VLDB 2026 Research / reviewers in the wild / expert
Emmanouil Vasilomanolakis
dblp:140/6565
· DBLP profile ↗
30ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0001-5068-9158ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 2 first-author · 9 since 2021Computer networks · 7 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reactive cyber deception: Stealth-based adaptive redirection to on-demand honeypots with AI-driven data generationabstractCybersecurity is evolving rapidly, incorporating paradigms such as Cyber Deception (CYDEC) and Moving Target Defense (MTD) to counter sophisticated attacks. CYDEC misleads adversaries by diverting their actions into controlled environments where they unknowingly interact with decoy assets. This work introduces a deception mechanism based on stealthy TCP redirection to dynamically instantiated honeypots. Unlike static decoys, the system creates a honey server on-demand that replicates the victim asset in real time. To enhance credibility, the replica is enriched with fake but coherent data generated by a Large Language Model (LLM), producing realistic documents, logs, or configurations tailored to the compromised pillar, that is, confidentiality, integrity, or availability. The architecture builds on Software-Defined Networking (SDN), enabling flexible deployment and adaptive deception at scale. The SDN Controller manages redirection and cloning while preserving TCP session continuity through sequence-number manipulation, making the diversion virtually undetectable. Experiments validated the approach in diverse environments. Results show negligible latency overheads, even under encrypted protocols, seamless honeypot instantiation, and highly plausible LLM-generated honeydata that deceives Attackers while enriching threat intelligence. Deployment on resource-constrained hardware such as Raspberry Pi demonstrates feasibility for IoT and embedded contexts. Overall, combining SDN and LLM technologies enables a scalable, adaptive, and robust CYDEC-based defense capable of deceiving adversaries in real time while strengthening cyber threat intelligence. Pedro Beltrán López, Manuel Gil Pérez, Emmanouil Vasilomanolakis, Pantaleone Nespoli |
Comput. Networks | 3 |
| 2026 | Measuring what matters: Revisiting internet exposure of OT networksabstractMany Internet-wide measurement studies report thousands of vulnerable OT (ot) devices exposed to the Internet. This growing focus on ot is essential for informing new regulations, mitigation techniques, and defense strategies, but many studies overlook false positives in their datasets. Ignoring artifacts such as honeypots, network telescopes, and tarpits leads to misinterpretations and a distorted view of the Internet. This paper revisits the exposure of ot networks to the public Internet. We apply a noise-aware methodology to an Internet-wide scan of networks that expose Modbus, Fox, EtherNet/IP, and IEC 60870-5-104 services, and we filter likely noise from vulnerable devices. Our findings show that noise systematically pollutes datasets and inflates estimates of exposed ot services; across protocols, 7% of the total observations, and up to 20% for particular protocols, can be traced reliably to four sources of noise that we term condensation, displacement, volatility , and hostility using conservative policies with high-confidence signaling classifiers. That said, even after filtering these artifacts, the security landscape of Internet-facing ot devices remains largely unchanged. Devices are still widely affected by misconfigurations, obsolescence, and broader security management issues. Ricardo Yaben, Mathias Anguita, Emmanouil Vasilomanolakis |
Comput. Secur. | 3 |
| 2026 | Digital Ghost Ships: Abandoned, Neglected, and Obsolete IoT and OT Devices Exposed to the InternetabstractThe rapid adoption of Internet of Things (IoT) and Operational Technology (OT) devices to control systems remotely has introduced significant cyber-security challenges. Attackers have compromised millions of such devices over the years, exploiting their lack of management and weak cybersecurity. This paper examines cyber-security issues of neglected, obsolete, and abandoned IoT and OT devices exposed to the Internet. To unify these issues under an umbrella term, we coined the term Digital Ghost Ships (DGSs). Our work focuses on identifying DGSs using common scanning tools to find indicators of security misconfigurations