Sotiris Ioannidis

dblp:33/2939 · also Sotirios Ioannidis · DBLP profile ↗
← Back
112ranked-venue papers
3as first author
41since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 47 · 2 first-author · 10 since 2021Computer networks · 24 · 11 since 2021Databases, data management, data science and information retrieval · 12 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 since 2021Systems, architecture and hardware · 9 · 6 since 2021Artificial intelligence and machine learning · 7 · 5 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 6 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 Physics-Aware RIS Codebook Compilation for Near-Field Beam Focusing under Mutual Coupling and Specular Reflections
Alexandros I. Papadopoulos, Maria Anna Pistela, Dimitrios Tyrovolas, Antonios Lalas, Konstantinos Votis, Sotiris Ioannidis, George K. Karagiannidis, Christos Liaskos
ICC6
2026 MEDIATE: Multi-Faceted Implementation of a Mixed Software/Hardware-Based Zero Trust Framework for the Computing Continuum
Apostolos P. Fournaris, Evangelos Haleplidis, Shahin Abdoul-Soukour, Chih-Kai Huang 0001, Niemat Khoder, Georgios Bouloukakis, Andreas Brokalakis, Konstantinos Georgopoulos, Sotiris Ioannidis
MDM9
2026 A novel RF-enabled Non-Destructive Inspection Method through Machine Learning and Programmable Wireless Environments
Stavros Tsimpoukis, Dimitrios Tyrovolas, Sotiris Ioannidis, Maria Kafesaki, Ian F. Akyildiz, George K. Karagiannidis, Christos Liaskos
Comput. Networks3
2026 How Many Pinching Antennas Are Enough?
abstract
Programmable wireless environments (PWEs) have emerged as a key paradigm for next-generation communication networks, aiming to transform wireless propagation from an uncontrollable phenomenon into a reconfigurable process that can adapt to diverse service requirements. In this framework, pinching-antenna systems (PASs) have recently been proposed as a promising enabling technology, as they allow the radiation location and effective propagation distance to be adjusted by selectively exciting radiating points along a dielectric waveguide. However, most existing studies on PASs rely on the idealized assumption that pinching-antenna (PA) positions can be continuously adjusted along the waveguide, while realistically only a finite set of pinching locations is available. Motivated by this, this paper analyzes the performance of two-state PASs, where the PA positions are fixed and only their activation state can be controlled. By explicitly accounting for the spatial discreteness of the available pinching points, closed-form analytical expressions for the outage probability and the ergodic achievable data rate are derived. In addition, we introduce the pinching discretization efficiency to quantify the performance gap between discrete and continuous pinching configurations, enabling a direct assessment of the number of PAs required to approximate the ideal continuous case. Finally, numerical results validate the analytical framework and show that near-continuous performance can be achieved with a limited number of PAs, offering useful insights for the design and deployment of PASs in PWEs.
Dimitrios Tyrovolas, Sotiris A. Tegos, Yue Xiao 0002, Panagiotis D. Diamantoulakis, Sotiris Ioannidis, Christos Liaskos, George K. Karagiannidis, Stylianos D. Asimonis
IEEE Internet Things J.5
2025 BotArtist: Generic Approach for Bot Detection in Twitter via Semi-automatic Machine Learning Pipeline
Alexander Shevtsov, Despoina Antonakaki, Ioannis Lamprou 0002, Polyvios Pratikakis, Sotiris Ioannidis
ASONAM (2)5
2025 Multi-Partner Project: CyberSecDome - Framework for Secure, Collaborative, and Privacy-Aware Incident Handling for Digital Infrastructure
abstract
Digital infrastructure is vital for the economy, democracy, and everyday life, yet it is becoming increasingly vulnerable to strategic cyber-attacks. These attacks can lead to significant disruptions, resulting in widespread service outages, financial losses, and a decline in public trust. Ensuring resilience is difficult due to the infrastructure's complexity, the large volume of data involved, and the growing need for quick, coordinated responses. In the EU Horizon project CyberSecDome, we propose a multi-layered framework that provides AI-driven solutions for incident prediction and detection, automated testing, risk assessment, and rapid incident response, supporting continuity amid complex, large-scale cyber threats. Additionally, Cyber-SecDome introduces a virtual reality interface to enhance AI model explainability and provide real-time contextual awareness of ongoing attacks and defense mechanisms. It also enables privacy-aware model sharing across AI systems, fostering secure collaboration among different domes.
Mohammad Hamad, Michael Kühr, Haralambos Mouratidis, Eleni-Maria Kalogeraki, Christos-Antonios Gizelis, Dimitrios Papanikas, Athanasios Bountioukos-Spinaris, Charilaos Skandylas, Evangelos Raptis, Andreas Alexopoulos, Grigorios Chrysos 0001, Mina Marmpena, Sevasti Politi, Konstantinos Lieros, Nikolaos Papagiannopoulos, Iordanis Xanthopoulos, Spyridon Papastergiou, Sotiris Ioannidis, Mikael Asplund, Marc-Oliver Pahl, Sebastian Steinhorst
DATE18
2025 Multi-Partner Project: Safe, Secure and Dependable Multi-UAV Systems for Search and Rescue Operations
abstract
Unmanned Aerial Vehicles (UAVs) have become essential in search and rescue operations, especially in disaster management scenarios. Their effective navigation and the integration of a plethora of sensors assist in efficient person detection, making them an essential technological tool to first responders. Multi-UAV systems extend these benefits by using coordinated strategies to cover large areas efficiently, reducing overall mission response time and enhancing its success. Despite these advantages, challenges remain in ensuring the safety, security, and dependability of (mutli-)UAV missions. Issues such as navigation risks, potential cyber threats, and hardware-/software-related reliability issues can impact the mission results. Additionally, UAVs are highly constrained devices with limited battery capacity, requiring the use of lightweight technologies. In this paper, we present part of the results of the SESAME project, an EU multi-partner project that aims to develop safe and secure multi-robot Systems. In particular, we present some of the developed SESAME Executable Digital Dependability Identities (EDDI) technologies based on Markov models, statistical distance measures, and other advanced approaches for enhancing safety, security and dependability of the UAV platform and underlying models. These EDDI technologies are seamlessly integrated using the ConSerts framework in a multi-UAV platform and tested using search and rescue scenarios. The results demonstrate significant improvements in multi-UAV safety, with an availability rate of 91% and a search and rescue algorithmic accuracy of 99.8%. Additionally, the system achieves precise detection of spoofing attacks, using collaborative localization as a mitigation technique to guide the UAV to a safe landing, even in the absence of GPS signals,
Panagiota Nikolaou, Antonis D. Savva, Ioannis Sorokos, Koorosh Aslansefat, Sondess Missaoui, Mohammed Naveed Akram, Daniel Hillen, Marc Lorenz, Martin D. Walker, Manos Papoutsakis, Simos Gerasimou, Panayiotis Kolios, Yiannis Papadopoulos, Jan Reich, Sotiris Ioannidis, Maria K. Michael
DATE15
2025 Dredging the River Styx: Fortifying the Web through Robust and Real-Time Script Attribution
abstract
The modern web ecosystem relies heavily on the inclusion of third-party scripts as they offer useful, and often necessary, functionality. This inclusion leads to the "blending" of code from different origins, which has significant ramifications. Specifically, the inability to effectively and robustly disambiguate between first-party and embedded third-party scripts can severely undermine the security and privacy guarantees of existing defenses (e.g., blocking trackers or preventing vulnerabilities such as DOM XSS), as well as the validity of web measurement studies. To address that gap we propose StyxJS, a system that is able to provide real-time attribution of third-party scripts while preventing evasive tactics that can be employed by malicious scripts. This is achieved through an automated pipeline consisting of stack walking, script rewriting, browser API overriding, and tamper-proofing mechanisms. Crucially, our system does not require any developer input or prior knowledge about the website and can, thus, be readily incorporated into any countermeasure or web measurement apparatus that requires robust script attribution. We conduct an extensive experimental evaluation of our system and demonstrate that it accurately captures more script inclusion techniques compared to prior work, while incurring a negligible performance overhead, and effectively maintains page-deployed security mechanisms (e.g., CSP). We also detail the straightforward process and benefits of retrofitting a varied set of existing defenses on top of StyxJS, as well as leveraging it to analyze the web ecosystem. We will release our system as an open source project, to allow security researchers and practitioners to benefit from StyxJS’ capabilities.
Kostas Drakonakis, Sotiris Ioannidis, Iasonas Polakis
EuroS&P2
2025 SHIELD: A Codebook-Based Methodology for RIS-Based Covert Communications
abstract
Programmable Wireless Environments (PWEs) leverage Reconfigurable Intelligent Surfaces (RISes) to actively shape electromagnetic (EM) propagation, enabling advanced control over wireless channels. Beyond improved performance in B5G/6G networks, this control also introduces new security capabilities. Exploiting this, we propose RF-Fencing: a service that selectively suppresses EM signals toward eavesdroppers while preserving reliable communication for legitimate users, thereby significantly enhancing network covertness. Building on that, in this paper, we introduce SHIELD, the first RF-Fencing algorithm that partitions the PWE into Signal Suppression Areas (SSAs) and Signal Delivery Areas (SDAs) through on-the-fly merging of RIS configurations. Extensive EM analysis confirms SHIELD’s effectiveness in preventing wardens from intercepting critical information and achieving covert communications with minimal impact on legitimate users. Moreover, SHIELD can serve also as a jamming-mitigation mechanism and is applicable across various frequency bands and RIS designs.
Alexandros I. Papadopoulos, Dimitrios Tyrovolas, Alexandros Pitilakis, Panagiotis D. Diamantoulakis, Antonios Lalas, Konstantinos Votis, Nikolaos V. Kantartzis, Sotiris Ioannidis, Christos Liaskos
PIMRC8
2025 Outage Analysis of Pinching-Antenna Systems
abstract
The evolution toward sixth-generation wireless networks introduces the concept of intelligent and reconfigurable environments designed to support advanced services. Achieving this paradigm shift requires addressing the limitations of traditional wireless systems, particularly their inability to effectively counteract path loss or adapt to diverse user scenarios. Pinching antenna systems (PASs) have emerged as a promising solution, enabling dynamic control over path loss by leveraging dielectric waveguides to support low-loss transmission at high frequencies. This work presents an analytical framework for assessing the reliability of PASs through the derivation of closed-form expressions for the outage probability under both free-space and waveguide attenuation. In addition, a rigorous formulation is provided for the optimal positioning of the pinching antennas to maximize signal reception, taking into account the trade-off between waveguide losses and spatial separation. Simulation results validate the impact of waveguide attenuation on performance and show that PASs consistently outperform conventional architectures in terms of outage behavior, confirming their suitability for next-generation wireless networks.
Dimitrios Tyrovolas, Sotiris A. Tegos, Panagiotis D. Diamantoulakis, Sotiris Ioannidis, Christos Liaskos, George K. Karagiannidis
PIMRC4
2025 On Modeling the RIS as a Resource: Multi-User Allocation and Efficiency-Proportional Pricing
abstract
Programmable Wireless Environments aim to render the communication environment a controllable, software-defined medium. Reconfigurable Intelligent Surfaces (RISes) are the key enabling technology, which can offer the real-time capability to manipulate impinging waves. RISes are expected to be widely deployed in B5G/6G networks to serve a large number of users simultaneously. Despite numerous analyses highlighting the benefits of utilizing previously unexploitable propagation factors through the use of RISes, there is a lack of analysis regarding their relation to the concept of network resource, their allocation to users/stakeholders and their fair pricing. Thus, this paper models RISes as networked resources. Based on this definition, the PRIME algorithm is proposed, the first algorithm for RIS resource allocation and joint pricing. PRIME strives for proportionality between the offered end-user performance level and the corresponding resource pricing, promoting fairness. The algorithm is validated via full-wave electromagnetic simulations and applies to multiple RIS functionalities and frequency bands.
