VLDB 2026 Research / reviewers in the wild / expert
Dimitris Gritzalis
dblp:48/4664
· DBLP profile ↗
120ranked-venue papers
22as first author
13since 2021 · last 2026
0000-0002-7793-6128ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 106 · 20 first-author · 13 since 2021Computer networks · 9 · 1 first-authorSystems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | INFFLOW-RT+: Transforming Real-Time Risk into Adaptive Incentives
Argiro Anagnostopoulou, Konstantinos Karlis, Dimitris Gritzalis |
SECRYPT (2) | 3 |
| 2026 | DRIMAX: An intelligence-driven and context-aware dynamic risk assessment methodology for cyber security
Eleftherios Eleftheriadis, Pavlos Cheimonidis, Athanasios Dimitriadis, Konstantinos Rantos, Ioannis Mavridis, Dimitris Gritzalis |
Comput. Secur. | 6 |
| 2025 | Bolstering IIoT Resilience: The Synergy of Blockchain and CapBAC
Argiro Anagnostopoulou, Eleni Kehrioti, Ioannis Mavridis, Dimitris Gritzalis |
SECRYPT | 4 |
| 2025 | MIDAS: Multi-layered attack detection architecture with decision optimisationabstractThe proliferation of cyber attacks has led to the use of data-driven detection countermeasures, in an effort to mitigate this threat. Machine learning techniques, such as the use of neural networks, have become mainstream and proven effective in attack detection. However, these data-driven solutions are limited by: a) high computational overhead associated with data pre-processing and inference cost, b) inability to scale beyond a centralised deployment to cope with environmental variances, and c) requirement to use multiple bespoke detection models for effective attack detection coverage across the cyber kill chain. In this context, this paper introduces MIDAS, a cost-effective framework for attack detection, which introduces a dynamic decision boundary that is used in a multi-layered detection architecture. This is achieved by modelling the decision confidence of the participating detection models and judging its benefits using a novel reward policy. Specifically, a reward is assigned to a set of available actions, corresponding to a decision boundary, based on its cost-to-performance, where an overall cost-saving is prioritised. We evaluate our approach on two widely used datasets representing two of the most common threats today, i.e., phishing and malware. MIDAS shows that it effectively reduces the expenditure on detection inference and processing costs by controlling the frequency of expensive detection operations. This is achieved without significant sacrifice of attack detection performance. Kieran Rendall, Alexios Mylonas, Stilianos Vidalis, Dimitris Gritzalis |
Comput. Secur. | 4 |
| 2024 | From Plant to Lab: Industrial Emulation Tools for Real-World Security Testing in Industrial Control Systems
Argiro Anagnostopoulou, Thomas Papaloukas, George Stergiopoulos, Dimitris Gritzalis |
SECRYPT | 4 |
| 2024 | Utilizing Machine Learning for Optimizing Cybersecurity Spending in Critical Infrastructures
George Stergiopoulos, Michalis Detsis, Sozon Leventopoulos, Dimitris Gritzalis |
SECRYPT | 4 |
| 2024 | Smart homes under siege: Assessing the robustness of physical security against wireless network attacksabstractNowadays domestic smart security devices, such as smart locks, smart doorbells, and security cameras, are becoming increasingly popular with users, due to their ease of use, convenience, and declining prices. Unlike conventional non-smart security devices, such as alarms and locks, performance standards for smart security devices, such as the British TS 621, are not easily understandable by end users due to the technical language employed. Users also have very few sources of unbiased information regarding product performance in real world conditions and protection against attacks from cyber attacker-burglars and, as a result, tend to take manufacturer claims at face value. This means that, as this work proves, users may be exposed to threats, such as theft, impersonation (should an attacker steal their credentials), and even physical injury, if the device fails and is used to prevent access to hazardous environments. As such, this paper deploys several attacks using popular wireless attack vectors (i.e., 433MHz radio, Bluetooth, and RFID) against domestic smart security devices to assess the protection offered against a cyber attacker-burglar. Our results suggest that users are open to considerable cyber physical attacks, irrespective if they use lesser known (i.e., no name) or branded smart security devices, due to the poor security offered by these devices. Ashley Allen, Alexios Mylonas, Stilianos Vidalis, Dimitris Gritzalis |
Comput. Secur. | 4 |
| 2023 | Risk-Based Illegal Information Flow Detection in the IIoT
Argiro Anagnostopoulou, Ioannis Mavridis, Dimitris Gritzalis |
SECRYPT | 3 |
