Sokratis K. Katsikas

dblp:36/6241 · DBLP profile ↗
← Back
70ranked-venue papers
8as first author
26since 2021 · last 2025
0000-0003-2966-9683ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 47 · 3 first-author · 20 since 2021Computer networks · 7 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-authorArtificial intelligence and machine learning · 5 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-authorSystems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 RePAD3: Advanced Lightweight Adaptive Anomaly Detection for Univariate Time Series of Any Pattern
Ming-Chang Lee, Jia-Chun Lin, Sokratis K. Katsikas
ICAART (2)3
2025 Investigating the Effectiveness of Zero-Trust Architecture for Satellite Cybersecurity
Masrur Masqub Utsash, Georgios Kavallieratos, Konstantinos Antonakopoulos, Sokratis K. Katsikas
ICISSP (2)4
2025 Cracks in the chain: A technical analysis of real-life supply chain security incidents
abstract
As Industry 5.0 drives greater digitalization and interconnectivity, supply chains have become vital to global commerce, ensuring the seamless flow of goods, services, and data. However, this reliance has also swelled the attack surface, rendering supply chains a prime target for evildoers. Meanwhile, the inherent complexity of supply chain ecosystems prevents defenders from fully applying contemporary security controls promptly and effectively. Clearly, the combination of these hindering factors has led to some of the most severe cybersecurity incidents of the past years. This study is the first to our knowledge that undertakes a comprehensive technical analysis of reported supply chain security incidents. Our analysis is done both from offensive and defensive prisms, leveraging well-established cybersecurity frameworks and guidelines, namely, the ATT&CK MITRE knowledge base matrix and the NIST SP 800-161, respectively. Furthermore, to consolidate our findings and facilitate future research initiatives, we compiled a fundamental dataset that can be used as the basis for automated analysis and potential integration with cybersecurity workflows. The key observations of a 33-incident analysis through the lens of an ATT&CK MITRE- and NIST SP 800-161-based taxonomies we propose can be wrapped up into two key points. First, the attack surface continues to expand, following an upward spiral due to the mushrooming of tactics and techniques that can facilitate the early or late stages of attacks, highlighting their complexity, sophistication, and widespread impact. Second, our findings underscore the necessity of a multifaceted approach to strengthening supply chain resilience. This includes implementing robust cybersecurity controls, comprehensive risk assessment methodologies, and transparent collaboration among suppliers, customers, and vendors to ensure adherence to state-of-the-art cybersecurity best practices.
Vyron Kampourakis, Georgios Kavallieratos, Vasileios Gkioulos, Sokratis K. Katsikas
Comput. Secur.4
2025 A step-by-step definition of a reference architecture for cyber ranges
abstract
Being on the advent of Industry 5.0, organizations have been progressively incorporating information technology into their formerly air-gapped operational technology architectures. This coalescence has nevertheless amplified the attack surface, ringing the bells of preparedness. In this direction, Cyber Ranges (CRs) have cropped up as a valuable and attractive solution, providing a diverse perspective on reinforcing the overall cybersecurity stance. However, there exists a significant literature gap in attempts to define a complete approach for CR design, development, evaluation, and operation as per the up-to-date guidelines. To address this shortcoming, this work introduces the first to our knowledge overarching, fine-grained reference architecture for CR. This is done by adopting a three-step, systematic methodology. First, we scrutinize contemporary guidelines to extract an abstract architectural model that structurally entrenches the foundations of CR reference architecture. Then, we percolate and pinpoint common functionalities and capabilities of existing CRs, towards delineating the functional and informational aspects of the reference architecture. Finally, we devise an evaluation formula that approximates the conformance of a CR with the state-of-the-art. Through the latter step, we impart a unified means of identifying the most appropriate components to implement the structural, functional, and informational aspects of a CR. Overall, this work can be seen as an attempt towards CR unification and standardization, therefore it is anticipated to serve as a basis and point of reference for multiple stakeholders at varying levels.
Vyron Kampourakis, Vasileios Gkioulos, Sokratis K. Katsikas
J. Inf. Secur. Appl.3
2024 Deployment of Cybersecurity Controls in the Norwegian Industry 4.0
abstract
Cybersecurity threats and attacks on Industry are increasing, and the outcome of a successful cyber-attack can be severe for organizations. A successful cyber-attack on an Industry where Cyber-Physical Systems are present can be particularly devastating as such systems could cause harm to people and the environment if they malfunction. This paper reports on the results of a survey investigating what security measures organizations implement within the industry to strengthen their security posture. The survey instrument used has been developed using the NIST Special Publication "Guide to Operational Technology" and contained 70 questions to determine the level of security controls deployed within the Norwegian Industry. The results show that the average usage of the different security controls is 63%, and 53% of the organizations have a security controls usage of 60% or more. The most used security control is backup of critical software, whereas the two least used are specific-OT cybersecurity training and response planning. Both are highlighted as areas for improvement. Dedicated OT security standards have not been found to influence the level of security controls used. However, employees within an organization following a dedicated security standard have higher cybersecurity knowledge.
Kristian Kannelønning, Sokratis K. Katsikas
ARES2
2024 A Blockchain-based Multi-Factor Honeytoken Dynamic Authentication Mechanism
abstract
The evolution of authentication mechanisms in ensuring secure access to systems has been crucial for mitigating vulnerabilities and enhancing system security. However, despite advancements in two-factor authentication (2FA) and multi-factor authentication (MFA), authentication mechanisms remain weak in system security, particularly when individuals accessing critical systems are involved. In response to this challenge, we propose a novel blockchain-based multi-factor dynamic authentication mechanism (BMFA) that integrates honeytoken technology to enhance security. Our proposed mechanism leverages Ethereum blockchain technology and smart contracts to provide a decentralized and robust authentication framework. By incorporating honeytokens into smart contracts, we introduce a dynamic layer of security that continuously adapts to prevent potential attacks. Our evaluation demonstrates that our BMFA mechanism effectively addresses various security challenges, including brute force attacks, man-in-the-middle attacks, and smart contract vulnerabilities, while providing robust protection against unauthorized access. Our findings emphasise the efficacy of the BMFA mechanism in enhancing system security and mitigating evolving threats in authentication processes for next-generation critical industrial control systems.