Alexandros I. Papadopoulos, Dimitrios Tyrovolas, Antonios Lalas, Konstantinos Votis, Stefan Schmid 0001, Sotiris Ioannidis, George K. Karagiannidis, Christos Liaskos
IEEE Trans. Netw. Serv. Manag.6
2024 SYNAPSE - An Integrated Cyber Security Risk & Resilience Management Platform, With Holistic Situational Awareness, Incident Response & Preparedness Capabilities: SYNAPSE
abstract
In an era of escalating cyber threats, the imperative for robust and comprehensive cybersecurity measures has never been more pressing. To address this challenge, SYNAPSE presents a pioneering approach by conceptualising, designing, and delivering an Integrated cybersecurity Risk & Resilience Management Platform. The innovation of this platform lies in the integration of key elements, such as situational awareness, incident response, and preparedness (i.e., cyber range), augmented by advanced AI capabilities. Through its holistic approach, SYNAPSE aims to elevate cyber resilience by not only mitigating threats but also fostering a culture of proactive defence, informed decision-making, and collaborative response within organisations and across industries.
Panagiotis Bountakas, Konstantinos Fysarakis, Thomas Kyriakakis, Panagiotis Karafotis, Aristeidis Sotiropoulos, Maria Tasouli, Cristina Alcaraz, George Alexandris, Vassiliki Andronikou, Tzortzia Koutsouri, Romarick Yatagha, George Spanoudakis, Sotiris Ioannidis, Fabio Martinelli, Oleg Illiashenko
ARES13
2024 Exploring Crisis-Driven Social Media Patterns: A Twitter Dataset of Usage During the Russo-Ukrainian War
Ioannis Lamprou 0002, Alexander Shevtsov, Despoina Antonakaki, Polyvios Pratikakis, Sotiris Ioannidis
ASONAM (1)5
2024 SECURED for Health: Scaling Up Privacy to Enable the Integration of the European Health Data Space
abstract
In this paper, we present the SECURED project11Funded in part by the European Union (EU), Grant Agreement no. 10109571. Views and opinions expressed are those of the authors and do not necessarily reflect those of the EU or the Health and Digital Executive Agency. Neither the EU nor the granting authority are responsible for them., aimed at improving privacy-preserving processing of data in the health domain. The technologies developed in the project will be demonstrated in four health-related use cases and with the involvement of SME's selected through an open funding call.
Francesco Regazzoni 0001, Gergely Ács, Albert Zoltan Aszalos, Christos Avgerinos, Nikolaos Bakalos, Josep Lluís Berral, Joppe W. Bos, Marco Brohet, Andrés G. Castillo, Gareth T. Davies, Stefanos Florescu, Pierre-Elisée Flory, Alberto Gutierrez-Torre, Evangelos Haleplidis, Alice Héliou, Sotiris Ioannidis, Alexander El-Kady, Katarzyna Kapusta, Konstantina Karagianni, Pieter Kruizinga, Kyrian Maat, Zoltán Ádám Mann, Kalliopi Mastoraki, SeoJeong Moon, Maja Nisevic, Balazs Pejo, Kostas Papagiannopoulos, Vassilis Paliouras, Paolo Palmieri 0001, Francesca Palumbo, Juan Carlos Pérez Baun, Péter Pollner, Eduard Porta-Pardo, Luca Pulina, Muhammad Ali Siddiqi, Daniela Spajic, Christos Strydis, George Tasopoulos, Vincent Thouvenot, Christos Tselios, Apostolos P. Fournaris
DATE16
2024 REBECCA: Reconfigurable Heterogeneous Highly Parallel Processing Platform for Safe and Secure AI
Andreas Brokalakis, Iakovos Mavroidis, Konstantinos Georgopoulos, Pavlos Malakonakis, Konstantinos Harteros, Dimitris Andronikou, Yannis Galanomatis, Charalampos Savvakos, Grigorios Chrysos 0001, Sotiris Ioannidis, Ioannis Papaefstathiou
DSD10
2024 Broken Agreement: The Evolution of Solidity Error Handling
abstract
Background. A smart contract is a computer program enclosing the terms of a legal agreement between two or more parties which is automatically verified and executed via a computer network called blockchain. Once a smart contract transaction is completed the blockchain is updated and the transaction cannot be changed anymore. This implies that any error codified in the smart contract program cannot be rectified. Therefore, it is of vital importance that developers of smart contracts properly exploit error handling to prevent issues during and after the contract execution. Existing programming languages for smart contracts, support developers in this task by providing a set of Error Handling (EH) features. However, it is unclear the extent to which developers effectively use EH in practice. Aims. Our work aims to fill this gap by empirically investigating the state of practice on the adoption of EH features of one of the most popular programming languages for smart contracts, namely Solidity. Method. We empirically analyse the usage of EH features in 283K unique open-source Solidity smart contracts for the Ethereum blockchain. Results. Our analysis of the documentation of the different versions of Solidity coupled with the empirical evaluation of the EH uses and misuses found in real-word smart contracts, indicate that, among other things, Solidity EH features have been changing frequently across versions, and that the adoption of most of the Solidity EH features has been limited in practice. However, we observe an upward trend in the usage of the require EH feature, which is specifically designed for smart contract development. Conclusions. The insights from our study could help developers improve their EH practice as well as designers of smart contract programming languages to equip their language with appropriate EH features.
Charalambos Mitropoulos, Maria Kechagia, Chrysostomos Maschas, Sotiris Ioannidis, Federica Sarro, Dimitris Mitropoulos
ESEM4
2024 Energy-Aware Trajectory Design for UAV-mounted Full-duplex Relays
abstract
Unmanned aerial vehicles (UAVs) equipped with full-duplex relays (FDRs) are pivotal in overcoming connectivity challenges by dynamically establishing effective communication channels. However, despite their potential in network performance via trajectory optimization, integrating energy consumption models for UAV-mounted FDRs remains unexplored, crucial for trajectory design adhering to existing energy constraints. To this end, we introduce an energy-aware trajectory optimization framework to maximize network performance and user fairness within the UAV’s energy constraints. Specifically, we present a detailed energy consumption model describing the operational needs of UAV-mounted FDRs and formulate a joint time-division multiple access (TDMA) user scheduling-UAV trajectory optimization problem considering the power dynamics of UAV-mounted FDRs. Finally, our simulation results highlight the role of energy awareness in achieving optimal trajectory and scheduling, contributing to UAV-mounted FDRs’ performance in future networks.
Dimitrios Tyrovolas, Nikos A. Mitsiou, Thomas G. Boufikos, Sotiris A. Tegos, Prodromos-Vasileios Mekikis, Panagiotis D. Diamantoulakis, Sotiris Ioannidis, Christos Liaskos, George K. Karagiannidis
PIMRC7
2024 Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety Section
Ioannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis, Iasonas Polakis, Panagiotis Ilia
USENIX Security Symposium4
2024 Fingerprinting the Shadows: Unmasking Malicious Servers with Machine Learning-Powered TLS Analysis
abstract
Over the last few years, the adoption of encryption in network traffic has been constantly increasing. The percentage of encrypted communications worldwide is estimated to exceed 90%. Although network encryption protocols mainly aim to secure and protect users' online activities and communications, they have been exploited by malicious entities that hide their presence in the network. It was estimated that in 2022, more than 85% of the malware used encrypted communication channels.
Andreas Theofanous, Eva Papadogiannaki, Alexander Shevtsov, Sotiris Ioannidis
WWW4
2024 Energy-Aware Trajectory Optimization for UAV-Mounted RIS and Full-Duplex Relay
abstract
In the evolving landscape of sixth-generation (6G) wireless networks, unmanned aerial vehicles (UAVs) have emerged as transformative tools for dynamic and adaptive connectivity. However, dynamically adjusting their position to offer favorable communication channels introduces operational challenges in terms of energy consumption, especially when integrating advanced communication technologies like reconfigurable intelligent surfaces (RISs) and full-duplex relays (FDRs). To this end, by recognizing the pivotal role of UAV mobility, the paper introduces an energy-aware trajectory design for UAV-mounted RISs and UAV-mounted FDRs using the decode-and-forward (DF) protocol, aiming to maximize the network’s minimum rate and enhance user fairness, while taking into consideration the available on-board energy. Specifically, this work highlights their distinct energy consumption characteristics and their associated integration challenges by developing appropriate energy consumption models for both UAV-mounted RISs and FDRs that capture the intricate relationship between key factors such as weight, and their operational characteristics. Furthermore, a joint time-division multiple access (TDMA) user scheduling-UAV trajectory optimization problem is formulated, considering the power dynamics of both systems, while assuring that the UAV energy is not depleted mid-air. Finally, simulation results underscore the importance of energy considerations in determining the optimal trajectory and scheduling and provide insights into the performance comparison of UAV-mounted RISs and FDRs in UAV-assisted wireless networks.
Dimitrios Tyrovolas, Nikos A. Mitsiou, Thomas G. Boufikos, Prodromos-Vasileios Mekikis, Sotiris A. Tegos, Panagiotis D. Diamantoulakis, Sotiris Ioannidis, Christos Liaskos, George K. Karagiannidis
IEEE Internet Things J.7
2024 WRIT: Web Request Integrity and Attestation Against Malicious Browser Extensions
abstract
The powerful capabilities of modern browsers have pushed the web application logic to the user side, in order to minimize latency, increase scalability of the service and improve users’ quality of experience. What is more, browsers provide a rich toolchest for browser extensions to provide additional functionality, but at the same time enable them to become a powerful vehicle for malicious actors. Such actors may spy, phish or fraud users, thus making the user's browser untrusted for the web servers. In this article, we present WRIT, a practical framework that enables websites to protect critical functionality from abuse in the presence of malicious extensions. In WRIT, the integrity of outgoing web requests is attested and verified to ensure they were triggered by a user's action and not automatically generated by a malicious browser extension. WRIT is immediately applicable by leveraging existing HTML5 and other native browser features and does not require any modification of the browser. Performance results of our prototype show that it adds a negligible 7.29 ms latency to sensitive user-triggered actions (e.g., post message).
Giorgos Vasiliadis, Apostolos Karampelas, Alexandros Shevtsov, Panagiotis Papadopoulos, Sotiris Ioannidis, Alexandros Kapravelos
IEEE Trans. Dependable Secur. Comput.5
2024 Zero-Energy Reconfigurable Intelligent Surfaces (zeRIS)
abstract
A primary objective of the forthcoming sixth generation (6G) of wireless networking is to support demanding applications, while ensuring energy efficiency. Programmable wireless environments (PWEs) have emerged as a promising solution, leveraging reconfigurable intelligent surfaces (RISs), to control wireless propagation and deliver exceptional quality-of-service. In this paper, we analyze the performance of a network supported byzero-energy RISs (zeRISs), which harvest energy for their operation and contribute to the realization of PWEs. Specifically, we investigate joint energy-data rate outage probability and the energy efficiency of a zeRIS-assisted communication system by employing three harvest-and-reflect (HaR) methods, i) power splitting, ii) time switching, and iii) element splitting. Furthermore, we consider two zeRIS deployment strategies, namely BS-side zeRIS and UE-side zeRIS. Simulation results validate the provided analysis and examine which HaR method performs better depending on the zeRIS placement. Finally, valuable insights and conclusions for the performance of zeRIS-assisted wireless networks are drawn from the presented results.
Dimitrios Tyrovolas, Sotiris A. Tegos, Vasilis K. Papanikolaou, Yue Xiao 0002, Prodromos-Vasileios Mekikis, Panagiotis D. Diamantoulakis, Sotiris Ioannidis, Christos Liaskos, George K. Karagiannidis
IEEE Trans. Wirel. Commun.7
2023 BinWrap: Hybrid Protection against Native Node.js Add-ons
abstract
Modern applications, written in high-level programming languages, enjoy the security benefits of memory and type safety. Unfortunately, even a single memory-unsafe library can wreak havoc on the rest of an otherwise safe application, nullifying all the security guarantees offered by the high-level language and its managed runtime. We perform a study across the Node.js ecosystem to understand the use patterns of binary add-ons. Taking the identified trends into account, we propose a new hybrid permission model aimed at protecting both a binary add-on and its language-specific wrapper. The permission model is applied all around a native add-on and is enforced through a hybrid language-binary scheme that interposes on accesses to sensitive resources from all parts of the native library. We infer the add-on’s permission set automatically over both its binary and JavaScript sides, via a set of novel program analyses. Applied to a wide variety of native add-ons, we show that our framework, BinWrap, reduces access to sensitive resources, defends against real-world exploits, and imposes an overhead that ranges between 0.71%–10.4%.
