VLDB 2026 Research / reviewers in the wild / expert
Panayiotis Kotzanikolaou
dblp:12/5285
· DBLP profile ↗
36ranked-venue papers
8as first author
10since 2021 · last 2025
0000-0002-8771-9020ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 3 first-author · 5 since 2021Security and privacy · 12 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AI-Based MITRE ATT&CK Detection System: A Feasibility StudyabstractThe rise in cyber threats necessitates automated detection systems that can effectively identify and respond to hostile techniques. This paper presents a feasibility assessment of adopting Large Language Models (LLMs) to enhance cyber-security operations within the MITRE ATT&CK framework. We research how AI can automate Kusto Query Language (KQL) development to better cyber threat detection in Microsoft Sentinel. We start with prompt engineering to improve AI-generated queries, then compare LLMs to determine the top models. Through successive breakthroughs, we progressed from a naïve prompting method to an advanced Chain of Thought (CoT) prompting technique, enabling AI models to give more contextually accurate and structured KQL queries. We extensively tested both open-source and closed-source models, evaluating their performance using two separate accuracy scoring formulae. Our results demonstrate that CoT significantly enhances the precision of AI-generated queries, while ChatGPT-4o-mini surpasses other models in generating structured KQL queries. Our technology leverages real-time MITRE ATT&CK Intelligence and Microsoft Sentinel log analysis for automated threat identification and response in order to minimize human effort and enhance productivity. Our approach applies AI to automate cybersecurity tasks, whereas most other research on LLM-assisted security analytics remains theoretical and thus fills an important gap between theory and practice. Dimitris Koutras, Michalis Karamousadakis, Giannis Konstantinidis, Christos Grigoriadis, Vangelis Malamas, Panayiotis Kotzanikolaou |
CoDIT | 6 |
| 2025 | HA-CAAP: Hardware-Assisted Continuous Authentication and Attestation Protocol for IoT Based on BlockchainabstractThe increasing integration of Internet of Things (IoT) devices in various sectors has created complex and dynamically changing interconnected systems. In several multiauthority and multidomain applications, IoT devices may continuously change their connectivity status, leading to dynamic topologies; an IoT device may be connected to different gateways at different times, to support the provisioning of a distributed service. However, these complex environments increase exposure to security threats, such as device spoofing or cloning attacks. Even worse, without continuous device inventorying, an adversary may easily duplicate a cloned device and concurrently connect compromised Sybil nodes at different gateways, without getting noticed. This article proposes Hardware-assisted, continuous authentication and attestation protocol (HA-CAAP), a hardware-assisted continuous authentication and attestation protocol for IoT devices. By using a physically unclonable function-based periodic authentication mechanism, gateways can continuously authenticate their connected devices and detect modifications in their connectivity status, in nearly real-time. Through a private blockchain, gateways are able to continuously exchange information about their connectivity state and securely share a dynamic device inventory, to detect possible Sybil attacks. In addition, by integrating a continuous gateway attestation mechanism in the blockchain, the protocol prevents nontrusted gateways from joining in and assures their integrity. To evaluate HA-CAAP, security is formally analyzed, while a proof-of-concept implementation is used to analyze the protocol’s performance, for realistic application scenarios. Vangelis Malamas, Panayiotis Kotzanikolaou, Konstantinos Nomikos, Christos Zonios, Vasileios Tenentes, Mihalis Psarakis |
IEEE Internet Things J. | 2 |
| 2024 | An Edge Multi Factor Authentication System for Cyber Physical Systems Based on OTPabstractThe Internet of Things (IoT) optimizes remote operations in Cyber-Physical Systems (CPS) by enabling real-time bidirectional communication with cloud services, thus supporting efficient management. However, this increases security risks. Ensuring strong remote user authentication is crucial. This paper presents a Multi-Factor Authentication (MFA) system using Time-based One-Time Passwords (T-OTP) for securing user access at the edge layer of CPS. We validate the system through test cases in smart buildings and Industrial IoT (IIoT) scenarios, demonstrating its broad applicability in enhancing secure remote management of critical systems. Christos Theodoropoulos 0003, Dimitris Koutras, Christos Douligeris, Panayiotis Kotzanikolaou |