Vassilis Papaspirou, Ioanna Kantzavelou, Yagmur Yigit, Leandros Maglaras, Sokratis K. Katsikas
ARES5
2024 NEWSROOM: Towards Automating Cyber Situational Awareness Processes and Tools for Cyber Defence
abstract
Cyber Situational Awareness (CSA) is an important element in both cyber security and cyber defence to inform processes and activities on strategic, tactical, and operational level. Furthermore, CSA enables informed decision making. The ongoing digitization and interconnection of previously unconnected components and sectors equally affects the civilian and military sector. In defence, this means that the cyber domain is both a separate military domain as well as a cross-domain and connecting element for the other military domains comprising land, air, sea, and space. Therefore, CSA must support perception, comprehension, and projection of events in the cyber space for persons with different roles and expertise. This paper introduces NEWSROOM, a research initiative to improve technologies, methods, and processes specifically related to CSA in cyber defence. For this purpose, NEWSROOM aims to improve methods for attacker behavior classification, cyber threat intelligence (CTI) collection and interaction, secure information access and sharing, as well as human computer interfaces (HCI) and visualizations to provide persons with different roles and expertise with accurate and easy to comprehend mission- and situation-specific CSA. Eventually, NEWSROOM’s core objective is to enable informed and fast decision-making in stressful situations of military operations. The paper outlines the concept of NEWSROOM and explains how its components can be applied in relevant application scenarios.
Markus Wurzenberger, Stephan Krenn, Max Landauer, Florian Skopik, Cora Lisa Perner, Jarno Lötjönen, Jani Päijänen, Georgios Gardikis, Nikos Alabasis, Liisa Sakerman, Kristiina Omri, Juha Röning, Kimmo Halunen, Vincent Thouvenot, Martin Weise, Andreas Rauber, Vasileios Gkioulos, Sokratis K. Katsikas, Luigi Sabetta, Jacopo Bonato, Rocío Ortíz, Daniel Navarro, Nikolaos Stamatelatos, Ioannis Avdoulas, Rudolf Mayer, Andreas Ekelhart, Ioannis Giannoulakis, Emmanouil Kafetzakis, Antonello Corsi, Ulrike Lechner, Corinna Schmitt
ARES18
2024 Impact of Recurrent Neural Networks and Deep Learning Frameworks on Real-Time Lightweight Time Series Anomaly Detection
Ming-Chang Lee, Jia-Chun Lin, Sokratis K. Katsikas
ICICS (1)3
2024 Perceptions of Cyber Security Risk of the Norwegian Advanced Metering Infrastructure
Eirik Lien, Karl Magnus Grønning Bergh, Sokratis K. Katsikas
ICISSP3
2024 AIS Data Analysis: Reality in the Sea of Echos
abstract
The global trend of progressive digitalisation of the world is affecting many industries, including the maritime transport sector. Electronic navigation equipment used on board modern ships has undoubtedly decreased naval accidents over the years, but these devices may suffer from cyber security vulnerabilities. The Automatic Identification System (AIS) is a well-studied navigational system with considerable weaknesses. Many publications discuss different methods for detecting anomalies in AIS. Still, validation is often missing or based on synthetic data because of the lack of publicly available AIS datasets, collected from real environments. To satisfy the need for such a dataset, we collected AIS data for six months with a receiver installed near the shore. This paper presents both the dataset and the analysis of the collected data from different perspectives; highlighting the differences between the expected and realistic features of AIS data. In our research we identified several anomalies regarding the AIS transmission propagation and periodicity, and the ship’s positional data. We believe that our realistic dataset, with its labelled anomalies, will serve as an ideal testbed for developing AIS-related anomaly-detection systems.
Gábor Visky, Alexander Rohl, Sokratis K. Katsikas, Olaf Maennel
LCN3
2024 Hacking on the High Seas: How Automated Reverse-Engineering Can Assist Vulnerability Discovery of a Proprietary Communication Protocol
abstract
The digitalisation of the world is a global trend affecting many industries, including the maritime transport sector. Electronic navigational equipment aboard modern ships has undoubtedly decreased naval accidents, but these devices may suffer from cybersecurity vulnerabilities. One such vector, is its reliance on a great number of protocols for communication. Currently there is limited awareness of the security strengths and weaknesses of maritime protocols, because of the manual-reverse-engineering cost due to their proprietary nature. However, we substantiate that advances in automated protocol reverse-engineering are effectively lowering this cost. Our paper analyses a proprietary protocol, widely used in naval equipment. This protocol was reverse engineered through manual and automated techniques, revealing the advantages and drawbacks of both. Our results show that statistical automated protocol reverse-engineering techniques were sufficient to discover the relevant protocol fields. We introduce the disclosed communication structure and its vulnerabilities, which are both verified by the success of rudimentary attacks. The disclosed protocol, by manual and automated techniques, could also aid intrusion detection (and prevention) system development for maritime operational technology systems, to help vendors avoid the identified vulnerabilities during system design and implementation.