| 2022 | Towards an Automated Business Process Model Risk Assessment: A Process Mining Approach
Panagiotis Dedousis, Melina Raptaki, George Stergiopoulos, Dimitris Gritzalis |
SECRYPT | 4 |
| 2021 | Towards Integrating Security in Industrial Engineering Design Practices
Panagiotis Dedousis, George Stergiopoulos, George Arampatzis, Dimitris Gritzalis |
SECRYPT | 4 |
| 2021 | Design and Evaluation of COFELET-based Approaches for Cyber Security Learning and Training
Menelaos Katsantonis, Ioannis Mavridis, Dimitris Gritzalis |
Comput. Secur. | 3 |
| 2021 | Dropping malware through sound injection: A comparative analysis on Android operating systems
George Stergiopoulos, Dimitris Gritzalis, Efstratios Vasilellis, Argiro Anagnostopoulou |
Comput. Secur. | 2 |
| 2021 | Analysis and Classification of Mitigation Tools against Cyberattacks in COVID-19 EraabstractThe COVID-19 outbreak has forced businesses to shift to an unprecedented “work from home” company environment. While this provides advantages for employees and businesses, it also leads to a multitude of shortcomings, most prevalent of which is the emergence of additional security risks. Previous to the outbreak, company computer networks were mainly confined within its facilities. The pandemic has now caused this network to “spread thin,” as the majority of employees work remotely. This has opened up a variety of new vulnerabilities, as workers’ cyber protection is not the same at home as it is in office. Although the effects of the virus are now subsiding, working remotely has embedded itself as the new normal. Thus, it is imperative for company management to take the necessary steps to ensure business continuity and be prepared to deal with an increased number of cyber threats. In our research, we provide a detailed classification for a group of tools which will facilitate risk mitigation and prevention. We also provide a selection of automated tools such as vulnerability scanners, monitoring and logging tools, and antivirus software. We outline each tool using tables, to show useful information such as advantages, disadvantages, scalability, cost, and other characteristics. Additionally, we implement decision trees for each category of tools, in an attempt to assist in navigating the large amount of information presented in this paper. Our objective is to provide a multifaceted taxonomy and analysis of mitigation tools, which will support companies in their endeavor to protect their computer networks. Our contribution can also help companies to have some type of cyber threat intelligence so as to put themselves one step ahead of cyber criminals. George Iakovakis, Constantinos-Giovanni Xarhoulacos, Konstantinos Giovas, Dimitris Gritzalis |
Secur. Commun. Networks | 4 |
| 2020 | Automatic network restructuring and risk mitigation through business process asset dependency analysis
George Stergiopoulos, Panagiotis Dedousis, Dimitris Gritzalis |
Comput. Secur. | 3 |
| 2019 | Using side channel TCP features for real-time detection of malware connectionsabstractDuring the past years, deep packet inspection has been prevalent in network intrusion detection systems. Most solutions employ complex algorithms to analyze the intended behaviour and underlying characteristics of packets and their payloads, in an effort to detect and prevent malicious users and software from communicating over business intranets and wider networks. Still, there are multiple issues that inhibit their success rate. Most signature-based security software is plagued by false positives and/or false negatives. On the other hand, behavioral-based solutions achieve better detection rates but need to analyze large amounts of traffic. In this article, we present a real-time network traffic monitoring system that implements machine learning over side channel characteristics of TCP network packets to distinguish normal from malicious TCP sessions, even when encryption is in place. We test in university networks and test multiple different types of traffic. We show that, our approach (i) requires notably less information to achieve similar (if not better) detection rates, (ii) works over encrypted traffic as well, and (iii) has notably low false positives and false negatives in everyday case study scenarios. George Stergiopoulos, Georgia Chronopoulou, Evangelos Bitsikas, Nikolaos Tsalis, Dimitris Gritzalis |
J. Comput. Secur. | 5 |
| 2018 | Cybersecurity Self-assessment Tools: Evaluating the Importance for Securing Industrial Control Systems in Critical Infrastructures
Georgia Lykou, Argiro Anagnostopoulou, George Stergiopoulos, Dimitris Gritzalis |
CRITIS | 4 |
| 2018 | Automatic Detection of Various Malicious Traffic Using Side Channel Features on TCP Packets
George Stergiopoulos, Alexander Talavari, Evangelos Bitsikas, Dimitris Gritzalis |
