VLDB 2026 Research / reviewers in the wild / expert
Costas Lambrinoudakis
dblp:16/6779 · also Constantinos Lambrinoudakis, Konstantinos Lambrinoudakis
· DBLP profile ↗
42ranked-venue papers
5as first author
2since 2021 · last 2021
0000-0003-3101-5347ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 4 first-author · 2 since 2021Computer networks · 6 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Launching Adversarial Label Contamination Attacks Against Malicious URL Detection
Bruno Marchand, Nikolaos Pitropakis, William J. Buchanan, Costas Lambrinoudakis |
TrustBus | 4 |
| 2021 | On Android's activity hijacking prevention
Christos Lyvas, Costas Lambrinoudakis, Dimitris Geneiatakis |
Comput. Secur. | 2 |
| 2020 | A NIS Directive Compliant Cybersecurity Maturity Assessment FrameworkabstractThe EU NIS Directive introduces obligations related to the security of the network and information systems for Operators of Essential Services and for Digital Service Providers. Moreover, National Competent Authorities for cybersecurity are required to assess the compliance to these obligations. This paper describes a novel Cybersecurity Maturity Assessment Framework (CMAF) that is tailored to the NIS Directive requirements. CMAF can be used either as a self assessment tool from Operators of Essential Services and Digital Service Providers or as an audit tool from the National Competent Authorities for cybersecurity George Drivas, Argyro Chatzopoulou, Leandros Maglaras, Costas Lambrinoudakis, Allan Cook, Helge Janicke |
COMPSAC | 4 |
| 2020 | Cloud Computing Framework for e-Health Security Requirements and Security Policy Rules Case Study: A European Cloud-Based Health System
Dimitra Georgiou, Costas Lambrinoudakis |
TrustBus | 2 |
| 2020 | Microtargeting or Microphishing? Phishing Unveiled
Bridget Khursheed, Nikolaos Pitropakis, Sean McKeown, Costas Lambrinoudakis |
TrustBus | 4 |
| 2020 | GDPR compliance: proposed technical and organizational measures for cloud providerabstractPurpose The purpose of this paper is to give a brief guidance on what a cloud provider should consider and what further actions to take to comply with General Data Protection Regulation (GDPR). Design/methodology/approach This paper presents in detail the requirements for GDPR compliance of cloud computing environments, presents the GDPR roles (data controller and data processor) in a cloud environment and discusses the applicability of GDPR compliance requirements for each cloud architecture (Infrastructure as a Service, Platform as a Service, Software as a Service), proposes countermeasures for satisfying the aforementioned requirements and demonstrates the applicability of the aforementioned requirements and countermeasures to a PaaS environment offering services for building, testing, deploying and managing applications through cloud managed data centers. The applicability of the method has been demonstrated on in a PaaS environment that offers services for building, testing, deploying and managing applications through cloud managed data centers. Findings The results of the proposed GDPR compliance measures for cloud providers highlight the effort and criticality required from cloud providers to achieve compliance. Originality/value Zafeiroula Georgiopoulou, Eleni-Laskarina Makri, Costas Lambrinoudakis |
Inf. Comput. Secur. | 3 |
| 2020 | Utilizing a privacy impact assessment method using metrics in the healthcare sectorabstractPurpose This study aims to assist organizations to protect the privacy of their users and the security of the data that they store and process. Users may be the customers of the organization (people using the offered services) or the employees (users who operate the systems of the organization). To be more specific, this paper proposes a privacy impact assessment (PIA) method that explicitly takes into account the organizational characteristics and employs a list of well-defined metrics as input, demonstrating its applicability to two hospital information systems with different characteristics. Design/methodology/approach This paper presents a PIA method that employs metrics and takes into account the peculiarities and other characteristics of the organization. The applicability of the method has been demonstrated on two Hospital Information Systems with different characteristics. The aim is to assist the organizations to estimate the criticality of potential privacy breaches and, thus, to select the appropriate security measures for the protection of the data that they collect, process and store. Findings The results of the proposed PIA method highlight the criticality of each privacy principle for every data set maintained by the organization. The method employed for the calculation of the criticality level, takes into