly in recent years. However, we argue FIDO2 has broader potential applications. In this paper, we introduce EAP-FIDO, a novel Extensible Authentication Protocol (EAP) method for use in IEEE 802.1X-protected networks. This allows organisations with WPA2/3-Enterprise wireless networks or MACSec-enabled wired networks to leverage FIDO2’s passwordless authentication in compliance with existing standards. Additionally, we provide a comprehensive security and performance analysis to support the feasibility of this approach. Martiño Rivera-Dourado, Christos Xenakis, Alejandro Pazos, José Manuel Vázquez-Naya |
Comput. Networks | 2 |
| 2025 | CRASHED: Cyber risk assessment for smart home electronic devicesabstractThe rapid proliferation of Internet of Things (IoT) technology has enriched modern households with smart home devices , enhancing convenience, but simultaneously increasing vulnerability to cyber threats. This paper introduces CRASHED , an innovative cyber risk assessment methodology specifically designed for smart home ecosystems. Compared to existing approaches, CRASHED integrates the MITRE ATT&CK and CAPEC frameworks to systematically identify and analyze threats, vulnerabilities, and potential impacts. By employing device-specific profiling, quantitative metrics, and sophisticated weighting mechanisms, it delivers a multilayered assessment of cyber risks that accounts for asset criticality and threat severity, distinguishing it from conventional methods lacking such granularity . The novelty of CRASHED lies in its comprehensive evaluation of systemic vulnerabilities and domestic repercussions. Case studies on various smart home configurations demonstrate its effectiveness in modeling, analyzing, and mitigating risks compared to existing frameworks. This work represents a significant advancement in safeguarding smart home environments, underscoring the urgent need for specialized cyber risk assessment models in our interconnected era. The proposed methodology not only enhances threat detection and response, but also addresses critical gaps in vulnerability databases and risk calculation processes, offering a transformative solution to the evolving challenges of smart home cybersecurity. Georgios Paparis, Apostolis Zarras, Aristeidis Farao, Christos Xenakis |
J. Inf. Secur. Appl. | 4 |
| 2024 | AIAS: AI-ASsisted cybersecurity platform to defend against adversarial AI attacksabstractThe increasing integration of Artificial Intelligence (AI) in critical sectors such as healthcare, finance, and cybersecurity has simultaneously exposed these systems to unique vulnerabilities and cyber threats. This paper discusses the escalating risks associated with adversarial AI and outlines the development of AIAS. AIAS is a comprehensive, AI-driven security platform designed to enhance the resilience of AI systems against such threats. In addition, AIAS features advanced modules for threat simulation, detection, mitigation, and deception, using adversarial defense techniques, attack detection mechanisms, and sophisticated honeypots. The platform leverages explainable AI (XAI) to improve the transparency and effectiveness of threat countermeasures. Through meticulous analysis and innovative methodologies, AIAS aims to revolutionize cybersecurity defenses, enhancing the robustness of AI systems against adversarial attacks while fostering a safer deployment of AI technologies in critical applications. The paper details the components of the AIAS platform, explores its operational framework, and discusses future research directions for advancing AI security measures. George Petihakis 0002, Aristeidis Farao, Panagiotis Bountakas, Athanasia Sabazioti, John Polley, Christos Xenakis |
ARES | 6 |
| 2024 | NITRO: an Interconnected 5G-IoT Cyber RangeabstractThis paper presents NITRO cyber range, which aims at creating a specialized cybersecurity testing and training environment for 5G and IoT networks. NITRO provides a platform for researchers and security professionals to simulate real-world scenarios, assess vulnerabilities, and validate security measures. It focuses on identifying novel cascading attacks that exploit the interdependencies between devices. Another innovation of the NITRO platform is the adversarial AI exercises on 5G and IoT networks, aiming at raising awareness of the vulnerabilities of AI models, how they can be attacked and how robust AI can defend against these vulnerabilities. The overarching goal of NITRO is to enhance security of 5G and IoT networks and serve as a precursor to the development of new cyber ranges within critical infrastructure sectors. Aristeidis Farao, Christoforos Ntantogian, Stylianos Karagiannis, Emmanouil Magkos, Alexandra Dritsa, Christos Xenakis |
ARES | 6 |
| 2024 | Integrating Hyperledger Fabric with Satellite Communications: A Revolutionary Approach for Enhanced Security and Decentralization in Space NetworksabstractThis paper explores the integration of blockchain technology, specifically Hyperledger Fabric, with satellite communications to enhance the security and reliability of global navigation satellite systems (GNSS). Given the inherent vulnerabilities in satellite systems, such as the susceptibility to various cyberattacks and the risk posed by GNSS signal attacks, this research proposes a novel security framework. By leveraging blockchain’s decentralized and immutable nature, the paper aims to fortify the integrity and verification of GNSS data. The enhancement of GNSS data integrity and verification is achieved through a consensus mechanism that aim to prevent unauthorized data alterations and provide robust anti-spoofing and anti-jamming capabilities. Integrating blockchain with satellite communications not only ensures data security but also fosters a transparent and decentralized operational model by enhancing the trustworthiness of satellite-derived data. In addition, this paper outlines the current state-of-the-art, the architecture of the proposed solution, and discusses the potential challenges and future research directions in optimizing blockchain for space applications. Anastassios Voudouris, Aristeidis Farao, Aggeliki Panou, John Polley, Christos Xenakis |
ARES | 5 |