ESORICS (1) | 4 |
| 2018 | Using formal distributions for threat likelihood estimation in cloud-enabled IT risk assessment
George Stergiopoulos, Dimitris Gritzalis, Vasilis Kouktzoglou |
Comput. Networks | 2 |
| 2018 | A new methodology toward effectively assessing data center sustainability
Georgia Lykou, Despina Mentzelioti, Dimitris Gritzalis |
Comput. Secur. | 3 |
| 2018 | A new strategy for improving cyber-attacks evaluation in the context of Tallinn Manual
Kosmas Pipyros, Christos Thraskias, Lilian Mitrou, Dimitris Gritzalis, Theodoros K. Apostolopoulos |
Comput. Secur. | 4 |
| 2017 | Analysis and Classification of Adaptation Tools for Transport Sector Adaptation Planning
Georgia Lykou, George Iakovakis, George Chronis, Dimitris Gritzalis |
CRITIS | 4 |
| 2017 | Stress level detection via OSN usage pattern and chronicity analysis: An OSINT threat intelligence module
Miltiadis Kandias, Dimitris Gritzalis, Vasilis Stavrou, Kostas Nikoloulis |
Comput. Secur. | 2 |
| 2017 | Program analysis with risk-based classification of dynamic invariants for logical error detection
George Stergiopoulos, Panagiotis Katsaros, Dimitris Gritzalis |
Comput. Secur. | 3 |
| 2017 | Exploring the protection of private browsing in desktop browsers
Nikolaos Tsalis, Alexios Mylonas, Antonia Nisioti, Dimitris Gritzalis, Vasilios Katos |
Comput. Secur. | 4 |
| 2016 | Combining Invariant Violation with Execution Path Classification for Detecting Multiple Types of Logical Errors and Race ConditionsabstractContext: Modern automated source code analysis techniques can be very successful in detecting a priori de- fined defect patterns and security vulnerabilities. Yet, they cannot detect flaws that manifest due to erroneous translation of the software’s functional requirements into the source code. The automated detection of logical errors that are attributed to a faulty implementation of applications’ functionality, is a relatively uncharted territory. In previous research, we proposed a combination of automated analyses for logical error detection. In this paper, we develop a novel business-logic oriented method able to filter mathematical depictions of software logic in order to augment logical error detection, eliminate previous limitations in analysis and provide a formal tested logical error detection classification without subjective discrepancies. As a proof of concept, our method has been implemented in a prototype tool called PLATO that can detect various types of logical errors. Potential logical errors are thus detected that are ranked using a fuzzy logic system with two scales characterizing their impact: (i) a Severity scale, based on the execution paths’ characteristics and Information Gain, (ii) a Reliability scale, based on the measured program’s Computational Density. The method’s effectiveness is shown using diverse experiments. Albeit not without restrictions, the proposed automated analysis seems able to detect a wide variety of logical errors, while at the same time limiting the false positives. George Stergiopoulos, Panagiotis Katsaros, Dimitris Gritzalis, Theodore K. Apostolopoulos |
SECRYPT | 3 |
| 2016 | Cyberoperations and international humanitarian law: A review of obstacles in applying international law rules in cyber warfareabstractPurpose – The increasing number of cyber attacks has transformed the “cyberspace” into a “battlefield”, bringing out “cyber warfare” as the “fifth dimension of war” and emphasizing the States’ need to effectively protect themselves against these attacks. The existing legal framework seem inadequate to deal effectively with cyber operations and, from a strictly legal standpoint, it indicates that addressing cyber attacks does not fall within the jurisdiction of just one legal branch. This is mainly because of the fact that the concept of cyber warfare itself is open to many different interpretations, ranging from cyber operations performed by the States within the context of armed conflict, under International Humanitarian Law, to illicit activities of all kinds performed by non-State actors including cybercriminals and terrorist groups. The paper initially presents major cyber-attack incidents and their impact on the States. On this basis, it examines the existing legal framework at the European and international levels. Furthermore, it approaches “cyber warfare” from the perspective of international law and focuses on two major issues relating to cyber operations, i.e. “jurisdiction” and “attribution”. The multi-layered process of attribution in combination with a variety of jurisdictional bases in international law makes the successful tackling of cyber attacks difficult. The paper aims to identify technical, legal and, last but not least, political difficulties and emphasize the complexity in applying international law