ISCC | 4 |
| 2023 | Blockchain Service Layer for ERP data interoperability among multiple supply chain stakeholdersabstractCompanies in the supply chain recognize Enterprise Resource Planning (ERP) software as an indispensable component of their businesses that significantly helps with planning, decision-making, and cost reductions. However, despite the benefits of ERP, the interaction between supply chain stakeholders with varying and even contradictory security and privacy requirements could be challenging. In addition, incorporating a cross-domain access control might be hard because parties may require different access levels for information maintained outside their own ERP. In this work, we propose a blockchain architecture that acts as a service layer on top of existing ERP systems to achieve fine-grained intra- and cross-domain access control. A private blockchain is combined with four fully functional Smart Contracts to enable access control and trust management services, a data handler service, ensuring data integrity for both insiders and outsiders, and an audit mechanism. Vangelis Malamas, Thomas K. Dasaklis, Theodore G. Voutsinas, Panayiotis Kotzanikolaou |
CoDIT | 4 |
| 2023 | Assessing the Security Risks of Medical Mobile ApplicationsabstractIn this study, we conducted a comprehensive security analysis of 140 medical mobile applications tested on both Android and iOS platforms. Our methodology included looking for side channel leaks that can be abused by third-party applications installed on the device, assessing support for old and potentially vulnerable versions of Android and iOS, evaluating device and application integrity protections, conducting dynamic analysis to observe runtime behavior such as local data storage practices, and searching for hardcoded keys or other sensitive information embedded in the code. We also performed traffic analysis to observe communication between the mobile applications and their associated APIs. Our findings reveal that significant underlooked risks still exist. The majority of the apps we analyzed lacked typical security safeguards, such as root detection and secure local data storage, leaving sensitive Patient Health Information (PHI) vulnerable to attackers with local or physical access to the device. Four of the apps were communicating over plain HTTP, which poses a significant risk to the confidentiality and integrity of the patient data that was transmitted. These results highlight the urgent need for improved security measures in medical mobile applications, both from a technical and regulatory point of view. George Chatzisofroniou, Chris Markellos, Panayiotis Kotzanikolaou |
ISCC | 3 |
| 2023 | Automated WiFi Incident Detection Attack Tool on 802.11 NetworksabstractIn this paper we propose a methodology for intrusion detection of attacks originating from WiFi networks, along with WiFi-NID, a WiFi Network Intrusion Detection tool, developed to automate the detection such attacks at the 802.11 networks. In particular, WiFi-NID has the ability to detect and trace possible illegal network scanning attacks, which originate from attacks at the WiFi access layer. A penetration testing methodology is defined, in order to discover the environmental security characteristics, related with the current configuration of the devices connected to the 802.11 network. The methodology covers known WiFi attacks such as deauthentication attacks, capturing and cracking WPA-WPA/2 handshake, captive portal and WPA attacks, mostly based on various open source software tools, as well as on specialized hardware. For the validation process, a testbed is set based on realistic scenarios of WiFi network topologies. Dimitris Koutras, Panos Dimitrellos, Panayiotis Kotzanikolaou, Christos Douligeris |
ISCC | 3 |
| 2022 | Automating environmental vulnerability analysis for network servicesabstractThe goal of this paper is to propose a framework in order to automate the environmental vulnerability assessment of communication protocols and networked services in operational environments. Initially, a network security ontology is defined, to model the environmental characteristics related with the current security status of available communication protocols channels within an examined infrastructure. The functionality of this infrastructure is presented by an ontology. All active communication services are initially identified and enumerated using a combination of different information gathering tools. Then by combining passive scanning and active security analysis tools each active communication service is assessed to output an environmental security score. This score may be utilized in vulnerability scoring systems such as CVSS, to properly adjust relevant scores and to identify implementation or configuration weaknesses in real environments. By using a test environment that involves various networks and communication protocols, we validate the proposed framework and we provide concrete examples for popular communication protocols. Dimitris Koutras, Christos Grigoriadis, Michalis Papadopoullos, Panayiotis Kotzanikolaou, Christos Douligeris |