Gábor Visky, Alexander Rohl, Risto Vaarandi, Sokratis K. Katsikas, Olaf Maennel
LCN4
2024 GAD: A Real-Time Gait Anomaly Detection System with Online Adaptive Learning
Ming-Chang Lee, Jia-Chun Lin, Sokratis K. Katsikas
SEC3
2024 Authentication of underwater assets
abstract
Secure digital wireless communication in the acoustic domain has become a key issue as underwater operations shift towards employing a heterogeneous mix of robotic assets and as the security of digital systems becomes challenged across all domains. At the same time, a proliferation of underwater signal coding and physical layer options are delivering greater bandwidth and flexibility, but mostly without the standards necessary for interoperability. We address here an essential requirement for security, namely a confirmation of asset identities also known as authentication. We propose, implement, verify and validate an authentication protocol based on the first digital underwater communications standard. Our scheme is applicable primarily to AUVs operating around offshore oil and gas facilities, but also to other underwater devices that may in the future have acoustic modems. It makes communication including command and control significantly more secure, and provides a foundation for the development of more sophisticated security mechanisms.
Bálint Z. Téglásy, Emil Wengle, John R. Potter, Sokratis K. Katsikas
Comput. Networks4
2024 Exploring the effects of RNNs and deep learning frameworks on real-time, lightweight, adaptive time series anomaly detection
abstract
Summary Real‐time, lightweight, adaptive time series anomaly detection is increasingly critical in cybersecurity, industrial control, finance, healthcare, and many other domains due to its capability to promptly process time series and detect anomalies without requiring extensive computation resources. While numerous anomaly detection approaches have emerged recently, they generally employ a single type of recurrent neural network (RNN) and are implemented using a single type of deep learning framework. The impacts of using various RNN types across different deep learning frameworks on the performance of these approaches remain unclear due to a lack of comprehensive evaluations. In this article, we aim to investigate the impact of different RNN variants and deep learning frameworks on real‐time, lightweight, and adaptive time series anomaly detection. We reviewed several state‐of‐the‐art anomaly detection approaches and implemented a representative approach using several RNN variants supported by three popular deep learning frameworks. A thorough evaluation was conducted to analyze the detection accuracy, time efficiency, and resource consumption of each implementation using four real‐world, open‐source time series datasets. The results show that RNN variants and deep learning frameworks have a significant impact. Therefore, it is crucial to carefully select appropriate RNN variants and deep learning frameworks for the implementation.
Ming-Chang Lee, Jia-Chun Lin, Sokratis K. Katsikas
Concurr. Comput. Pract. Exp.3
2024 Ethical hardware reverse engineering for securing the digital supply chain in critical infrastructure
abstract
Purpose This paper aims to discuss the ethical aspects of hardware reverse engineering (HRE) and propose an ethical framework for HRE when used to mitigate cyber risks of the digital supply chain of critical infrastructure operators. Design/methodology/approach A thorough review and analysis of existing relevant literature was performed to establish the current state of knowledge in the field. Ethical frameworks proposed for other areas/disciplines and identified pertinent ethical principles have been used to inform the proposed framework’s development. Findings The proposed framework provides actionable guidance to security professionals engaged with such activities to support them in assessing whether an HRE project conforms to ethical principles. Recommendations on action needed to complement the framework are also proposed. According to the proposed framework, reverse engineering is neither unethical nor illegal if performed honourably. Collaboration with vendors and suppliers at an industry-wide level is critical for appropriately endorsing the proposed framework. Originality/value To the best of the authors’ knowledge, no ethical framework currently guides cybersecurity research, far less of cybersecurity vulnerability research and reverse engineering.
Arne Roar Nygård, Sokratis K. Katsikas
Inf. Comput. Secur.2
2023 Leveraging Hardware Reverse Engineering to Improve the Cyber Security and Resilience of the Smart Grid
abstract
Cyber-attacks on digital supply chains are rising, and Critical Infrastructures (CIs) such as the Smart Grid are prime targets. There is increasing evidence that vendors, service providers, and outsourced IT -providers are at equal risk of being used by malicious actors to gain a foothold in the power grid - delivering exploits that can disrupt electric power delivery and severely damage our economy. Long digital supply chains with components from different manufacturers require a new approach and methods to ensure the needed security in Critical Infrastructures. Hardware Reverse Engineering (HRE), commonly used for verifying the security of an embedded system, includes disassembling to analyse, test, and document the functionality and vulnerability of the target system. This paper proposes leveraging HRE for improving both the security and the resilience of the power infrastructure against cyber-attacks enabled through the digital supply chain, by organising HRE activities, and how this can be organized within the equipment procurement process in a Distribution System Operator (DSO).
Arne Roar Nygård, Sokratis K. Katsikas
SECRYPT2
2023 Honey-list based authentication protocol for industrial IoT swarms
Mohamed A. El-Zawawy, Pallavi Kaliyar, Mauro Conti, Sokratis K. Katsikas
Comput. Commun.4
2023 A systematic literature review on wireless security testbeds in the cyber-physical realm
abstract
The Cyber-Physical System (CPS) lies in the core of Industry 4.0, accelerating the convergence of formerly barricaded operational technology systems with modern information technology ones. Nevertheless, the increased connectivity in terms of both wired and wireless links and associated attack surfaces that comes along, requires higher security for safeguarding critical industrial systems and manufacturing lines from cyberattacks. In this rapidly evolving ecosystem, security testbeds have emerged as a versatile, cost-effective solution for investigating potential attack vectors and devising appropriate countermeasures, without putting the real system at risk. The present work seeks to address a prominent literature gap, namely, the lack of a systematic review regarding the use of wireless-oriented security testbeds in CPS. We contribute an overarching, manifold review on this topic from 2016 onward, examining the various literature works from diverse angles, namely, the wireless technologies used, the implemented attacks, the employed security controls, and more. The analysis is done on a per-sector basis, including water and wastewater systems, healthcare, transportation, agriculture, energy, maritime, unmanned aircraft systems, and others. Finally yet importantly, we discuss key takeaways, open issues, and challenges. The key observations of our analysis, including almost 50 articles, can be wrapped up into two salient points: on the one hand, wireless technologies are increasingly penetrating into the CPS domain as an orthogonal, versatile solution to their wired counterparts, but on the other, they widen the window of opportunity for threat actors targeting wireless links. In this context, testbed thoroughness and security as a trade-off seem to be of major importance, alongside a modular, possibly sector-neutral reference architecture that overarches the peculiarities of CPS. Overall, to our knowledge, this work provides the first full-fledged survey on the use of wireless-oriented security testbeds in CPS, and it is therefore anticipated to serve as a groundwork and touchstone for several stakeholders at different levels.