rules in cyber operations. Design/methodology/approach – The paper focuses on the globalization of the “cyber warfare phenomenon” by observing its evolutionary process from the early stages of its appearance until today. It examines the scope, duration and intensity of major cyber-attacks throughout the years in relation to the reactions of the States that were the victims. Having this as the base of discussion, it expands further by exemplifying “cyber warfare” from the perspective of the existing European and International legal framework. The main aim of this part is to identify and analyze major obstacles that arise, for instance in terms of “jurisdiction” and “attribution” in applying international law rules to “cyber warfare”. Findings – The absence of a widely accepted legal framework to regulate jurisdictional issues of cyber warfare and the technical difficulties in identifying, with absolute certainty, the perpetrators of an attack, make the successful tackling of cyber attacks difficult. Originality/value – The paper fulfills the need to identify difficulties in applying international law rules in cyber warfare and constitutes the basis for the creation of a method that will attempt to categorize and rank cyber operations in terms of their intensity and seriousness. Kosmas Pipyros, Lilian Mitrou, Dimitris Gritzalis, Theodoros K. Apostolopoulos |
Inf. Comput. Secur. | 3 |
| 2015 | An Intensive Analysis of Security and Privacy Browser Add-Ons
Nikolaos Tsalis, Alexios Mylonas, Dimitris Gritzalis |
CRiSIS | 3 |
| 2015 | "Water, Water, Every Where": Nuances for a Water Industry Critical Infrastructure Specification Exemplar
Shamal Faily, George Stergiopoulos, Vasilios Katos, Dimitris Gritzalis |
CRITIS | 4 |
| 2015 | Access Control Issues in Utilizing Fog Computing for Transport Infrastructure
Stavros Salonikias, Ioannis Mavridis, Dimitris Gritzalis |
CRITIS | 3 |
| 2015 | Automated Exploit Detection using Path Profiling - The Disposition Should Matter, Not the PositionabstractAbstract: Recent advances in static and dynamic program analysis resulted in tools capable to detect various types of security bugs in the Applications under Test (AUTs). However, any such analysis is designed for a priori specified types of bugs and it is characterized by some rate of false positives or even false negatives and certain scalability limitations. We present a new analysis and source code classification technique, and a pro-totype tool aiming to aid code reviews in the detection of general information flow dependent bugs. Our approach is based on classifying the criticality of likely exploits in the source code using two measuring functions, namely Severity and Vulnerability. For an AUT, we analyse every single pair of input vector and program sink in an execution path, which we call an Information Block (IB). A classification technique is introduced for quantifying the Severity (danger level) of an IB by static analysis and computation of its En-tropy Loss. An IB’s Vulnerability is quantified using a tainted object propagation analysis along with a Fuzzy Logic system. Possible exploits are then characterized with respect to their Risk by combining the computed Severity and Vulnerability measurements through an aggregation operation over two fuzzy sets. An IB is characterized of a high risk, when both its Severity and Vulnerability rankings have been found to be above the low zone. In this case, a detected code exploit is reported by our prototype tool, called Entroine. The effectiveness of our approach has been tested by analysing 45 Java programs of NIST’s Juliet Test Suite, which implement three different common weakness exploits. All existing code exploits were detected without any false positive. 1 George Stergiopoulos, Panagiotis Petsanas, Panagiotis Katsaros, Dimitris Gritzalis |
SECRYPT | 4 |
| 2015 | Introduction to Social Media Investigation - A hands-on Approach, Jennifer Golbeck, Elsevier Publications, USA (2015)
Vasilis Stavrou, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2015 | Hacking and Penetration Testing with Low Power Devices
George Stergiopoulos, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2015 | Hacking Web Intelligence: Open Source Intelligence and Web Reconnaissance Concepts and Techniques, Sudhanshu Chauhan, Nutan Kumar Panda, Elsevier Publications, USA (2015)
Nikolaos Tsalis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2015 | Security Busters: Web browser security vs. rogue sites
Nikos Virvilis, Alexios Mylonas, Nikolaos Tsalis, Dimitris Gritzalis |
Comput. Secur. | 4 |
| 2014 | Automated Detection of Logical Errors in Programs
George Stergiopoulos, Panagiotis Katsaros, Dimitris Gritzalis |
CRiSIS | 3 |