and misuse. Moreover, we compare two Internet-wide scans conducted two years apart, focusing on security issues in eight IoT and OT protocols: MQTT, CoAP, XMPP, Modbus, OPC UA, RTPS, DNP3, and BACnet. During our first scan (S1) we found 675,896 DGSs, and 75,007 during our second scan (S2). Lastly, we examine the IP reputation of the vulnerable devices and find that 7,424 (S1) and 792 (S2) DGSs were reported at least once. Ricardo Yaben, Emmanouil Vasilomanolakis |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | Cheaper than you thought? A dive into the darkweb market of cyber-crime productsabstractThe darkweb is nowadays considered a very popular place to sell and buy illegal cyber-crime related content. From botnet services and malware, to user data such as credit card information and passwords, darkweb marketplaces offer ease of use, product variety, and most importantly effective anonymity to both buyers and vendors. In this paper, we crawl 8 popular darkweb marketplaces and perform a comprehensive quantitative analysis with a focus on cyber-crime related products. Moreover, we report some preliminary findings when examining the same marketplaces through their I2P mirrors. Our results suggest that overall there is a multitude of products that fall into the cyber-crime category, with products under the Fraud category dominating the market, and that the average cyber-crime products’ price is relatively low. Furthermore, we explore how the vendors of this specific product group are distributed across platforms, utilizing harvested information such as usernames and PGP keys, and investigate how their reputation scores affect their operation. Dimitrios Georgoulias, Ricardo Yaben, Emmanouil Vasilomanolakis |
ARES | 3 |
| 2022 | Interaction matters: a comprehensive analysis and a dataset of hybrid IoT/OT honeypotsabstractThe Internet of things (IoT) and critical infrastructure utilizing operational technology (OT) protocols are nowadays a common attack target and/or attack surface used to further propagate malicious actions. Deception techniques such as honeypots have been proposed for both IoT and OT but they either lack an extensive evaluation or are subject to fingerprinting attacks. In this paper, we extend and evaluate RIoTPot, a hybrid-interaction honeypot, by exposing it to attacks on the Internet and perform a longitudinal study with multiple evaluation parameters for three months. Furthermore, we publish the aforementioned study in the form of a dataset that is available to researchers upon request. We leverage RIoTPot’s hybrid-interaction model to deploy it in three interaction variants with six protocols deployed on both cloud and self-hosted infrastructure to study and compare the attacks gathered. At a glance, we receive 10.87 million attack events originating from 22,518 unique IP addresses that involve brute-force, poisoning, multistage and other attacks. Moreover, we fingerprint the attacker IP addresses to identify the type of devices who participate in the attacks. Lastly, our results indicate that the honeypot interaction levels have an important role in attracting specific attacks and scanning probes. Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis |
ACSAC | 3 |
| 2022 | Is Your Password Sexist? a Gamification-Based Analysis of the Cultural Context of Leaked Passwords
Daniel Mølmark-O'Connor, Emmanouil Vasilomanolakis |
ESORICS (3) | 2 |
| 2022 | A Study on the Use of 3rd Party DNS Resolvers for Malware Filtering or Censorship Circumvention
Martin Fejrskov, Emmanouil Vasilomanolakis, Jens Myrup Pedersen |
SEC | 2 |
| 2022 | Tick Tock Break the Clock: Breaking CAPTCHAs on the DarkwebabstractNowadays, almost all major websites employ CAPTCHAs. This prevents website scraping, fake account creation as well as DDoS or bruteforce attacks. For anonymity reasons, mainstream CAPTCHAs such as Google’s reCAPTCHA cannot be used on the darkweb. Due to the evolution of machine learning and computer vision, the CAPTCHA challenges used there, such as the clock CAPTCHA, are usually more arduous than those found on the clearweb. This paper presents an automated system that uses machine learning to break clock CAPTCHA challenges with a high success rate. We evaluate our system in a real world setting against 725 clock challenges from live darkweb marketplaces. Our results show an accuracy of 96.83% while maintaining low time requirements while analyzing, predicting and submitting the CAPTCHA solution. David Holm Audran, Marcus Braunschweig Andersen, Mark Højer Hansen, Mikkel Møller Andersen, Thomas B. Frederiksen, Kasper H. Hansen, Dimitrios Georgoulias, Emmanouil Vasilomanolakis |