Vyron Kampourakis, Vasileios Gkioulos, Sokratis K. Katsikas
Comput. Secur.3
2023 Understanding situation awareness in SOCs, a systematic literature review
abstract
Situation awareness is shown through human factors research to be a valuable construct to understand and improve how humans perform while operating complex systems in critical environments. Within cyber security one such environment is the Security Operations Center (SOC). With the increasing threat of hybrid warfare, knowledge about situation awareness within SOC environments, where human error or low performance may be detrimental, must be developed. This paper reports on the results of a Systematic Descriptive Literature Review of the current research on situation awareness within SOCs. The goal of the paper is to analyze how situation awareness is understood in the current research. To achieve this goal three aspects of understanding were addressed: Theoretical foundations; levels of conceptualization; and measurement of situation awareness. Theoretical foundations in the literature were assessed by how situation awareness was defined and the presence of references to theoretical models of SA. The results show a clear trend of basing the research on Endsley's three level situation awareness model; this model has been developed into a domain specific formulation called “Cyber Situation Awareness”. Some parts of the literature, particularly in research aimed at developing tools for improving situation awareness, lack a theoretical foundation; some refer to alternative theoretical foundations of situation awareness like Stanton et al.’s Distributed Situation Awareness. Further, a balance between conceptualizations on the individual, group and system level has been identified. Within research aimed at developing tools for improving situation awareness there are some examples of specialized and precise measurements of situation awareness, but in general the research seems too reliant on indirect measures of situation awareness. The paper concludes with the proposition of connecting the systems-based theoretical perspective of distributed situation awareness into the research, utilizing a systems level conceptualization of situation awareness. This might prove to be a useful bridge between the human cognitive perspective of situation awareness and the development of the complex technical environment of critical importance that SOCs represent.
Håvard Jakobsen Ofte, Sokratis K. Katsikas
Comput. Secur.2
2023 A systematic literature review of how cybersecurity-related behavior has been assessed
abstract
Purpose Cybersecurity attacks on critical infrastructures, businesses and nations are rising and have reached the interest of mainstream media and the public’s consciousness. Despite this increased awareness, humans are still considered the weakest link in the defense against an unknown attacker. Whatever the reason, naïve-, unintentional- or intentional behavior of a member of an organization, the result of an incident can have a considerable impact. A security policy with guidelines for best practices and rules should guide the behavior of the organization’s members. However, this is often not the case. This paper aims to provide answers to how cybersecurity-related behavior is assessed. Design/methodology/approach Research questions were formulated, and a systematic literature review (SLR) was performed by following the recommendations of the Preferred Reporting Items for Systematic Reviews and Meta-Analyses statement. The SLR initially identified 2,153 articles, and the paper reviews and reports on 26 articles. Findings The assessment of cybersecurity-related behavior can be classified into three components, namely, data collection, measurement scale and analysis. The findings show that subjective measurements from self-assessment questionnaires are the most frequently used method. Measurement scales are often composed based on existing literature and adapted by the researchers. Partial least square analysis is the most frequently used analysis technique. Even though useful insight and noteworthy findings regarding possible differences between manager and employee behavior have appeared in some publications, conclusive answers to whether such differences exist cannot be drawn. Research limitations/implications Research gaps have been identified, that indicate areas of interest for future work. These include the development and employment of methods for reducing subjectivity in the assessment of cybersecurity-related behavior. Originality/value To the best of the authors’ knowledge, this is the first SLR on how cybersecurity-related behavior can be assessed. The SLR analyzes relevant publications and identifies current practices as well as their shortcomings, and outlines gaps that future research may bridge.
Kristian Kannelønning, Sokratis K. Katsikas
Inf. Comput. Secur.2
2023 Assessing Cyber Risk in Cyber-Physical Systems Using the ATT&CK Framework
abstract
Autonomous transport is receiving increasing attention, with research and development activities already providing prototype implementations. In this article we focus on Autonomous Passenger Ships (APS) , which are being considered as a solution for passenger transport across urban waterways. The ambition of the authors has been to examine the safety and security implications of such a Cyber Physical System (CPS) , particularly focusing on threats that endanger the passengers and the operational environment of the APS. Accordingly, the article presents a new risk assessment approach based on a Failure Modes Effects and Criticality Analysis (FMECA) that is enriched with selected semantics and components of the MITRE ATT&CK framework, in order to utilize the encoded common knowledge and facilitate the expression of attacks. Then, the proposed approach is demonstrated through conducting a risk assessment for a communication architecture tailored to the requirements of APSs that were proposed in earlier work. Moreover, we propose a group of graph theory-based metrics for estimating the impact of the identified risks. The use of this method has resulted in the identification of risks and their corresponding countermeasures, in addition to identifying risks with limited existing mitigation mechanisms. The benefits of the proposed approach are the comprehensive, atomic, and descriptive nature of the identified threats, which reduce the need for expert judgment, and the granular impact estimation metrics that reduce the impact of bias. All these features are provided in a semi-automated approach to reduce the required effort and collectively are argued to enrich the design-level risk assessment processes with an updatable industry threat model standard, namely ATT&CK.