| 2014 | Mobile Devices - A Phisher's ParadiseabstractMobile devices — especially smartphones — have gained widespread adoption in recent years, due to the plethora of features they offer. The use of such devices for web browsing and accessing email services is also getting continuously more popular. The same holds true with other more sensitive online activities, such as online shopping, contactless payments, and web banking. However, the security mechanisms that are available on smartphones and protect their users from threats on the web are not yet mature, as well as their effectiveness is still questionable. As a result, smartphone users face increased risks when performing sensitive online activities with their devices, compared to desktop/laptop users. In this paper, we present an evaluation of the phishing protection mechanisms that are available with the popular web browsers of Android and iOS. Then, we compare the protection they offer against their desktop counterparts, revealing and analyzing the significant gap between the two. Nikos Virvilis, Nikolaos Tsalis, Alexios Mylonas, Dimitris Gritzalis |
SECRYPT | 4 |
| 2014 | Business Process Modeling for Insider Threat Monitoring and Handling
Vasilis Stavrou, Miltiadis Kandias, Georgios Karoulas, Dimitris Gritzalis |
TrustBus | 4 |
| 2014 | Editorial
Lakshmish Ramaswamy, Barbara Carminati, Lujo Bauer, Dongwan Shin, James B. D. Joshi, Calton Pu, Dimitris Gritzalis |
Comput. Secur. | 7 |
| 2014 | Introduction to Computer and Network Security: Navigating Shades of Gray
Vasilis Stavrou, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2014 | A Bug Hunter's Diary
George Stergiopoulos, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2014 | Securing cloud and mobility: A practitioner's guide
Nikolaos Tsalis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2014 | Automatic Defense Against Zero-day Polymorphic Worms in Communication Networks
Nikos Virvilis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2014 | A game-theoretic analysis of preventing spam over Internet Telephony via audio CAPTCHA-based authenticationabstractSpam over Internet Telephony (SPIT) is a potential source of disruption in Voice over IP (VoIP) systems. The use of anti-SPIT mechanisms, such as filters and audio CAPTCHA (Completely Automated Public Turing Test to Tell Computer and Humans Apart) can prevent unsolicited calls and lead to less unwanted traffic. In this paper, we present a game-theoretic model, in which the game is played between SPIT senders and internet telephony users. The game includes call filters and audio CAPTCHA, so as to classify incoming calls as legitimate or malicious. We show how the resulting model can be used to decide upon the trade-offs present in this problem and help us predict the SPIT sender’s behavior. We also highlight the advantages in terms of SPIT call reduction of merely introducing CAPTCHA, and provide experimental verification of our results. Yannis Soupionis, Remous-Aris Koutsiamanis, Pavlos S. Efraimidis, Dimitris Gritzalis |
J. Comput. Secur. | 4 |
| 2013 | The Big Four - What We Did Wrong in Advanced Persistent Threat Detection?abstractAs both the number and the complexity of cyber-attacks continuously increase, it is becoming evident that current security mechanisms have limited success in detecting sophisticated threats. Stuxnet, Duqu, Flame and Red October have troubled the security community due to their severe complexity and their ability to evade detection - in some cases for several years. The significant technical and financial resources needed for orchestrating such complex attacks are a clear indication that perpetrators are well organized and, likely, working under a state umbrella. In this paper we perform a technical analysis of these advanced persistent threats, highlighting particular characteristics and identifying common patterns and techniques. We also focus on the issues that enabled the malware authors to evade detection from a wide range of security solutions and propose technical countermeasures for strengthening our defenses against similar threats. Nikos Virvilis, Dimitris Gritzalis |
ARES | 2 |
| 2013 | Privacy Risk, Security, Accountability in the CloudabstractMigrating data, applications or services to the cloud exposes a business to a number of new threats and vulnerabilities, which need to be properly assessed. Assessing privacy risk in cloud environments remains a complex challenge, mitigation of this risk requires trusting a cloud service provider to implement suitable privacy controls. Furthermore, auditors and authorities need to be able to hold service providers accountable for their actions, enforcing rules and regulations through penalties and other mechanisms, and ensuring that any problems are remedied promptly and adequately. This paper examines privacy risk assessment for cloud, and identifies threats, vulnerabilities and countermeasures that clients and providers should implement in order to achieve privacy compliance and accountability. Marianthi Theoharidou, Nikolaos Papanikolaou 0001, Siani Pearson, Dimitris Gritzalis |