SECRYPT | 8 |
| 2022 | Processing of botnet tracking data under the GDPRabstractBotnet research is one of the many research areas affected by the coming into force of the General Data Protection Regulation (GDPR). This article aims to identify the most appropriate legal bases that would legitimise data processing in the context of botnet tracking and to give an overview of the practical implications for practitioners. First, we give a technical introduction to botnet tracking techniques and the types of processed data. Afterward, we argue that botnet tracking qualifies as ”processing of personal data” and falls under the material scope of the GDPR. We then present three scenarios where these botnet tracking techniques apply: botnet tracking research in the public interest, botnet tracking in the commercial interest and botnet tracking conducted by Internet service providers. For each scenario, we discuss the differing goals, identify the appropriate legal bases, and elaborate on the practical implications. This article concludes that the legal implications are very different for each of the three scenarios, highlighting the importance of carefully considering the legal bases before engaging in botnet tracking. Leon Bock, Martin Fejrskov, Katerina Demetzou, Shankar Karuppayah, Max Mühlhäuser, Emmanouil Vasilomanolakis |
Comput. Law Secur. Rev. | 6 |
| 2021 | Open for hire: attack trends and misconfiguration pitfalls of IoT devicesabstractMirai and its variants have demonstrated the ease and devastating effects of exploiting vulnerable Internet of Things (IoT) devices. In many cases, the exploitation vector is not sophisticated; rather, adversaries exploit misconfigured devices (e.g. unauthenticated protocol settings or weak/default passwords). Our work aims at unveiling the state of IoT devices along with an exploration of the current attack landscape. In this paper, we perform an Internet-level IPv4 scan to unveil 1.8 million misconfigured IoT devices that may be exploited to perform large-scale attacks. These results are filtered to exclude a total of 8,192 devices that we identify as honeypots during our scan. To study current attack trends, we deploy six state-of-art IoT honeypots for a period of 1 month. We gather a total of 200, 209 attacks and investigate how adversaries leverage misconfigured IoT devices. In particular, we study different attack types, including denial of service, multistage attacks and attacks from infected online hosts. Furthermore, we analyze data from a /8 network telescope covering a total of 81 billion requests towards IoT protocols (e.g. CoAP, UPnP). Combining knowledge from the aforementioned experiments, we identify 11, 118 IP addresses (that are part of the detected misconfigured IoT devices) that attacked our honeypot setup and the network telescope. Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis |
Internet Measurement Conference | 3 |
| 2021 | Using NetFlow to Measure the Impact of Deploying DNS-based Blacklists
Martin Fejrskov, Jens Myrup Pedersen, Emmanouil Vasilomanolakis |
SecureComm (1) | 3 |
| 2021 | On Generating Network Traffic Datasets with Synthetic Attacks for Intrusion DetectionabstractMost research in the field of network intrusion detection heavily relies on datasets. Datasets in this field, however, are scarce and difficult to reproduce. To compare, evaluate, and test related work, researchers usually need the same datasets or at least datasets with similar characteristics as the ones used in related work. In this work, we present concepts and the Intrusion Detection Dataset Toolkit (ID2T) to alleviate the problem of reproducing datasets with desired characteristics to enable an accurate replication of scientific results. Intrusion Detection Dataset Toolkit (ID2T) facilitates the creation of labeled datasets by injecting synthetic attacks into background traffic. The injected synthetic attacks created by ID2T blend with the background traffic by mimicking the background traffic’s properties. This article has three core contributions. First, we present a comprehensive survey on intrusion detection datasets. In the survey, we propose a classification to group the negative qualities found in