ISCC | 4 |
| 2022 | Assessing smart light enabled cyber-physical attack paths on urban infrastructures and servicesabstractInternet-of-Things (IoT) extends the provision of remotely managed services across different domains. At the same time, IoT devices primarily designed for home environments may also be installed within the premises of critical urban environments, such as government, banking and corporate domains, without proper risk evaluation. In this paper, we examine the effect of cascading attacks triggered by the integration of vulnerable smart lighting systems in critical domains. In particular, we utilise known vulnerabilities of smart lighting systems to demonstrate the potential risk propagation on popular installation domains found in smart cities and urban infrastructures and services. Based on validated vulnerabilities on popular off-the-shelf smart lighting systems, we set up realistic proof-of-concept connectivity scenarios for various urban infrastructures and domains. Using these scenarios, we evaluate the risk of cascading attacks, by applying a targeted risk assessment methodology for identifying and assessing IoT-enabled attacks. Ioannis Stellios, Kostas Mokos, Panayiotis Kotzanikolaou |
Connect. Sci. | 3 |
| 2022 | Exploiting WiFi usability features for association attacks in IEEE 802.11: Attack analysis and mitigation controlsabstractAssociation attacks aim to manipulate WiFi clients into associating with a malicious access point, by exploiting protocol vulnerabilities and usability features implemented on the network managers of modern operating systems. In this paper we classify association attacks based on the network manager features that each attack exploits. To validate their current validity status, we implement and test all known association attacks against the network managers of popular operating systems, by using our Wifiphisher tool. We analyze various strategies that may be implemented by an adversary in order to increase the success rate of association attacks. Furthermore, we examine the behavior of association attacks against upcoming security protocols and certifications for IEEE 802.11, such as WPA3, Wi-Fi Enhanced Open and Easy Connect. Our results show that even though the network managers have hampered the effectiveness of some known attacks (e.g. KARMA), other techniques (e.g. Known Beacons) are still active threats. More importantly, our results show that even the newer security protocols leave room for association attacks. Finally, we describe novel detection and prevention techniques for association attacks, as well as security controls based on user awareness. George Chatzisofroniou, Panayiotis Kotzanikolaou |
J. Comput. Secur. | 2 |
| 2021 | Assessing IoT enabled cyber-physical attack paths against critical systems
Ioannis Stellios, Panayiotis Kotzanikolaou, Christos Grigoriadis |
Comput. Secur. | 2 |
| 2020 | On a Security-oriented Design Framework for Medical IoT Devices: The Hardware Security PerspectiveabstractAs medical devices more and more use Internet of Things based technologies, serious concerns are raised about their security and the privacy of patient's personal health data. To address these concerns, while maintaining reasonable overheads, designers of medical devices need to take security into account from the beginning until the completion of their designs. In this work we identify the relevant security domains and focus to the Hardware Security perspective. Additionally, we present a secure design and evaluation framework which can assist designers towards more secure medical devices. The framework integrates a complete insulin pump architecture containing all the basic components used in such applications. To illustrate the advantages of the proposed framework we perform a Side Channel Analysis attack against the embedded encryption algorithm of the device to obtain the secret encryption key. Then, we make use of the framework to identify all the components of the system which are either directly or indirectly affected by the attack. This analysis leads us to determine more complex combined attacks which may complement the SCA attack into compromising the overall security of the system. Konstantinos Nomikos, Athanasios Papadimitriou, George Stergiopoulos, Dimitris Koutras, Mihalis Psarakis, Panayiotis Kotzanikolaou |
DSD | 6 |
