VLDB 2026 Research / reviewers in the wild / expert
Emmanouil A. Panaousis
dblp:41/8089 · also Emmanouil Panaousis, Emmanuel A. Panaousis, Manos Panaousis
· DBLP profile ↗
37ranked-venue papers
3as first author
17since 2021 · last 2025
0000-0001-7306-4062ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 12 since 2021Computer networks · 7 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Doing cybersecurity at home: A human-centred approach for mitigating attacks in AI-enabled home devicesabstract• To identify cyber-attacks on the AI, users must have some prior understanding of the AI parameters and their normativity. • Multimodal indicators embedded across the ecosystem of AI-enabled devices are an effective way in raising users’ attention to cyber-attacks. • Engaging users to actively diagnose and resolve cyber-attacks on AI-enabled devices in the home context must take into consideration the home routines, and be designed to avoid cognitive overload. • One way to minimise overload is to make use of users’ propensity to generalise their cybersecurity knowledge and skills where possible. AI-enabled devices are increasingly introduced in the home context and cyber-attacks targeting their AI component are becoming more frequent. Moving away from seeing the user as the problem to recognising the user as part of the solution, our research reports on a novel cybersecurity intervention (comprising Explainable AI features, assisted remediation) designed to support users to identify, diagnose and mitigate cyber-attacks on the AI component of their smart devices. We carried out a case study of a bespoke smart heating device inclusive of this intervention and conducted fieldwork with ten households who experienced simulated integrity cyber-attacks over a month. Our research contributes an understanding of how to design AI-enabled devices and their ecosystems to support users to perceive integrity cyber-attacks, offering new considerations for intervention design that exploits multimodal indicators and supports users to troubleshoot themselves the causes as well as actions of cyber-attacks. Contributing to the growing area of human-centred cybersecurity, we evidence the distinctive challenges users face when evaluating integrity attacks on the AI component in the home context. Asimina Vasalou, Laura Benton, Ana Luisa Serta, Andrea Gauthier, Ceylan Besevli, Sarah Turner, Rea Gill, Rachael Payler, Etienne B. Roesch, Kevin McAreavey, Kim Bauters, Weiru Liu, Hsueh-Ju Chen, Dennis Ivory, Emmanouil A. Panaousis, George Loukas |
Comput. Secur. | 15 |
| 2023 | Privacy Impact Assessment of Cyber Attacks on Connected and Autonomous VehiclesabstractConnected and autonomous vehicles (CAVs) are vulnerable to security gaps that can result in serious consequences, including cyber-physical and privacy risks. For example, an attacker can reconstruct a vehicle’s location trajectory by knowing the speed and steering wheel position of the vehicle. Such inferences not only lead to safety issues but also significantly threaten privacy. This paper assesses the privacy impacts of cyber threats on vehicular networks. We augment the Privacy Risk Assessment Methodology (PRAM), proposed by the National Institute of Standards and Technology, with cyber threats, with cyber threats, which are, in practice, mapped to PRAM impact metrics. We demonstrate the practical application of the enhanced PRAM methodology through a use case that highlights attacks leading to privacy risks in CAVs. The consideration of cyber attacks for privacy risk assessment addresses a major gap in current practices, which is to integrate privacy risk into cyber risk management. Sakshyam Panda, Emmanouil A. Panaousis, George Loukas, Konstantinos Kentrotis |
ARES | 2 |
| 2023 | Principled Data-Driven Decision Support for Cyber-Forensic InvestigationsabstractIn the wake of a cybersecurity incident, it is crucial to promptly discover how the threat actors breached security in order to assess the impact of the incident and to develop and deploy countermeasures that can protect against further attacks. To this end, defenders can launch a cyber-forensic investigation, which discovers the techniques that the threat actors used in the incident. A fundamental challenge in such an investigation is prioritizing the investigation of particular techniques since the investigation of each technique requires time and effort, but forensic analysts cannot know which ones were actually used before investigating them. To ensure prompt discovery, it is imperative to provide decision support that can help forensic analysts with this prioritization. A recent study demonstrated that data-driven decision support, based on a dataset of prior incidents, can provide