Ahmed Amro, Vasileios Gkioulos, Sokratis K. Katsikas
ACM Trans. Priv. Secur.3
2022 SoK: Combating threats in the digital supply chain
abstract
Supply chain attacks have been a security concern for many years, and their number and severity are expected to continue to grow in the years to come. In the ICT domain, ensuring the integrity of the supply chain is becoming an essential concern, as components are often manufactured, owned, and operated by different entities across the globe; thus, the cascading effects from a single attack may have a widely propagated impact. This is even more so when components are used in industrial control systems in critical infrastructures. It is therefore important to understand such attacks and attack vectors, the security challenges thereof, and measures to mitigate these; it is also important to educate cybersecurity professionals on these issues. This paper systematizes the security threats and challenges in digital supply chains, as well as relevant cybersecurity measures, discusses the necessary knowledge and skills that cybersecurity professionals should possess to ensure efficient management of the cyber risks in the digital supply chain, and systematizes areas where further research is needed.
Arne Roar Nygård, Sokratis K. Katsikas
ARES2
2022 Cyber Security When IT Meets OT
Sokratis K. Katsikas
SECRYPT1
2022 Reverse Engineering for Thwarting Digital Supply Chain Attacks in Critical Infrastructures: Ethical Considerations
Arne Roar Nygård, Arvind Sharma, Sokratis K. Katsikas
SECRYPT3
2022 Modeling effective cybersecurity training frameworks: A delphi method-based study
abstract
Today, cybersecurity training is commonplace in both large companies and Small & Medium Enterprise (SME). Nonetheless, the effectiveness of many of the current training offerings is put into question by reports of increasing successful cyber-attacks. While a number of models for developing Cybersecurity (CS) training frameworks for industrial personnel or general audience have been proposed, these models often lack consideration for humans aspects of learning (cognitive abilities, learning styles, meta-cognition among others) during development. Additionally, the success of a CS training program highly depends on its ability to engage participants. To develop a CS training framework that is able to motivate participants, we must consider individual-specific factors that can affect the result of training, besides establishing optimal training delivery methods and assessment. For this, in this work we propose a CS training framework based on a revised version of the ADDIE model and more recent research personalised learning theory. The Delphi method was used to both develop and validate our decisions during the development of the training framework model. The results of the decision of the Delphi method have later been compared to recommendations in the literature to create the finalised framework. This work presents two major distinctions from other CS training frameworks models described in the literature. First, the developed model is strongly based in learning theory foundations and takes into consideration differences in learning styles, cognitive abilities and metacognition of individuals, to offer tailored solutions optimized for each group of employees and single individual. Second, the use of the Delphi method and the involvement of experts stakeholders from various sides of academia and industry gave a wide insight into current needs and recommendations for CS training, as well as formal validation for the final development.
Nabin Chowdhury, Sokratis K. Katsikas, Vasileios Gkioulos
Comput. Secur.2
2022 Investigating machine learning attacks on financial time series models
abstract
Machine learning and Artificial Intelligence (AI) already support human decision-making and complement professional roles, and are expected in the future to be sufficiently trusted to make autonomous decisions. To trust AI systems with such tasks, a high degree of confidence in their behaviour is needed. However, such systems can make drastically different decisions if the input data is modified, in a way that would be imperceptible to humans. The field of Adversarial Machine Learning studies how this feature could be exploited by an attacker and the countermeasures to defend against them. This work examines the Fast Gradient Signed Method (FGSM) attack, a novel Single Value attack and the Label Flip attack on a trending architecture, namely a 1-Dimensional Convolutional Neural Network model used for time series classification. The results show that the architecture was susceptible to these attacks and that, in their face, the classifier accuracy was significantly impacted.
Michael Gallagher, Nikolaos Pitropakis, Christos Chrysoulas, Pavlos Papadopoulos, Alexios Mylonas, Sokratis K. Katsikas
Comput. Secur.6
2020 Modelling Shipping 4.0: A Reference Architecture for the Cyber-Enabled Ship
Georgios Kavallieratos, Sokratis K. Katsikas, Vasileios Gkioulos
ACIIDS (2)2
2020 Leveraging Blockchain Technology to Enhance Security and Privacy in the Internet of Things
Sokratis K. Katsikas
ICISSP1
2020 Shipping 4.0: Security Requirements for the Cyber-Enabled Ship
abstract
The cyber-enabled ship (C-ES) is either an autonomous or a remotely controlled vessel which relies on interconnected cyber physical-systems for its operations. Such systems are not well protected against cyberattacks. Considering the criticality of the functions that such systems provide, it is important to address their security challenges, thereby ensuring the ship's safe voyage. In this article, we leverage the maritime architectural framework reference architecture to analyze and describe the environment of the C-ES. We then apply the Secure Tropos methodology to systematically elicit the security requirements of the three most vulnerable cyber-physical systems (CPSs) onboard a C-ES, namely the automatic identification system (AIS), the electronic chart display information system, and the global maritime distress and safety system. The outcome is a set of cyber-security requirements for the C-ES ecosystem in general and these systems in particular.
Georgios Kavallieratos, Vasiliki Diamantopoulou, Sokratis K. Katsikas
IEEE Trans. Ind. Informatics3
2019 White Paper on Industry Experiences in Critical Information Infrastructure Security: A Special Session at CRITIS 2019
Giacomo Assenza, Valerio Cozzani, Francesco Flammini, Nadezhda Gotcheva, Tommy Gustafsson, Anders Hansson, Jouko Heikkilä, Matteo Iaiani, Sokratis K. Katsikas, Minna Nissilä, Gabriele Oliva, Eleni Richter, Maaike Roelofs, Mehdi Saman Azari, Roberto Setola, Wouter Stejin, Alessandro Tugnoli, Dolf Vanderbeek, Lars Westerdahl, Marja Ylönen, Heather Young
CRITIS9
2019 Threat Analysis in Dynamic Environments: The Case of the Smart Home
abstract
The rapid advancement of information and communication technologies has fostered the development and deployment of complex interrelated systems, many of which also present highly dynamic operational characteristics. These are further integrated within highly connected environments such as smart cities, smart homes, and smart cars, continuously adopting new technological developments. In this article, we focus on the smart home environment, as a case study for such ecosystems, where the integration of IoT devices increases the attack surface, evaluating whether existing risk assessment methods can be utilized for the identification and monitoring of risks, while also capturing the dynamic operational aspects. Accordingly, we review existing dynamic risk assessment methodologies and we leverage a smart home reference architecture to identify the security threats of a smart home's physical and communication viewpoints by leveraging the STRIDE methodology and Microsoft's threat modelling tool.