| 2023 | Multi-Attribute Decision Making-based Trust Score Calculation in Trust Management in IoTabstractThe proliferation of IoT networks across various sectors necessitates robust Trust Management mechanisms for secure and reliable operations. This paper proposes a Multi-Attribute Decision Making (MADM)-based approach for trust score calculation in IoT Trust Management. This solution addresses limitations of existing methods by considering multiple attributes and providing a comprehensive evaluation of trustworthiness. The methodology computes a device's trust score by integrating factors such as Cyber Risk, Ease of Access, and Security Level using a weighted sum-based calculation. The Analytical Hierarchy Process (AHP) to determine the factors’ weights is utilized, contributing a novel approach to IoT Trust Management. Furthermore, this approach includes dynamic trust score updates throughout the device's lifetime, accommodating changes in the device's Cyber Risk for accurate trust assessment. A trust score penalization mechanism for devices below a predefined threshold is also introduced, enabling prompt risk mitigation. A simulated assessment, considering varying numbers of IoT devices, evaluates the effectiveness of the proposed methodology. By addressing limitations and introducing innovative components, the proposed MADM-based approach enhances security, reliability, and overall performance of IoT networks. This research advances trust management in IoT and provides valuable insights for developing secure and trustworthy IoT ecosystems. Michail Bampatsikos, Ilias Politis, Vaios Bolgouras, Christos Xenakis |
ARES | 4 |
| 2023 | Enabling Qualified Anonymity for Enhanced User Privacy in the Digital EraabstractThis paper presents a privacy-enhancing identity management platform designed to address the challenges associated with online identity verification and privacy protection. INCOGNITO offers a comprehensive solution by leveraging concepts such as Qualified Anonymity and cryptographic credentials, along with technologies including blockchain, Tor Network, and software stacks like Idemix. By employing these mechanisms, INCOGNITO aims to enable users to securely acquire and manage their identity attributes, while preserving their privacy and ensuring compliance with both regulatory bodies and Service Providers’ requirements. The platform facilitates the issuance and verification of cryptographic credentials, granting users access to online services based on fine-grained subsets of their identity attributes. Furthermore, the effectiveness and feasibility of the platform are demonstrated through two pilot projects focused on online multimedia content sharing and identifying bots or fake users in online social networks. These pilots showcase the practical applicability of INCOGNITO in solving identity-related challenges while safeguarding user privacy and security. Vaios Bolgouras, Kostantinos Papadamou, Ioana Stroinea, Michail Papadakis, George Gugulea, Michael Sirivianos, Christos Xenakis |
ARES | 7 |
| 2023 | Securing the Flow: Security and Privacy Tools for Flow-based ProgrammingabstractThis paper presents a comprehensive collection of reusable artifacts for addressing security and privacy issues in the context of flow-based programming in Function-as-a-Service (FaaS) environments. With the rapid adoption of FaaS platforms, it becomes important to guarantee the security and privacy of applications. The presented artifacts incorporate a wide variety of nodes and techniques into the popular Node-RED architecture. They intend to improve the security and privacy of applications by addressing critical aspects such as secure data flow management, code authenticity and validation, access control mechanisms, and runtime monitoring and anomaly detection. Using these artifacts, developers can construct more robust and resilient applications in FaaS environments while mitigating potential security and privacy risks. Thodoris Ioannidis, Vaios Bolgouras, Christos Xenakis, Ilias Politis |
ARES | 3 |
| 2023 | An inclusive Lifecycle Approach for IoT Devices Trust and Identity ManagementabstractERATOSTHENES is an EC, co-funded, research project strongly considering modern security challenges in the domain of Internet of Things in mind of their huge penetration into our day to day lives. There are a series of recent challenges that recently have been converted into obstacles or risk points that could block the secure operation of IoT networks in all day to day activities, from home to office, to leisure and security. These include examples such as the highly increased number of connected devices (at all network levels) that are on top forming inhomogeneous networks and systems of systems. Different vendor characteristics further increase the attack surface that is expected to further rise in the upcoming years. Such, highly critical, characteristics, dramatically increase the needs for confidentiality access control, user and things’ privacy, devices’ trustworthiness and compliance that require lifecycle considerations. The ERATOSTHENES project orchestrates a novel distributed, automated, auditable, yet privacy-respectful, Trust and Identity Management Framework and Reference Architecture with the ultimate scope to dynamically and holistically manage IoT devices in a lifecycle approach, strengthening trust, identities, and resilience in the entire IoT ecosystem while supporting the enforcement of the NIS directive, GDPR and Cybersecurity Act. This publication describes the ERATOSTHENES technical concept and reference architecture as well as design considerations, architecture characteristics, connectivity and interoperability. Konstantinos Loupos, Harris Niavis, Fotis Michalopoulos, George Misiakoulis, Antonio F. Skarmeta, Jesús Garcia, Angel Palomares, Rustem Dautov, Francesca Giampaolo, Rosella Mancilla, Francesca Costantino, Dimitri Van Landuyt, Sam Michiels, Stefan More, Christos Xenakis, Michail Bampatsikos, Ilias Politis, Konstantinos Krilakis, Sokratis Vavilis |
ARES | 16 |
| 2023 | Adversarial Machine Learning Attacks on Multiclass Classification of IoT Network TrafficabstractMachine Learning-based Intrusion Detection Systems have been proven to be very effective in the protection of IoT Networks. However, the expansion of Adversarial Machine Learning attacks threatens their efficacy affecting also the security of IoT networks. Thus, this paper proposes a Machine Learning-driven methodology for multiclass classification of cyber-attacks in IoT networks and investigates the robustness of the Machine and Deep Learning classifiers against several well-known Adversarial Machine Learning attacks (JSMA, FGSM, DeepFool). Moreover, the effectiveness of the Adversarial Training defense method has been studied in tackling Adversarial Machine Learning attacks. The proposed methodology was evaluated using a new and large IoT dataset (IoTID20) and the experimental results concluded that the Random Forest classifier can classify the cyber-attacks with high classification accuracy (99.9%) as well as the JSMA, FGSM, and DeepFool attacks can significantly reduce the performance of all the classifiers. Finally, based on the evaluation adversarial training can overall enhance the classifiers’ robustness against all the utilized Adversarial Machine Learning attacks without affecting the performance when only normal samples are present. Vasileios Pantelakis, Panagiotis Bountakas, Aristeidis Farao, Christos Xenakis |