the datasets. Second, the architecture of ID2T is revised, improved, and expanded in comparison to previous work. The architectural changes enable ID2T to inject recent and advanced attacks, such as the EternalBlue exploit or a peer-to-peer botnet. ID2T’s functionality provides a set of tests, known as TIDED, that helps identify potential defects in the background traffic into which attacks are injected. Third, we illustrate how ID2T is used in different use-case scenarios to replicate scientific results with the help of reproducible datasets. ID2T is open source software and is made available to the community to expand its arsenal of attacks and capabilities. Carlos Garcia Cordero, Emmanouil Vasilomanolakis, Aidmar Wainakh, Max Mühlhäuser, Simin Nadjm-Tehrani |
ACM Trans. Priv. Secur. | 2 |
| 2020 | Visualizing the Bitcoin's OP_RETURN operatorabstractBitcoin is undoubtedly the most used distributed ledger technology nowadays. Bitcoin's OP_RETURN operator allows for saving arbitrary data on the blockchain. This comes as an extension of Bitcoin's core usage (i.e. cryptocurrency) and opens up a multitude of use cases. These range from benign applications (e.g. ownership of a digital/physical asset) to illegal/malicious scenarios (e.g. blockchain-based botnets). In this paper, we present a system that provides advanced analytic and visual capabilities with regard to the OP_RETURN operator. Furthermore, we showcase a quantitative and qualitative analysis of the OP_RETURN along with a number of interesting findings. Johannes Mols, Emmanouil Vasilomanolakis |
MobiHoc | 2 |
| 2020 | Towards systematic honeytoken fingerprintingabstractWith the continuous rise in the numbers and sophistication of cyber-attacks, defenders are moving towards more proactive lines of defense. Deception methods such as honeypots and moving target defense paradigms, are nowadays utilized in a multitude of ways. A honeytoken is an umbrella term that describes honeypot-like entities/resources that can be inserted into a network or system. The moment an adversary interacts with a honeytoken, an alert is raised. Similar to honeypots, the value of honeytokens lies in their indistinguishability; if an attacker can detect them, e.g. via a fingerprinting tool, they can easily evade them. In this paper, we propose and discuss honeytoken fingerprinting methods. To the best of our knowledge, this is the first paper to examine honeytoken-specific fingerprinting. Furthermore, we showcase a proof of concept that is able to successfully detect a number of honeytoken types. Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis |
SIN | 3 |
| 2019 | Poster: Challenges of Accurately Measuring Churn in P2P BotnetsabstractPeer-to-peer (P2P) botnets are known to be highly resilient to takedown attempts. Such attempts are usually carried out by exploiting vulnerabilities in the bots communication protocol. However, a failed takedown attempt may alert botmasters and allow them to patch their vulnerabilities to thwart subsequent attempts. As a promising solution, takedowns could be evaluated in simulation environments before attempting them in the real world. To ensure such simulations are as realistic as possible, the churn behavior of botnets must be understood and measured accurately. This paper discusses potential pitfalls when measuring churn in live P2P botnets and proposes a botnet monitoring framework for uniform data collection and churn measurement for P2P botnets. Leon Bock, Shankar Karuppayah, Kory Fong, Max Mühlhäuser, Emmanouil Vasilomanolakis |
CCS | 5 |
| 2019 | Autonomously detecting sensors in fully distributed botnetsabstractBotnet attacks have devastating effects on public and private infrastructures. The botmasters controlling these networks aim to prevent takedown attempts by using highly resilient P2P overlays to commandeer their botnets, and even harden them with countermeasures against intelligence gathering attempts. In fact, recent research indicates that advanced countermeasures can hamper the ability to gather the necessary intelligence for taking down botnets. In this article, we take the perspective of the botmaster to eventually anticipate their behavior. That said, we present a novel mechanism, namely Trust Based Botnet Monitoring Countermeasure (TrustBotMC), that combines computational trust with specially crafted bot messages to detect the presence of monitoring activity. We study and evaluate different computational trust models, to create a local and autonomous mechanism that ensures the avoidance of common botnet tracking mechanisms, such as sensors. Furthermore, we show, via our experimental results, that our approach can reduce the gathered intelligence by at least 53% compared to techniques that have been seen in botnets to date. Finally, we investigate techniques for mitigating our approach. Leon Bock, Emmanouil Vasilomanolakis, Jan Helge Wolf, Max Mühlhäuser |