George Christou, Grigoris Ntousakis, Eric Lahtinen, Sotiris Ioannidis, Vasileios P. Kemerlis, Nikos Vasilakis
AsiaCCS4
2023 Russo-Ukrainian War: Prediction and explanation of Twitter suspension
abstract
On 24 February 2022, Russia invaded Ukraine, starting what is now known as the Russo-Ukrainian War, initiating an online discourse on SNs. Twitter one of the most popular SNs, with an open and democratic character, enables a transparent discussion among its large user base. Unfortunately, this often leads to Twitter's policy violations, propaganda, abusive actions, civil integrity violations, and consequently to user accounts' suspension and deletion. This study focuses on the Twitter suspension mechanism and the analysis of shared content and features leading to an accurate machine-learning suspension prediction. Toward this goal, we have obtained a dataset containing 107.7M tweets, originating from 9.8 million users, using Twitter API. We extract the categories of shared content of the suspended accounts and explain their characteristics, through the extraction of text embeddings in junction with cosine similarity clustering. Our results reveal scam campaigns taking advantage of trending topics regarding the Russia-Ukrainian conflict for Bitcoin and Ethereum fraud, spam, and advertisement campaigns. Additionally, we apply a ML methodology including a SHapley Additive explainability model to understand and explain how user accounts get suspended.
Alexander Shevtsov, Despoina Antonakaki, Ioannis Lamprou 0002, Ioannis Kontogiorgakis, Polyvios Pratikakis, Sotiris Ioannidis
ASONAM6
2023 Syntax-Aware Mutation for Testing the Solidity Compiler
Charalambos Mitropoulos, Thodoris Sotiropoulos, Sotiris Ioannidis, Dimitris Mitropoulos
ESORICS (3)3
2023 Pump Up the JARM: Studying the Evolution of Botnets Using Active TLS Fingerprinting
abstract
The growing adoption of network encryption protocols, like TLS, has altered the scene of monitoring network traffic. With the advent increase in network encryption, typical DPI systems that monitor network packet payload contents are becoming obsolete, while in the meantime, adversaries abuse the utilization of the TLS protocol to bypass them. In this paper, aiming to understand the botnet ecosystem in the wild, we contact IP addresses known to participate in malicious activities using the JARM tool for active probing. Based on packets acquired from TLS handshakes, server fingerprints are constructed during a time period of 7 months. We investigate if it is feasible to detect suspicious servers and re-identify other similar within blocklists with no prior knowledge of their activities. We show that it is important to update fingerprints often or follow a more effective fingerprinting approach, since the overlapping ratio with legitimate servers rises over time.
Eva Papadogiannaki, Sotiris Ioannidis
ISCC2
2023 ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application Scanning
Kostas Drakonakis, Sotiris Ioannidis, Iasonas Polakis
NDSS2
2023 On the Impact of Coding Depth in Sliding Window Random Linear Network Coding Schemes
abstract
Sliding Window Random Linear Network Coding (RLNC) offers a clear path towards achieving ultra-high reliability and low latency at the same time. Such requirements are pivotal for a wide range of applications in the future Internet as well as in 5G and beyond networks. While traditional RLNC has been extensively used for some years now, its Sliding Window flavor is rather recent and extremely promising because of its implementation advantages and the high degree of customization. Probably the most essential parameter of Sliding Window RLNC is the coding depth, i.e., the extent of non-coded packets protected by a coded one. In this work, for the first time, we elaborate on properly choosing the coding depth and shed light on the related trade-offs. We, first, show, experimentally, that significant performance gains can be obtained by fine-tuning the coding depth. Then, we propose and validate an analytical framework that allows us to decide the coding depth based on a channel’s reliability profile. Finally, we introduce a dynamic algorithm that, based on our analytical findings, can improve the performance of sliding window RLNC in the presence of bursts of errors.
Foteini Karetsi, Christos Liaskos, Sotiris Ioannidis, Evangelos Papapetrou
WoWMoM3
2022 A Blueprint for Collaborative Cybersecurity Operations Centres with Capacity for Shared Situational Awareness, Coordinated Response, and Joint Preparedness
abstract
With digital technologies now being part of the fabric of our societies, identifying and managing cybersecurity threats becomes imperative. Within the European Union, several initiatives are underway, aiming to motivate, regulate and eventually orchestrate the establishment of capacity and enhancement of situational awareness, incident response, and preparedness capabilities, with an expected emphasis on operators of essential services and state actors entrusted with cybersecurity. In this context, the institution of cooperation and information exchange channels to allow for coordinated cross-border responses to large-scale incidents is particularly prioritized. Motivated by the above, this work presents a conceptual blueprint in support of architecting and establishing interoperable Cyber Security Operations Centres that combine capacity for situational awareness, incident response, and preparedness, also benefiting from the interplay between them, ultimately enhancing national cybersecurity capabilities, cross-border collaboration, and national supervision of their critical sectors, in line with current and upcoming regulatory requirements and the ever-increasing need for national and international cooperation.
Konstantinos Fysarakis, Vasileios Mavroeidis, Manos Athanatos, George Spanoudakis, Sotiris Ioannidis
IEEE Big Data5
2022 An Open Platform for Simulating the Physical Layer of 6G Communication Systems with Multiple Intelligent Surfaces
abstract
Reconfigurable Intelligent Surfaces (RIS) constitute a promising technology that could fulfill the extreme performance and capacity needs of the upcoming 6G wireless networks, by offering software-defined control over wireless propagation phenomena. Despite the existence of many theoretical models describing various aspects of RIS from the signal processing perspective (e.g., channel fading models), there is no open platform to simulate and study their actual physical-layer behavior, especially in the multi-RIS case. In this paper, we develop an open simulation platform, aimed at modeling the physical-layer electromagnetic coupling and propagation between RIS pairs. We present the platform by initially designing a basic unit cell, and then proceeding to progressively model and simulate multiple and larger RISs. The platform can be used for producing verifiable stochastic models for wireless communication in multi-RIS deployments, such as vehicle-to-everything (V2X) communications in autonomous vehicles and cybersecurity schemes, while its code is freely available to the public.
Alexandros I. Papadopoulos, Antonios Lalas, Konstantinos Votis, Dimitrios Tyrovolas, George K. Karagiannidis, Sotiris Ioannidis, Christos Liaskos
CNSM6
2022 Assessing the Effectiveness of Active Fences Against SCAs for Multi-Tenant FPGAs
abstract
The rising use of FPGAs, in the context of cloud computing, has created security concerns. Previous works have shown that malicious users can implement voltage fluctuation sensors and mount successful power analysis attacks against cryptographic algorithms that share the same Power Distribution Network (PDN). So far, masking and hiding schemes are the two main mitigation strategies against such attacks and previous work has shown that the use of an active fence of Ring Oscillators (ROs) holds the potential for constituting an effective hiding countermeasure if placed between two adversary users. Nevertheless, developing an effective proposition against remote Side-Channel Attacks (SCAs) remains an open research topic. This work presents the mapping of an intra-FPGA adversary scenario on a Xilinx UltraScale+ MPSoC to assess the effectiveness of the Ring Oscillator active fence countermeasure. We compare different active fence configurations, with a varying number of Ring Oscillators, while using a new, resource efficient, activation method aiming at the achievement of noise injection hiding. The results show that by using our active fence scheme, which exhibits lower area overhead and lower power consumption than the algorithm under attack, the side-channel leakage is reduced to such a degree that the amount of traces that need to be collected for a successful attack is more than ten times higher compared to no fence present. Moreover, this work presents qualitative results that FPGA cloud providers can consider in order to assess the benefits gained through the deployment of active fence mechanisms within their platforms for multi-tenant services.
Christos Diktopoulos, Konstantinos Georgopoulos, Andreas Brokalakis, Georgios Christou, Grigorios Chrysos 0001, Ioannis Morianos, Sotiris Ioannidis
FPL7
2022 Identification of Twitter Bots Based on an Explainable Machine Learning Framework: The US 2020 Elections Case Study
Alexander Shevtsov, Christos Tzagkarakis, Despoina Antonakaki, Sotiris Ioannidis
ICWSM4
2022 Incident Handling for Healthcare Organizations and Supply-Chains
abstract
Healthcare ecosystems form a critical type of infrastructures that provide valuable services in today societies. However, the underlying sensitive information is also of interest of malicious entities around the globe, with the attack volume being continuously increasing. Safeguarding this complex computerized setting constitutes a major challenge for the involved organizations. This paper presents an incident handling system for healthcare organizations and their supply-chain. The proposed approach utilizes swarm intelligence in order to assess the current security posture in a continuous basis and respond to attacks in real-time. The overall solution is based on the related NIST 800.61 standard and implements the operations of i) preparation, ii) detection and analysis, iii) containment, eradication, and recovery, and iv) post-incident activity. The system is developed under the EU funded project AI4HEALTHSEC and is applied in the relevant healthcare pilots.
Eftychia Lakka, George Hatzivasilis, Stylianos Karagiannis, Andreas Alexopoulos, Manos Athanatos, Sotiris Ioannidis, Manolis Chatzimpyrros, Grigoris Kalogiannis, George Spanoudakis
ISCC6
2022 Integrating Software-Defined Metasurfaces into Wireless Communication Systems: Design and Prototype Evaluation
abstract
Software-Defined Metasurfaces (SDMs) have ad-vanced from basic theoretical ideas to a key enabler for next generation wireless systems. When massively deployed in a wireless environment, they can realize precise, software-defined propagation of signals and wireless channel customizations. A plethora of studies have thoroughly investigated the physical design of the SDMs and their wireless channel engineering capa-bilities. This work introduces a novel architecture and associated processes for integrating SDMs into existing networked wireless systems. First, the integration architecture and the according complex underlying physics of the SDMs are presented. Then the software abstractions are proposed that enable the interaction of the surfaces in a physics-agnostic manner. These software abstractions require an SDM profile to operate in real-time, i.e., a database that accurately describes the capabilities of a given metasurface. Thus, the manufacturing time workflows are suggested to produce such a profile. The proposed solutions are evaluated in an actual physical setup/testbed.
Christos Liaskos, Georgios G. Pyrialakos, Alexandros Pitilakis, Ageliki Tsioliaridou, Michail Christodoulou, Nikolaos V. Kantartzis, Sotiris Ioannidis, Andreas Pitsillides, Ian F. Akyildiz
ISCC7
2022 Scheduling of multiple network packet processing applications using Pythia
Giannis Giakoumakis, Eva Papadogiannaki, Giorgos Vasiliadis, Sotiris Ioannidis
Comput. Networks4
2022 Software-Defined Reconfigurable Intelligent Surfaces: From Theory to End-to-End Implementation
abstract
Programmable wireless environments (PWEs) utilize internetworked intelligent metasurfaces to transform wireless propagation into a software-controlled resource. In this article, the interplay is explored between the user devices, the metasurfaces, and the PWE control system from the theory to the end-to-end implementation. This article first discusses the metasurface hardware and software, covering the complete workflow from the user device initialization to its final service via the PWE. Furthermore, to be compatible with the 5G and 6G wireless systems, the software-defined networking (SDN) paradigm is extended to achieve scalable internetworking and central control in PWE deployments with multiple metasurfaces and multihop communication. Subsequently, the set of SDN foundations is exploited in order to abstract the physics behind PWEs and a theoretical framework is established to describe and manipulate them in an algorithmic form. This can lead to smart radio environments that are readily accessible from various engineering disciplines, facilitating their integration into existing networks, wireless systems, and applications. This article is concluded by outlining strategies for the optimal placement of metasurfaces within a PWE-controlled space, open challenges in PWE security, specialized SDN integration issues, and theoretical problems toward the graph-driven modeling of PWEs.