state-of-the-art prioritization. However, this data-driven approach, called DISCLOSE, is based on a heuristic that utilizes only a subset of the available information and does not approximate optimal decisions. To improve upon this heuristic, we introduce a principled approach for data-driven decision support for cyber-forensic investigations. We formulate the decision-support problem using a Markov decision process, whose states represent the states of a forensic investigation. To solve the decision problem, we propose a Monte Carlo tree search based method, which relies on a k-NN regression over prior incidents to estimate state-transition probabilities. We evaluate our proposed approach on multiple versions of the MITRE ATT&CK dataset, which is a knowledge base of adversarial techniques and tactics based on real-world cyber incidents, and demonstrate that our approach outperforms DISCLOSE in terms of techniques discovered per effort spent. Soodeh Atefi, Sakshyam Panda, Emmanouil A. Panaousis, Aron Laszka |
AAAI | 3 |
| 2023 | Virtually secure: A taxonomic assessment of cybersecurity challenges in virtual reality environments
Blessing Odeleye, George Loukas, Ryan Heartfield, Georgia Sakellari, Emmanouil A. Panaousis, Fotis Spyridonis |
Comput. Secur. | 5 |
| 2023 | Game-theoretic APT defense: An experimental study on roboticsabstractThis paper proposes a novel game-theoretic framework for defending against Advanced Persistent Threats (APTs). It applies the original Cut-The-Rope model into an experimental study extending the previously studied attacker movements beyond the Poisson distribution to a realistic set of attack actions. More importantly, it demonstrates the value of this framework on an experimental study of an APT defense game on attack graphs, which lets a security officer establish an optimized defense policy against stealthy intrusions. The security model and algorithm under study is designed for practical use with attack graphs as threat models, possibly including vulnerability information if available. The game-theoretic optimization delivers a proactive defense policy under the following assumptions or requirements: first, we do not need to assume that the system is, or has been, clean from adversaries at any time. At the moment when the defender computes the defense policy, the attacker is assumed to already be in the system (also having penetrated it until an unknown depth). Second, the defender does not rely on any signaling or other indicators of adversarial activity, nor is there a reliable feedback mechanism to tell the defender if its actions were successful or not. Third, the model can use information on exploits, such as Common Vulnerabilities and Exposures (CVE) numbers, to refine the defense game, but can also operate without such information. We corroborate our findings on publicly documented attack graphs from the robotics domain; without and with CVE information. We run experiments against two different types of defense regimes, and compare the results against an intuitive baseline defense heuristic. The results show that the optimized defense strongly outperforms simple heuristics, like taking the shortest or easiest attack paths. Stefan Rass, Sandra König, Jasmin Wachter, Victor Mayoral Vilches, Emmanouil A. Panaousis |
Comput. Secur. | 5 |
| 2023 | CROSS: A framework for cyber risk optimisation in smart homesabstractThis work introduces a decision support framework, called Cyber Risk Optimiser for Smart homeS (CROSS), which advises both smart home users and smart home service providers on how to select an optimal portfolio of cyber security controls to counteract cyber attacks in a smart home including traditional cyber attacks and adversarial machine learning attacks. CROSS is based on a multi-objective bi-level two-stage optimisation. In stage-one optimisation, the problem is modelled as a multi-leader-follower game that considers both security and economic objectives, where the provider selects a security portfolio to protect both itself and its users, while rational attackers target the weakest path. Stage-two optimisation is a Stackelberg security game that focuses on additional user security controls under the remit of smart home users. While CROSS can potentially be applied to other similar use cases, in this paper, our aim is to address threats against artificial intelligence (AI) applications as the use of AI in smart Internet of Things (IoT) devices introduces new cyber threats to home environments. Specifically, we have implemented and assessed CROSS in a smart heating use case in a prototypical AI-enabled IoT environment that combines characteristics and vulnerabilities currently present on existing commercial off-the-shelf (COTS) devices, demonstrating the selection of optimal decisions. Yunxiao Zhang 0001, Pasquale Malacaria, George Loukas, Emmanouil A. Panaousis |