Comput. Secur. | 2 |
| 2019 | Network entity characterization and attack prediction
Václav Bartos, Martin Zádník, Sheikh Mahbub Habib, Emmanouil Vasilomanolakis |
Future Gener. Comput. Syst. | 4 |
| 2018 | HoneyDrone: A medium-interaction unmanned aerial vehicle honeypotabstractOver the last years, we have experienced an increased utilization of Unmanned Aerial Vehicles (UAVs) not only in personal, but also commercial and public safety applications. Simultaneously, malicious activities have emerged too; from hijacking of UAVs (and their cargo), to the theft of private information stored in UAVs, attacks not only exist but seem to increase both in their numbers and their sophistication. In this paper, we propose HoneyDrone, the first honeypot that is specifically designed for the protection of UAVs. HoneyDrone emulates a number of UAV-specific and UAV-tailored protocols, making it possible to lure adversaries into attacking it. The honeypot is designed to run in portable low-cost devices, e.g., Raspberry Pis, which makes it possible to strategically deploy it in a variety of locations. Our system can assist in detecting active attackers in a certain area, as well as in shedding light into the adversaries' techniques for compromising UAVs. We evaluate HoneyDrone's performance and also examine a number of different realistic attack scenarios to show how the honeypot can cope with them. Jörg Daubert, Dhanasekar Boopalan, Max Mühlhäuser, Emmanouil Vasilomanolakis |
NOMS | 4 |
| 2018 | Don't steal my drone: Catching attackers with an unmanned aerial vehicle honeypotabstractThe increased utilization of Unmanned Aerial Vehicles (UAVs) in both personal as well as commercial and public safety scenarios has also opened the door to adversaries. In more details, such malicious activities may include the hijacking of the UAV (and its cargo), the theft of private information stored in the device, etc. In this paper, we introduce the idea of a honeypot that is specifically designed for the protection of UAVs. The honeypot, which is also capable of running on small portable devices, e.g., a Raspberry Pi, emulates a number of UAV-specific and UAV-tailored protocols, making it possible to lure adversaries into attacking it. Our system can assist into detecting active attackers in a certain area as well as into shedding light into the adversaries' techniques for compromising UAVs. Emmanouil Vasilomanolakis, Jörg Daubert, Dhanasekar Boopalan, Max Mühlhäuser |
NOMS | 1 |
| 2018 | Next Generation P2P Botnets: Monitoring Under Adverse Conditions
Leon Bock, Emmanouil Vasilomanolakis, Max Mühlhäuser, Shankar Karuppayah |
RAID | 2 |
| 2017 | Towards Blockchain-Based Collaborative Intrusion Detection Systems
Nikolaos Alexopoulos, Emmanouil Vasilomanolakis, Natália Réka Ivánkó, Max Mühlhäuser |
CRITIS | 2 |
| 2017 | Defending against Probe-Response AttacksabstractWith the increase in the sophistication of cyberattacks, collaborative defensive approaches such as Collaborative IDSs (CIDSs) have emerged. CIDSs utilize a multitude of heterogeneous monitors to create a holistic picture of the monitored network. Nowadays, a number of research institutes and companies deploy CIDSs that publish their alert data publicly, over the Internet. Such systems are important for researchers and security administrators as they provide a source of real-world alert data for experimentation. However, a class of attacks exist, called Probe-Response Attacks (PRAs), which can significantly reduce the benefits of a CIDS. In particular, such attacks allow an adversary to detect the network location of the monitors of a CIDS. In this paper, we first study the related work and analyze the various mitigation techniques for defending against PRAs. Subsequently, we propose a novel mitigation mechanism that improves the state of the art. Our method, namely the Shuffle-based PRA Mitigation (SPM), is based on the idea of shuffling the watermarks, so-called markers, which the adversary requires to successfully perform a PRA. By doing so the whole process of the attack is disrupted leading to a very small number of identified monitors. Our experimental results suggest that our proposed method significantly reduces the impact of a PRA whilst it does not introduce a trade-off for the usability of the data produced by the CIDS. Emmanouil Vasilomanolakis, Noorulla Sharief, Max Mühlhäuser |