Christos Liaskos, Lefteris Mamatas, Arash Pourdamghani, Ageliki Tsioliaridou, Sotiris Ioannidis, Andreas Pitsillides, Stefan Schmid 0001, Ian F. Akyildiz
Proc. IEEE5
2021 This Sneaky Piggy Went to the Android Ad Market: Misusing Mobile Sensors for Stealthy Data Exfiltration
abstract
Mobile sensors have transformed how users interact with modern smartphones and enhance their overall experience. However, the absence of sufficient access control for protecting these sensors enables a plethora of threats. As prior work has shown, malicious apps and sites can deploy a wide range of attacks that use data captured from sensors. Unfortunately, as we demonstrate, in the modern app ecosystem where most apps fetch and render third-party web content, attackers can use ads for delivering attacks. In this paper, we introduce a novel attack vector that misuses the advertising ecosystem for delivering sophisticated and stealthy attacks that leverage mobile sensors. These attacks do not depend on any special app permissions or specific user actions, and affect all Android apps that contain in-app advertisements due to the improper access control of sensor data in WebView. We outline how motion sensor data can be used to infer users' sensitive touch input (e.g., credit card information) in two distinct attack scenarios, namely intra-app and inter-app data exfiltration. While the former targets the app displaying the ad, the latter affects every other Android app running on the device. To make matters worse, we have uncovered serious flaws in Android's app isolation, life cycle management, and access control mechanisms that enable persistent data exfiltration even after the app showing the ad is moved to the background or terminated by the user. Furthermore, as in-app ads can "piggyback" on the permissions intended for the app's core functionality, they can also obtain information from protected sensors such as the camera, microphone and GPS. To provide a comprehensive assessment of this emerging threat, we conduct a large-scale, end-to-end, dynamic analysis of ads shown in apps available in the official Android Play Store. Our study reveals that ads in the wild are already accessing and leaking data obtained from motion sensors, thus highlighting the need for stricter access control policies and isolation mechanisms.
Michalis Diamantaris, Serafeim Moustakas, Lichao Sun 0001, Sotiris Ioannidis, Iasonas Polakis
CCS4
2021 Demo: Detecting Third-Party Library Problems with Combined Program Analysis
abstract
Third-party libraries ease the software development process and thus have become an integral part of modern software engineering. Unfortunately, they are not usually vetted by human developers and thus are often responsible for introducing bugs, vulnerabilities, or attacks to programs that will eventually reach end-users. In this demonstration, we present a combined static and dynamic program analysis for inferring and enforcing third-party library permissions in server-side JavaScript. This analysis is centered around a RWX permission system across library boundaries. We demonstrate that our tools can detect zero-day vulnerabilities injected into popular libraries and often missed by state-of-the-art tools such as snyk test and npm audit.
Grigoris Ntousakis, Sotiris Ioannidis, Nikos Vasilakis
CCS2
2021 Andromeda: Enabling Secure Enclaves for the Android Ecosystem
Dimitris Deyannis, Dimitris Karnikis, Giorgos Vasiliadis, Sotiris Ioannidis
ISC4
2021 A survey of Twitter research: Data model, graph structure, sentiment analysis and attacks
Despoina Antonakaki, Paraskevi Fragopoulou, Sotiris Ioannidis
Expert Syst. Appl.3
2021 WARDOG: Awareness Detection Watchdog for Botnet Infection on the Host Device
abstract
Botnets constitute nowadays one of the most dangerous security threats worldwide. High volumes of infected machines are controlled by a malicious entity and perform coordinated cyber-attacks. The problem will become even worse in the era of the Internet of Things (IoT) as the number of insecure devices is going to be exponentially increased. This paper presents WARDOG - an awareness and digital forensic system that informs the end-user of the botnet's infection, exposes the botnet infrastructure, and captures verifiable data that can be utilized in a court of law. The responsible authority gathers all information and automatically generates a unitary documentation for the case. The document contains undisputed forensic information, tracking all involved parties and their role in the attack. The deployed security mechanisms and the overall administration setting ensures non-repudiation of performed actions and enforces accountability. The provided properties are verified through theoretic analysis. In simulated environment, the effectiveness of the proposed solution, in mitigating the botnet operations, is also tested against real attack strategies that have been captured by the FORTHcert honeypots, overcoming state-of-the-art solutions. Moreover, a preliminary version is implemented in real computers and IoT devices, highlighting the low computational/communicational overheads of WARDOG in the field.
George Hatzivasilis, Othonas Sultatos, Panos Chatziadam, Konstantinos Fysarakis, Ioannis G. Askoxylakis, Sotiris Ioannidis, George Alexandris, Vasilios Katos, George Spanoudakis
IEEE Trans. Sustain. Comput.6
2020 The Million Dollar Handshake: Secure and Attested Communications in the Cloud
abstract
The number of applications and services that are hosted on cloud platforms is constantly increasing. Nowadays, more and more applications are hosted as services on cloud platforms, co-existing with other services in a mutually untrusted environment. Facilities such as virtual machines, containers and encrypted communication channels aim to offer isolation between the various applications and protect sensitive user data. However, such techniques are not always able to provide a secure execution environment for sensitive applications nor they offer guarantees that data are not monitored by an honest but curious provider once they reach the cloud infrastructure. The recent advancements of trusted execution environments within commodity processors, such as Intel SGX, provide a secure reverse sandbox, where code and data are isolated even from the underlying operating system. Moreover, Intel SGX provides a remote attestation mechanism, allowing the communicating parties to verify their identity as well as prove that code is executed on hardware-assisted software enclaves. Many approaches try to ensure code and data integrity, as well as enforce channel encryption schemes such as TLS, however, these techniques are not enough to achieve complete isolation and secure communications without hardware assistance or are not efficient in terms of performance. In this work, we design and implement a practical attestation system that allows the service provider to offer a seamless attestation service between the hosted applications and the end clients. Furthermore, we implement a novel caching system that is capable to eliminate the latencies introduced by the remote attestation process. Our approach allows the parties to attest one another before each communication attempt, with improved performance when compared to a standard TLS handshake.
Nikolaos Chalkiadakis, Dimitris Deyannis, Dimitris Karnikis, Giorgos Vasiliadis, Sotiris Ioannidis
CLOUD5
2020 The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws
abstract
In this paper, we focus on authentication and authorization flaws in web apps that enable partial or full access to user accounts. Specifically, we develop a novel fully automated black-box auditing framework that analyzes web apps by exploring their susceptibility to various cookie-hijacking attacks while also assessing their deployment of pertinent security mechanisms (e.g., HSTS). Our modular framework is driven by a custom browser automation tool developed to transparently offer fault-tolerance during extended interactions with web apps. We use our framework to conduct the first automated large-scale study of cookie-based account hijacking in the wild. As our framework handles every step of the auditing process in a completely automated manner, including the challenging process of account creation, we are able to fully audit 25K domains. Our framework detects more than 10K domains that expose authentication cookies over unencrypted connections, and over 5K domains that do not protect authentication cookies from JavaScript access while also embedding third party scripts that execute in the first party's origin. Our system also automatically identifies the privacy loss caused by exposed cookies and detects 9,324 domains where sensitive user data can be accessed by attackers (e.g., address, phone number, password). Overall, our study demonstrates that cookie-hijacking is a severe and prevalent threat, as deployment of even basic countermeasures (e.g., cookie security flags) is absent or incomplete, while developers struggle to correctly deploy more demanding mechanisms.
Kostas Drakonakis, Sotiris Ioannidis, Iasonas Polakis
CCS2
2020 TrustAV: Practical and Privacy Preserving Malware Analysis in the Cloud
abstract
While the number of connected devices is constantly growing, we observe an increased incident rate of cyber attacks that target user data. Typically, personal devices contain the most sensitive information regarding their users, so there is no doubt that they can be a very valuable target for adversaries. Typical defense solution to safeguard user devices and data, are based in malware analysis mechanisms. To amortize the processing and maintenance overheads, the outsourcing of network inspection mechanisms to the cloud has become very popular recently. However, the majority of such cloud-based applications usually offers limited privacy preserving guarantees for data processing in third-party environments. In this work, we propose TrustAV, a practical cloud-based malware detection solution destined for a plethora of device types. TrustAV is able to offload the processing of malware analysis to a remote server, where it is executed entirely inside, hardware supported, secure enclaves. By doing so, TrustAV is capable to shield the transfer and processing of user data even in untrusted environments with tolerable performance overheads, ensuring that private user data are never exposed to malicious entities or honest-but-curious providers. TrustAV also utilizes various techniques in order to overcome performance overheads, introduced by the Intel SGX technology, and reduce the required enclave memory --a limiting factor for malware analysis executed in secure enclave environments-- offering up to 3x better performance.
Dimitris Deyannis, Eva Papadogiannaki, Giorgos Kalivianakis, Giorgos Vasiliadis, Sotiris Ioannidis
CODASPY5
2020 Mobility-Aware Beam Steering in Metasurface-Based Programmable Wireless Environments
abstract
Programmable wireless environments (PWEs) utilize electromagnetic metasurfaces to transform wireless propagation into a software-controlled resource. In this work we study the effects of user device mobility on the efficiency of PWEs. An analytical model is proposed, which describes the potential misalignment between user-emitted waves and the active PWE configuration, and can constitute the basis for studying queuing problems in PWEs. Subsequently, a novel, beam steering approach is proposed which can effectively mitigate the misalignment effects. Ray-tracing-based simulations evaluate the proposed scheme.
Christos Liaskos, Shuai Nie 0002, Ageliki Tsioliaridou, Andreas Pitsillides, Sotiris Ioannidis, Ian F. Akyildiz
ICASSP5
2020 Pythia: Scheduling of Concurrent Network Packet Processing Applications on Heterogeneous Devices
abstract
Modern commodity computing systems are composed of a number of heterogeneous processing units, each one with its own unique performance and energy characteristics. However, the majority of current network packet processing frameworks targets only one device (either the CPU or an accelerator), leaving the remaining computational resources underutilized or even idle. In this paper, we propose an adaptive scheduling approach for network packet processing applications that exploits any heterogeneous architecture that can be found in a commodity high-end hardware setup. Our scheduler not only distributes the workloads to the appropriate devices in the system to achieve the desired performance results, but also enables the multiplexing of diverse, concurrently executed network packet processing applications, eliminating the interference effects introduced at run-time. The evaluation results show that our scheduler is able to tackle any interference in the shared hardware resources as well to respond quickly to dynamic fluctuations (e.g., application overloads, traffic bursts, infrastructural changes, etc.) that may occur at real time.
Giannis Giakoumakis, Eva Papadogiannaki, Giorgos Vasiliadis, Sotiris Ioannidis
NetSoft4
2020 On Architectural Support for Instruction Set Randomization
abstract
Instruction Set Randomization (ISR) is able to protect against remote code injection attacks by randomizing the instruction set of each process. Thereby, even if an attacker succeeds to inject code, it will fail to execute on the randomized processor. The majority of existing ISR implementations is based on emulators and binary instrumentation tools that unfortunately: (i) incur significant runtime performance overheads, (ii) limit the ease of deployment, (iii) cannot protect the underlying operating system kernel, and (iv) are vulnerable to evasion attempts that bypass the ISR protection itself. To address these issues, we present the design and implementation of ASIST, an architecture with both hardware and operating system support for ISR. ASIST uses our extended SPARC processor that is mapped onto a FPGA board and runs our modified Linux kernel to support the new features. In particular, before executing a new user-level process, the operating system loads its randomization key into a newly defined register, and the modified processor decodes the process’s instructions with this key. Besides that, ASIST uses a separate randomization key for the operating system to protect the base system against attacks that exploit kernel vulnerabilities to run arbitrary code with elevated privileges. Our evaluation shows that ASIST can transparently protect both user-land applications and the operating system kernel from code injection and code reuse attacks, with about 1.5% runtime overhead when using simple encryption schemes, such as XOR and Transposition; more secure ciphers, such as AES, even though they are much more complicated for mapping them to hardware, they are still within acceptable margins,with approximately 10% runtime overhead, when efficiently leveraging the spatial locality of code through modern instruction cache configurations.
George Christou, Giorgos Vasiliadis, Vassilis Papaefstathiou, Antonis Papadogiannakis, Sotiris Ioannidis
ACM Trans. Archit. Code Optim.5
2020 End-to-End Wireless Path Deployment With Intelligent Surfaces Using Interpretable Neural Networks
abstract
Intelligent surfaces exert deterministic control over the wireless propagation phenomenon, enabling novel capabilities in performance, security and wireless power transfer. Such surfaces come in the form of rectangular tiles that cascade to cover large surfaces such as walls, ceilings or building facades. Each tile is addressable and can receive software commands from a controller, manipulating an impinging electromagnetic wave upon it by customizing its reflection direction, focus, polarization and phase. A new problem arises concerning the orchestration of a set of tiles towards serving end-to-end communication objectives. Towards that end, we propose a novel intelligent surface networking algorithm based on interpretable neural networks. Tiles are mapped to neural network nodes and any tile line-of-sight connectivity is expressed as a neural network link. Tile wave manipulation functionalities are captured via geometric reflection with virtually rotatable tile surface norm, thus being able to tunable distribute power impinging upon a tile over the corresponding neural network links, with the corresponding power parts acting as the link weights. A feedforward/backpropagate process optimizes these weights to match ideal propagation outcomes (normalized network power outputs) to wireless user emissions (normalized network power inputs). An interpretation process translates these weights to the corresponding tile wave manipulation functionalities.