CloudCom (1) | 4 |
| 2013 | Return on Security Investment for Cloud PlatformsabstractCloud migration is a complex decision because of the multiple parameters that contribute for or against it (e.g. available budget, costs, performance, etc.). One of these parameters is information security and the investment required in order to ensure it. A potential client needs to evaluate various deployment options and Cloud Service Providers (CSP). This paper proposes a set of metrics focused on the assessment of security controls of a cloud deployment, in terms of cost and mitigation. Such an approach can support the client to decide whether she selects to deploy part of her services, data or infrastructure to a CSP, or not. Nikolaos Tsalis, Marianthi Theoharidou, Dimitris Gritzalis |
CloudCom (2) | 3 |
| 2013 | Insiders Trapped in the Mirror Reveal Themselves in Social Media
Miltiadis Kandias, Konstantina Galbogini, Lilian Mitrou, Dimitris Gritzalis |
NSS | 4 |
| 2013 | On Business Logic Vulnerabilities Hunting: The APP_LogGIC Framework
George Stergiopoulos, Bill Tsoumas, Dimitris Gritzalis |
NSS | 3 |
| 2013 | Which Side Are You On? - A New Panopticon vs. Privacy
Miltiadis Kandias, Lilian Mitrou, Vasilis Stavrou, Dimitris Gritzalis |
SECRYPT | 4 |
| 2013 | Approaching Encryption through Complex Number Logarithms
George Stergiopoulos, Miltiadis Kandias, Dimitris Gritzalis |
SECRYPT | 3 |
| 2013 | A Qualitative Metrics Vector for the Awareness of Smartphone Security Users
Alexios Mylonas, Dimitris Gritzalis, Bill Tsoumas, Theodore K. Apostolopoulos |
TrustBus | 2 |
| 2013 | Cybercrime in the Digital Economy - Editorial
Dimitris Gritzalis, Gurvirender Tejay 0001 |
Comput. Secur. | 1 |
| 2013 | Metasploit the Penetration Tester's Guide
Miltiadis Kandias, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2013 | Delegate the smartphone user? Security awareness in smartphone platforms
Alexios Mylonas, Anastasia Kastania, Dimitris Gritzalis |
Comput. Secur. | 3 |
| 2013 | Smartphone sensor data as digital evidence
Alexios Mylonas, Vasilis Meletiadis, Lilian Mitrou, Dimitris Gritzalis |
Comput. Secur. | 4 |
| 2013 | Hacking VoIP
Yannis Soupionis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2012 | Probabilistic Model Checking of CAPTCHA Admission Control for DoS Resistant Anti-SPIT Protection
Emmanouela Stachtiari, Yannis Soupionis, Panagiotis Katsaros, Anakreon Mentis, Dimitris Gritzalis |
CRITIS | 5 |
| 2012 | Smartphone Forensics: A Proactive Investigation Scheme for Evidence Acquisition
Alexios Mylonas, Vasilis Meletiadis, Bill Tsoumas, Lilian Mitrou, Dimitris Gritzalis |
SEC | 5 |
| 2012 | A Risk Assessment Method for Smartphones
Marianthi Theoharidou, Alexios Mylonas, Dimitris Gritzalis |
SEC | 3 |
| 2012 | Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
Alexios Mylonas, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2012 | Inside Cyber Warfare: Mapping the Cyber Underworld
Bill Tsoumas, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2011 | ASPF: Adaptive anti-SPIT Policy-based FrameworkabstractSPam over Internet Telephony (SPIT) is a rising IP voice telephony threat. Voice over IP enables the transmission of telephone calls over the Internet, as opposed to plain old telephone service. Internet Telephony essentially means low-cost phone calls, i.e. a clear benefit for both consumers and businesses, which may also lead to cheap methods of mass advertising. Still, industry observers warn that VoIP's low-cost and openness makes it relatively easy for spammers to send unsolicited audio-commercials to VoIP voice-mail inboxes, in much the same way they currently bombard e-mail inboxes. In this paper we set the foundations of an adaptive approach that handles SPIT through an adaptive anti-SPIT policy-based framework (ASPF). ASPF incorporates a set of rules for SPIT detection, together with appropriate actions and controls that should be enforced, so as to counter these attacks. ASPF is formally described through an XML schema. A working prototype is also demonstrated for evaluating ASPF. The prototype is able to make policy alterations, based on abnormal network events. Yannis Soupionis, Dimitris Gritzalis |
ARES | 2 |
| 2011 | The Insider Threat in Cloud Computing
Miltiadis Kandias, Nikos Virvilis, Dimitris Gritzalis |
CRITIS | 3 |
| 2011 | Interdependencies between Critical Infrastructures: Analyzing the Risk of Cascading Effects
Panayiotis Kotzanikolaou, Marianthi Theoharidou, Dimitris Gritzalis |
CRITIS | 3 |