ARES | 4 |
| 2023 | A Bring Your Own Device security awareness survey among professionalsabstractThe increasing prevalence of Bring Your Own Device (BYOD) practices in the workplace has posed significant challenges to organizations in terms of security and management. This paper presents a survey-based study aimed at exploring the adoption, implications, and security considerations associated with BYOD policies. The study utilized a questionnaire developed based on guidelines provided by the National Institute of Standards and Technology (NIST). The primary objectives of this research are to investigate the cautiousness and awareness of BYOD users, as well as the effectiveness of security measures implemented by organizations, in order to gain insights into the key aspects of BYOD practices in the workplace. The findings of this paper highlight the need for increased caution among BYOD users regarding device security, a lack of knowledge among users about organizational security measures, and the potential for enhancing security policies and implementing additional measures despite organizations having achieved a satisfactory level of security for BYOD. George Petihakis 0002, Dimitrios Kiritsis, Aristeidis Farao, Panagiotis Bountakas, Aggeliki Panou, Christos Xenakis |
ARES | 6 |
| 2023 | Enhancing 3GPP CAPIF Authentication and Authorization Across Mobile Operators Using OpenID Connect and Single Sign-OnabstractA key enabler for vertical businesses to adopt the 5G networking paradigm is the introduction of Network Applications as the horizontal middleware layer between 5G operators and vertical applications. The Network Application ecosystem allows reliable and secure interaction between the control plane of mobile operators and the various vertical businesses, in a standardised way defined by the Common API Framework. Although the framework's security features and mechanisms ensure robust communication between mobile operators and vertical applications, they cannot sustain the rapidly evolving Network Application marketplaces, which require seamless onboarding, authentication and authorization of Network Applications across multiple mobile operators. The paper investigates the security enhancements of incorporating the OpenID Connect protocol in the Common API Framework standard and supporting the single sign-on authentication scheme for Network Applications across different Common API Framework instances. The work, which builds on top of the EU funded EVOLVED-5G, aims on a robust and distributed solution using open-source protocols for authentication and authorization, incorporating security-as- a-service features for 5G and beyond network implementations. Ioannis Stylianou, Ilias Politis, Christos Xenakis |
ICC | 3 |
| 2023 | HELPHED: Hybrid Ensemble Learning PHishing Email DetectionabstractPhishing email attack is a dominant cyber-criminal strategy for decades. Despite its longevity, it has evolved during the COVID-19 pandemic, indicating that adversaries exploit critical situations to lure victims. Plenty of detectors have been proposed over the years, which mainly focus on the contents or the textual information of emails; however, to cope with the evolution of phishing emails more sophisticated approaches should be introduced that will exploit all the emails' traits to enhance the detection capability of Machine Learning/Deep Learning classifiers. To tackle the limitations of existing works, this paper proposes a phishing email detection methodology, named HELPHED that focuses on the detection of phishing emails by combining Ensemble Learning methods with hybrid features. The hybrid features provide an accurate representation of emails by fusing their content and textual traits. We propose two methods of HELPHED, the first one employs the Stacking Ensemble Learning method, while the second method utilizes the Soft Voting Ensemble Learning. Both methods deploy two different Machine Learning algorithms to handle the hybrid features separately, yet in parallel, minimizing the features' complexity and improving the model's performance. A thorough evaluation analysis is carried out considering innovative guidelines that aim to prevent partial and misleading results. Experimental tests verified that the combination of hybrid features with Ensemble Learning, overall, accomplishes better detection performance than when employing only content-based or text-based features. Numerical results on a rich imbalanced dataset (i.e., 32,051 benign and 3,460 phishing email samples) that considers the evolution of phishing emails show that Soft Voting Ensemble Learning outperforms other prominent Machine Learning/Deep Learning algorithms and existing works yielding F1-score equal to 0.9942. Panagiotis Bountakas, Christos Xenakis |
J. Netw. Comput. Appl. | 2 |
| 2022 | MITRE ATT&CK-driven Cyber Risk AssessmentabstractAssessing the risk posed by Advanced Cyber Threats (APTs) is challenging without understanding the methods and tactics adversaries use to attack an organisation. The MITRE ATT&CK provides information on the motivation, capabilities, interests and tactics, techniques and procedures (TTPs) used by threat actors. In this paper, we leverage these characteristics of threat actors to support informed cyber risk characterisation and assessment. In particular, we utilise the MITRE repository of known adversarial TTPs along with attack graphs to determine the attack probability as well as the likelihood of success of an attack. We further identify attack paths with the highest likelihood of success considering the techniques and procedures of a threat actor. The assessment is supported by a case study of a health care organisation to identify the level of risk against two adversary groups– Lazarus and menuPass. Sakshyam Panda, Christos Xenakis, Emmanouil A. Panaousis |
ARES | 3 |
