VLDB 2026 Research / reviewers in the wild / expert
Anna Georgiadou
dblp:130/2390
· DBLP profile ↗
8ranked-venue papers
5as first author
8since 2021 · last 2023
0000-0002-0078-6969ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | A security awareness and competency evaluation in the energy sector
Anna Georgiadou, Ariadni Michalitsi-Psarrou, Dimitris Askounis |
Comput. Secur. | 1 |
| 2022 | Evaluating The Cyber-Security Culture of the EPES Sector: Applying a Cyber-Security Culture Framework to assess the EPES Sector's resilience and readinessabstractThe Energy Sector is highly targeted by cyber threats because of its inherent value and profitability. Recent reported security incidents verify its key playing role in the entire economic and societal concurrent reality. This paper aims to assess the cyber-security culture status of European representatives in the entire electrical power supply chain during the coronavirus pandemic and the Ukrainian war. An evaluation campaign has been carefully designed and held from 3rd March 2022 to 18th March 2022. During that period, participants from different Electrical Power and Energy Systems (EPES) organizations participated in the campaign. Gathered results were analyzed and co-examined using different techniques revealing important findings regarding the cyber-security status and resilience of individuals and organizations in the European EPES sector. Anna Georgiadou, Ariadni Michalitsi-Psarrou, Dimitris Askounis |
ARES | 1 |
| 2022 | Cyber-Security Culture Assessment in Academia: A COVID-19 Study: Applying a Cyber-Security Culture Framework to assess the Academia's resilience and readinessabstractTimes of crisis have long been combined with an increase in cybercrime, exploiting the general instability; therefore, in such times, systems and infrastructures face greater exposure to vulnerabilities. On top of that, the COVID-19 crisis has increased our reliance on the internet, while working-from-home has been the daily reality for a large proportion of the population worldwide. Increased cyber-security awareness becomes a necessity for everyone, starting from a more knowledgeable audience; IT professionals, and software engineers. In this context, this paper aims to assess the cyber-security culture readiness of representatives studying or working within a European Polytechnique Academic Institution, during the COVID-19 crisis. Towards that end, a targeted evaluation campaign was launched for two weeks, from 28th February 2022 to 13th March 2022. The campaign consisted of four questionnaires of increased difficulty and a phishing quiz, all assessing the security culture of the participants against three dimensions; their security attitude, their competency, and their actual behavior. The campaign results have been thoroughly analyzed, and the findings were unforeseen in many cases, supporting the identification of security awareness weaknesses and assisting in drafting targeted, customized training programs. Anna Georgiadou, Ariadni Michalitsi-Psarrou, Dimitris Askounis |
ARES | 1 |
| 2022 | A tool for assisting in the forensic investigation of cyber-security incidentsabstractThe exponential growth of networking capabilities including the Internet of Things (IoT), has led to an outburst of cyberattacks. Many well-documented cyber-attacks have targeted critical energy infrastructures as well as any kind of cloud-based IT platforms. Early examination of critical systems’ vulnerabilities, as well as previous cyber-security incidents, are of utmost importance to prevent new ones. A thorough investigation to examine the context of the cyber-security breach can reveal facts about the source of the attack, the profile of the attacker, the resources, and the skills required and can further reveal mitigations for preventing the attack from re-appearing in the future. To safeguard critical energy infrastructures, many forensic approaches have been developed to collect, analyze, and digitalize evidence assisting in the in-depth investigation of an incident. However, up to now, the many open-source vulnerability data sources which have been developed to provide valuable information for a cyber-attack are yet to be employed to assist in forensic investigation. This paper introduces the Automated Forensic Tool, a platform that employs machine learning algorithms to combine different vulnerability data sources for facilitating the forensic procedure while minimizing the time and effort needed. A use case is also demonstrated that displays how the tool can be used towards assisting the forensic investigation of cyber-security incidents on an energy infrastructure, but the tool can also be applied to other critical energy and IT infrastructures with minor adaptations. Konstantinos Touloumis, Ariadni Michalitsi-Psarrou, Anna Georgiadou, Dimitris Askounis |
IEEE Big Data | 3 |