Georgios Kavallieratos, Vasileios Gkioulos, Sokratis K. Katsikas
DCOSS3
2019 A Forensics-by-Design Management Framework for Medical Devices Based on Blockchain
abstract
The Internet of Medical Things (IoMT) provides ubiquitous healthcare services for patient monitoring and treatment. However, the interaction between doctors, patients, healthcare personnel and device manufacturers, with different and often conflicting security and privacy objectives, make such services vulnerable and subject to exploitation. In addition, since parties may require different access levels and the IoMT devices involve different functionalities, access control can be challenging. In this paper, we propose a blockchain-enabled authorization framework for managing both IoMT devices and medical files by creating a distributed chain of custody and health data privacy scheme. The core idea is to build trust domains for the various stakeholders and IoMT devices, in such a way that fine-grain access is enabled by taking into account critical attributes of the IoMT ecosystem such as a) the different roles and capabilities of the IoMT devices and b) their interaction with the users/stakeholders. A private blockchain is used in combination with on-chain smart contracts to allow for a forensics-by-design management architecture with audit trails for integrity and provenance guarantees as well as health data privacy. The private blockchain ecosystem is authenticated by a proof-of-medical-stake consensus mechanism that is tailored for medical applications.
Vangelis Malamas, Thomas K. Dasaklis, Panayiotis Kotzanikolaou, Mike Burmester, Sokratis K. Katsikas
SERVICES5
2018 Implementing a Forms of Consent Smart Contract on an IoT-based Blockchain to promote user trust
abstract
The H2020 European research project Safe-Guarding Home IoT Environments with Personalised Real-time Risk Control (GHOST) aims to develop a cyber-security layer on IoT smart home installations. The proposed system analyses packet-level data flows for building patterns of communications between IoT devices and external entities. To ensure non-repudiation, integrity and authentication of the data captured, they are stored in a Blockchain, a distributed ledger network, as digitally-signed transactions. Since the data can potentially include sensitive user information, it is imperative to promote trust by informing users about the operating principles of the network as well as to request the acceptance of a consent form by them. This paper presents the design and implementation of a Forms of Consent application, a Distributed Application that interacts with a set of Smart Contracts deployed on a private Ethereum network. The application is being developed as part of the GHOST project.
Charalampos S. Kouzinopoulos, Konstantinos M. Giannoutakis, Konstantinos Votis, Dimitrios Tzovaras, Anastasija Collen, Niels A. Nijdam, Dimitri Konstantas, Georgios P. Spathoulas, Pankaj Pandey, Sokratis K. Katsikas
INISTA10
2018 Towards Reliable Integrity in Blacklisting: Facing Malicious IPs in GHOST Smart Contracts
abstract
The European research project GHOST challenges the traditional cyber security solutions for the Internet of Things (IoT) sector by exploiting novel technologies, such as blockchain, to provide resilience and integrity of decision making on the communication exchange in a smart home context. When it comes to novel cyber security solutions for extremely heterogeneous environments like IoT and smart homes, the key focus is typically given to the understanding of network activities and elimination of suspicious traffic. The GHOST project adds an extra dimension to this approach by integrating blockchain technology at its core decision mechanism. On a daily basis, each GHOST installation is encountering malicious behaviour and suspicious IoT communications, where easy information sharing with other installations, as well as decentralised decision making, are mandatory features for the efficient protection of the end-user. GHOST's Smart Contracts (SC) are designed to tackle in an easy, yet productive way, the reporting on suspicious IP addresses which the IoT devices in a smart home are trying to communicate with. Two variations of blacklisting smart contracts are presented in this paper, covering a diverse spectrum of possible attack vectors while closely following the Privacy by Design (PbD) principles. A reputation scoring scheme for malicious IPs reporting is integrated in the SC, uncovering the implementation details on the penalisation of existing entries in case of malicious behaviour of reporting devices.
Georgios P. Spathoulas, Anastasija Collen, Pankaj Pandey, Niels A. Nijdam, Sokratis K. Katsikas, Charalampos S. Kouzinopoulos, Maher Ben Moussa, Konstantinos M. Giannoutakis, Konstantinos Votis, Dimitrios Tzovaras
INISTA5
2018 A Secured and Trusted Demand Response system based on Blockchain technologies
abstract
The aim of the proposed work is to introduce a secure and interoperable Demand Response (DR) management platform that will assist Aggregators (or other relevant Stakeholders involved in DR business scenarios) in their decision making mechanisms over their portfolios of prosumers. This novel architecture incorporates multiple strategies and policies provided from energy market stakeholders, establishing a more modular and future-proof DR solution. By employing an innovative multi-agent decision making system and self-learning algorithms to enable aggregation, segmentation and coordination of several diverse clusters, consisting of supply and demand assets, a fully autonomous design will be delivered. This DR framework is further fortified in terms of data security by not only implementing cutting-edge blockchain infrastructure, but also by making use of Smart Contracts and Decentralized Applications (dApps) which will further secure and facilitate Aggregators-to-Prosumers transactions. The blockchain technologies will be combined with well-known open protocols (i.e. OpenADR) towards also supporting interoperability in terms of information exchange.