| 2022 | Trusted and Secure Self-Sovereign Identity frameworkabstractDigitization, in terms of online services, work environment and other day-to-day procedures, has lead to the wide adoption and use of the respective digital identities. Users utilize their digital personas and their corresponding attributes on a daily basis, in order to gain access to resources and services. This is achieved through the use of numerous identity management schemes, which often suffer from multiple vulnerabilities and are susceptible to threats. This results in the compromise of user privacy and data security. In the recent years, new technologies related to identity management, like the Self-Sovereign Identity (SSI) and eIDAS concepts, are employed to mitigate these issues. This paper presents an architecture that combines state-of-the-art technologies regarding identity management, authentication and secure storage. More specifically, the proposed framework utilizes IOTA-based SSI, the eIDAS framework, FIDO protocol and Trusted Execution Environment (TEE), resulting in a trusted and secure identity management framework. Our solution is thoroughly presented via scenarios, showcasing its robustness and how well it copes in relation to our threat model. Vaios Bolgouras, Anna Angelogianni, Ilias Politis, Christos Xenakis |
ARES | 4 |
| 2022 | GTM: Game Theoretic Methodology for optimal cybersecurity defending strategies and investmentsabstractInvestments on cybersecurity are essential for organizations to protect operational activities, develop trust relationships with clients, and maintain financial stability. A cybersecurity breach can lead to financial losses as well as to damage the reputation of an organization. Protecting an organization from cyber attacks demands considerable investments; however, it is known that organisations unequally divide their budget between cybersecurity and other technological needs. Organizations must consider cybersecurity measures, including but not limited to security controls, in their cybersecurity investment plans. Nevertheless, designing an effective cybersecurity investment plan to optimally distribute the cybersecurity budget is a primary concern. This paper presents GTM, a methodology depicted as a tool dedicated to providing optimal cybersecurity defense strategies and investment plans. GTM utilizes attack graphs to predict all possible cyber attacks, game theory to simulate the cyber attacks and 0-1 Knapsack to optimally allocate the budget. The output of GTM is an optimal cybersecurity strategy that includes security controls to protect the organisation against potential cyber attacks and enhance its cyber defenses. Furthermore, GTM’s effectiveness is evaluated against three use cases and compared against different attacker types under various scenarios. Ioannis Kalderemidis, Aristeidis Farao, Panagiotis Bountakas, Sakshyam Panda, Christos Xenakis |
ARES | 5 |
| 2022 | Improving Network, Data and Application Security for SMEsabstractThe evolution of Information and Communications Technology and Cloud Computing, combined with the advent of novel telecommunication frameworks such as 5G, have introduced the notion of ubiquitous connectivity combined with a seemingly vast pool of resources, storage and services. This immense transformation introduced new types of security threats mostly due to the significant increase of the attack surface, which can now be compromised by malicious users. Despite the fact that malicious attacks constantly become more and more sophisticated, SMEs and public administrations remain reluctant to invest in cybersecurity since they operate on a limited budget and are mostly focused in time to market and cost minimization. The purpose of this book chapter is to provide an overview on how the most common network-related cybersecurity attacks are orchestrated, which are the systems and services they affect the most as well as present specific design principles and guidelines for crafting platforms and frameworks capable of mitigating such attacks and ensure a certain level of secure operation. Christos Tselios, Ilias Politis, Christos Xenakis |
ARES | 3 |
| 2022 | Secret sharing a key in a distributed way, Lagrange vs NewtonabstractIn secret sharing, a dealer knows the secret it shares. In a distributed key generation (DKG) protocol, a shared secret is collectively generated in a group in a completely distributed way such that any subset of size greater than a threshold can reveal or use the shared secret, while smaller subsets do not have any knowledge about it. The most important aspect is that there is no dealer or trusted party. The core idea of secret sharing schemes is Shamir’s secret sharing method, which uses Lagrange’s interpolation to reconstruct the shared secret key. This paper investigates an alternative method, called Newton’s interpolation and it cites the probability of implementing it on current DKG protocols. Anastassios Voudouris, Ilias Politis, Christos Xenakis |
ARES | 3 |
| 2022 | Facilitating DoS Attack Detection using Unsupervised Anomaly DetectionabstractModern techniques in intrusion and DoS (Denial of Service) detection tend to be either supervised or semi-supervised, i.e., they require training and labelled data. In this work, we study the problem of correlating security attacks with anomalies reported at runtime by a fully unsupervised outlier detection module, i.e., a component that does not require any training at all. Through a concrete proof-of-concept case study, we demonstrate that unsupervised anomaly detection is both efficient and effective, but still, it needs to be combined with additional mechanisms to yield a complete intrusion detection and prevention solution. Christos Bellas, Georgia Kougka, Athanasios Naskos, Anastasios Gounaris, Athena Vakali, Christos Xenakis, Apostolos N. Papadopoulos |
SSDBM | 6 |
| 2022 | A Digital Twin for the 5G Era: the SPIDER Cyber RangeabstractService providers, 5G network operators and, more generally, vertical industries face today a dangerous shortage of highly skilled cybersecurity experts. Along with the escalation and growing sophistication of cyber-attacks, 5G networks require the training of skilled and highly competent cyber forces. To meet these requirements, the SPIDER cyber range focuses specifically on 5G, and is based on three pillars, (i) cyber security assessment, (ii) training cyber security teams to defend against complex cyber-attack scenarios, and (iii) evaluation of cyber risk. The SPIDER cyber range replicates a customized 5G network, enabling the execution of cyber-exercises that take advantage of hands-on interaction in real time, the sharing of information between participants, and the gathering of feedback from network equipment, as well as the development and adaptation of advanced operational procedures. This aims to help 5G security professionals improve their ability to collaboratively manage and predict security incidents, complex attacks, and propagated vulnerabilities. The SPIDER cyber range is validated in two relevant use case scenarios aimed at demonstrating, in a realistic, measurable, and replicable way the transformations SPIDER will bring to the cybersecurity industry. Filippo Rebecchi, Antonio Pastor 0001, Alberto Mozo, Chiara Lombardo, Roberto Bruschi, Ilias Aliferis, Roberto Doriguzzi Corin, Panagiotis Gouvas, Antonio Álvarez Romero, Anna Angelogianni, Ilias Politis, Christos Xenakis |