Comput. Secur. | 4 |
| 2023 | Secure genotype imputation using homomorphic encryptionabstractGenotype imputation estimates missing genotypes from the haplotype or genotype reference panel in individual genetic sequences, which boosts the potential of genome-wide association and is essential in genetic data analysis. However, the genetic sequences involve people’s privacy, confirming an individual’s identification and even disease information. This work proposes a secure genotype imputation model, which uses a linear regression model and the homomorphic encryption scheme over ciphertext to impute missing genotypes. The inference model is trained with float plaintext parameters, which are round into integers to avoid high complexity homomorphic evaluation on float number operations without bootstrapping operations. Even though the rounding parameters in the inference model are not the same as those in the trained model, We find that it will no effect on the outcome of the homomorphic prediction. Thus, a high-efficiency genotype imputation inference model over the ciphertext is obtained while keeping the high-security level. The simulation results indicate that the accuracy of the secure inference model is almost the same as the original model trained on float parameters. The secure inference model’s accuracy is 98.6% for a single genotype. Junwei Zhou 0002, Botian Lei, Huile Lang, Emmanouil A. Panaousis, Kaitai Liang, Jianwen Xiang |
J. Inf. Secur. Appl. | 4 |
| 2022 | MITRE ATT&CK-driven Cyber Risk AssessmentabstractAssessing the risk posed by Advanced Cyber Threats (APTs) is challenging without understanding the methods and tactics adversaries use to attack an organisation. The MITRE ATT&CK provides information on the motivation, capabilities, interests and tactics, techniques and procedures (TTPs) used by threat actors. In this paper, we leverage these characteristics of threat actors to support informed cyber risk characterisation and assessment. In particular, we utilise the MITRE repository of known adversarial TTPs along with attack graphs to determine the attack probability as well as the likelihood of success of an attack. We further identify attack paths with the highest likelihood of success considering the techniques and procedures of a threat actor. The assessment is supported by a case study of a health care organisation to identify the level of risk against two adversary groups– Lazarus and menuPass. Sakshyam Panda, Christos Xenakis, Emmanouil A. Panaousis |
ARES | 4 |
| 2022 | FLVoogd: Robust And Privacy Preserving Federated Learning
Rui Wang 0070, Yanqi Qiao, Emmanouil A. Panaousis, Kaitai Liang |
ACML | 4 |
| 2022 | Practical algorithm substitution attack on extractable signatures
Yi Zhao 0011, Kaitai Liang, Yanqi Zhao, Bo Yang 0003, Yang Ming 0001, Emmanouil A. Panaousis |
Des. Codes Cryptogr. | 6 |
| 2022 | A Trusted Platform Module-based, Pre-emptive and Dynamic Asset Discovery ToolabstractThis paper presents an original Intelligent and Secure Asset Discovery Tool (ISADT) that uses artificial intelligence and TPM-based technologies to: (i) detect the network assets, and (ii) detect suspicious pattern in the use of the network. The architecture has specifically been designed to discover the assets of medium and large size companies and institutions, such as hospitals, universities, or government buildings. Given the distributed design of the architecture, it can cope with the problem of the isolation of different Virtual Local Area Networks (VLANs). This is done by collecting information from all the VLANs and storing it in a central node, which can be accessed by the network administrator, who may consult and visualize the status in any moment, or even by other authorized applications. The collected data is kept in a secure warehouse by the use of a Trusted Platform Module. Moreover, collected data is processed by the use of artificial intelligence in two ways: (i) the traffic of each network is analysed so that suspicious patterns can be detected, and (ii) identified ports and status are analysed to detect anomalous combinations of open ports in a device. Antonio Jesús Díaz-Honrubia, Alberto Blázquez-Herranz, Lucía Prieto Santamaría, Ernestina Menasalvas Ruiz, Alejandro Rodríguez González, Gustavo Gonzalez Granadillo, Emmanouil A. Panaousis, Christos Xenakis |
J. Inf. Secur. Appl. | 8 |