Apostolos Tsolakis, Ioannis Moschos, Konstantinos Votis, Dimosthenis Ioannidis, Dimitrios Tzovaras, Pankaj Pandey, Sokratis K. Katsikas, Evangelos Kotsakis, Raúl García-Castro
INISTA7
2017 A nifty collaborative intrusion detection and prevention architecture for Smart Grid ecosystems
Ahmed Patel, Hitham Alhussian 0001, Jens Myrup Pedersen, Bouchaib Bounabat, Joaquim Celestino Jr., Sokratis K. Katsikas
Comput. Secur.6
2017 A structured methodology for deploying log management in WANs
Vasileios Anastopoulos, Sokratis K. Katsikas
J. Inf. Secur. Appl.2
2016 Design of a Log Management Infrastructure Using Meta-Network Analysis
Vasileios Anastopoulos, Sokratis K. Katsikas
TrustBus2
2014 National Policy on Technology Supported Education in Greece
abstract
National policies on technology supported education at all levels in Greece are presented, assessed and put in the context of the corresponding European Union policies.
Sokratis K. Katsikas
ICALT1
2013 The Security of Information Systems in Greek Hospitals
George Aggelinos, Sokratis K. Katsikas
TrustBus2
2013 Enhancing IDS performance through comprehensive alert post-processing
Georgios P. Spathoulas, Sokratis K. Katsikas
Comput. Secur.2
2011 A Mobility and Energy-Aware Hierarchical Intrusion Detection System for Mobile Ad Hoc Networks
Eleni Darra, Christoforos Ntantogian, Christos Xenakis, Sokratis K. Katsikas
TrustBus4
2011 Enhancing SSADM with Disaster Recovery Plan activities
abstract
Purpose The purpose of this paper is to propose the integration of disaster recovery plan (DRP) objects development activities with the activities of the structured system analysis and design method (SSADM) methodology for developing an information system. Design/methodology/approach A step‐by‐step correlation of the SSADM methodology with DRP development activities is performed. By following this approach, a smaller system for emergency operations (DRP) can be designed in parallel with that for normal operations. Furthermore, the implementation of a normal operations system based on the requirements analysis and of an emergency operations system based on the critical business functions may follow the same line of reasoning. Findings The proposed enhancement brings benefits to both the organization and the system developer in terms of expenditure, self‐knowledge, personnel experience, reaction time, time and capability management and increase of competitiveness. Practical implications The practical acceptance of the proposed approach can drastically reduce the time elapsing between the completion of the normal operations system and the design of the emergency operations system. Moreover, the needs of the emergency operations system can be forecasted during the design of the normal operations system. Originality/value The paper extends the SSADM methodology by incorporating DRP development.
George Aggelinos, Sokratis K. Katsikas
Inf. Manag. Comput. Secur.2
2010 A game-based intrusion detection mechanism to confront internal attackers
Ioanna Kantzavelou, Sokratis K. Katsikas
Comput. Secur.2
2010 Reducing false positives in intrusion detection systems
Georgios P. Spathoulas, Sokratis K. Katsikas
Comput. Secur.2
2009 Editorial
Dimitris Gritzalis, Sokratis K. Katsikas
Comput. Secur.2
2008 Modeling Privacy Insurance Contracts and Their Utilization in Risk Management for ICT Firms
Athanasios N. Yannacopoulos, Costas Lambrinoudakis, Stefanos Gritzalis, Stylianos Z. Xanthopoulos, Sokratis K. Katsikas
ESORICS5
2008 A Generic Intrusion Detection Game Model in IT Security
Ioanna Kantzavelou, Sokratis K. Katsikas
TrustBus2
2007 Panel Discussion: Managing Digital Identities - Challenges and Opportunities
Günther Pernul, Marco Casassa Mont, Eduardo B. Fernández, Sokratis K. Katsikas, Alfred Kobsa, Rolf Oppliger
TrustBus4
2006 Effective identification of source code authors using byte-level information
abstract
Source code author identification deals with the task of identifying the most likely author of a computer program, given a set of predefined author candidates. This is usually .based on the analysis of other program samples of undisputed authorship by the same programmer. There are several cases where the application of such a method could be of a major benefit, such as authorship disputes, proof of authorship in court, tracing the source of code left in the system after a cyber attack, etc. We present a new approach, called the SCAP (Source Code Author Profiles) approach, based on byte-level n-gram profiles in order to represent a source code author's style. Experiments on data sets of different programming-language (Java or C++) and varying difficulty (6 to 30 candidate authors) demonstrate the effectiveness of the proposed approach.A comparison with a previous source code authorship identification study based on more complicated information shows that the SCAP approach is language independent and that n-gram author profiles are better able to capture the idiosyncrasies of the source code authors. Moreover, the SCAP approach is able to deal surprisingly well with cases where only a limited amount of very short programs per programmer is available for training. It is also demonstrated that the effectiveness of the proposed model is not affected by the absence of comments in the source code, a condition usually met in cyber-crime cases.
Georgia Frantzeskou, Efstathios Stamatatos, Stefanos Gritzalis, Sokratis K. Katsikas
ICSE4
2006 A Framework for Exploiting Security Expertise in Application Development
Theodoros Balopoulos, Lazaros Gymnopoulos, Maria Karyda 0001, Spyros Kokolakis, Stefanos Gritzalis, Sokratis K. Katsikas
TrustBus6
2005 Adaptive on-line multiple source detection
abstract
In this paper, an adaptive technique is presented for processing the output of a sensor array, which simultaneously estimates the number of sources and their directions of arrival. The method is based on the reformulation of the problem in the time domain, and the use of the adaptive multi-model partitioning algorithm (MMPA). The adaptive algorithm identifies the dimensionality of the problem (number of sources) using a bank of extended Kalman filters (EKF). The method has the ability of successfully tracking changes in the model structure in real time. This means that, for example, variations in the number of emitting sources are successfully detected. Simulation results demonstrate the performance of the proposed method in multiple source detection and DOA estimation.