Christos Liaskos, Shuai Nie 0002, Ageliki Tsioliaridou, Andreas Pitsillides, Sotiris Ioannidis, Ian F. Akyildiz
IEEE Trans. Commun.5
2020 MobileTrust: Secure Knowledge Integration in VANETs
abstract
Vehicular Ad hoc NETworks (VANET) are becoming popular due to the emergence of the Internet of Things and ambient intelligence applications. In such networks, secure resource sharing functionality is accomplished by incorporating trust schemes. Current solutions adopt peer-to-peer technologies that can cover the large operational area. However, these systems fail to capture some inherent properties of VANETs, such as fast and ephemeral interaction, making robust trust evaluation of crowdsourcing challenging. In this article, we propose MobileTrust—a hybrid trust-based system for secure resource sharing in VANETs. The proposal is a breakthrough in centralized trust computing that utilizes cloud and upcoming 5G technologies to provide robust trust establishment with global scalability. The ad hoc communication is energy-efficient and protects the system against threats that are not countered by the current settings. To evaluate its performance and effectiveness, MobileTrust is modelled in the SUMO simulator and tested on the traffic features of the small-size German city of Eichstatt. Similar schemes are implemented in the same platform to provide a fair comparison. Moreover, MobileTrust is deployed on a typical embedded system platform and applied on a real smart car installation for monitoring traffic and road-state parameters of an urban application. The proposed system is developed under the EU-founded THREAT-ARREST project, to provide security, privacy, and trust in an intelligent and energy-aware transportation scenario, bringing closer the vision of sustainable circular economy.
George Hatzivasilis, Othonas Sultatos, Sotiris Ioannidis, George Spanoudakis, Vasilios Katos, Giorgos Demetriou
ACM Trans. Cyber Phys. Syst.3
2020 The Seven Deadly Sins of the HTML5 WebAPI: A Large-scale Study on the Risks of Mobile Sensor-based Attacks
abstract
Modern smartphone sensors can be leveraged for providing novel functionality and greatly improving the user experience. However, sensor data can be misused by privacy-invasive or malicious entities. Additionally, a wide range of other attacks that use mobile sensor data have been demonstrated; while those attacks have typically relied on users installing malicious apps, browsers have eliminated that constraint with the deployment of HTML5 WebAPI. In this article, we conduct a comprehensive evaluation of the multifaceted threat that mobile web browsing poses to users by conducting a large-scale study of mobile-specific HTML5 WebAPI calls across more than 183K of the most popular websites. We build a novel testing infrastructure consisting of actual smartphones on top of a dynamic Android app analysis framework, allowing us to conduct an end-to-end exploration. In detail, our system intercepts and tracks data access in real time, from the WebAPI JavaScript calls down to the Android system calls. Our study reveals the extent to which websites are actively leveraging the WebAPI for collecting sensor data, with 2.89% of websites accessing at least one sensor. To provide a comprehensive assessment of the risks of this emerging practice, we create a taxonomy of sensor-based attacks from prior studies and present an in-depth analysis by framing our collected data within that taxonomy. We find that 1.63% of websites can carry out at least one attack and emphasize the need for a standardized policy across all browsers and the ability for users to control what sensor data each website can access.
Michalis Diamantaris, Francesco Marcantoni, Sotiris Ioannidis, Iasonas Polakis
ACM Trans. Priv. Secur.3
2019 Towards Configurable Cloud Application Security
abstract
Security solutions for cloud applications usually exploit security tools as is by utilising their default configuration. On one hand, this can lead to a waste of resources. On the other hand, it can also lead to not properly protecting the different application components based on their diverse security requirements. To this end, this paper proposes a security solution for cross-cloud applications which is configurable according to the flexible configuration specification given by the devops. Such a specification conforms to a certain UML-based meta-model and is independent of the underlying security tools exploited. In this way, devops can enable to produce a varied security level per each application component that better suits its security requirements. We demonstrate the suitability of our solution through an evaluation showcasing that it can lead to reduced resource consumption without compromising the security of the components that it protects.
Kyriakos Kritikos, Manos Papoutsakis, Sotiris Ioannidis, Kostas Magoutis
CCGRID3
2019 REAPER: Real-time App Analysis for Augmenting the Android Permission System
abstract
Android's app ecosystem relies heavily on third-party libraries as they facilitate code development and provide a steady stream of revenue for developers. However, while Android has moved towards a more fine-grained run time permission system, users currently lack the required resources for deciding whether a specific permission request is actually intended for the app itself or is requested by possibly dangerous third-party libraries. In this paper we present Reaper, a novel dynamic analysis system that traces the permissions requested by apps in real time and distinguishes those requested by the app's core functionality from those requested by third-party libraries linked with the app. We implement a sophisticated UI automator and conduct an extensive evaluation of our system's performance and find that Reaper introduces negligible overhead, rendering it suitable both for end users (by integrating it in the OS) and for deployment as part of an official app vetting process. Our study on over 5K popular apps demonstrates the large extent to which personally identifiable information is being accessed by libraries and highlights the privacy risks that users face. We find that an impressive 65% of the permissions requested do not originate from the core app but are issued by linked third-party libraries, 37.3% of which are used for functionality related to ads, tracking, and analytics. Overall, Reaper enhances the functionality of Android's run time permission model without requiring OS or app modifications, and provides the necessary contextual information that can enable users to selectively deny permissions that are not part of an app's core functionality.
Michalis Diamantaris, Elias P. Papadopoulos, Evangelos P. Markatos, Sotiris Ioannidis, Iasonas Polakis
CODASPY4
2019 The CE-IoT Framework for Green ICT Organizations: The interplay of CE-IoT as an enabler for green innovation and e-waste management in ICT
abstract
The growth of the global middle class provokes significant increment in product consumption. As the available resources are limited, Circular Economy (CE) raises as a promising initiative towards the sustainable development. Except from the traditional approaches of reusing or recycling products, the current trend utilizes modern computer technologies and involves a data-driven aspect. The Internet of Things (IoT) is the main enabler for the integration of CE with technology. This paper proposes a framework for implementing the cooperative vision of CE and IoT. Via this solution, a pilot system is developed in a medium size telecommunication company for administrating the lifecycle of the deployed electronic equipment and the management of the related supply chains. Mechanisms and devices are maintained/repaired/fabricated in a regular basis, green computing techniques are efficiently applied, and the productive period is prolonged. When the business upgrades the system, the retired counterparts can be sold in start-ups or gifted in third-world countries. The overall approach extends the working period of the well-maintained electronic assets not only for the examined business but for the collaborating organizations as well. Recycling companies can then trace this supply chain and the assets' status in order to define their investment strategy at the end-consumer, contributing in the reduction of the electronic waste problem in the third-world.
George Hatzivasilis, Nikos Christodoulakis, Christos Tzagkarakis, Sotiris Ioannidis, Giorgos Demetriou, Konstantinos Fysarakis, Marios Panayiotou
DCOSS4
2019 Review of Security and Privacy for the Internet of Medical Things (IoMT)
abstract
Day-by-day modern circular economy (CE) models gain ground and penetrate the traditional business sectors. The Internet of Medical Things (IoMT) is the main enabler for this interplay of CE with healthcare. Novel services, like remote sensing, assisting of elder people, and e-visit, enhance the people's health and convenience, while reducing the per-patient cost for the medical institutions. However, the rise of mobile, wearable, and telemedicine solutions means that security can no longer be examined within the neat, physical walls as it was considered before. The problem for a healthcare system further increases as the Bring Your Own Device (BYOD) reality, affects the way that the health services are accommodated nowadays. Both patients and healthcare staff utilize their personal devices (e.g. smart phones or tablets) in order to access, deliver, and process medical data. As the IoMT is materialized and the underlying devices maintain so valuable data, they become a popular target for ransomware and other attacks. In the CE case, the problem is further emerging as several of these assets can be used over-and-over by many actuators. However, medical users and vendors are less aware of the underlying vulnerabilities and spend less on the IoMT security. Nevertheless, the risk from exploiting vulnerabilities can be drastically reduced when the known and relevant controls are placed. This paper presents an overview of the core security and privacy controls that must be deployed in modern IoMT settings in order to safeguard the involved users and stakeholders. The overall approach can be considered as a best-practices guide towards the safe implementation of IoMT systems, featuring CE.
George Hatzivasilis, Othonas Sultatos, Sotiris Ioannidis, Christos V. Verikoukis, Giorgos Demetriou, Christos Iraklis Tsatsoulis
DCOSS3
2019 Organizing Network Management Logic with Circular Economy Principles
abstract
The traditional cycle of industrial products has been linear since its inception. Raw resources are acquired, processed, distributed, used and ultimately disposed of. This linearity has led to a dangerously low efficiency degree in resource use, and has brought forth serious concerns for the viability of our natural ecosystem. Circular economy is introducing a circular workflow for the lifetime of products. It generalizes the disposal phase, reconnecting it to manufacturing, distribution and end-use, thus limiting true deposition to the environment. This process has not been extended so far to software. Nonetheless, the development of software follows the same phases, and also entails the use-and waste-of considerable resources. This include human effort, as well as human and infrastructure sustenance products such as food, traveling and energy. This paper introduces circular economy principles to the software development, and particularly to network management logic and security. It employs a recently proposed concept-the Socket Store-which is an online store distributing end-user network logic in modular form. The Store modules act as mediators between the end-user network logic and the network resources. It is shown that the Socket Store can implement all circular economy principles to the software life-cycle, with considerable gains in resource waste.
Christos Liaskos, Ageliki Tsioliaridou, Sotiris Ioannidis
DCOSS3
2019 Joint Compressed Sensing and Manipulation of Wireless Emissions with Intelligent Surfaces
abstract
Programmable, intelligent surfaces can manipulate electromagnetic waves impinging upon them, producing arbitrarily shaped reflection, refraction and diffraction, to the benefit of wireless users. Moreover, in their recent form of HyperSurfaces, they have acquired inter-networking capabilities, enabling the Internet of Material Properties with immense potential in wireless communications. However, as with any system with inputs and outputs, accurate sensing of the impinging wave attributes is imperative for programming HyperSurfaces to obtain a required response. Related solutions include field nano-sensors embedded within HyperSurfaces to perform minute measurements over the area of the HyperSurface, as well as external sensing systems. The present work proposes a sensing system that can operate without such additional hardware. The novel scheme programs the HyperSurface to perform compressed sensing of the impinging wave via simple one-antenna power measurements. The HyperSurface can jointly be programmed for both wave sensing and wave manipulation duties at the same time. Evaluation via simulations validates the concept and highlight its promising potential.
Christos Liaskos, Ageliki Tsioliaridou, Alexandros Pitilakis, George Pirialakos, Odysseas Tsilipakos, Anna C. Tasolamprou, Nikolaos V. Kantartzis, Sotiris Ioannidis, Maria Kafesaki, Andreas Pitsillides, Ian F. Akyildiz
DCOSS8
2019 Security Applications of GPUs
Sotiris Ioannidis
ENASE1
2019 Secure Semantic Interoperability for IoT Applications with Linked Data
abstract
Interoperability stands for the capacity of a system to interact with the units of another entity. Although it is quite easy to accomplish this within the products of the same brand, it is not facile to provide compatibility for the whole spectrum of the Internet-of-Things (IoT) and the Linked Data (LD) world. Currently, the different applications and devices operate in their own cloud/platform, without supporting sufficient interaction with different vendor-products. As it concerns the meaning of data, which is the main focus of this paper, semantics can settle commonly agreed information models and ontologies for the used terms. However, as there are several ontologies for describing each distinct 'Thing', we need Semantic Mediators (SMs) in order to perform common data mapping across the various utilized formats (i.e. XML or JSON) and ontology alignment (e.g. resolve conflicts). Our goal is to enable end-to-end vertical compatibility and horizontal cooperation at all levels (field/network/backend). Moreover, the implication of security must be taken into consideration as the unsafe adoption of semantic technologies exposes the linking data and the user's privacy, issues that are neglected by the majority of the semantic-web studies. A motivating example of smart sensing is described along with a preliminary implementation on real heterogeneous devices. Two different IoT platforms are integrating in the case study, detailing the main SM features. The proposed setting is secure, scalable, and the overall overhead is sufficient for runtime operation, while providing significant advances over state-of-the-art solutions.