WoWMoM | 12 |
| 2022 | EKnad: Exploit Kits' network activity detection
Panagiotis Bountakas, Christoforos Ntantogian, Christos Xenakis |
Future Gener. Comput. Syst. | 3 |
| 2022 | A Trusted Platform Module-based, Pre-emptive and Dynamic Asset Discovery ToolabstractThis paper presents an original Intelligent and Secure Asset Discovery Tool (ISADT) that uses artificial intelligence and TPM-based technologies to: (i) detect the network assets, and (ii) detect suspicious pattern in the use of the network. The architecture has specifically been designed to discover the assets of medium and large size companies and institutions, such as hospitals, universities, or government buildings. Given the distributed design of the architecture, it can cope with the problem of the isolation of different Virtual Local Area Networks (VLANs). This is done by collecting information from all the VLANs and storing it in a central node, which can be accessed by the network administrator, who may consult and visualize the status in any moment, or even by other authorized applications. The collected data is kept in a secure warehouse by the use of a Trusted Platform Module. Moreover, collected data is processed by the use of artificial intelligence in two ways: (i) the traffic of each network is analysed so that suspicious patterns can be detected, and (ii) identified ports and status are analysed to detect anomalous combinations of open ports in a device. Antonio Jesús Díaz-Honrubia, Alberto Blázquez-Herranz, Lucía Prieto Santamaría, Ernestina Menasalvas Ruiz, Alejandro Rodríguez González, Gustavo Gonzalez Granadillo, Emmanouil A. Panaousis, Christos Xenakis |
J. Inf. Secur. Appl. | 9 |
| 2022 | A large-scale analysis of Wi-Fi passwords
Eleni Veroni, Christoforos Ntantogian, Christos Xenakis |
J. Inf. Secur. Appl. | 3 |
| 2021 | Solving the cold start problem in Trust Management in IoTabstractInternet of Things has a profound effect on everyday life and critical vertical services including healthcare, factories of the future and intelligent transport systems. The highly distributed nature of such networks and the heterogeneity of the devices, which constitute them, necessitates that their users should be able to trust them at all times. A method to determine the device's service trustworthiness is Trust Management (TM), which assigns scores to devices according to their trustworthiness level, based on evaluations from other entities that interacted with it. Often Internet of Things devices that just joined the network, have not interacted with any other entity of this network before, hence there is no way to determine its trustworthiness. Such an event is referred to as the cold start trust score or initial trust score problem. The majority of the trust management approaches address this problem by setting an arbitrary initial trust score, while others will ignore it. Assigning arbitrary trust scores for devices connected to the network for the first time has the potential to disrupt the operation of the entire system, when a high trust score is assigned to a non-trusted malicious device, or lead to unfair policies, when trusted devices are assumed as potential intruders, which also deteriorates the performance of the system. This paper proposes a mechanism, which combines the blockchain based BARRETT remote attestation protocol with a set of device's properties and communication and operational context parameters, in order to determine accurately and assign the initial trust score to each device. Through a set of extensive simulations over different experimental setups, the proposed scheme is achieving to safely distribute initial trust scores to one thousand devices over less than 6ms, while minimising the risk of computational denial of service attacks due to the inherent characteristics of the BARRETT remote attestation protocol. Michail Bampatsikos, Ilias Politis, Christos Xenakis, Stelios C. A. Thomopoulos |
ARES | 3 |
| 2021 | A Comparison of Natural Language Processing and Machine Learning Methods for Phishing Email DetectionabstractPhishing is the most-used malicious attempt in which attackers, commonly via emails, impersonate trusted persons or entities to obtain private information from a victim. Even though phishing email attacks are a known cybercriminal strategy for decades, their usage has been expanded over last couple of years due to the COVID-19 pandemic, where attackers exploit people’s consternation to lure victims. Therefore, further research is needed in the phishing email detection field. Recent phishing email detection solutions that extract representational text-based features from the email’s body have proved to be an appropriate strategy to tackle these threats. This paper proposes a comparison approach for the combined usage of Natural Language Processing (TF-IDF, Word2Vec, and BERT) and Machine Learning (Random Forest, Decision Tree, Logistic Regression, Gradient Boosting Trees, and Naive Bayes) methods for phishing email detection. The evaluation was performed on two datasets, one balanced and one imbalanced, both of which were comprised of emails from the well-known Enron corpus and the most recent emails from the Nazario phishing corpus. The best combination in the balanced dataset proved to be the Word2Vec with the Random Forest algorithm, while in the imbalanced dataset the Word2Vec with the Logistic Regression algorithm. Panagiotis Bountakas, Konstantinos Koutroumpouchos, Christos Xenakis |
ARES | 3 |
| 2021 | A web tool for analyzing FIDO2/WebAuthn Requests and ResponsesabstractPasswords are a problem in today's digital world. FIDO2, through WebAuthn, brought alternative password-less authentication that is more usable and secure than classic password-based systems, for web applications and services. In this work, we give a brief overview of FIDO2, and we present WebDevAuthn, a novel FIDO2/WebAuthn requests and responses analyser web tool. This tool can be used to help developers understand how FIDO2 works, aid in the development processes by speeding debugging using the WebAuthn traffic analyser and to test the security of an application through penetration testing by editing the WebAuhn requests or responses. Athanasios Vasileios Grammatopoulos, Ilias Politis, Christos Xenakis |