account the consequences that the organization may experience in case of a security or privacy violation incident on a specific data set, the weighting of each privacy principle and the unique characteristics of each organization. So, the results of the proposed PIA method offer a strong indication of the security measures and privacy enforcement mechanisms that the organization should adopt to effectively protect its data. Originality/value The novelty of the method is that it handles security and privacy requirements simultaneously, as it uses the results of risk analysis together with those of a PIA. A further novelty of the method is that it introduces metrics for the quantification of the requirements and also that it takes into account the specific characteristics of the organization. Eleni-Laskarina Makri, Zafeiroula Georgiopoulou, Costas Lambrinoudakis |
Inf. Comput. Secur. | 3 |
| 2018 | The General Data Protection Regulation (GDPR) Era: Ten Steps for Compliance of Data Processors and Data Controllers
Costas Lambrinoudakis |
TrustBus | 1 |
| 2018 | Towards a Security Assurance Framework for Connected VehiclesabstractSecurity assurance is defined as the degree of confidence that the security requirements of an IT system are satisfied. In view of the emerging paradigm of connected vehicles i.e., dynamic Cyber-Physical systems of highly-equipped infrastructure-connected vehicles, specifying the involved assurance becomes highly-critical yet challenging; vehicles increasingly exploit various communication means to exchange rich data of relevance with the infrastructure resulting in a large attack surface. Both the complexity and uncertainty are increased rendering the so-far generic methods for security assurance costly-to-apply. In this position paper we introduce a security assurance framework tailored for connected vehicles, as explored by the EU-funded H2020 SAFERtec project. We put under the microscope two instances of vehicle-to-infrastructure communications and relying on an innovative modeling methodology we identify the involved security and privacy requirements. We then present the way to enhance the processes of the credible yet generic Common Criteria approach to gain evidence that the above requirements are met. The experimental evaluation of the framework is carried-out over a reference implementation of a prototype vehicle connected to road-side units and cloud-based services. The expectations are that our work assists to effectively construct assurance arguments increasing trust in connected vehicles. Panagiotis Pantazopoulos, Sammy Haddad, Costas Lambrinoudakis, Christos Kalloniatis, Konstantinos Maliatsos, Athanasios G. Kanatas, András Varádi, Matthieu Gay, Angelos Amditis |
WOWMOM | 3 |
| 2018 | Dypermin: Dynamic permission mining framework for android platform
Christos Lyvas, Costas Lambrinoudakis, Dimitris Geneiatakis |
Comput. Secur. | 2 |
| 2016 | Literature Review of Trust Models for Cloud ComputingabstractProper trust management in cloud computing environments can significantly assist their widespread adoption. Trust can act as a countermeasure to the several security threats that the cloud faces. This paper provides an overview of how trust has been applied in cloud computing. Trust models suggested in contemporary literature for cloud computing systems are presented. Furthermore, a critical comparison, based on the set of the main characteristics of an appropriate trust management method, is included. Zafeiroula Georgiopoulou, Costas Lambrinoudakis |
ISPDC | 2 |
| 2016 | The Far Side of Mobile Application Integrated Development Environments
Christos Lyvas, Nikolaos Pitropakis, Costas Lambrinoudakis |
TrustBus | 3 |
| 2015 | Privacy Principles: Towards a Common Privacy Audit Methodology
Eleni-Laskarina Makri, Costas Lambrinoudakis |
TrustBus | 2 |
| 2015 | Till All Are One: Towards a Unified Cloud IDS
Nikolaos Pitropakis, Costas Lambrinoudakis, Dimitris Geneiatakis |
TrustBus | 2 |
| 2014 | Obscuring users' identity in VoIP/IMS environments
Nikos Vrakas, Dimitris Geneiatakis, Costas Lambrinoudakis |
Comput. Secur. | 3 |
| 2013 | ProCAVE: Privacy-Preserving Collection and Authenticity Validation of Online Evidence
Efthymios Lalas, Lilian Mitrou, Costas Lambrinoudakis |
TrustBus | 3 |