| 2022 | On-the-Fly Privacy for Location HistogramsabstractAn important motivation for research in location privacy has been to protect against user profiling, i.e., inferring a user’s political affiliation, wealth level, sexual preferences, religious beliefs, and other sensitive attributes. Existing approaches focus on distorting or suppressing individual locations, but we argue that, for directly protecting against profiling, it is more appropriate to focus on the frequency with which various locations are visited – in other words, the histogram of a user’s locations. We introduce and explore a new privacy notion, namely, on-the-fly privacy for location histograms, in which a mobile user repeatedly submits obfuscated locations to a Location-Based Service aiming for the resulting histogram to resemble a target profile or differ from it. For example, she may want to avoid looking wealthy or to resemble a health-conscious person. We describe how to design concrete privacy mechanisms that operate under different assumptions on, e.g., the user’s mobility, including provably optimal mechanisms. We use a mobility dataset with 1083 users to illustrate how these mechanisms achieve privacy while minimizing the quality loss caused by the location obfuscation, in the context of two types of Location-Based Services: nearest-PoI, and geofence. George Theodorakopoulos 0001, Emmanouil A. Panaousis, Kaitai Liang, George Loukas |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | MFF-AMD: Multivariate Feature Fusion for Android Malware Detection
Guangquan Xu, Meiqi Feng, Litao Jiao, Jian Liu 0004, Hongning Dai, Emmanouil A. Panaousis, James Xi Zheng |
CollaborateCom (1) | 7 |
| 2021 | A Lightweight Certificateless Non-interactive Authentication and Key Exchange Protocol for IoT EnvironmentsabstractIn order to protect user privacy and provide better access control in Internet of Things (IoT) environments, designing an appropriate two-party authentication and key exchange protocol is a prominent challenge. In this paper, we propose a lightweight certificateless non-interactive authentication and key exchange (CNAKE) protocol for mutual authentication between remote users and smart devices. Based on elliptic curves, our lightweight protocol provides high security performance, realizes non-interactive authentication between the two entities, and effectively reduces communication overhead. Under the random oracle model, the proposed protocol is provably secure based on the Computational Diffie-Hellman and Bilinear Diffie-Hellman hardness assumption. Finally, through a series of experiments and comprehensive performance analysis, we demonstrate that our scheme is fast and secure. Menghan Pan, Daojing He, Xuru Li, Sammy Chan, Emmanouil A. Panaousis |
ISCC | 5 |
| 2021 | TT-SVD: An Efficient Sparse Decision-Making Model With Two-Way Trust Recommendation in the AI-Enabled IoT SystemsabstractThe convergence of AI and IoT enables data to be quickly explored and turned into vital decisions, and however, there are still some challenging issues to be further addressed. For example, lacking of enough data in AI-based decision making [so-called sparse decision making (SDM)] will decrease the efficiency dramatically, or even disable the intelligent IoT networks. Taking the intelligent IoT networks as the network infrastructure, the recommendation systems have been facing such SDM problems. A naive solution is to introduce trust information. However, trust information may also face the difficulty of sparse trust evidence (also known as sparse trust problem). In our work, an accurate SDM model with two-way trust recommendation in the AI-enabled IoT systems is proposed, named TT-SVD. Our model incorporates both trust information and rating information more thoroughly, which can efficiently alleviate the above-mentioned sparse trust problem and therefore be able to solve the cold start and data sparsity problems. Specifically, we first consider the twofold trust influences from both trustees and trusters, which can be represented by a factor named trust propensity. To this end, we propose a dual model, including a truster model (TrusterSVD) and a trustee model (TrusteeSVD) based on an existing rating-only recommendation model called SVD++, which are integrated by the weighted average and yield the final model, TT-SVD. The experimental results show that our model outperforms the state-of-the-art, including SVD and TrustSVD in both the “all users” and “cold start users” cases, and the accuracy improvement can reach a maximum of 29%. Complexity analysis shows that our model is equally suitable for the case of large sparse data sets. In summary, our model can effectively solve the sparse decision problem by introducing the two-way trust recommendation, and hence improve the efficiency of the intelligent recommendation systems. Guangquan Xu, Litao Jiao, Meiqi Feng, Zhong Ji, Emmanouil A. Panaousis, Si Chen 0009, James Xi Zheng |
IEEE Internet Things J. | 6 |