| 2022 | Detecting Insider Threat via a Cyber-Security Culture FrameworkabstractInsider threat has been recognized by both scientific community and security professionals as one of the gravest security hazards for private companies, institutions, and governmental organizations. Extended research on the types, associated internal and external factors, detection approaches and mitigation strategies has been conducted over the last decades. Various frameworks have been introduced in an attempt to understand and reflect the danger posed by this threat, whereas multiple identified cases have been classified in private or public databases. This paper aims to present how a cyber-security culture framework with a clear focus on the human factor can assist in detecting possible threats of both malicious and unintentional insiders. We link current insider threat categories with specific security domains of the framework and introduce an assessment methodology of the core contributing parameters. Specific approach takes into consideration technical, behavioral, cultural, and personal indicators and assists in identifying possible security perils deriving from privileged individuals. Anna Georgiadou, Spiros Mouzakitis, Dimitris Askounis |
J. Comput. Inf. Syst. | 1 |
| 2022 | A Cyber-Security Culture Framework for Assessing Organization ReadinessabstractThis paper presents a cyber-security culture framework for assessing and evaluating the current security readiness of an organization’s workforce. Having conducted a thorough review of the most commonly used security frameworks, we identify core security human-related elements and classify them by constructing a domain agnostic security model. We then proceed by presenting in detail each component of our model and attempt to quantify them in order to achieve a feasible assessment methodology. The paper thereafter presents the application of this methodology for the design and development of a security culture evaluation tool, that offers recommendations and alternative approaches to workforce training programs and techniques. The model has been designed to easily adapt on various application domains while focusing on their unique characteristics. The paper concludes on applications of our instrument on security-critical domains, and its contribution to current research by providing deeper insights regarding the human factor in cybersecurity. Anna Georgiadou, Spiros Mouzakitis, Kanaris Bounas, Dimitris Askounis |
J. Comput. Inf. Syst. | 1 |
| 2021 | Integrating Security Behavior into Attack SimulationsabstractThe increase of cyber-attacks raised security concerns for critical assets worldwide in the last decade. Leading to more efforts spent towards increasing the cyber security among companies and countries. For the sake of enhancing cyber security, representation and testing of attacks have prime importance in understanding system vulnerabilities. One of the available tools for simulating attacks on systems is the Meta Attack Language (MAL), which allows representing the effects of certain cyber-attacks. However, only understanding the component vulnerabilities is not enough in securing enterprise systems. Another important factor is the ‘human‘, which constitutes the biggest ‘insider threat‘. For this, Security Behavior Analysis (SBA) helps understanding which system components that might be directly affected by the ‘human‘. As such, in this work, the authors present an approach for integrating user actions, so called “security behavior”, by mapping SBA to a MAL-based language through MITRE ATT&CK techniques. Simon Hacks, Ismail Butun, Robert Lagerström, Andrei Buhaiu, Anna Georgiadou, Ariadni Michalitsi-Psarrou |
ARES | 5 |
| 2021 | Vulnerabilities Manager, a platform for linking vulnerability data sourcesabstractIn order to get a deeper understanding of security breaches, their severity, impact and ways to mitigate them, many vulnerability databases and dictionaries have been developed. However, all that information on vulnerabilities is scattered all over the web, which makes locating and mitigating vulnerabilities an arduous task. This paper introduces the Vulnerabilities Manager, a tool that automates the process of linking information from well-known external vulnerability data sources. Its goal is to present an enriched vulnerability report to its final users, assisting them in pinpointing software and hardware assets’ defects, categorizing and prioritizing them, thus, contributing to the cyber defense against potential security breaches and adversary actions. To achieve this, the Vulnerabilities Manager exploits current state of the art machine learning and artificial intelligence techniques. The tool may also be enriched with forensic capabilities, detecting cyber threats, unveiling information about the nature of the attacker, and proposing mitigations against them in real-time. Konstantinos Touloumis, Ariadni Michalitsi-Psarrou, Panagiotis Kapsalis, Anna Georgiadou, Dimitris Askounis |
IEEE BigData | 4 |