Vassilios C. Moussas, Spiridon D. Likothanassis, Sokratis K. Katsikas, Assimakis K. Leros
ICASSP (4)3
2003 Special issue: securing computer communications with Public Key Infrastructure
Sokratis K. Katsikas, Ahmed Patel
Comput. Commun.1
2002 Revisiting Legal and Regulatory Requirements for Secure E-Voting
Lilian Mitrou, Dimitris Gritzalis, Sokratis K. Katsikas
SEC3
2000 Evaluating certificate status information mechanisms
abstract
A wide spectrum of certificate revocation mechanisms is currently in use. A number of them have been proposed by standardisation bodies, while some others have originated from academic or private institutions. What is still missing is a systematic and robust framework for the sound evaluation of these mechanisms. We present a mechanism-neutral framework for the evaluation of mechanisms, which collect, process and distribute certificate status information. A detailed demonstration of its exploitation is also provided. The demonstration is mainly based on the evaluation of Certificate Revocation Lists, as well as of the Online Certificate Status Protocol.
John Iliadis, Diomidis Spinellis, Dimitris Gritzalis, Bart Preneel, Sokratis K. Katsikas
CCS5
2000 A Postgraduate Programme on Information and Communication Systems Security
Sokratis K. Katsikas
SEC1
2000 Securing The Electronic Market: The KEYSTONE Public Key Infrastructure Architecture
Stefanos Gritzalis, Sokratis K. Katsikas, Dimitrios Lekkas, Konstantinos Moulinos, Eleni Polydoro
Comput. Secur.2
1999 Trusted third party services for deploying secure telemedical applications over the WWW
Diomidis Spinellis, Stefanos Gritzalis, John Iliadis, Dimitris Gritzalis, Sokratis K. Katsikas
Comput. Secur.5
1998 Enforcing Security Policies in Large Scale Communication Networks
abstract
Due to unexpected network interconnection growth, the security of technological and information infrastructures is becoming difficult to be managed and controlled. In addition, security is becoming more and more crucial for an organisation's information systems operation. The management of an organisation has to establish rules and regulations in order to face the threats that its information systems face. The network manager is obliged to enforce the regulations that senior management addresses. We propose a framework that a network manager could use in order to effectively enforce security policies. In addition, we present a scalable security management architecture suitable for TCP/IP networks. The communication of systems' logical components is based on the use of the SNMP protocol. Finally, the system includes facilities for collecting and efficiently storing raw and aggregate historical security management information in a temporal database for off-line analysis.
Theodore K. Apostolopoulos, Victoria C. Daskalou, Sokratis K. Katsikas, K. D. Moulinos
SRDS3
1998 Optimal seismic deconvolution: distributed algorithms
abstract
Deconvolution is one of the most important aspects of seismic signal processing. The objective of the deconvolution procedure is to remove the obscuring effect of the wavelet's replica making up the seismic trace and therefore obtain an estimate of the reflection coefficient sequence. This paper introduces a new deconvolution algorithm. Optimal distributed estimators and smoothers are utilized in the proposed solution. The new distributed methodology, perfectly suitable for a multisensor environment, such as the seismic signal processing, is compared to the centralized approach, with respect to computational complexity and architectural efficiency. It is shown that the distributed approach greatly outperforms the currently used centralized methodology offering flexibility in the design of the data fusion network.
Konstantinos N. Plataniotis, Sokratis K. Katsikas, Demetrios G. Lainiotis, Anastasios N. Venetsanopoulos
IEEE Trans. Geosci. Remote. Sens.2
1997 An attack detection system for secure computer systems - outline of the solution
Ioanna Kantzavelou, Sokratis K. Katsikas
SEC2
1996 Towards a formal system-to-system authentication protocol
Dimitris Gritzalis, Sokratis K. Katsikas
Comput. Commun.2
1996 Model for network behaviour under viral attack
Sokratis K. Katsikas, Thomas Spyrou, Dimitris Gritzalis, John Darzentas
Comput. Commun.1
1995 Design of a neural network for recognition and classification of computer viruses
Anastasia Doumas, Konstantinos Mavroudakis, Dimitris Gritzalis, Sokratis K. Katsikas
Comput. Secur.4
1995 Underwater tracking of a maneuvering target using time delay measurements
Sokratis K. Katsikas, Assimakis K. Leros, Demetrios G. Lainiotis
Signal Process.1
1992 A zero knowledge probabilistic login protocol
Dimitris Gritzalis, Sokratis K. Katsikas, Stefanos Gritzalis
Comput. Secur.2
1992 Determining access rights for medical information systems
Dimitris Gritzalis, Sokratis K. Katsikas, J. Keklikoglou, A. Tomaras
Comput. Secur.2
1991 Optimal state estimation for uncertain, time varying systems with non-Gaussian initial state
abstract
The problem of state estimation for partially unknown, time-varying, linear systems with non-Gaussian initial conditions is addressed. It is shown that the optimal estimator for this problem is an adaptive Lainiotis (1989) filter with nonlinear Lainiotis filters for non-Gaussian initial conditions as elemental filters. Closed-form solutions for several explicit cases of the initial state PDFs are given. Simulation experiments show the superiority of the proposed algorithm over an adaptive Lainiotis filter with Kalman filters as elemental filters.>
Demetrios G. Lainiotis, Pavlos K. Giannakopoulos, Sokratis K. Katsikas
ICASSP3
1991 Data security in medical information systems: The Greek case
Dimitris Gritzalis, A. Tomaras, Sokratis K. Katsikas, J. Keklikoglou
Comput. Secur.3
1991 On the parallel implementations of the linear Kalman and Lainiotis filters and their efficiency
Sokratis K. Katsikas, Spiridon D. Likothanassis, Demetrios G. Lainiotis
Signal Process.1