George Hatzivasilis, Lukasz Ciechomski, Othonas Sultatos, Darko Anicic, Arne Bröring, Konstantinos Fysarakis, George Spanoudakis, Eftychia Lakka, Sotiris Ioannidis, Mirko Falchetto
GLOBECOM9
2019 Please Forget Where I Was Last Summer: The Privacy Risks of Public Location (Meta)Data
Kostas Drakonakis, Panagiotis Ilia, Sotiris Ioannidis, Iasonas Polakis
NDSS3
2019 Master of Web Puppets: Abusing Web Browsers for Persistent and Stealthy Computation
Panagiotis Papadopoulos, Panagiotis Ilia, Michalis Polychronakis, Evangelos P. Markatos, Sotiris Ioannidis, Giorgos Vasiliadis
NDSS5
2019 TALON: An Automated Framework for Cross-Device Tracking Detection
Kostas Solomos, Panagiotis Ilia, Sotiris Ioannidis, Nicolas Kourtellis
RAID3
2019 Towards Specification of a Software Architecture for Cross-Sectoral Big Data Applications
abstract
The proliferation of Big Data applications puts pressure on improving and optimizing the handling of diverse datasets across different domains. Among several challenges, major difficulties arise in data-sensitive domains like banking, telecommunications, etc., where strict regulations make very difficult to upload and experiment with real data on external cloud resources. In addition, most Big Data research and development efforts aim to address the needs of IT experts, while Big Data analytics tools remain unavailable to non-expert users to a large extent. In this paper, we report on the work-in-progress carried out in the context of the H2020 project I-BiDaaS (Industrial-Driven Big Data as a Self-service Solution) which aims to address the above challenges. The project will design and develop a novel architecture stack that can be easily configured and adjusted to address cross-sectoral needs, helping to resolve data privacy barriers in sensitive domains, and at the same time being usable by non-experts. This paper discusses and motivates the need for Big Data as a self-service, reviews the relevant literature, and identifies gaps with respect to the challenges described above. We then present the I-BiDaaS paradigm for Big Data as a self-service, position it in the context of existing references, and report on initial work towards the conceptual specification of the I-BiDaaS software architecture.
Ioannis Arapakis, Yolanda Becerra 0001, Omer Boehm, George Bravos, Vasilis Chatzigiannakis, Cesare Cugnasco, Giorgos Demetriou, Iliada Eleftheriou, Julien-Etienne Mascolo, Lidija Fodor, Sotiris Ioannidis, Dusan Jakovetic, Leonidas Kallipolitis, Evangelia Kavakli, Despina Kopanaki, Nicolas Kourtellis, Mario Maawad Marcos, Ramon Martín de Pozuelo, Nemanja Milosevic, Giuditta Morandi, Enric Pages, Gerald H. Ristow, Rizos Sakellariou, Raül Sirvent, Srdjan Skrbic, Ilias Spais, Giorgos Vasiliadis, Michael Vinov
SERVICES11
2019 A Large-scale Study on the Risks of the HTML5 WebAPI for Mobile Sensor-based Attacks
abstract
Smartphone sensors can be leveraged by malicious apps for a plethora of different attacks, which can also be deployed by malicious websites through the HTML5 WebAPI. In this paper we provide a comprehensive evaluation of the multifaceted threat that mobile web browsing poses to users, by conducting a large-scale study of mobile-specific HTML5 WebAPI calls used in the wild. We build a novel testing infrastructure consisting of actual smartphones on top of a dynamic Android app analysis framework, allowing us to conduct an end-to-end exploration. Our study reveals the extent to which websites are actively leveraging the WebAPI for collecting sensor data, with 2.89% of websites accessing at least one mobile sensor. To provide a comprehensive assessment of the potential risks of this emerging practice, we create a taxonomy of sensor-based attacks from prior studies, and present an in-depth analysis by framing our collected data within that taxonomy. We find that 1.63% of websites could carry out at least one of those attacks. Our findings emphasize the need for a standardized policy across browsers and the ability for users to control what sensor data each website can access.
Francesco Marcantoni, Michalis Diamantaris, Sotiris Ioannidis, Iasonas Polakis
WWW3
2019 A novel communication paradigm for high capacity and security via programmable indoor wireless environments in next generation wireless systems
Christos Liaskos, Shuai Nie 0002, Ageliki Tsioliaridou, Andreas Pitsillides, Sotiris Ioannidis, Ian F. Akyildiz
Ad Hoc Networks5
2019 On the Network-Layer Modeling and Configuration of Programmable Wireless Environments
abstract
Programmable wireless environments enable the software-defined propagation of waves within them, yielding exceptional performance. Several building-block technologies have been implemented and evaluated at the physical layer in the past. The present work contributes a network-layer solution to configure such environments for multiple users and objectives, and for any underlying physical-layer technology. Supported objectives include any combination of Quality of Service and power transfer optimization, eavesdropping, and Doppler effect mitigation, in multi-cast or uni-cast settings. In addition, a graph-based model of programmable environments is proposed, which incorporates core physical observations and efficiently separates physical and networking concerns. The evaluation takes place in a specially developed simulation tool, and in a variety of environments, validating the model and reaching insights into the user capacity of programmable environments.
Christos Liaskos, Ageliki Tsioliaridou, Shuai Nie 0002, Andreas Pitsillides, Sotiris Ioannidis, Ian F. Akyildiz
IEEE/ACM Trans. Netw.5
2018 A Large-scale Analysis of Content Modification by Open HTTP Proxies
Giorgos Tsirantonakis, Panagiotis Ilia, Sotiris Ioannidis, Elias Athanasopoulos, Michalis Polychronakis
NDSS3
2018 Realizing Wireless Communication Through Software-Defined HyperSurface Environments
abstract
Wireless communication environments are unaware of the ongoing data exchange efforts within them. Moreover, their effect on the communication quality is intractable in all but the simplest cases. The present work proposes a new paradigm, where indoor scattering becomes software-defined and, subsequently, optimizable across wide frequency ranges. Moreover, the controlled scattering can surpass natural behavior, exemplary overriding Snell's law, reflecting waves towards any custom angle (including negative ones). Thus, path loss and multi-path fading effects can be controlled and mitigated. The core technology of this new paradigm are metasurfaces, planar artificial structures whose effect on impinging electromagnetic waves is fully defined by their macro-structure. The present study contributes the software-programmable wireless environment model, consisting of several HyperSurface tiles controlled by a central, environment configuration server. HyperSurfaces are a novel class of metasurfaces whose structure and, hence, electromagnetic behavior can be altered and controlled via a software interface. Multiple networked tiles coat indoor objects, allowing fine-grained, customizable reflection, absorption or polarization overall. A central server calculates and deploys the optimal electromagnetic interaction per tile, to the benefit of communicating devices. Realistic simulations using full 3D ray-tracing demonstrate the groundbreaking potential of the proposed approach in 2.4GHz and 60GHz frequencies.
Christos Liaskos, Shuai Nie 0002, Ageliki Tsioliaridou, Andreas Pitsillides, Sotiris Ioannidis, Ian F. Akyildiz
WOWMOM5
2018 Network Topology Effects on the Detectability of Crossfire Attacks
abstract
New strains of distributed denial-of-service (DDoS) attacks have exhibited potential to disconnect communication networks, even cutting off entire countries from the Internet. The “crossfire” is a new, indirect DDoS link-flooding attack, which masks itself as natural congestion, making it very hard to counter. Several studies have proposed online attack detection schemes, whose efficiency has been shown to vary in different network topologies. However, the topology/detection relation has been studied qualitatively, without formal proof or quantification metric. This paper is motivated by the fact that network topology changes are generally expensive and slow. Therefore, network designers should be provided with means of evaluating the effects of topology modifications to the attack detection efficiency. This paper fills this gap by contributing a formal proof for the topology-detection efficiency relation, as well as a novel off-line metric that quantifies it. Full attack prototypes are implemented and evaluated in real-Internet topologies, validating the analytical findings. It is shown that the novel metric expresses the topology-detection relation efficiently, while existing and widely used metrics do not constitute good choices for this task.
Christos Liaskos, Sotiris Ioannidis
IEEE Trans. Inf. Forensics Secur.2
2017 Reveal: Fine-grained Recommendations in Online Social Networks
abstract
Content selection in social networks is driven by numerous extraneous factors that can result in the loss of content of interest. In this paper we present Reveal, a fine-grained recommender system for social networks, designed to recommend media content posted by the user's friends. The intuition is to leverage the abundance of pre-existing information and identify overlapping user interests in specific sub-categories. While our system is intended as a component of the social network, we develop a proof-of-concept implementation for Facebook and experimentally evaluate the effectiveness of our approach.
Markos Aivazoglou, Orestis Roussos, Sotiris Ioannidis, Dimitris Spiliotopoulos, Iasonas Polakis
ASONAM3
2017 SAMPAC: Socially-Aware collaborative Multi-Party Access Control
abstract
According to the current design of content sharing services, such as Online Social Networks (OSNs), typically (i) the service provider has unrestricted access to the uploaded resources and (ii) only the user uploading the resource is allowed to define access control permissions over it. This results in a lack of control from other users that are associated, in some way, with that resource. To cope with these issues, in this paper, we propose a privacy-preserving system that allows users to upload their resources encrypted, and we design a collaborative multi-party access control model allowing all the users related to a resource to participate in the specification of the access control policy. Our model employs a threshold-based secret sharing scheme, and by exploiting users' social relationships, sets the trusted friends of the associated users responsible to partially enforce the collective policy. Through replication of the secret shares and delegation of the access control enforcement role, our model ensures that resources are timely available when requested. Finally, our experiments demonstrate that the performance overhead of our model is minimal and that it does not significantly affect user experience.
Panagiotis Ilia, Barbara Carminati, Elena Ferrari 0001, Paraskevi Fragopoulou, Sotiris Ioannidis
CODASPY5
2017 No Sugar but All the Taste! Memory Encryption Without Architectural Support
Panagiotis Papadopoulos, Giorgos Vasiliadis, Giorgos Christou, Evangelos P. Markatos, Sotiris Ioannidis
ESORICS (2)5
2017 The Socket Store: An app model for the application-network interaction
abstract
A developer of mobile or desktop applications is responsible for implementing the network logic of his software. Nonetheless: i) Developers are not network specialists, while pressure for emphasis on the visible application parts places the network logic out of the coding focus. Moreover, computer networks undergo evolution at paces that developers may not follow. ii) From the network resource provider point of view, marketing novel services and involving a broad audience is also challenge for the same reason. Moreover, the objectives of end-user networking logic are neither clear nor uniform. This constitutes the central optimization of network resources an additional challenge. As a solution to these problems, we propose the Socket Store. The Store is a marketplace containing end-user network logic in modular form. The Store modules act as intelligent mediators between the end-user and the network resources. Each module has a clear, specialized objective, such as connecting two clients over the Internet while avoiding transit networks suspicious for eavesdropping. The Store is populated and peer-reviewed by network specialists, whose motive is the visibility, practical applicability and monetization potential of their work. A developer first purchases access to a given socket module. Subsequently, he incorporates it to his applications under development, obtaining state-of-the-art performance with trivial coding burden. A full Store prototype is implemented and a critical data streaming module is evaluated as a driving case.
Christos Liaskos, Ageliki Tsioliaridou, Sotiris Ioannidis
ISCC3
2017 The Long-Standing Privacy Debate: Mobile Websites vs Mobile Apps
abstract
The vast majority of online services nowadays, provide both a mobile friendly website and a mobile application to their users. Both of these choices are usually released for free, with their developers, usually gaining revenue by allowing advertisements from ad networks to be embedded into their content. In order to provide more personalized and thus more effective advertisements, ad networks usually deploy pervasive user tracking, raising this way significant privacy concerns. As a consequence, the users do not have to think only their convenience before deciding which choice to use while accessing a service: web or app, but also which one harms their privacy the least.