ARES | 3 |
| 2021 | NodeXP: NOde.js server-side JavaScript injection vulnerability DEtection and eXPloitation
Christoforos Ntantogian, Panagiotis Bountakas, Dimitris Antonaropoulos, Constantinos Patsakis, Christos Xenakis |
J. Inf. Secur. Appl. | 5 |
| 2020 | Calculation of the Hubble Universe Expansion Constant by Analyzing Observational Data: An Exploratory Teaching Proposal based on STEM EpistemologyabstractApproaches to STEM epistemology are related to the so-called “Integrated STEM Education Curriculum integration of STEM contents based in constructivism theories of learning as a context to implement the STEM epistemology. There are two approaches for STEM education integration: the content integration and the context integration. Computational Pedagogy is a didactic model that applies the Computational Science experiment in order to collect and analyze real- time data in alignment with the practices of Computational Thinking. In this work, the inquiry based teaching and learning strategy is implemented in order to measure the Hubble Universe expansion constant in agreement with the standard Scientific and Engineering practices as a computational experiment. Apostolos Xenakis, Christos Xenakis, Sarantos Psycharis, Konstantinos Kalovrektis |
EDUCON | 2 |
| 2020 | SECONDO: A Platform for Cybersecurity Investments and Cyber Insurance Decisions
Aristeidis Farao, Sakshyam Panda, Sofia-Anna Menesidou, Entso Veliou, Nikolaos Episkopos, George Kalatzantonakis, Farnaz Mohammadi, Nikolaos Georgopoulos, Michael Sirivianos, Nikos Salamanos, Spyros Loizou, Michalis Pingos, John Polley, Andrew Fielder, Emmanouil A. Panaousis, Christos Xenakis |
TrustBus | 16 |
| 2020 | Introduction to the special issue of the journal of information security and applications on" cyber security in ICS & SCADA systems"
Kevin I. Jones, Helge Janicke, Leandros Maglaras, Christos Xenakis |
J. Inf. Secur. Appl. | 4 |
| 2020 | Killing the Password and Preserving Privacy With Device-Centric and Attribute-Based AuthenticationabstractCurrent authentication methods on the Web have serious weaknesses. First, services heavily rely on the traditional password paradigm, which diminishes the end-users' security and usability. Second, the lack of attribute-based authentication does not allow anonymity-preserving access to services. Third, users have multiple online accounts that often reflect distinct identity aspects. This makes proving combinations of identity attributes hard on the users. In this paper, we address these weaknesses by proposing a privacy-preserving architecture for device-centric and attribute-based authentication based on: 1) the seamless integration between usable/strong device-centric authentication methods and federated login solutions; 2) the separation of the concerns for Authorization, Authentication, Behavioral Authentication and Identification to facilitate incremental deployability, wide adoption and compliance with NIST assurance levels; and 3) a novel centralized component that allows end-users to perform identity profile and consent management, to prove combinations of fragmented identity aspects, and to perform account recovery in case of device loss. To the best of our knowledge, this is the first effort towards fusing the aforementioned techniques under an integrated architecture. This architecture effectively deems the password paradigm obsolete with minimal modification on the service provider's software stack. Kostantinos Papadamou, Steven Gevers, Christos Xenakis, Michael Sirivianos, Savvas Zannettou, Bogdan Chifor, Sorin Teican, George Gugulea, Alberto Caponi, Annamaria Recupero, Claudio Pisa, Giuseppe Bianchi 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | Distributed Key Management in MicrogridsabstractSecurity for smart industrial systems is prominent due to the proliferation of cyber threats threatening national critical infrastructures. Smart grid comes with intelligent applications that can utilize the bidirectional communication network among its entities. Microgrids are small-scale smart grids that enable machine-to-machine (M2M) communications as they can operate with some degree of independence from the main grid. In addition to protecting critical microgrid applications, an underlying key management scheme is needed to enable secure M2M message transmission and authentication. Existing key management schemes are not adequate due to microgrid special features and requirements. In this article, we propose the Micro sElf-orgaNiSed mAnagement (MENSA), which is the first hybrid key management and authentication scheme that combines public key infrastructure and web-of-trust concepts in microgrids. Our experimental results demonstrate the efficiency of MENSA in terms of scalability and swiftness. Vaios Bolgouras, Christoforos Ntantogian, Emmanouil A. Panaousis, Christos Xenakis |
IEEE Trans. Ind. Informatics | 4 |
| 2019 | SealedGRID: A Secure Interconnection of Technologies for Smart Grid Applications
Aristeidis Farao, Juan E. Rubio, Cristina Alcaraz, Christoforos Ntantogian, Christos Xenakis, Javier López 0001 |
CRITIS | 5 |
| 2019 | Secure Edge Computing with Lightweight Control-Flow Property-based AttestationabstractThe Internet of Things (IoT) is rapidly evolving, while introducing several new challenges regarding security, resilience and operational assurance. In the face of an increasing attack landscape, it is necessary to cater for the provision of efficient mechanisms to collectively verify software- and device-integrity in order to detect run-time modifications. Towards this direction, remote attestation has been proposed as a promising defense mechanism. It allows a third party, the verifier, to ensure the integrity of a remote device, the prover. However, this family of solutions do not capture the real-time requirements of industrial IoT applications and suffer from scalability and efficiency issues. In this paper, we present a lightweight dynamic control-flow property-based attestation architecture (CFPA) that can be applied on both resource-constrained edge and cloud devices and services. It is a first step towards a new line of security mechanisms that enables the provision of control-flow attestation of only those specific, critical software components that are comparatively small, simple and limited in function, thus, allowing for a much more efficient verification. Our goal is to enhance run-time software integrity and trustworthiness with a scalable and decentralized solution eliminating the need for federated infrastructure trust. Based on our findings, we posit open issues and challenges, and discuss possible ways to address them, so that security do not hinder the deployment of intelligent edge computing systems. Nikos Koutroumpouchos, Christoforos Ntantogian, Sofia-Anna Menesidou, Kaitai Liang, Panagiotis Gouvas, Christos Xenakis, Thanassis Giannetsos |
