Charilaos Skandylas

dblp:224/4422 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0002-5057-2790ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Compositional security analysis of dynamic component-based systems
abstract
Context: To reason about and enforce security in dynamic software systems, automated analysis and verification approaches are required. However, such approaches often encounter scalability issues, particularly when employed for runtime analysis, which is necessary in software systems with dynamically changing architectures, such as self-adaptive systems. Objective: In this work, we propose an automated formal approach for security analysis of component-based systems with dynamic architectures. Methods: This approach leverages formal abstraction and incremental analysis techniques to reduce the complexity of runtime analysis. We have implemented and evaluated our approach against ZNN, a widely known self-adaptive system exemplar. Results: Compared to the state of the art, our results demonstrate an improvement both in the size of systems that can be analyzed and at the time required to complete the analysis. In particular, our incremental analysis is well suited for systems that alter their architectures at runtime. Conclusion: Therefore, this approach is suitable for analyzing the security dynamic component based both statically and at runtime.
Charilaos Skandylas, Narges Khakpour
Inf. Softw. Technol.1
2025 Multi-Partner Project: CyberSecDome - Framework for Secure, Collaborative, and Privacy-Aware Incident Handling for Digital Infrastructure
abstract
Digital infrastructure is vital for the economy, democracy, and everyday life, yet it is becoming increasingly vulnerable to strategic cyber-attacks. These attacks can lead to significant disruptions, resulting in widespread service outages, financial losses, and a decline in public trust. Ensuring resilience is difficult due to the infrastructure's complexity, the large volume of data involved, and the growing need for quick, coordinated responses. In the EU Horizon project CyberSecDome, we propose a multi-layered framework that provides AI-driven solutions for incident prediction and detection, automated testing, risk assessment, and rapid incident response, supporting continuity amid complex, large-scale cyber threats. Additionally, Cyber-SecDome introduces a virtual reality interface to enhance AI model explainability and provide real-time contextual awareness of ongoing attacks and defense mechanisms. It also enables privacy-aware model sharing across AI systems, fostering secure collaboration among different domes.
Mohammad Hamad, Michael Kühr, Haralambos Mouratidis, Eleni-Maria Kalogeraki, Christos-Antonios Gizelis, Dimitrios Papanikas, Athanasios Bountioukos-Spinaris, Charilaos Skandylas, Evangelos Raptis, Andreas Alexopoulos, Grigorios Chrysos 0001, Mina Marmpena, Sevasti Politi, Konstantinos Lieros, Nikolaos Papagiannopoulos, Iordanis Xanthopoulos, Spyridon Papastergiou, Sotiris Ioannidis, Mikael Asplund, Marc-Oliver Pahl, Sebastian Steinhorst
DATE8
2025 Automated penetration testing: Formalization and realization
abstract
Recent changes in standards and regulations, driven by the increasing importance of software systems in meeting societal needs, mandate increased security testing of software systems. Penetration testing has been shown to be a reliable method to asses software system security. However, manual penetration testing is labor-intensive and requires highly skilled practitioners. Given the shortage of cybersecurity experts and current societal needs, increasing the degree of automation involved in penetration testing can aid in fulfilling the demands for increased security testing. In this work, we formally express the penetration testing problem at the architectural level and suggest a general self-organizing architecture that can be instantiated to automate penetration testing of real systems. We further describe and implement a specialization of the architecture in ADAPT, an architecture-driven automated penetration testing tool, targeting systems composed of hosts and services. We evaluate and demonstrate the feasibility of ADAPT by automatically performing penetration tests with success against: Metasploitable2, Metasploitable3, and a realistic virtual network used as a lab environment for penetration tester training.
Charilaos Skandylas, Mikael Asplund
Comput. Secur.1
2024 Compositional Security Analysis of Dynamic Component-based Systems
abstract
To reason about and enforce security in dynamic software systems, automated analysis and verification approaches are required. However, such approaches often encounter scalability issues, particularly when employed for runtime analysis, which is necessary in software systems with dynamically changing architectures, such as self-adaptive systems. In this work, we propose an automated formal approach for security analysis of component-based systems with dynamic architectures. This approach leverages formal abstraction and incremental analysis techniques to reduce the complexity of runtime analysis. We have implemented and evaluated our approach against ZNN, a widely known self-adaptive system exemplar. Our experimental results demonstrate the effectiveness of our approach in addressing scalability issues.
Narges Khakpour, Charilaos Skandylas
ASE2
2022 Security Countermeasure Selection for Component-Based Software-Intensive Systems
abstract
Given the increasing complexity of softwareintensive systems as well as the sophistication and high frequency of cyber-attacks, automated and sound approaches to select countermeasures are required to effectively protect software systems. In this paper, we propose a formal architecturecentered approach to analyze the security of a software-intensive component-based system to find cost-efficient countermeasures that consider both the system architecture and its behavior. We evaluate our approach by applying it on a case study.
Charilaos Skandylas, Narges Khakpour, Javier Cámara 0001
QRS1
2021 Design and Implementation of Self-Protecting systems: A Formal Approach
Charilaos Skandylas, Narges Khakpour
Future Gener. Comput. Syst.1
2020 AT-DIFC+: Toward Adaptive and Trust-Aware Decentralized Information Flow Control
abstract
Modern software systems and their corresponding architectures are increasingly decentralized, distributed, and dynamic. As a consequence, decentralized mechanisms are required to ensure security in such architectures. Decentralized Information Flow Control (DIFC) is a mechanism to control information flow in distributed systems. This article presents and discusses several improvements to an adaptive decentralized information flow approach that incorporates trust for decentralized systems to provide security. Adaptive Trust-Aware Decentralized Information Flow (AT-DIFC + ) combines decentralized information flow control mechanisms, trust-based methods, and decentralized control architectures to control and enforce information flow in an open, decentralized system. We strengthen our approach against newly discovered attacks and provide additional information about its reconfiguration, decentralized control architectures, and reference implementation. We evaluate the effectiveness and performance of AT-DIFC + on two case studies and perform additional experiments and to gauge the mitigations’ effectiveness against the identified attacks.
Charilaos Skandylas, Narges Khakpour, Jesper Andersson
ACM Trans. Auton. Adapt. Syst.1
2018 Synthesis of a Permissive Security Monitor
Narges Khakpour, Charilaos Skandylas
ESORICS (1)2