| 2013 | Evaluating and enriching information and communication technologies compliance frameworks with regard to privacyabstractPurpose The aim of the paper is to highlight gaps in compliance environments regarding information privacy and provide recommendations for global information privacy standards. Design/methodology/approach The paper draws conceptually upon an existing security standard's framework and omissions in information privacy compliance frameworks are recognized. As a result, an extended framework of information security and privacy standards is developed. Moreover, taking into account the different attributes and focus of information privacy as compared to information security, the elicitation of usability criteria for web applications and interfaces that will assist users to protect their privacy, is being proposed. Findings Within ICT standards numerous information security standards exist, which enable a common understanding of security requirements and promote global rules and practices for security mechanisms. Through their usage, designed information systems ultimately reach a commonly accepted security level and interoperate with other systems in an efficient and secure way. Nevertheless, a similar compliance environment is missing with regard to information privacy. Often security controls are seen as the solution to privacy protection and security compliance frameworks are regarded as guidance to information privacy as well. This is clearly the wrong approach since the main security and privacy attributes are different; information security refers to information stored, processed and transmitted for completing the information system's functions and purpose, while information privacy is the protection of the information's subject identity. Research limitations/implications The identified gaps in compliance environments are based on extensive literature review, while the proposed enhancements for the information privacy standards are, at this stage, an opinion‐based piece of work. Originality/value Currently, information privacy is treated mostly as a legal compliance requirement and thus is not adequately handled by security standards. The paper provides recommendations and further guidance in managerial, procedural and technical level for handling information privacy. Costas Lambrinoudakis |
Inf. Manag. Comput. Secur. | 1 |
| 2012 | Special issue on next generation communication and network securityabstractMobile Internet and Computer Communication is a part of our daily life. People use mobile Internet and network communication applications such as YouTube, Twitter, and Facebook, as well as mobile web and e-mail via mobile communication devices such as smartphones, tablet PCs, and embedded mobile devices. We are also moving to an era of cloud computing services that store important and proprietary information on remote machines, which are accessible through various networks and mobile internet environments. Although such applications may help businesses and also make personal services more efficient, they are vulnerable to attacks, which include various communication and network infringement, system violation, stealing data, and obstructing the operations of a business or a person. In addition, the environment of the Next Generation Communications and Networks has raised many issues on heterogeneous communications system and network security, which are vulnerable to various attacks. This special issue of Security and Communication Networks highlights the latest research results and presents novel and innovative security and privacy techniques for Next Generation Communication and Network Security. It summarizes the current state-of-the-art research and provides valuable insights into future directions and challenges in the field. The first paper, “The Effective Method of Database Server Forensics on the Enterprise Environment” by Son et al., addresses that a method of detecting a server and acquiring and investigating data in the server can be effectively used for such an investigation on the enterprise environment. For the existing investigation on server systems, severs should be shut down, and disk imaging should be conducted first. However, such a method may inflict great losses on the company in some cases. That is why we need a method to acquire data of a server in online state, and this study discusses this method. Besides, on the basis of methodology, this study attempts to determine a possibility that this new forensic investigation method can be practically used by directly applying this method to SQL Server and MySQL databases. The second paper, “Detection of Botnets before Activation: An Enhanced Honeypot System for Intentional Infection and Behavioral Observation of Malware” by Moon et al., introduces a system that is designed to detect botnets prior to their activation. Predetection of botnets becomes available with our enhanced honeypot system that allows us to intentionally infect virtual machines in honeynets. The third paper, “Adaptive Scheduling Strategies for Cloud-based Resource Infrastructures” by Deng Lingli et al., proposes to employ linear programming algorithms for global resource scheduling to reduce the extra cost, including power consumption as well as