| 2011 | Exploitation of auctions for outsourcing security-critical projectsabstractICT outsourcing may introduce several risks. This paper attempts to mitigate this problem by applying an auctioning scheme. By adopting the scheme, the involved organization selects one or more potential outsourced service providers via an auction similar to the FCC spectrum ones. The project is divided in sub-projects, bidders are pre-evaluated, in terms of security and each bid is assessed in terms of cost and appropriate security metrics. The bidding process continues according to the auction rules allocating all the sub-projects to the best bidders. The ultimate goal is to achieve upgraded security, while keeping the cost at a reasonable level and meeting adequate security requirements. In this direction our model provokes competition and motivates providers to place superior bids, in terms of security, while providing flexibility to the organization. The auction process is demonstrated through a case study, where the outsourcer is a critical infrastructure organization. Miltiadis Kandias, Alexios Mylonas, Marianthi Theoharidou, Dimitris Gritzalis |
ISCC | 4 |
| 2011 | Smartphone Security Evaluation - The Malware Attack Case
Alexios Mylonas, Stelios Dritsas, Bill Tsoumas, Dimitris Gritzalis |
SECRYPT | 4 |
| 2011 | A Secure Smartphone Applications Roll-out Scheme
Alexios Mylonas, Bill Tsoumas, Stelios Dritsas, Dimitris Gritzalis |
TrustBus | 4 |
| 2011 | Secure Cloud Storage: Available Infrastructures and Architectures Review and Evaluation
Nikos Virvilis, Stelios Dritsas, Dimitris Gritzalis |
TrustBus | 3 |
| 2011 | Editorial
Dimitris Gritzalis, James B. D. Joshi |
Comput. Secur. | 1 |
| 2011 | Guest Editor's Prefaceabstractwas held on September 2010 in Athens, Greece.The symposium has a tradition that goes back for two decades.It brings together the international research community in a top quality event that covers all the areas of computer security, ranging from theory to applications.ESORICS-2010 received 201 submissions, which went through a careful review process.As a result of this process, 42 papers were selected for the final program (21% acceptance rate).To further promote the fast-evolving research in security, a few research papers were selected, among those published in the proceedings of ESORICS-2010, for a Special Issue in the Journal of Computer Security.These papers were significantly extended and went through another rigorous review.As a result, the Special Issue finally includes four papers.The papers reflect different aspects of security, ranging from RFID privacy and PKI-based systems, to information flow, and the IO2BO threat.A brief description of them is provided below.In their paper, entitled "On bounding problems of quantitative information flow", H. Yasuoka and T. Terauchi investigate the hardness of precisely checking the quantitative information flow of a program.More precisely, the authors study the "bounding problem" of quantitative information flow, defined as follows: Given a program M and a positive real number q, decide if the quantitative information flow of M is less than or equal to q. Authors prove that the bounding problem is not a k-safety property for any k (even when q is fixed, for the Shannon-entropy-based definition with the uniform distribution), and thus is not amenable to the self-composition technique that has been successfully applied to checking non-interference.They also prove complexity theoretic hardness results for the case when the program is restricted to loop-free Boolean programs.C. Zhang, T. Wang, T. Wei, Y. Chen and W. Zou, in their paper, entitled "Using type analysis in compiler to mitigate integer-overflow-to-buffer-overflow threat", deal with one of the top two causes of software vulnerabilities in operating systems, i.e., the integer overflow and, in specific, the Integer Overflow to Buffer Overflow (IO2BO) vulnerability.Authors present the design and implementation of IntPatch, a compiler extension for automatically fixing IO2BO vulnerabilities in C/C++ programs at compile time.IntPatch utilizes classic type theory and a dataflow analysis framework to identify potential IO2BO vulnerabilities.Then uses backward slicing to find out related vulnerable arithmetic operations and instruments programs with Dimitris Gritzalis |
J. Comput. Secur. | 1 |