| 2020 | TS-LoRa: Time-slotted LoRaWAN for the Industrial Internet of ThingsabstractAutomation and data capture in manufacturing, known as Industry 4.0, requires the deployment of a large number of wireless sensor devices in industrial environments. These devices have to be connected via a reliable, low-latency, low-power and low operating-cost network. Although LoRaWAN provides a low-power and reasonable-cost network technology, its current ALOHA-based MAC protocol limits its scalability and reliability. A common practise in wireless networks is to solve this issue and improve scalability through the use of time-slotted communications. However, any time-slotted approach comes with overheads to compute and disseminate the transmission schedule in addition to ensuring global time synchronisation. Affording these overheads is not straight forward with LoRaWAN restrictions on radio duty-cycle and downlink availability. Therefore, in this work, we propose TS-LoRa, an approach that tackles these overheads by allowing devices to self-organise and determine their slot positions in a frame autonomously. In addition to that, only one dedicated slot in each frame is used to ensure global synchronisation and handle acknowledgements. Our experimental results with 25 nodes show that TS-LoRa can achieve more than 99% packet delivery ratio even for the most distant nodes. Moreover, our simulations with a higher number of nodes revealed that TS-LoRa exhibits a lower energy consumption than the confirmable version of LoRaWAN while not compromising the packet delivery ratio. Dimitrios Zorbas, Khaled Q. Abdelfadeel, Panayiotis Kotzanikolaou, Dirk Pesch |
Comput. Commun. | 3 |
| 2020 | A Dependency Analysis Model for Resilient Wide Area Measurement Systems in Smart GridabstractWide Area Measurement Systems (WAMS) consist of the measuring and the communication layers (infrastructures) of smart grids, which are used to monitor, operate and control the electrical infrastructure. Resilience is a very important requirement in smart grids, since they must be able to resist in failures at any layer, caused both by intentional attacks or unintentional events. Thus, while cost optimization is usually the most important concern when designing WAMS, increasing the resilience of the WAMS layers should also be considered as an important constraint. In this paper we propose a model for WAMS designing that takes into consideration both optimization and resilience metrics. The proposed model extends a WAMS placement optimization model by combining an optimization algorithm with a graph-based dependency analysis approach that considers the internal dependencies between the measuring and the communication WAMS layers. Based on simulation results, we show that the proposed model increases WAMS resilience by reducing the dependency levels of carefully selected nodes and/or by selectively adding measurement units and/or communication links in places indicated by the proposed algorithm. Thus, our approach can be categorized as a hybrid resilience algorithm that combines both robustness and redundancy. Mohammad Shahraeini, Panayiotis Kotzanikolaou |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | A Forensics-by-Design Management Framework for Medical Devices Based on BlockchainabstractThe Internet of Medical Things (IoMT) provides ubiquitous healthcare services for patient monitoring and treatment. However, the interaction between doctors, patients, healthcare personnel and device manufacturers, with different and often conflicting security and privacy objectives, make such services vulnerable and subject to exploitation. In addition, since parties may require different access levels and the IoMT devices involve different functionalities, access control can be challenging. In this paper, we propose a blockchain-enabled authorization framework for managing both IoMT devices and medical files by creating a distributed chain of custody and health data privacy scheme. The core idea is to build trust domains for the various stakeholders and IoMT devices, in such a way that fine-grain access is enabled by taking into account critical attributes of the IoMT ecosystem such as a) the different roles and capabilities of the IoMT devices and b) their interaction with the users/stakeholders. A private blockchain is used in combination with on-chain smart contracts to allow for a forensics-by-design management architecture with audit trails for integrity and provenance guarantees as well as health data privacy. The private blockchain ecosystem is authenticated by a proof-of-medical-stake consensus mechanism that is tailored for medical applications. Vangelis Malamas, Thomas K. Dasaklis, Panayiotis Kotzanikolaou, Mike Burmester, Sokratis K. Katsikas |
SERVICES | 3 |