operation expenditures, for remote resource access in a cloud-based resource pool. Unlike previous static work in this field, the proposed scheduler adapts the problem-modeling granularity and resolution algorithm to the changing demands of an integral procedure comprising various stages including the initial construction and subsequent operation/extension of a cloud-based resource infrastructure. The fourth paper, “Bayesian Approach with Maximum Entropy Principle for Trusted Quality of Web Service Metric in E-commerce Applications” by Shangguang Wang et al., proposes a trusted QoWS metric approach, that is, Bayesian Approach with Maximum Entropy Principle. The key of our proposed approach is to extract QoWS prior distribution of Web service by using Maximum Entropy Principle and then to infer QoWS posterior distribution of Web service by using Bayesian Approach. The fifth paper, “Identity-based Construction for Secure and Efficient Handoff Authentication Schemes in Wireless Networks” by Yinghui Zhang et al., proposes a new identity-based construction for secure and efficient handoff authentication schemes, in which an identity-based online/offline encryption scheme is the primary ingredient. Compared with the scheme of Kim et al., our construction enjoys desirable efficiency in terms of the computation cost and the communication cost. The sixth paper, “Detecting SYN Flooding Attacks based on Traffic Prediction” by Shangguang Wang et al., proposes a detection approach that makes use of SYN traffic prediction to determine whether SYN flooding attacks happen at the early stage. We first adopt gray prediction model to predict SYN traffic, and then, we employ cumulative sum algorithm to detect SYN flooding attack traffic among forecasted SYN traffic. The seventh paper, “Study on the Security of the Extended Version for the ISO/IEC International Standardized Block Cipher SEED” by Jongsung Kim, analyzes the block cipher SEED-192, which is an extended version of the ISO/IEC block cipher SEED. The eighth paper, “Self-organizing Life Cycle Management of Mobile Ad Hoc Networks” by Candido Caballero-Gil et al., includes the performance evaluation of the scheme, and the obtained experimental results show that SLCM significantly improves both the quality and the security of life cycle management of self-organized MANETs. The ninth paper, “On the Security of PPPoE Network” by Fanbao Liu et al., points out that PPPoE cannot be used anymore until all of the weak authentication protocols including PAP, CHAP, and Microsoft CHAP are abolished right now and replaced with more secure Extensible Authentication Protocols. The 10th paper, “Proactive Recovery Approach for Intrusion Tolerance with Dynamic Configuration of Physical and Virtual Replicas” by Feng Zhao et al., describes an approach for tolerating intrusions, or more precisely, damages to replicated data, through dynamic configuration of physical and virtual replicas, which follows a general approach called proactive recovery, and proposes to dynamically adjust recovery frequency to handle potentially changing fault rate. The 11th paper, “A Quantitative Approach to Estimate the Security Risk of a Website using the Whitelist Database” by Young-Gab Kim et al., presents a quantitative approach for evaluating the phishing possibility of a given website by using the refined security risk elements for domain and web page. Design and implementation of the website risk assessment system for antiphishing are also included. The 12th paper, “A Partially Reconstructed Previous Gmail Session by Live Digital Evidences Investigation through Volatile Data Acquisition” by Chu Hai-Cheng et al., pinpoints the imminent threat of IT savvy cyber criminals and the corresponding counter procedures used to crack criminal cases if web-based e-mail utilities are essentially involved. This paper is focused on the prevalent e-mail utility, Gmail, as the research subject. The 13th paper, “Quantitative Intrusion Intensity Assessment for Intrusion Detection Systems” by Dong-Seong Kim et al., describes a new approach named Quantitative Intrusion Intensity Assessment (QIIA) that exploits proximity metrics computation so that it provides intrusion (or normal) quantitative intensity value. It is capable of representing how an instance of audit data is proximal to intrusion or normal in a numerical value. The last paper, “Simple SMS Spam Filtering on Independent Mobile Phone” by Nuruzzaman M et al., proposes to filter SMS spam on independent mobile phones by using Text Classification techniques. The training, filtering, and updating processes are performed on an independent mobile phone. The mobile phone has storage, memory, and CPU limitations compared with a computer. We are thankful to all those authors who