| 2021 | Self-Configurable Cyber-Physical Intrusion Detection for Smart Homes Using Reinforcement LearningabstractThe modern Internet of Things (IoT)-based smart home is a challenging environment to secure: devices change, new vulnerabilities are discovered and often remain unpatched, and different users interact with their devices differently and have different cyber risk attitudes. A security breach's impact is not limited to cyberspace, as it can also affect or be facilitated in physical space, for example, via voice. In this environment, intrusion detection cannot rely solely on static models that remain the same over time and are the same for all users. We present MAGPIE, the first smart home intrusion detection system that is able to autonomously adjust the decision function of its underlying anomaly classification models to a smart home's changing conditions (e.g., new devices, new automation rules and user interaction with them). The method achieves this goal by applying a novel probabilistic cluster-based reward mechanism to non-stationary multi-armed bandit reinforcement learning. MAGPIE rewards the sets of hyperparameters of its underlying isolation forest unsupervised anomaly classifiers based on the cluster silhouette scores of their output. Experimental evaluation in a real household shows that MAGPIE exhibits high accuracy because of two further innovations: it takes into account both cyber and physical sources of data; and it detects human presence to utilise models that exhibit the highest accuracy in each case. MAGPIE is available in open-source format, together with its evaluation datasets, so it can benefit from future advances in unsupervised and reinforcement learning and be able to be enriched with further sources of data as smart home environments and attacks evolve. Ryan Heartfield, George Loukas, Anatolij Bezemskij, Emmanouil A. Panaousis |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Data-Driven Decision Support for Optimizing Cyber Forensic InvestigationsabstractCyber attacks consisting of several attack actions can present considerable challenge to forensic investigations. Consider the case where a cybersecurity breach is suspected following the discovery of one attack action, for example by observing the modification of sensitive registry keys, suspicious network traffic patterns, or the abuse of legitimate credentials. At this point, the investigator can have multiple options as to what to check next to discover the rest, and will likely pick one based on experience and training. This will be the case at each new step. We argue that the efficiency of this aspect of the job, which is the selection of what next step to take, can have significant impact on its overall cost (e.g., the duration) of the investigation and can be improved through the application of constrained optimization techniques. Here, we present DISCLOSE, the first data-driven decision support framework for optimizing forensic investigations of cybersecurity breaches. DISCLOSE benefits from a repository of known adversarial tactics, techniques, and procedures (TTPs), for each of which it harvests threat intelligence information to calculate its probabilistic relations with the rest. These relations, as well as a proximity parameter derived from the projection of quantitative data regarding the adversarial TTPs on an attack life cycle model, are both used as input to our optimization framework. We show the feasibility of this approach in a case study that consists of 31 adversarial TTPs, data collected from 6 interviews with experienced cybersecurity professionals and data extracted from the MITRE ATT&CK STIX repository and the Common Vulnerability Scoring System (CVSS). Antonia Nisioti, George Loukas, Aron Laszka, Emmanouil A. Panaousis |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | SECONDO: A Platform for Cybersecurity Investments and Cyber Insurance Decisions
Aristeidis Farao, Sakshyam Panda, Sofia-Anna Menesidou, Entso Veliou, Nikolaos Episkopos, George Kalatzantonakis, Farnaz Mohammadi, Nikolaos Georgopoulos, Michael Sirivianos, Nikos Salamanos, Spyros Loizou, Michalis Pingos, John Polley, Andrew Fielder, Emmanouil A. Panaousis, Christos Xenakis |
TrustBus | 15 |