IM | 1 |
| 2016 | BoobyTrap: On autonomously detecting and characterizing crawlers in P2P botnetsabstractThe ever-growing number of cyber attacks from botnets has made them one of the biggest threats on the Internet. Thus, it is crucial to study and analyze botnets, to take them down. For this, an extensive monitoring is a pre-requisite for preparing a botnet takedown, e.g., via a sinkholing attack. However, every new monitoring mechanism developed for botnets is usually tackled by the botmasters by introducing novel antimonitoring countermeasures. In this paper, we anticipate these countermeasures by proposing a set of lightweight techniques for detecting the presence of crawlers in P2P botnets, called BoobyTrap. For that, we exploit botnet-specific protocol and design constraints. We evaluate the performance of our BoobyTrap mechanism on two real-world botnets: Sality and ZeroAccess. Our results indicate that we can distinguish many crawlers from benign bots. In fact, we discovered close to 10 crawler nodes within our observation period in the Sality botnet and around 120 in the ZeroAccess botnet. In addition, we also describe the observable characteristics of the detected crawlers and suggest crawler improvements for enabling monitoring in the presence of the BoobyTrap mechanism. Shankar Karuppayah, Emmanouil Vasilomanolakis, Steffen Haas, Max Mühlhäuser, Mathias Fischer 0001 |
ICC | 2 |
| 2016 | Towards the creation of synthetic, yet realistic, intrusion detection datasetsabstractIntrusion Detection Systems (IDSs) are an important defense tool against the sophisticated and ever-growing network attacks. With this in mind, the research community has been immersed in the field of IDSs over the past years more than before. Still, assessing and comparing performance between different systems and algorithms remains one of the biggest challenges in this research area. IDSs need to be evaluated and compared against high quality datasets; nevertheless, the existing ones have become outdated or lack many essential requirements. We present the Intrusion Detection Dataset Toolkit (ID2T), an approach for creating out-of-the-box labeled datasets that contain user defined attacks. In this paper, we discuss the essential requirements needed to create synthetic, yet realistic, datasets with user defined attacks. We also present typical problems found in synthetic datasets and propose a software architecture for building tools that can cope with the most typical problems. A publicly available prototype, is implemented and evaluated. The evaluation comprises a performance analysis and a quality assessment of the generated datasets. We show that our tool can handle large amounts of network traffic and that it can generate synthetic datasets without the problems or shortcomings we identified in other datasets. Emmanouil Vasilomanolakis, Carlos Garcia Cordero, Nikolay Milanov, Max Mühlhäuser |
NOMS | 1 |
| 2016 | Multi-stage attack detection and signature generation with ICS honeypotsabstractNew attack surfaces are emerging with the rise of Industrial Control System (ICS) devices exposed on the Internet. ICS devices must be protected in a holistic and efficient manner; especially when these are supporting critical infrastructure. Taking this issue into account, cyber-security research is recently being focused on providing early detection and warning mechanisms for ICSs. In this paper we present a novel honeypot capable of detecting multi-stage attacks targeting ICS networks. Upon detecting a multi-stage attack, our honeypot can generate signatures so that misuse Intrusion Detection Systems (IDSs) can subsequently thwart attacks of the same type. Our experimental results indicate that our honeypot and the signatures it generates provide good detection accuracy and that the Bro IDS can successfully use the signatures to prevent future attacks. Emmanouil Vasilomanolakis, Shreyas Srinivasa, Carlos Garcia Cordero, Max Mühlhäuser |
NOMS | 1 |