considered submitting their work to this Special Issue, irrespective of whether their papers could be accepted or not. Also, we are grateful to the editor-in-chief, Professor Hsiao-Hwa Chen, and the editorial staff of this journal for supporting the launch of this Special Issue. Prof. Taeshik Shon received his PhD degree in Information Security from Korea University, Seoul, Korea and his MS and BS degrees in Computer Engineering from Ajou University, Suwon, Korea. While he was working toward his PhD degree, he was awarded a KOSEF scholarship to be a research scholar in the Digital Technology Center, University of Minnesota, Minneapolis, U.S.A., from February 2004 to February 2005. From August 2005 to February 2011, Dr. Shon had been a senior engineer in the Convergence S/W Lab, DMC R&D Center of Samsung Electronics Co., Ltd. He is currently a professor at the Division of Information and Computer Engineering, College of Information Technology, Ajou University, Suwon, Korea. He was awarded the Gold Prize for the Sixth Information Security Best Paper Award from the Korea Information Security Agency in 2003, the Honorable Prize for the 24th Student Best Paper Award from Microsoft-KISS, 2005, the Bronze Prize for the Samsung Best Paper Award, 2006, and the Second Level of TRIZ Specialist certification in compliance with the International TRIZ Association requirements, 2008. He is also serving as a guest editor, an editorial staff, and a review committee of Computers and Electrical Engineering—Elsevier, Mobile Network and Applications—Springer, Security and Communication Networks—Wiley InterScience, Wireless Personal Communications—Springer, Journal of The Korea Institute of Information Security and Cryptology, IAENG International Journal of Computer Science, and other journals. His research interests include convergence platform security, mobile cloud computing security, mobile/wireless network security, WPAN/WSN security, anomaly detection algorithms, and machine learning applications. Dr. Costas Lambrinoudakis holds a BSc (Electrical and Electronic Engineering) from the University of Salford (1985), an MSc (Control Systems) from the University of London (Imperial College—1986), and a PhD (Computer Science) from the University of London (Queen Mary and Westfield College—1991). Currently, he is an assistant professor at the Department of Digital Systems, University of Piraeus, Greece. From 1998 until 2009, he has held teaching position with the University of the Aegean, Department of Information and Communication Systems Engineering, Greece. His current research interests are in the areas of Information and Communication Systems Security and of Privacy Enhancing Technologies. He is an author of more than 85 scientific publications in refereed international journals, books, and conferences, most of them on ICT security and privacy protection issues. He has served as program committee chair of two international scientific conferences and as a member on the program and organizing committees of many others. Also, he participates in the editorial board of two international scientific journals, and he acts as a reviewer for more than 20 journals. He has been involved in many national and EU funded R&D projects in the area of Information and Communication Systems Security. He is a member of the ACM and the IEEE. Prof. Zhou is the chair of the Department of Computer Science, University of Colorado, Colorado Springs. He is the director of Distributed and Internet Systems Lab and the director and cofounder of PhD in Engineering with a focus in security degree program. He obtained BS, MS, and PhD degrees in Computer Science from Nanjing University, China, in 1994, 1997, and 2000, respectively. He was a visiting scientist in 1999 and a postdoctorate research associate in 2000 at the Paderborn Center for Parallel Computing, University of Paderborn, Germany. His research is mainly in computer network systems, more specifically, autonomic computing in data centers, cloud computing, server virtualization, scalable Internet services and architectures, and computer network security. His research was supported in part by National Science Foundation, Air Force, and Army. He was a recipient of NSF CAREER Award 2009. He received the 2010–2011 University Faculty Award for Excellence in Research. He is a general cochair of the IEEE ICCCN 2012, a TPC cochair of the IEEE ICCCN 2011, a TPC vice chair of the IEEE GLOBECOM 2010, ICCCN 2009, HPCC 2008, and IEEE/IFIP EUC 2008, and the workshop general chair of the IEEE ICCCN 2010, ICCCN 2007, and IFIP EUC 2006. He served ACM Transactions on Autonomous and Adaptive Systems and the Journal of Parallel and Distributed Computing as a guest editor. He is an associate editor of Elsevier's Computer Communications and Journal of Network and Computer Applications. Taeshik Shon, Costas Lambrinoudakis |