| 2019 | Guest Editorial Special Issue on Secure Embedded IoT Devices for Resilient Critical InfrastructuresabstractThe Internet of Things (IoT) creates new technological opportunities for a wide range of systems, such as industrial control systems, smart power grids, vehicular networks (VNs) and intelligent transportation systems, body area networks and healthcare monitoring and control systems and smart homes. At the same time, IoT also increases the threat surface for potential adversaries targeting critical interconnected systems that may depend on embedded IoT systems, such as supervisory control and data acquisition (SCADA) systems. At this point, attackers could take advantage from the incorporation of the paradigm to exploit new security gaps, probably caused by unforeseen interoperability and adaptability problems. Indeed, the deployment of Internet-enabled embedded devices that are distributed over major critical domains may create indirect and nonobvious interconnections with the underlying critical infrastructures (CIs). There is a need to further explore the security issues related to IoT technologies and to assure the resilience of CIs against advanced IoT-enabled attacks. The focus of this special issue is therefore to provide readers with the latest advances in securing the interaction between embedded IoT devices and CIs in order to increase their resilience to advanced IoT-enabled threats. Cristina Alcaraz, Mike Burmester, Jorge Cuéllar, Xinyi Huang 0001, Panayiotis Kotzanikolaou, Mihalis Psarakis |
IEEE Internet Things J. | 5 |
| 2018 | R-TSCH: Proactive Jamming Attack Protection for IEEE 802.15.4-TSCH NetworksabstractTime Slotted Channel Hopping (TSCH) has been proposed in various wireless protocols as a solution to combat external interference, path-loss fading and static jamming attacks. However, since TSCH algorithms generate a deterministic and periodic pattern of channel hops, they are still subject to jamming attacks. Proactive randomization of the channel generation process could provide a good solution against jamming attacks, however due to the strict time constraints of the timeslots, practical solutions should be very efficient. In this paper, we propose R-TSCH, a randomized radio channel generation algorithm that can be used to proactively protect wireless nodes from jamming attacks. Based on a cryptographic hash function and a secret key, R-TSCH produces a new pseudo-random channel sequence, which looks as truly random to anyone who has no access to the key. Our simulation results show that the attacked links of the TSCH network enhanced with the proposed mechanism can achieve an over 90% Packet Reception Rate (PRR) in presence of multiple jammers. Dimitrios Zorbas, Panayiotis Kotzanikolaou, Christos Douligeris |
ISCC | 2 |
| 2016 | Lightweight private proximity testing for geospatial social networks
Panayiotis Kotzanikolaou, Constantinos Patsakis, Emmanouil Magkos, Michalis Korakakis |
Comput. Commun. | 1 |
| 2016 | SCN-SI-021 achieving privacy and access control in pervasive computing environmentsabstractAbstract This paper focuses on the inherent trade‐off between privacy and access control in pervasive computing environments (PCEs). On one hand, service providers require user authentication and authorization for the provision of a service, while at the same time end users require untraceability and unlinkability for their transactions. There are also cases where the anonymity of a specific credential must be revoked and a real identity be traced, in order to establish accountability. We analyze privacy and security requirements for PCEs and we show that existing privacy‐preserving access control schemes do not fully satisfy these requirements. Then we propose two approaches towards privacy‐preserving access control in PCEs. Our goal is twofold: (a) to enhance privacy by achieving untraceability and unlinkability even against malicious insiders and (b) to enhance security by achieving conditional traceability of user credentials, and if possible, non‐repudiation of evidence concerning the user's participating in a transaction. Finally, we analyze and compare the proposed schemes against existing schemes. Copyright © 2011 John Wiley & Sons, Ltd. Emmanouil Magkos, Panayiotis Kotzanikolaou |
Secur. Commun. Networks | 2 |
| 2014 | Towards Secure and Practical Location Privacy through Private Equality Testing
Emmanouil Magkos, Panayiotis Kotzanikolaou, Marios Magioladitis, Spyros Sioutas, Vassilios S. Verykios |
Privacy in Statistical Databases | 2 |