NetSoft | 6 |
| 2019 | Evaluation of password hashing schemes in open source web platforms
Christoforos Ntantogian, Stefanos Malliaros, Christos Xenakis |
Comput. Secur. | 3 |
| 2019 | Transforming malicious code to ROP gadgets for antivirus evasionabstractThis study advances research in offensive technology by proposing return oriented programming (ROP) as a means to achieve code obfuscation. The key inspiration is that ROP's unique structure poses various challenges to malware analysis compared to traditional shellcode inspection and detection. The proposed ROP‐based attack vector provides two unique features: (i) the ability to automatically analyse and generate equivalent ROP chains for a given code, and (ii) the ability to reuse legitimate code found in an executable in the form of ROP gadgets. To this end, a software tool named ROPInjector was developed which, given any piece of shellcode and any legitimate executable file, it transforms the shellcode to its ROP equivalent re‐using the available code in the executable and finally patches the ROP chain infecting the executable. After trying various combinations of evasion techniques, the results show that ROPInjector can evade nearly and completely all antivirus software employed in the online VirusTotal service, making ROP an effective ingredient for code obfuscation. This attack vector poses a serious threat which malicious actors can take advantage to perform cyber‐attack campaigns. Christoforos Ntantogian, George Poulios, Georgios Karopoulos, Christos Xenakis |
IET Inf. Secur. | 4 |
| 2018 | MASKER: Masking for privacy-preserving aggregation in the smart grid ecosystem
Georgios Karopoulos, Christoforos Ntantogian, Christos Xenakis |
Comput. Secur. | 3 |
| 2017 | Analyzing, quantifying, and detecting the blackhole attack in infrastructure-less networks
Christoforos Panos, Christoforos Ntantogian, Stefanos Malliaros, Christos Xenakis |
Comput. Networks | 4 |
| 2016 | Protecting Sensitive Information in the Volatile Memory from Disclosure AttacksabstractThe protection of the volatile memory data is an issue of crucial importance, since authentication credentials and cryptographic keys remain in the volatile memory. For this reason, the volatile memory has become a prime target for memory scrapers, which specifically target the volatile memory, in order to steal sensitive information, such as credit card numbers. This paper investigates security measures, to protect sensitive information in the volatile memory from disclosure attacks. Experimental analysis is performed to investigate whether the operating systems (Windows or Linux) perform data zeroization in the volatile memory. Results show that Windows kernel zeroize data after a process termination, while the Linux kernel does not. Next, we examine functions and software techniques in C/C++ programming language that can be used by developers to modify at process runtime the contents of the allocated blocks in the volatile memory. We have identified that only the Windows operating system provide a specific function named SecureZeroMemory that can reliably zeroize data. Finally, driven by the fact that malware scrapers primarily target web browsers, we examine whether it is feasible to extract authentication credentials from the volatile memory allocated by web browsers. The presented results show that in most cases we can successfully recover user authentication credentials from all the web browsers except when the user has closed the tab that used to access the website. Stefanos Malliaros, Christoforos Ntantogian, Christos Xenakis |
ARES | 3 |
| 2016 | (U)SimMonitor: A mobile application for security evaluation of cellular networks
Christos Xenakis, Christoforos Ntantogian, Orestis Panos |
Comput. Secur. | 1 |
| 2015 | Attacking GSM Networks as a Script Kiddie Using Commodity Hardware and Software
Christoforos Ntantogian, Grigoris Valtas, Nikos Kapetanakis, Faidon Lalagiannis, Georgios Karopoulos, Christos Xenakis |
TrustBus | 6 |
| 2015 | Gaithashing: A two-factor authentication scheme based on gait features
Christoforos Ntantogian, Stefanos Malliaros, Christos Xenakis |
Comput. Secur. | 3 |
| 2014 | A specification-based intrusion detection engine for infrastructure-less networks
Christoforos Panos, Christos Xenakis, Platon Kotzias, Ioannis Stavrakakis |
Comput. Commun. | 2 |
| 2014 | Evaluating the privacy of Android mobile applications under forensic analysis
Christoforos Ntantogian, Giannis Marinakis, Christos Xenakis |
Comput. Secur. | 4 |
| 2014 | An advanced persistent threat in 3G networks: Attacking the home network from roaming networks
Christos Xenakis, Christoforos Ntantogian |
Comput. Secur. | 1 |
| 2013 | A Better Time Approximation Scheme for e-Passports
Charalampos Petrou, Christoforos Ntantogian, Christos Xenakis |
TrustBus | 3 |
| 2012 | Analysis and Modeling of False Synchronizations in 3G-WLAN Integrated Networks
Christoforos Ntantogian, Christos Xenakis, Ioannis Stavrakakis |
SEC | 2 |
| 2011 | A Mobility and Energy-Aware Hierarchical Intrusion Detection System for Mobile Ad Hoc Networks
Eleni Darra, Christoforos Ntantogian, Christos Xenakis, Sokratis K. Katsikas |
TrustBus | 3 |
| 2011 | An Evaluation of Anomaly-Based Intrusion Detection Engines for Mobile Ad Hoc Networks
Christoforos Panos, Christos Xenakis, Ioannis Stavrakakis |
TrustBus | 2 |
| 2011 | A comparative evaluation of intrusion detection architectures for mobile ad hoc networks
Christos Xenakis, Christoforos Panos, Ioannis Stavrakakis |
Comput. Secur. | 1 |