Secur. Commun. Networks | 2 |
| 2011 | IS IP Multimedia Subsystem Affected by ‘Malformed Message' Attacks? - An Evaluation of OpenIMS
Nikos Vrakas, Dimitris Geneiatakis, Costas Lambrinoudakis |
SECRYPT | 3 |
| 2011 | Privacy preserving context transfer schemes for 4G networksabstractAbstract In the near future, wireless heterogeneous networks are expected to interconnect in an all‐IP architecture. An open issue towards this direction is the uninterrupted continuation of the received services during handover between networks employing different access technologies. In this context, Mobile IP (MIP) is a protocol that allows fast and secure handovers. However, MIP per se cannot handle all the issues that surface during handovers in certain services, and more specifically, when the information of the current state of a service requires re‐establishment on the new subnet without having to repeat the entire protocol exchange with the mobile host from the outset. A number of methods have been proposed to solve the aforementioned problem, commonly referred to as secure context transfer. However, while such methods do succeed in minimising the disruption caused by security‐related delays, it seems that little has been done to protect the end‐users' privacy as well. In this paper, a number of privacy enhanced (PE) context transfer schemes are presented. The first two of them have been introduced in a previous work of ours while the other two are novel. All schemes are analysed in terms of message exchange and evaluated through simulations. The performance of our schemes is compared with the standard ones proposed by the Seamoby work group (WG). The results demonstrate that the proposed schemes are very efficient in terms of application handover times, while at the same time guarantee the privacy of the end‐user. Copyright © 2010 John Wiley & Sons, Ltd. Iosif Terzis, Georgios Kambourakis, Georgios Karopoulos, Costas Lambrinoudakis |
Wirel. Commun. Mob. Comput. | 4 |
| 2010 | A Call Conference Room Interception Attack and Its Detection
Nikos Vrakas, Dimitris Geneiatakis, Costas Lambrinoudakis |
TrustBus | 3 |
| 2009 | A First Order Logic Security Verification Model for SIPabstractIt is well known that no security mechanism can provide full protection against a potential attack. There is always a possibility that a security incident may happen, mainly as a result of a new or modified attack that the employed countermeasures cannot handle or identify. It is therefore useful to perform a deferred analysis of logged network data, in an attempt to identify abnormal behavior/traffic that flags some type of security incident that has not been detected by the security countermeasures. Such an analysis of logged data for critical real time applications, like VoIP services, is certainly a valuable tool for enhancing the security level of the provided service. In this paper we introduce a practical tool that can be employed for the analysis of logged VoIP data and thus validate the effectiveness of the security mechanisms and the conformance with the corresponding security policy rules. For the analysis of the data we capitalize on our security model for VoIP services that is based on first order logic concepts, while the Protege API and the semantic Web rule language (SWRL) are also exploited. The proposed tool has been evaluated in terms of an experimental environment, while the results obtained confirm the validity of its operation and demonstrate its effectiveness. Dimitris Geneiatakis, Costas Lambrinoudakis, Georgios Kambourakis, Aggelos Kafkalas, Sven Ehlert |
ICC | 2 |
| 2009 | A Hierarchical Model for Cross-Domain Communication of Health Care UnitsabstractCommon practice for healthcare organizations is to maintain locally their own files, thus causing a geographic distribution of healthcare records. On the other hand, healthcare personnel treating a patient needs access to previous diagnosis and treatment data, maintained by various institutions in many different locations. Currently, the lack of a reliable authentication and authorization framework is considered a major obstacle for interchanging electronic healthcare records (EHRs). This paper proposes a hierarchical model for controlling access to EHRs and protecting the privacy of subjects of care and healthcare personnel, while facilitating the exchange of information among healthcare information systems. Dimitris Geneiatakis, Costas Lambrinoudakis, Stefanos Gritzalis |
NSS | 2 |
| 2009 | Utilizing bloom filters for detecting flooding attacks against SIP based services
Dimitris Geneiatakis, Nikos Vrakas, Costas Lambrinoudakis |
Comput. Secur. | 3 |