| 2013 | Toward early warning against Internet worms based on critical-sized networksabstractABSTRACT In this paper, we build on a recent worm propagation stochastic model, in which random effects during worm spreading were modeled by means of a stochastic differential equation. On the basis of this model, we introduce the notion of thecritical sizeof a network, which is the least size of a network that needs to be monitored, in order to correctly project the behavior of a worm in substantially larger networks. We provide a method for the theoretical estimation of the critical size of a network in respect to a worm with specific characteristics. Our motivation is the requirement in real systems to balance the needs for accuracy (i.e., monitoring a network of a sufficient size in order to reduce false alarms) and performance (i.e., monitoring a small‐scale network to reduce complexity). In addition, we run simulation experiments in order to experimentally validate our arguments. Finally, based on notion of critical‐sized networks, we propose a logical framework for a distributed early warning system against unknown and fast‐spreading worms. In the proposed framework, propagation parameters of an early detected worm are estimated in real time by studying a critical‐sized network. In this way, security is enhanced as estimations generated by a critical‐sized network may help large‐scale networks to respond faster to new worm threats. Copyright © 2012 John Wiley & Sons, Ltd. Emmanouil Magkos, Markos Avlonitis, Panayiotis Kotzanikolaou, Michalis Stefanidakis |
Secur. Commun. Networks | 3 |
| 2012 | Chord-PKI: A distributed trust infrastructure based on P2P networks
Agapios Avramidis, Panayiotis Kotzanikolaou, Christos Douligeris, Mike Burmester |
Comput. Networks | 2 |
| 2011 | Interdependencies between Critical Infrastructures: Analyzing the Risk of Cascading Effects
Panayiotis Kotzanikolaou, Marianthi Theoharidou, Dimitris Gritzalis |
CRITIS | 1 |
| 2010 | A distributed privacy-preserving scheme for location-based queriesabstractIn this paper we deal with security and historical privacy in Location Based Service (LBS) applications where users submit accurate location samples to an LBS provider. Specifically we propose a distributed scheme that establishes access control while protecting the privacy of a user in both sporadic and continuous LBS queries. Our solution employs a hybrid network architecture where LBS users: (a) are able to communicate with an LBS provider through a network (e.g., cellular) operator, and (b) they are also able to create wireless ad-hoc networks with other peers in order to obtain privacy against an adversary that performs traffic analysis. Our threat model considers the network operator, the LBS provider and other peers, as potential privacy adversaries. For historical privacy we adopt the generic approach of using multiple pseudonyms that are changed frequently. In order to establish untraceability against traffic analysis attacks, a message is not sent directly to the cellular operator, but it is distributed among mobile neighbors who act like mixes and re-encrypt a message before sending it to the LBS provider via the cellular operator. As an extension, we also discuss how to aggregate independent data from different mobile peers before sending them to the LBS provider. This approach may be suitable in applications where aggregate location data are useful (e.g., traffic monitoring and control). Emmanouil Magkos, Panayiotis Kotzanikolaou, Spyros Sioutas |
WOWMOM | 2 |
| 2010 | Solving coverage problems in wireless sensor networks using cover sets
Dimitrios Zorbas, Dimitris Glynos, Panayiotis Kotzanikolaou, Christos Douligeris |
Ad Hoc Networks | 3 |
| 2010 | A multi-layer Criticality Assessment methodology based on interdependencies
Marianthi Theoharidou, Panayiotis Kotzanikolaou, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2009 | Secure and practical key establishment for distributed sensor networksabstractAbstract Key establishment in sensor networks is a challenging task, due to the physical constraints of sensor devices and their exposure to several threats. Existing protocols based on symmetric cryptography are very efficient but they are weak against several node impersonation and insider attacks. On the other hand, asymmetric protocols are resilient to such attacks but unfortunately, they are not feasible for sensor networks, even in their most efficient versions (e.g. the elliptic curve (EC) Diffie‐Hellman family of key agreement protocols). In this paper, we present two pairwise key establishment protocols for sensor nodes in unattended distributed sensor networks (DSNs). The first protocol is hybrid and it combines asymmetric (elliptic curve (EC)) cryptography with symmetric key techniques. The second protocol is fully asymmetric. Furthermore, through simulations, we measure the efficiency of the proposed protocols in comparison with existing hybrid protocols. Our results show that under conditions, it is feasible for highly sensitive applications of static sensor networks to employ partial or fully asymmetric key establishment techniques and thus extend their security properties. Copyright © 2009 John Wiley & Sons, Ltd. Panayiotis Kotzanikolaou, Emmanouil Magkos, Dimitrios D. Vergados, Michalis Stefanidakis |