| 2020 | Distributed Key Management in MicrogridsabstractSecurity for smart industrial systems is prominent due to the proliferation of cyber threats threatening national critical infrastructures. Smart grid comes with intelligent applications that can utilize the bidirectional communication network among its entities. Microgrids are small-scale smart grids that enable machine-to-machine (M2M) communications as they can operate with some degree of independence from the main grid. In addition to protecting critical microgrid applications, an underlying key management scheme is needed to enable secure M2M message transmission and authentication. Existing key management schemes are not adequate due to microgrid special features and requirements. In this article, we propose the Micro sElf-orgaNiSed mAnagement (MENSA), which is the first hybrid key management and authentication scheme that combines public key infrastructure and web-of-trust concepts in microgrids. Our experimental results demonstrate the efficiency of MENSA in terms of scalability and swiftness. Vaios Bolgouras, Christoforos Ntantogian, Emmanouil A. Panaousis, Christos Xenakis |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | Multiobjective Optimization Algorithms for Wireless Sensor Networksabstract<p /> Dionisis Kandris, Alex Alexandridis, Tasos Dagiuklas, Emmanouil A. Panaousis, Dimitrios D. Vergados |
Wirel. Commun. Mob. Comput. | 4 |
| 2019 | Attacking IEC-60870-5-104 SCADA SystemsabstractThe rapid evolution of the Information and Communications Technology (ICT) services transforms the conventional electrical grid into a new paradigm called Smart Grid (SG). Even though SG brings significant improvements, such as increased reliability and better energy management, it also introduces multiple security challenges. One of the main reasons for this is that SG combines a wide range of heterogeneous technologies, including Internet of Things (IoT) devices as well as Supervisory Control and Data Acquisition (SCADA) systems. The latter are responsible for monitoring and controlling the automatic procedures of energy transmission and distribution. Nevertheless, the presence of these systems introduces multiple vulnerabilities because their protocols do not implement essential security mechanisms such as authentication and access control. In this paper, we focus our attention on the security issues of the IEC 60870-5-104 (IEC-104) protocol, which is widely utilized in the European energy sector. In particular, we provide a SCADA threat model based on a Coloured Petri Net (CPN) and emulate four different types of cyber attacks against IEC-104. Last, we used AlienVault's risk assessment model to evaluate the risk level that each of these cyber attacks introduces to our system to confirm our intuition about their severity. Panagiotis I. Radoglou-Grammatikis, Panagiotis G. Sarigiannidis, Ioannis Giannoulakis, Emmanouil Kafetzakis, Emmanouil A. Panaousis |
SERVICES | 5 |
| 2019 | A taxonomy and survey of cyber-physical intrusion detection approaches for vehicles
George Loukas, Eirini D. Karapistoli, Emmanouil A. Panaousis, Panagiotis G. Sarigiannidis, Anatolij Bezemskij, Tuan Vuong |
Ad Hoc Networks | 3 |
| 2019 | Apparatus: A framework for security analysis in internet of things systems
Orestis Mavropoulos, Haralambos Mouratidis, Andrew Fish, Emmanouil A. Panaousis |
Ad Hoc Networks | 4 |
| 2019 | Post-incident audits on cyber insurance discountsabstractWe introduce a game-theoretic model to investigate the strategic interaction between a cyber insurance policyholder whose premium depends on her self-reported security level and an insurer with the power to audit the security level upon receiving an indemnity claim. Audits can reveal fraudulent (or simply careless) policyholders not following reported security procedures, in which case the insurer can refuse to indemnify the policyholder. However, the insurer has to bear an audit cost even when the policyholders have followed the prescribed security procedures. As audits can be expensive, a key problem insurers face is to devise an auditing strategy to deter policyholders from misrepresenting their security levels to gain a premium discount. This decision-making problem was motivated by conducting interviews with underwriters and reviewing regulatory filings in the U.S.; we discovered that premiums are determined by security posture, yet this is often self-reported and insurers are concerned by whether security procedures are practised as reported by the policyholders. To address this problem, we model this interaction as a Bayesian game of incomplete information and devise optimal auditing strategies for the insurers considering the possibility that the policyholder may misrepresent her security level. To the best of our knowledge, this work is the first theoretical consideration of post-incident claims management in cyber security. Our model captures the trade-off between the incentive to exaggerate security posture during the application process and the possibility of punishment for non-compliance with reported security policies. Simulations demonstrate that common sense techniques are not as efficient at providing effective cyber insurance audit decisions as the ones computed using game theory. Sakshyam Panda, Daniel W. Woods, Aron Laszka, Andrew Fielder, Emmanouil A. Panaousis |