| 2008 | Modeling Privacy Insurance Contracts and Their Utilization in Risk Management for ICT Firms
Athanasios N. Yannacopoulos, Costas Lambrinoudakis, Stefanos Gritzalis, Stylianos Z. Xanthopoulos, Sokratis K. Katsikas |
ESORICS | 2 |
| 2008 | A Mechanism for Ensuring the Validity and Accuracy of the Billing Services in IP Telephony
Dimitris Geneiatakis, Georgios Kambourakis, Costas Lambrinoudakis |
TrustBus | 3 |
| 2008 | Message from the SecPri Workshop Organizing Technical Co-chairsabstractPresents the introductory welcome message from the conference proceedings. Peter Mueller, Kaisa Nyberg, Stefanos Gritzalis, Costas Lambrinoudakis |
WiMob | 4 |
| 2008 | An ontology-based policy for deploying secure SIP-based VoIP services
Dimitris Geneiatakis, Costas Lambrinoudakis, Georgios Kambourakis |
Comput. Secur. | 2 |
| 2007 | A framework for protecting a SIP-based infrastructure against malformed message attacks
Dimitris Geneiatakis, Georgios Kambourakis, Costas Lambrinoudakis, Tasos Dagiuklas, Stefanos Gritzalis |
Comput. Networks | 3 |
| 2007 | An ontology description for SIP security flaws
Dimitris Geneiatakis, Costas Lambrinoudakis |
Comput. Commun. | 2 |
| 2006 | An ontology for secure e-government applicationsabstractThis paper addresses the issue of accommodating security requirements in application development. It proposes the use of ontologies for capturing and depicting the security experts' knowledge. In this way developers can exploit security expertise in order to make design choices that help them fulfil security requirements more effectively. We have developed a security ontology for two different application scenarios to illustrate its use. To validate the ontology we have used queries. Maria Karyda 0001, Theodoros Balopoulos, Lazaros Gymnopoulos, Spyros Kokolakis, Costas Lambrinoudakis, Stefanos Gritzalis, Stelios Dritsas |
ARES | 5 |
| 2006 | Outsourcing digital signatures: a solution to key management burdenabstractPurpose Digital signatures are only enjoying a gradual and reluctant acceptance, despite the long existence of the relevant legal and technical frameworks. One of the major drawbacks of client‐generated digital signatures is the requirement for effective and secure management of the signing keys and the complexity of the cryptographic operations that must be performed by the signer. Outsourcing digital signatures to a trusted third party would be an elegant solution to the key management burden. Aims to investigate whether this is legally and technically feasible. Design/methodology/approach In this paper's approach a relying party trusts a Signature Authority (SA) for the tokens it issues, rather than a Certification Authority for the certificates it creates in a traditional public key infrastructure scheme. Findings The paper argues that passing the control of signature creation to a SA rather than the signer herself, is not a stronger concession than the dependence on an identity certificate issued by a Certification Authority. Originality/value The paper proposes a framework for outsourced digital signatures. Dimitrios Lekkas, Costas Lambrinoudakis |
Inf. Manag. Comput. Secur. | 2 |
| 2006 | Risk analysis of a patient monitoring system using Bayesian Network modeling
Ilias Maglogiannis, Elias P. Zafiropoulos, Agapios N. Platis, Costas Lambrinoudakis |
J. Biomed. Informatics | 4 |
| 2005 | A framework for detecting malformed messages in SIP networksabstractInternet telephony like any other Internet service suffers from security flaws caused by various implementation errors (e.g. in end-users terminals, protocols, operating systems, hardware, etc). These implementation problems usually lead VoIP subsystems (e.g. SIP servers) to various unstable operations whenever trying to process a message not conforming to the underlying standards. As Internet telephony becomes more and more popular, attackers will attempt to exhaustively "test" implementations' robustness, transmitting various types of malformed messages to them. Since it is almost infeasible to avoid or predict every potential error caused during the developing process of these subsystems, it is necessary to specify an appropriate and robust, from the security point of view, framework that will facilitate the successful detection and handling of any kind of malformed messages aiming to destruct the provided service. In this paper, we adequately present malformed message attacks against SIP network servers and/or SIP end-user terminals and we propose a new detection "framework" of prototyped attacks' signatures that can assist the detection procedure and provide effective defence against this category of attacks Dimitris Geneiatakis, Georgios Kambourakis, Tasos Dagiuklas, Costas Lambrinoudakis, Stefanos Gritzalis |
LANMAN | 4 |