| 2015 | SkipMon: A locality-aware Collaborative Intrusion Detection SystemabstractDue to the increasing quantity and sophistication of cyber-attacks, Intrusion Detection Systems (IDSs) are nowadays considered mandatory security mechanisms for protecting critical networks. Research on cyber-security is moving from such isolated IDSs towards Collaborative IDSs (CIDSs) in order to protect large-scale networks. In CIDSs, a number of IDS sensors work together for creating a holistic picture of the monitored network. Our contribution in this paper is a novel distributed and scalable CIDS, called SkipMon. Our system supports, both, the idea of locality and privacy preserving communication by means of exchanging compact alert data. Furthermore, we propose a mechanism for interconnecting sensors that experience similar traffic patterns. The experimental results suggest that our CIDS, with our technique of connecting monitoring nodes that experience similar traffic, is scalable and offers a good accuracy rate compared to a centralized system with full knowledge of the participating sensors' data. Emmanouil Vasilomanolakis, Matthias Krugl, Carlos Garcia Cordero, Max Mühlhäuser, Mathias Fischer 0001 |
IPCCC | 1 |
| 2015 | A survey of technologies for the internet of thingsabstractThe number of smart things is growing exponentially. By 2020, tens of billions of things will be deployed worldwide, collecting a wealth of diverse data. Traditional computing models collect in-field data and then transmit it to a central data center where analytics are applied to it, but this is no longer a sustainable model. New approaches and new technologies are required to transform enormous amounts of collected data into meaningful information. Technology also will enable the interconnection around things in the IoT ecosystem but further research is required in the development, convergence and interoperability of the different IoT elements. In this paper, we provide a picture of the main technological components needed to enable the interconnection among things in order to realize IoT concepts and applications. Evangelos N. Gazis, Manuel Görtz, Marco F. Huber, Alessandro Leonardi, Kostas Mathioudakis, Alexander Wiesmaier, Florian Zeiger, Emmanouil Vasilomanolakis |
IWCMC | 8 |
| 2015 | Community-Based Collaborative Intrusion Detection
Carlos Garcia Cordero, Emmanouil Vasilomanolakis, Max Mühlhäuser, Mathias Fischer 0001 |
SecureComm | 2 |
| 2015 | A honeypot-driven cyber incident monitor: lessons learned and steps aheadabstractIn recent years, the amount and the sophistication of cyber attacks has increased significantly. This creates a plethora of challenges from a security perspective. First, for the efficient monitoring of a network, the generated alerts need to be presented and summarized in a meaningful manner. Second, additional analytics are required to identify sophisticated and correlated attacks. In particular, the detection of correlated attacks requires collaboration between different monitoring points. Cyber incident monitors are platforms utilized for supporting the tasks of network administrators and provide an initial step towards coping with the aforementioned challenges. Emmanouil Vasilomanolakis, Shankar Karuppayah, Panayotis Kikiras, Max Mühlhäuser |
SIN | 1 |
| 2014 | HosTaGe: a Mobile Honeypot for Collaborative DefenseabstractThe continuous growth of the number of cyber attacks along with the massive increase of mobile devices creates a highly heterogeneous landscape in terms of security challenges. We argue that in order for security researchers to cope with both the massive amount and the complexity of attacks, a more pro-active approach has to be taken into account. In addition, distributed attacks that are carried out by interconnected attackers require a collaborative defense. Diverging from traditional security defenses, honeypots are systems whose value lies on in being attacked and compromised. In this paper, we extend the idea of HosTaGe, i.e., a low interaction honeypot for mobile devices. Our system is specifically designed in a user-centric manner and runs out-of-the-box in the Android operating system. We present the design rational and discuss the different attack surfaces that HosTaGe is able to handle. The main contribution of this paper is the introduction of the collaborative capabilities of HosTaGe. Emmanouil Vasilomanolakis, Shankar Karuppayah, Max Mühlhäuser, Mathias Fischer 0001 |
SIN | 1 |