Comput. Secur. | 5 |
| 2019 | Using Sparse Representation to Detect Anomalies in Complex WSNsabstractIn recent years, wireless sensor networks (WSNs) have become an active area of research for monitoring physical and environmental conditions. Due to the interdependence of sensors, a functional anomaly in one sensor can cause a functional anomaly in another sensor, which can further lead to the malfunctioning of the entire sensor network. Existing research work has analysed faulty sensor anomalies but fails to show the effectiveness throughout the entire interdependent network system. In this article, a dictionary learning algorithm based on a non-negative constraint is developed, and a sparse representation anomaly node detection method for sensor networks is proposed based on the dictionary learning. Through experiment on a specific thermal power plant in China, we verify the robustness of our proposed method in detecting abnormal nodes against four state of the art approaches and proved our method is more robust. Furthermore, the experiments are conducted on the obtained abnormal nodes to prove the interdependence of multi-layer sensor networks and reveal the conditions and causes of a system crash. Xiaoming Li 0006, Guangquan Xu, James Xi Zheng, Kaitai Liang, Emmanouil A. Panaousis, Tao Li 0022, Wei Wang 0012, Chao Shen 0001 |
ACM Trans. Intell. Syst. Technol. | 5 |
| 2018 | Unsupervised Learning for Trustworthy IoTabstractThe advancement of Internet-of-Things (IoT) edge devices with various types of sensors enables us to harness diverse information with Mobile Crowd-Sensing applications (MCS). This highly dynamic setting entails the collection of ubiquitous data traces, originating from sensors carried by people, introducing new information security challenges; one of them being the preservation of data trustworthiness. What is needed in these settings is the timely analysis of these large datasets to produce accurate insights on the correctness of user reports. Existing data mining and other artificial intelligence methods are the most popular to gain hidden insights from IoT data, albeit with many challenges. In this paper, we first model the cyber trustworthiness of MCS reports in the presence of intelligent and colluding adversaries. We then rigorously assess, using real IoT datasets, the effectiveness and accuracy of well-known data mining algorithms when employed towards IoT security and privacy. By taking into account the spatio-temporal changes of the underlying phenomena, we demonstrate how concept drifts can masquerade the existence of attackers and their impact on the accuracy of both the clustering and classification processes. Our initial set of results clearly show that these unsupervised learning algorithms are prone to adversarial infection, thus, magnifying the need for further research in the field by leveraging a mix of advanced machine learning models and mathematical optimization techniques. Nikhil Banerjee, Thanassis Giannetsos, Emmanouil A. Panaousis, Clive Cheong Took |
FUZZ-IEEE | 3 |
| 2018 | Towards the Definition of a Security Incident Response Modelling Language
Myrsini Athinaiou, Haralambos Mouratidis, Theo Fotis, Michalis Pavlidis, Emmanouil A. Panaousis |
TrustBus | 5 |
| 2018 | An Enhanced Cyber Attack Attribution Framework
Nikolaos Pitropakis, Emmanouil A. Panaousis, Alkiviadis Giannakoulias, George Kalpakis, Rodrigo Diaz Rodriguez, Panagiotis G. Sarigiannidis |
TrustBus | 2 |
| 2017 | ASTo: A tool for security analysis of IoT systemsabstractIn this paper, a software tool for security analysis of IoT systems is presented. The tool, named ASTo (Apparatus Software Tool) enables the visualization of IoT systems using a domain-specific modeling language. The modeling language provides constructs to express the hardware, software and social concepts of an IoT system along with security concepts. Security issues of IoT systems are identified based on the attributes of the constructs and their relationships. Security analysis is facilitated using the visualization mechanisms of the tool to recognize the secure posture of an IoT system. Orestis Mavropoulos, Haralambos Mouratidis, Andrew Fish, Emmanouil A. Panaousis |
SERA | 4 |
| 2017 | Selecting Security Mechanisms in Secure Tropos
Michalis Pavlidis, Haralambos Mouratidis, Emmanouil A. Panaousis, Nikolaos Argyropoulos |
TrustBus | 3 |
| 2017 | Game theoretic path selection to support security in device-to-device communications
Emmanouil A. Panaousis, Eirini D. Karapistoli, Hadeer Elsemary, Tansu Alpcan, M. H. R. Khouzani, Anastasios A. Economides |
Ad Hoc Networks | 1 |