Secur. Commun. Networks | 1 |
| 2008 | Secure log management for privacy assurance in electronic communications
Vassilios Stathopoulos 0001, Panayiotis Kotzanikolaou, Emmanouil Magkos |
Comput. Secur. | 2 |
| 2007 | Privacy Threats of Data Retention in Internet CommunicationsabstractData retention refers to the legal obligation of Internet service providers (ISPs) to retain the communication data of their subscribers for a certain period, in order to enable the legal investigation of possible crimes. However, the retention of communication data increases the security threats against the privacy of theirs subscribers. In this paper we explore the privacy issues of data retention in Internet communications. We also describe possible security mechanisms which may thwart these threats and minimize the risks against user privacy. Panayiotis Kotzanikolaou, Christos Douligeris |
PIMRC | 1 |
| 2007 | SecMR - a secure multipath routing protocol for ad hoc networks
Rosa Mavropodi, Panayiotis Kotzanikolaou, Christos Douligeris |
Ad Hoc Networks | 2 |
| 2006 | A Framework for Secure and Verifiable Logging in Public Communication Networks
Vassilios Stathopoulos 0001, Panayiotis Kotzanikolaou, Emmanouil Magkos |
CRITIS | 2 |
| 2006 | Secure distributed intelligent networks
Panayiotis Kotzanikolaou, Rosa Mavropodi, Christos Douligeris, Vassilios Chrissikopoulos |
Comput. Commun. | 1 |
| 2005 | Performance Analysis of a Hybrid Key Establishment Protocol for Wireless Sensor NetworksabstractDistributed sensor networks are becoming increasingly popular, as they can be used in a variety of applications. However, limitations arising from the sensor nodes structure, such as limitations in energy, memory and computing power require new networking techniques to be introduced. DSNs are in general more vulnerable to security threats than other wired or wireless networks. Several key establishment schemes for multiphase deployment have been presented, however such schemes are unable to provide adequate security against attacks, such as fake generation attacks. In this paper, the performance analysis of the hybrid key establishment protocol proposed by Kotzanikolaou et al. (2005) for wireless sensor networks is analyzed. Panayiotis Kotzanikolaou, Dimitrios D. Vergados, Giannis Stergiou |
ISM | 1 |
| 2005 | Preventing Impersonation Attacks in MANET with Multi-Factor AuthenticationabstractExisting MANET authentication schemes cannot fully protect nodes from well-known impersonation attacks. Although these schemes cryptographically link an entity to a claimed identity, the actual entity is never linked to the physical node device. However, the link is implicitly assumed. This shortcoming may be easily exploited within a MANET setting, due to the broadcast nature of the access medium. In this paper we propose a multifactor authentication framework that extends the cryptographic link, binding an entity to a physical node device. This is achieved by using two distinct authentication factors; certified keys and certified node characteristics. Although the proposed framework requires additional sensing capabilities from the MANET nodes, it provides the additional confidence level required for node authentication in critical applications. Dimitris Glynos, Panayiotis Kotzanikolaou, Christos Douligeris |
WiOpt | 2 |
| 2005 | Hybrid Key Establishment for Multiphase Self-Organized Sensor NetworksabstractRecent work on key establishment for sensor networks has shown that it is feasible to employ limited elliptic curve cryptography in sensor networks through hybrid protocols. We propose a hybrid key establishment protocol for uniform self-organized sensor networks. The proposed protocol combines elliptic curve Diffie-Hellmann key establishment with implicit certificates and symmetric-key cryptographic techniques. The protocol can be implemented on uniform networks comprised of restricted functional devices. Furthermore, due to its public-key nature, the protocol is resilient to a wide range of passive and active attacks, such as known-key attacks, as well as attacks against the confidentiality, integrity and authenticity of the communication. The protocol is scalable and efficient for low-capability devices in terms of storage, communication and computational complexity; the cost per node for a key establishment is reduced to one scalar multiplication with a random point, plus one with a fixed point. Panayiotis Kotzanikolaou, Emmanouil Magkos, Christos Douligeris, Vassilios Chrissikopoulos |
WOWMOM | 1 |
| 2001 | Strong Forward Security
Mike Burmester, Vassilios Chrissikopoulos, Panayiotis Kotzanikolaou, Emmanouil Magkos |
SEC | 3 |
| 2000 | Secure Transactions with Mobile Agents in Hostile Environments
Panayiotis Kotzanikolaou, Mike Burmester, Vassilios Chrissikopoulos |
ACISP | 1 |