Elias P. Papadopoulos, Michalis Diamantaris, Panagiotis Papadopoulos, Thanasis Petsas, Sotiris Ioannidis, Evangelos P. Markatos
WWW5
2017 Efficient Software Packet Processing on Heterogeneous and Asymmetric Hardware Architectures
abstract
Heterogeneous and asymmetric computing systems are composed by a set of different processing units, each with its own unique performance and energy characteristics. Still, the majority of current network packet processing frameworks targets only a single device (the CPU or some accelerator), leaving the rest processing resources unused and idle. In this paper, we propose an adaptive scheduling approach that supports the heterogeneous and asymmetric hardware, tailored for network packet processing applications. Our scheduler is able to respond quickly to dynamic performance fluctuations that occur at real time, such as traffic bursts, application overloads, and system changes. The experimental results show that our system is able to match the peak throughput of a diverse set of packet processing applications, while consuming up to $3.5\times$ less energy.
Eva Papadogiannaki, Lazaros Koromilas, Giorgos Vasiliadis, Sotiris Ioannidis
IEEE/ACM Trans. Netw.4
2017 Design and Implementation of a Stateful Network Packet Processing Framework for GPUs
abstract
Graphics processing units (GPUs) are a powerful platform for building the high-speed network traffic processing applications using low-cost hardware. The existing systems tap the massively parallel architecture of GPUs to speed up certain computationally intensive tasks, such as cryptographic operations and pattern matching. However, they still suffer from significant overheads due to critical-path operations that are still being carried out on the CPU, and redundant inter-device data transfers. In this paper, we present GASPP, a programmable network traffic processing framework tailored to modern graphics processors. GASPP integrates optimized GPU-based implementations of a broad range of operations commonly used in the network traffic processing applications, including the first purely GPU-based implementation of network flow tracking and TCP stream reassembly. GASPP also employs novel mechanisms for tackling the control flow irregularities across SIMT threads, and for sharing the memory context between the network interfaces and the GPU. Our evaluation shows that GASPP can achieve multigigabit traffic forwarding rates even for complex and computationally intensive network operations, such as stateful traffic classification, intrusion detection, and packet encryption. Especially when consolidating multiple network applications on the same system, GASPP achieves up to 16.2× speedup compared with different monolithic GPU-based implementations of the same applications.
Giorgos Vasiliadis, Lazaros Koromilas, Michalis Polychronakis, Sotiris Ioannidis
IEEE/ACM Trans. Netw.4
2016 Investigating the complete corpus of referendum and elections tweets
abstract
Today, a considerable proportion of the public political discourse that proceeds nationwide elections is happening through Online Social Networks. Through analyzing this content, we can discover the major themes that prevailed during the discussion, investigate the temporal variation of positive and negative sentiment and examine the semantic proximity of these themes. According to existing studies, the results of similar tasks are heavily dependent on the quality and completeness of dictionaries for linguistic preprocessing, entity discovery and sentiment analysis. Additionally, noise reduction is achieved with methods for sarcasm detection and correction. Here we report on the application of these methods on the complete corpus of tweets regarding two local electoral events of worldwide impact: the Greek referendum of 2015 and the subsequent legislative elections. To this end, we compiled novel dictionaries for sentiment and entity detection for the Greek language tailored to these events. We subsequently performed volume analysis, sentiment analysis and sarcasm correction. Results showed that there was a strong anti-austerity sentiment accompanied with a critical view on European and Greek political actions.
Despoina Antonakaki, Dimitris Spiliotopoulos, Christos V. Samaras, Sotiris Ioannidis, Paraskevi Fragopoulou
ASONAM4
2016 HCFI: Hardware-enforced Control-Flow Integrity
abstract
Control-flow hijacking is the principal method for code-reuse techniques like Return-oriented Programming (ROP) and Jump-oriented Programming (JOP). For defending against such attacks, the community has proposed Control-flow Integrity (CFI), a technique capable of preventing exploitation by verifying that every (indirect) control-flow transfer points to a legitimate address. Enabling CFI in real systems is not straightforward, since in many cases the actual Control-flow Graph (CFG) of a program can be only approximated. Even in the case that there is perfect knowledge of the CFG, ensuring that all return instructions will return to their actual call sites, without employing a shadow stack, is questionable. On the other hand, the community has expressed concerns related to significant overheads stemming from enabling a shadow stack.
Nick Christoulakis, George Christou, Elias Athanasopoulos, Sotiris Ioannidis
CODASPY4
2016 A deployable routing system for nanonetworks
abstract
Nanonetworks comprise numerous wireless nodes, assembled at micro-to-nano scale. The unique manufacturing challenges and cost considerations of these networks make for minimal complexity solutions at all network layers. From a networking aspect, packet retransmissions should be kept minimal, while ensuring communication between any two nanonodes. In addition, assigning unique addresses to nanonodes is not straightforward, since it can entail a prohibitively high number of packet exchanges. Thus, efficient data routing is considered an open issue in nanonetworking. The present paper proposes a routing system which can be dynamically deployed within a nanonetwork. Static, dense topologies with numerous, identical nodes are examined. These attributes are especially important in the context of recently proposed applications of nanonetworks. The proposed scheme incurs a trivial setup overhead and requires integer processing capabilities only. Once deployed, it operates efficiently, inducing lower packet retransmission rates than related schemes.
Christos Liaskos, Ageliki Tsioliaridou, Sotiris Ioannidis, Nikolaos V. Kantartzis, Andreas Pitsillides
ICC3
2016 Usability Evaluation of Accessible Complex Graphs
Dimitris Spiliotopoulos, Despoina Antonakaki, Sotiris Ioannidis, Paraskevi Fragopoulou
ICCHP (1)3
2016 GRIM: Leveraging GPUs for Kernel Integrity Monitoring
Lazaros Koromilas, Giorgos Vasiliadis, Elias Athanasopoulos, Sotiris Ioannidis
RAID4
2015 Face/Off: Preventing Privacy Leakage From Photos in Social Networks
abstract
The capabilities of modern devices, coupled with the almost ubiquitous availability of Internet connectivity, have resulted in photos being shared online at an unprecedented scale. This is further amplified by the popularity of social networks and the immediacy they offer in content sharing. Existing access control mechanisms are too coarse-grained to handle cases of conflicting interests between the users associated with a photo; stories of embarrassing or inappropriate photos being widely accessible have become quite common. In this paper, we propose to rethink access control when applied to photos, in a way that allows us to effectively prevent unwanted individuals from recognizing users in a photo. The core concept behind our approach is to change the granularity of access control from the level of the photo to that of a user's personally identifiable information (PII). In this work, we consider the face as the PII. When another user attempts to access a photo, the system determines which faces the user does not have the permission to view, and presents the photo with the restricted faces blurred out. Our system takes advantage of the existing face recognition functionality of social networks, and can interoperate with the current photo-level access control mechanisms. We implement a proof-of-concept application for Facebook, and demonstrate that the performance overhead of our approach is minimal. We also conduct a user study to evaluate the privacy offered by our approach, and find that it effectively prevents users from identifying their contacts in 87.35% of the restricted photos. Finally, our study reveals the misconceptions about the privacy offered by existing mechanisms, and demonstrates that users are positive towards the adoption of an intuitive, straightforward access control mechanism that allows them to manage the visibility of their face in published photos.
Panagiotis Ilia, Iasonas Polakis, Elias Athanasopoulos, Federico Maggi 0001, Sotiris Ioannidis
CCS5
2015 Powerslave: Analyzing the Energy Consumption of Mobile Antivirus Software
Iasonas Polakis, Michalis Diamantaris, Thanasis Petsas, Federico Maggi 0001, Sotiris Ioannidis
DIMVA5
2015 GPU-Disasm: A GPU-Based X86 Disassembler
Evangelos Ladakis, Giorgos Vasiliadis, Michalis Polychronakis, Sotiris Ioannidis, Georgios Portokalidis
ISC4
2015 The Devil is in the Constants: Bypassing Defenses in Browser JIT Engines
Michalis Athanasakis, Elias Athanasopoulos, Michalis Polychronakis, Georgios Portokalidis, Sotiris Ioannidis
NDSS5
2015 Revealing the relationship network behind link spam
abstract
Accessing the large volume of information that is available on the Web is more important than ever before. Search engines are the primary means to help users find the content they need. To suggest the most closely related and the most popular Web pages for a user's query, search engines assign a ranking to each Web page, which typically increases with the number and ranking of other Web sites that link to this page. However, link spammers have developed several techniques to exploit this algorithm and improve the ranking of their Web pages. These techniques are commonly based on underground forums for collaborative link exchange; building a relationship network among spammers to favor their Web pages in search engine results. In this study, we provide a systematic analysis of the spam link exchange performed through 15 Search Engine Optimization (SEO) forums. We design a system, which is able to capture the activity of link spammers in SEO forums, identify spam link exchange, and visualize the link spam ecosystem. The outcomes of this study shed light on a different aspect of link spamming that is the collaboration among spammers.
Apostolis Zarras, Antonis Papadogiannakis, Sotiris Ioannidis, Thorsten Holz
PST3
2014 Efficient software packet processing on heterogeneous and asymmetric hardware architectures
abstract
Heterogeneous and asymmetric computing systems are composed by a set of different processing units, each with its own unique performance and energy characteristics. Still, the majority of current network packet processing frameworks targets only a single device (the CPU or some accelerator), leaving other processing resources idle. In this paper, we propose an adaptive scheduling approach that supports heterogeneous and asymmetric hardware, tailored for network packet processing applications. Our scheduler is able to respond quickly to dynamic performance fluctuations that occur at real-time, such as traffic bursts, application overloads and system changes. The experimental results show that our system is able to match the peak throughput of a diverse set of packet processing workloads, while consuming up to 3.5x less energy.
Lazaros Koromilas, Giorgos Vasiliadis, Ioannis Manousakis, Sotiris Ioannidis
ANCS4
2014 Faces in the Distorting Mirror: Revisiting Photo-based Social Authentication
abstract
In an effort to hinder attackers from compromising user accounts, Facebook launched a form of two-factor authentication called social authentication (SA), where users are required to identify photos of their friends to complete a log-in attempt. Recent research, however, demonstrated that attackers can bypass the mechanism by employing face recognition software. Here we demonstrate an alternative attack. that employs image comparison techniques to identify the SA photos within an offline collection of the users' photos.
Iasonas Polakis, Panagiotis Ilia, Federico Maggi 0001, Marco Lancini, Georgios Kontaxis, Stefano Zanero, Sotiris Ioannidis, Angelos D. Keromytis
CCS7
2014 PixelVault: Using GPUs for Securing Cryptographic Operations
abstract
Protecting the confidentiality of cryptographic keys in the event of partial or full system compromise is crucial for containing the impact of attacks. The Heartbleed vulnerability of April 2014, which allowed the remote leakage of secret keys from HTTPS web servers, is an indicative example. In this paper we present PixelVault, a system for keeping cryptographic keys and carrying out cryptographic operations exclusively on the GPU, which allows it to protect secret keys from leakage even in the event of full system compromise. This is possible by exposing secret keys only in GPU registers, keeping PixelVault's critical code in the GPU instruction cache, and preventing any access to both of them from the host. Due to the non-preemptive execution mode of the GPU, an adversary that has full control of the host cannot tamper with PixelVault's GPU code, but only terminate it, in which case all sensitive data is lost. We have implemented a PixelVault-enabled version of the OpenSSL library that allows the protection of existing applications with minimal modifications. Based on the results of our evaluation, PixelVault not only provides secure key storage using commodity hardware, but also significantly speeds up the processing throughput of cryptographic operations for server applications.