| 2016 | Security Challenges of Small Cell as a Service in Virtualized Mobile Edge Computing Environments
Vassilios G. Vassilakis, Emmanouil A. Panaousis, Haralambos Mouratidis |
WISTP | 2 |
| 2016 | Decision support approaches for cyber security investmentabstractWhen investing in cyber security resources, information security managers have to follow effective decision-making strategies. We refer to this as the cyber security investment challenge.In this paper, we consider three possible decision support methodologies for security managers to tackle this challenge. We consider methods based on game theory, combinatorial optimisation , and a hybrid of the two. Our modelling starts by building a framework where we can investigate the effectiveness of a cyber security control regarding the protection of different assets seen as targets in presence of commodity threats. As game theory captures the interaction between the endogenous organisation's and attackers' decisions, we consider a 2-person control game between the security manager who has to choose among different implementation levels of a cyber security control, and a commodity attacker who chooses among different targets to attack. The pure game theoretical methodology consists of a large game including all controls and all threats. In the hybrid methodology the game solutions of individual control-games along with their direct costs (e.g. financial) are combined with a Knapsack algorithm to derive an optimal investment strategy. The combinatorial optimisation technique consists of a multi-objective multiple choice Knapsack based strategy. To compare these approaches we built a decision support tool and a case study regarding current government guidelines. The endeavour of this work is to highlight the weaknesses and strengths of different investment methodologies for cyber security, the benefit of their interaction, and the impact that indirect costs have on cyber security investment. Going a step further in validating our work, we have shown that our decision support tool provides the same advice with the one advocated by the UK government with regard to the requirements for basic technical protection from cyber attacks in SMEs . Andrew Fielder, Emmanouil A. Panaousis, Pasquale Malacaria, Chris Hankin, Fabrizio Smeraldi |
Decis. Support Syst. | 2 |
| 2014 | Game Theory Meets Information Security Management
Andrew Fielder, Emmanouil A. Panaousis, Pasquale Malacaria, Chris Hankin, Fabrizio Smeraldi |
SEC | 2 |
| 2013 | Standardisation advancements in the area of routing for mobile ad-hoc networks
Tipu Arvind Ramrekha, Emmanouil A. Panaousis, Christos Politis |
J. Supercomput. | 2 |
| 2009 | A game theoretic approach for securing AODV in emergency Mobile Ad Hoc NetworksabstractIn many extreme emergency cases such as forest fires or tube terrorist attacks, the rescuers have difficulty using traditional legacy networks due to destruction or collapse of the infrastructure in such events. We use the term emergency Mobile Ad hoc NETworks (eMANETs) in order to describe Next Generation Networks (NGNs) which are deployed in emergency cases. The security of these networks is critical. Especially secure routing is important given the fact that potential attackers aim to disrupt the appropriate operation of the routing protocol within an eMANET. In this paper we propose a game theoretic approach called AODV-GT (AODV-Game Theoretic) and we integrate this into the reactive Ad hoc On-demand Distance Vector (AODV) routing protocol to provide defense against blackhole attacks. AODV-GT is based on the concept of non-cooperative game theory. AODV-GT outperforms AODV in terms of malicious dropped packets when blackhole nodes exist within the eMANET. Our simulations were implemented using the network simulator ns-2. Emmanouil A. Panaousis, Christos Politis |
LCN | 1 |
| 2008 | Optimizing the channel load reporting process in IEEE 802.11k-enabled WLANsabstractIEEE 802.11k is an extension of the IEEE 802.11 specification for radio resource measurements. In an IEEE 802.11k-enabled wireless LAN, an access point or other network element may request from a client or another access point to monitor and report the load of a channel. We call the latter a channel monitoring station. In this paper we propose a mechanism for a channel monitoring station to efficiently derive accurate values of channel load.We especially focus on optimizing the duration of channel monitoring and thus minimize the impact on applications. Note that such mechanisms are critical for the success of new sharing regimes such as Cognitive Radio and Open Spectrum Access. Emmanouil A. Panaousis, Pantelis A. Frangoudis, Christopher N. Ververidis, George C. Polyzos |
LANMAN | 1 |