| 2005 | Technical guidelines for enhancing privacy and data protection in modern electronic medical environmentsabstractRaising awareness and providing guidance to on-line data protection is undoubtedly a crucial issue worldwide. Equally important is the issue of applying privacy-related legislation in a coherent and coordinated way. Both these topics gain extra attention when referring to medical environments and, thus, to the protection of patients' privacy and medical data. Electronic medical transactions require the transmission of personal and medical information over insecure communication channels like the Internet. It is, therefore, a rather straightforward task to capture the electronic medical behavior of a patient, thus constructing "patient profiles," or reveal sensitive information related to a patient's medical history. The consequence is clearly a potential violation of the patient's privacy. We performed a risk analysis study for a Greek shared care environment for the treatment of patients suffering from beta-thalassemia, an empirically embedded scenario that is representative of many other electronic medical environments; we capitalized on its results to provide an assessment of the associated risks, focusing on the description of countermeasures, in the form of technical guidelines that can be employed in such medical environments for protecting the privacy of personal and medical information. Dimitris Gritzalis, Costas Lambrinoudakis, Dimitrios Lekkas, S. Deftereos |
IEEE Trans. Inf. Technol. Biomed. | 2 |
| 2003 | Security Policy Configuration Issues in Grid Computing Environments
George Angelis, Stefanos Gritzalis, Costas Lambrinoudakis |
SAFECOMP | 3 |
| 2003 | Security requirements for e-government services: a methodological approach for developing a common PKI-based security policy
Costas Lambrinoudakis, Stefanos Gritzalis, Fredj Dridi, Günther Pernul |
Comput. Commun. | 1 |
| 2002 | Functional Requirements for a Secure Electronic Voting System
Spyros Ikonomopoulos, Costas Lambrinoudakis, Dimitris Gritzalis, Spyros Kokolakis, K. Vassiliou |
SEC | 2 |
| 2001 | Pythia: Towards Anonymity in Authentication
Dimitris Gritzalis, Konstantinos Moulinos, John Iliadis, Costas Lambrinoudakis, S. Xarhoulacos |
SEC | 4 |
| 2000 | Using Smart Cards in an Educational Environment: Services and Security Features
Costas Lambrinoudakis |
SEC | 1 |
| 2000 | Smart card technology for deploying a secure information management frameworkabstractThe continuously increasing need for de‐centralized information systems offering data to the people who need them irrespective of their physical location, as well as the requirement for exchanging information between different but interoperable systems, make the system’s architectural and functional design more complex and in many cases extremely vulnerable in respect to its security attributes. The concept of a “secure portable information file”, that can nowadays be easily implemented through the available smart card technology, can significantly ease information management and ensure maximum data protection in respect to their integrity, confidentiality and availability. This paper presents the use of smart cards in an educational environment as a case‐study example for demonstrating the above mentioned benefits, focussing on the utilization of the smart card’s cryptographic functions for implementing mechanisms capable of providing an extremely secure operational framework in terms of user and application provider authenticity, management of access privileges and data integrity and confidentiality. Costas Lambrinoudakis |
Inf. Manag. Comput. Secur. | 1 |
| 1991 | GPFP: an array processing element for the next generation of massively parallel supercomputer architecturesabstractArticle GPFP: an array processing element for the next generation of massively parallel supercomputer architectures Share on Authors: Don Beal Department of Computer Science, Queen Mary and Westfield College, University of London, London E1 4NS, United Kingdom Department of Computer Science, Queen Mary and Westfield College, University of London, London E1 4NS, United KingdomView Profile , Costas Lambrinoudakis Department of Computer Science, Queen Mary and Westfield College, University of London, London E1 4NS, United Kingdom Department of Computer Science, Queen Mary and Westfield College, University of London, London E1 4NS, United KingdomView Profile Authors Info & Claims Supercomputing '91: Proceedings of the 1991 ACM/IEEE conference on SupercomputingAugust 1991 Pages 348–357https://doi.org/10.1145/125826.126024Online:01 August 1991Publication History 0citation252DownloadsMetricsTotal Citations0Total Downloads252Last 12 Months1Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Donald F. Beal, Costas Lambrinoudakis |
SC | 2 |