| 2011 | Reducing False Synchronizations in 3G-WLAN Integrated NetworksabstractAuthentication in 3G encompasses a mechanism, which ensures that the authentication vectors (AVs) are used only once. To achieve this, the employed mechanism maintains counters at both sides (mobile station and network) and verifies that the provided AVs are among the last α generated. However, there are many cases in which the mobile station receives AVs that have not been previously used, but the employed mechanism rejects them as outdated. This phenomenon, called false synchronization, causes signaling overhead and delays, and increases the cost of the network use. False synchronizations are more frequent in 3G-WLAN integrated networks. The frequency of false synchronizations decreases with α, while at the same time the risk of a replay attack increases. This paper aims at analytically determining an appropriate value of α, which balances effectively in 3G-WLANs the tradeoff between the rate of false synchronizations and exposure to adversaries exploiting compromised AVs. This is done by determining a threshold value of α beyond which the further reduction in false synchronizations is marginal, while the potential for a replay attack is constantly increasing and substantial. To this end, an analytical model based on a four dimensional Markov chain is developed whose accuracy is verified through simulations. Christoforos Ntantogian, Christos Xenakis, Ioannis Stavrakakis |
IEEE Trans. Wirel. Commun. | 2 |
| 2010 | A Quantitative Risk Analysis Approach for Deliberate Threats
Nikos Vavoulas, Christos Xenakis |
CRITIS | 2 |
| 2010 | A Novel Intrusion Detection System for MANETs
Christoforos Panos, Christos Xenakis, Ioannis Stavrakakis |
SECRYPT | 2 |
| 2010 | A generic mechanism for efficient authentication in B3G networks
Christoforos Ntantogian, Christos Xenakis, Ioannis Stavrakakis |
Comput. Secur. | 2 |
| 2008 | A network-assisted mobile VPN for securing users data in UMTS
Christos Xenakis, Christoforos Ntantogian, Ioannis Stavrakakis |
Comput. Commun. | 1 |
| 2007 | A Security Protocol for Mutual Authentication and Mobile VPN Deployment in B3G NetworksabstractThis paper proposes a security protocol that provides mutual authentication between a user and a WLAN that the first tries to connect to, and deploys a mobile Virtual Private Network (VPN) that protects the user's data conveyed over the wireless network. For the user authentication as well as for the initialization of the VPN and the related key agreement, the EAP-SIM encapsulated within the Internet Key Exchange version 2 (IKEv2) is proposed. The deployed VPN, which is based on IPsec, ensures confidentiality, source authentication and integrity of the data exchanged over the WLAN. At the same time, the user has been subscribed to the 3G-network for charging and billing purposes using the legacy EAP-SIM authentication protocol. The established VPN can seamlessly operate and continuously provide security services as the mobile user moves and roams, materializing the notion of mobile VPN. The proposed security protocol eliminates the required enhancements to the current network infrastructure and operates transparently to the existing network functionality. Christoforos Ntantogian, Christos Xenakis |
PIMRC | 2 |
| 2007 | Reducing Authentication Traffic in 3G-WLAN Integrated NetworksabstractThe security architecture of the 3G-WLAN integrated networks specifies that a WLAN user, in order to get access to the 3G packet switched services or the public internet through the 3G PLMN, he must follow a two-pass EAP-AKA authentication procedure. This involves a double execution of EAP-AKA, which introduces a duplicated authentication overhead. This paper proposes a one-pass EAP-AKA authentication procedure for the 3 G-WLAN integrated networks that reduces significantly the authentication traffic, compared to the two-pass EAP-AKA authentication, without compromising the provided level of security. The proposed procedure has minimal impact on the existing 3 G-WLAN network infrastructure and functionality. A security analysis of the proposed authentication procedure is elaborated that identifies potential attacks and proposes possible countermeasures. In addition, a cost analysis is considered that compares the total number of messages required for user's authentication using the two-pass EAP-AKA and the proposed one-pass EAP-AKA authentication. Christoforos Ntantogian, Christos Xenakis |
PIMRC | 2 |
| 2006 | Vulnerabilities and Possible Attacks Against the GPRS Backbone Network
Christos Xenakis, Lazaros F. Merakos |
CRITIS | 1 |
| 2006 | A generic characterization of the overheads imposed by IPsec and associated cryptographic algorithms
Christos Xenakis, Nikolaos Laoutaris, Lazaros F. Merakos, Ioannis Stavrakakis |
Comput. Networks | 1 |
| 2004 | Security in third Generation Mobile Networks
Christos Xenakis, Lazaros F. Merakos |
Comput. Commun. | 1 |
| 2004 | IPsec-based end-to-end VPN deployment over UMTS
Christos Xenakis, Lazaros F. Merakos |
Comput. Commun. | 1 |
| 2002 | Dynamic network-based secure VPN deployment in GPRSabstractA dynamic network-based virtual private network (VPN) deployment, which is established between the general packet radio services (GPRS) border gateway and a corporate intranet gateway, is presented and analyzed. By relying on a sequence of concatenated protection mechanisms (GPRS ciphering and VPN deployment), it is possible to provide secure remote access to mobile users without requiring an extra tunnel overhead on the radio link or the implementation of computationally intense encryption algorithms in the mobile station. The VPN functionality is based on IPsec. For VPN initialization and key agreement procedures, an Internet key exchange (IKE) protocol proxy scheme is proposed, which enables the mobile user to initiate a VPN, while shifting complex key negotiation to the network infrastructure. The required enhancements for security service provision can be integrated in the existing network infrastructure, and therefore, the proposed security scheme can be used as an add-on feature of the GPRS. Christos Xenakis, Lazaros F. Merakos |
PIMRC | 1 |
| 1998 | Signaling and mobility control for wireless intelligent ATM CPNsabstractA wireless intelligent ATM access system is explored from a signaling protocol viewpoint. The proposed architecture is consistent with the B-ISDN user-network interface (UNI) signaling structure as a wireless local area network to access the ATM core network infrastructure, and can be adapted to cater also for a wireless broadband access network for future mobile telecommunication systems. Emphasis is placed on taking advantage of well-developed protocol standards, where appropriate, to allow the easy introduction of the proposed architecture in the real world. The evaluation of the signaling performance of the system captures the effect of the proposed structure on the performance of call and mobility control and yields results, which fall within acceptable signaling performance measures. Nikolaos H. Loukas, Christos Xenakis, Lazaros F. Merakos, Iakovos S. Venieris |
PIMRC | 2 |