Giorgos Vasiliadis, Elias Athanasopoulos, Michalis Polychronakis, Sotiris Ioannidis
CCS4
2014 AndRadar: Fast Discovery of Android Applications in Alternative Markets
Martina Lindorfer, Stamatis Volanis, Alessandro Sisto 0001, Matthias Neugschwandtner, Elias Athanasopoulos, Federico Maggi 0001, Christian Platzer, Stefano Zanero, Sotiris Ioannidis
DIMVA9
2014 Flying Memcache: Lessons Learned from Different Acceleration Strategies
abstract
Distributed key-value and always-in-memory store is employed by large and demanding services, such as Facebook and Amazon. It is apparent that generic implementations of such caches can not meet the needs of every application, therefore further research for optimizing or speeding up cache operations is required. In this paper, we present an incremental optimization strategy for accelerating the most popular key-value store, namely memcached. First we accelerate the computational unit by utilizing commodity GPUs, which offer a significant performance increase on the CPU-bound part of memcached, but only moderate performance increase under intensive I/O. We then proceed to improve I/O performance by replacing TCP with a fast UDP implementation in user-space. Putting it all together, GPUs for computational operations instead of CPUs, and UDP for communication instead of TCP, we are able to experimentally achieve 20 Gbps line-rate, which significantly outperforms the original implementation of memcached.
Dimitris Deyannis, Lazaros Koromilas, Giorgos Vasiliadis, Elias Athanasopoulos, Sotiris Ioannidis
SBAC-PAD5
2014 Privacy Risks from Public Data Sources
Zacharias Tzermias, Vassilis Prevelakis, Sotiris Ioannidis
SEC3
2014 GASPP: A GPU-Accelerated Stateful Packet Processing Framework
Giorgos Vasiliadis, Lazaros Koromilas, Michalis Polychronakis, Sotiris Ioannidis
USENIX ATC4
2013 ASIST: architectural support for instruction set randomization
abstract
Code injection attacks continue to pose a threat to today's computing systems, as they exploit software vulnerabilities to inject and execute arbitrary, malicious code. Instruction Set Randomization (ISR) is able to protect a system against remote machine code injection attacks by randomizing the instruction set of each process. This way, the attacker will inject invalid code that will fail to execute on the randomized processor. However, all the existing implementations of ISR are based on emulators and binary instrumentation tools that (i) incur a significant runtime performance overhead, (ii) limit the ease of deployment of ISR, (iii) cannot protect the underlying operating system kernel, and (iv) are vulnerable to evasion attempts trying to bypass ISR protection.
Antonis Papadogiannakis, Laertis Loutsis, Vassilis Papaefstathiou, Sotiris Ioannidis
CCS4
2012 All your face are belong to us: breaking Facebook's social authentication
abstract
Two-factor authentication is widely used by high-value services to prevent adversaries from compromising accounts using stolen credentials. Facebook has recently released a two-factor authentication mechanism, referred to as Social Authentication, which requires users to identify some of their friends in randomly selected photos. A recent study has provided a formal analysis of social authentication weaknesses against attackers inside the victim's social circles. In this paper, we extend the threat model and study the attack surface of social authentication in practice, and show how any attacker can obtain the information needed to solve the challenges presented by Facebook. We implement a proof-of-concept system that utilizes widely available face recognition software and cloud services, and evaluate it using real public data collected from Facebook. Under the assumptions of Facebook's threat model, our results show that an attacker can obtain access to (sensitive) information for at least 42% of a user's friends that Facebook uses to generate social authentication challenges. By relying solely on publicly accessible information, a casual attacker can solve 22% of the social authentication tests in an automated fashion, and gain a significant advantage for an additional 56% of the tests, as opposed to just guessing. Additionally, we simulate the scenario of a determined attacker placing himself inside the victim's social circle by employing dummy accounts. In this case, the accuracy of our attack greatly increases and reaches 100% when 120 faces per friend are accessible by the attacker, even though it is very accurate with as little as 10 faces.
Iasonas Polakis, Marco Lancini, Georgios Kontaxis, Federico Maggi 0001, Sotiris Ioannidis, Angelos D. Keromytis, Stefano Zanero
ACSAC5
2012 Digging up social structures from documents on the web
abstract
We collected more than ten million Microsoft Office documents from public websites, analyzed the metadata stored in each document and extracted information related to social activities. Our analysis revealed the existence of exactly identified cliques of users that edit, revise and collaborate on industrial and military content. We also examined cliques in documents downloaded from Fortune-500 company websites. We constructed their graphs and measured their properties. The graphs contained many connected components and presented social properties. The a priori knowledge of a company's social graph may significantly assist an adversary to launch targeted attacks, such as targeted advertisements and phishing emails. Our study demonstrates the privacy risks associated with metadata by cross-correlating all members identified in a clique with users of Twitter. We show that it is possible to match authors collaborating in the creation of a document with Twitter accounts. To the best of our knowledge, this study is the first to identify individuals and create social cliques solely based on information derived from document metadata. Our study raises major concerns about the risks involved in privacy leakage due to document metadata.
Eleni Gessiou, Stamatis Volanis, Elias Athanasopoulos, Evangelos P. Markatos, Sotiris Ioannidis
GLOBECOM5
2012 Towards a Universal Data Provenance Framework Using Dynamic Instrumentation
Eleni Gessiou, Vasilis Pappas, Elias Athanasopoulos, Angelos D. Keromytis, Sotiris Ioannidis
SEC5
2011 MIDeA: a multi-parallel intrusion detection architecture
abstract
Network intrusion detection systems are faced with the challenge of identifying diverse attacks, in extremely high speed networks. For this reason, they must operate at multi-Gigabit speeds, while performing highly-complex per-packet and per-flow data processing. In this paper, we present a multi-parallel intrusion detection architecture tailored for high speed networks. To cope with the increased processing throughput requirements, our system parallelizes network traffic processing and analysis at three levels, using multi-queue NICs, multiple CPUs, and multiple GPUs. The proposed design avoids locking, optimizes data transfers between the different processing units, and speeds up data processing by mapping different operations to the processing units where they are best suited. Our experimental evaluation shows that our prototype implementation based on commodity off-the-shelf equipment can reach processing speeds of up to 5.2 Gbit/s with zero packet loss when analyzing traffic in a real network, whereas the pattern matching engine alone reaches speeds of up to 70 Gbit/s, which is an almost four times improvement over prior solutions that use specialized hardware.
Giorgos Vasiliadis, Michalis Polychronakis, Sotiris Ioannidis
CCS3
2011 we.b: the web of short urls
abstract
Short URLs have become ubiquitous. Especially popular within social networking services, short URLs have seen a significant increase in their usage over the past years, mostly due to Twitter's restriction of message length to 140 characters. In this paper, we provide a first characterization on the usage of short URLs. Specifically, our goal is to examine the content short URLs point to, how they are published, their popularity and activity over time, as well as their potential impact on the performance of the web.
Demetres Antoniades, Iasonas Polakis, Georgios Kontaxis, Elias Athanasopoulos, Sotiris Ioannidis, Evangelos P. Markatos, Thomas Karagiannis
WWW5
2010 D(e|i)aling with VoIP: Robust Prevention of DIAL Attacks
Alexandros Kapravelos, Iasonas Polakis, Elias Athanasopoulos, Sotiris Ioannidis, Evangelos P. Markatos
ESORICS4
2010 GrAVity: A Massively Parallel Antivirus Engine
Giorgos Vasiliadis, Sotiris Ioannidis
RAID2
2009 HoneyLab: Large-Scale Honeypot Deployment and Resource Sharing
abstract
Honeypots are valuable tools for detecting and analyzing malicious activity on the Internet. Successful and time-critical detection of such activity often depends on large-scale deployment. However, commercial organizations usually do not share honeypot data, and large, open honeypot initiatives only provide read-only alert feeds. As a result, while large and resourceful organizations can afford the high cost of this technology, smaller security firms and security researchers are fundamentally constrained. We propose and build a shared infrastructure for deploying and monitoring honeypots, called HoneyLab, that is similar in spirit to PlanetLab. With an overlay and distributed structure of address space and computing resources, HoneyLab increases coverage and accelerates innovation among security researchers as well as security industry experts relying on honeypot-based attack detection technology. Unlike current honeypot infrastructures, HoneyLab allows security firms and security researchers to deploy their own honeypot services, instrumentation code, and detection algorithms, dispensing the need for setting up a separate honeypot infrastructure whenever a new attack detection method needs to be deployed or tested.
W. Y. Chin, Evangelos P. Markatos, Spiros Antonatos, Sotiris Ioannidis
NSS4
2009 Regular Expression Matching on Graphics Hardware for Intrusion Detection
Giorgos Vasiliadis, Michalis Polychronakis, Spiros Antonatos, Evangelos P. Markatos, Sotiris Ioannidis
RAID5
2008 Antisocial Networks: Turning a Social Network into a Botnet
Elias Athanasopoulos, A. Makridakis, Spiros Antonatos, Demetres Antoniades, Sotiris Ioannidis, Kostas G. Anagnostakis, Evangelos P. Markatos
ISC5
2008 Compromising Anonymity Using Packet Spinning
Vasilis Pappas, Elias Athanasopoulos, Sotiris Ioannidis, Evangelos P. Markatos
ISC3
2008 Gnort: High Performance Network Intrusion Detection Using Graphics Processors
Giorgos Vasiliadis, Spiros Antonatos, Michalis Polychronakis, Evangelos P. Markatos, Sotiris Ioannidis
RAID5
2007 Distributed Privacy-Preserving Policy Reconciliation
abstract
Organizations use security policies to regulate how they share and exchange information, e.g., under what conditions data can be exchanged, what protocols are to be used, who is granted access, etc. Agreement on specific policies is achieved though policy reconciliation, where multiple parties, with possibly different policies, exchange their security policies, resolve differences, and reach a consensus. Current solutions for policy reconciliation do not take into account the privacy concerns of reconciliating parties. This paper addresses the problem of preserving privacy during security policy reconciliation. We introduce new protocols that meet the privacy requirements of the organizations and allow parties to find a common policy rule which maximizes their individual preferences.
Ulrike Meyer, Susanne Wetzel, Sotiris Ioannidis
ICC3
2006 Robust Reactions to Potential Day-Zero Worms Through Cooperation and Validation
Kostas G. Anagnostakis, Sotiris Ioannidis, Angelos D. Keromytis, Michael B. Greenwald
ISC2
2006 Preserving TCP Connections Across Host Address Changes
Vassilis Prevelakis, Sotiris Ioannidis
ISC2
2006 Privacy as an Operating System Service
Sotiris Ioannidis, Stelios Sidiroglou-Douskos, Angelos D. Keromytis
HotSec1
2006 Flexible network monitoring with FLAME
Kostas G. Anagnostakis, Michael B. Greenwald, Sotiris Ioannidis, Jonathan M. Smith
Comput. Networks3
2002 Efficient packet monitoring for network management
abstract
Network monitoring is a vital part of modern network infrastructure management. Existing techniques either present a restricted view of network behavior and state, or do not efficiently scale to higher network speeds and heavier monitoring workloads. We present a novel architecture for programmable packet-level network monitoring that addresses these shortcomings. Our approach allows users to customize the monitoring function at the lowest possible level of abstraction to suit a wide range of monitoring needs: we use operating system mechanisms that result in a programming environment providing a high degree of flexibility, retaining fine-grained control over security, and minimizing the associated performance overheads. We present an implementation of this architecture as well as a set of experimental applications.
Kostas G. Anagnostakis, Sotiris Ioannidis, Stefan Miltchev, Michael B. Greenwald, Jonathan M. Smith, John Ioannidis
NOMS2
2000 Implementing a distributed firewall
abstract
Conventional rewalls rely on topology restrictions and controlled network entry points to enforce traÆc ltering.Furthermore, a rewall cannot lter traÆc it does not see, so, eectively, e v eryone on the protected side is trusted.While this model has worked well for small to medium size networks, networking trends such as increased connectivity, higher line speeds, extranets, and telecommuting threaten to make it obsolete.To address the shortcomings of traditional rewalls, the concept of a \distributed rewall" has been proposed.In this scheme, security policy is still centrally de ned, but enforcement is left up to the individual endpoints.IPsec may be used to distribute credentials that express parts of the overall network policy.Alternately, these credentials may be obtained through out-of-band means.In this paper, we present the design and implementation of a distributed rewall using the KeyNote trust management system to specify, distribute, and resolve policy, and OpenBSD, an open source UNIX operating system.
Sotiris Ioannidis, Angelos D. Keromytis, Steven M. Bellovin, Jonathan M. Smith
CCS1