| 2011 | SPIDER: A platform for managing SIP-based Spam over Internet Telephony (SPIT)abstractThe Session Initiation Protocol (SIP) has become the first widely adopted protocol for managing IP-based telephony, video, and multimedia sessions. SIP advertises a contact point of an individual to the Web. This contact point, similar to an e-mail address, can be exploited for spam purposes. Spam over Internet Telephony, also called SPIT, in general denotes any bulk unsolicited information sent to any potential calling-end of a VoIP infrastructure. Even though SPIT is a new concept, it is more reasonable to address this problem right now, rather than waiting until the problem prevails. To mitigate SPIT, adequate technical countermeasures are required. The solution space may expand to nontechnical ones, as well. In this paper, we propose the SPIDER (SPam over Internet telephony Detection sERvice) platform, a modular and efficient system for fighting SPIT. SPIDER orchestrates several discrete modules that parse, analyze, process, and classify incoming SIP call requests. We discuss technical design details of the individual modules, that this platform consists of; then, we present how these modules are combined to support accurate decisions for any incoming SIP call being legitimate or not. Furthermore, we include a comprehensive evaluation scenario, which refers to the tests performed on the individual modules and on the integrated platform. Evaluation results indicate that the overall architecture manages to identify SPIT calls with low false ratio by using reasonable processing resources and tolerable decision time. Dimitris Gritzalis, Giannis F. Marias, Yacine Rebahi, Yannis Soupionis, Sven Ehlert |
J. Comput. Secur. | 1 |
| 2010 | A Formally Verified Mechanism for Countering SPIT
Yannis Soupionis, Stylianos Basagiannis, Panagiotis Katsaros, Dimitris Gritzalis |
CRITIS | 4 |
| 2010 | A Cloud Provider-Agnostic Secure Storage Protocol
Nikos Virvilis, Stelios Dritsas, Dimitris Gritzalis |
CRITIS | 3 |
| 2010 | An Insider Threat Prediction Model
Miltiadis Kandias, Alexios Mylonas, Nikos Virvilis, Marianthi Theoharidou, Dimitris Gritzalis |
TrustBus | 5 |
| 2010 | Editorial
Dimitris Gritzalis, Jan H. P. Eloff |
Comput. Secur. | 1 |
| 2010 | Editorial
Dimitris Gritzalis, Javier López 0001 |
Comput. Secur. | 1 |
| 2010 | Editorial
Dimitris Gritzalis, Pierangela Samarati |
Comput. Secur. | 1 |
| 2010 | Editorial
Dimitris Gritzalis, Sabrina De Capitani di Vimercati |
Comput. Secur. | 1 |
| 2010 | Audio CAPTCHA: Existing solutions assessment and a new implementation for VoIP telephony
Yannis Soupionis, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2010 | A multi-layer Criticality Assessment methodology based on interdependencies
Marianthi Theoharidou, Panayiotis Kotzanikolaou, Dimitris Gritzalis |
Comput. Secur. | 3 |
| 2010 | e-Passports as a means towards a Globally Interoperable Public Key InfrastructureabstractMillions of citizens around the world have already acquired their new electronic passport. The e-passport is equipped with contactless communication capability, as well as with an Integrated Circuit Chip enabling cryptographic functionality. Countries are required to build a national Public Key Infrastructure to support digital signatures, as this is considered the basic mechanism to prove the authenticity and integrity of the Machine Readable Travel Documents. The first, large-scale, worldwide PKI is currently under construction, by means of bilateral trust relationships between Countries. In this paper, we propose a set of good practices, which are essential for the establishment of a global identification scheme based on e-passports, together with an analysis of the security and privacy issues that may arise. We argue that an e-passport may also be exploited in other applications as a globally interoperable PKI-enabled tamperproof device. The preconditions, the benefits and the drawbacks of using e-passports in everyday electronic activities are further analyzed and assessed. Dimitrios Lekkas, Dimitris Gritzalis |
J. Comput. Secur. | 2 |
| 2009 | BLAST: Off-the-Shelf Hardware for Building an Efficient Hash-Based Cluster Storage SystemabstractDuring the past few years, large, reliable and efficient storage systems have become increasingly important in enterprise environments. Additional requirements for these environments include low installation, maintenance and administration costs. In this paper we propose a hash-based storage approach, combined with block-level operating system semantics. The experimental evaluation confirms that the proposed approach is viable and can offer a cost-effective storage solution. George Parisis, George Xylomenos, Dimitris Gritzalis |
NPC | 3 |
| 2009 | Audio CAPTCHA for SIP-Based VoIP
Yannis Soupionis, George Tountas, Dimitris Gritzalis |
SEC | 3 |
| 2009 | OntoSPIT: SPIT management through ontologies
Stelios Dritsas, Vicky Dritsou, Bill Tsoumas, Panos Constantopoulos, Dimitris Gritzalis |
Comput. Commun. | 5 |
| 2009 | Editorial
Dimitris Gritzalis, Steven Furnell |
Comput. Secur. | 1 |
| 2009 | Editorial
Dimitris Gritzalis, Sokratis K. Katsikas |
Comput. Secur. | 1 |
| 2009 | Editorial
Dimitris Gritzalis, Tom Karygiannis |
Comput. Secur. | 1 |
| 2009 | Editorial
Dimitris Gritzalis, Javier López 0001 |
Comput. Secur. | 1 |
| 2008 | An Adaptive Policy-Based Approach to SPIT Management
Yannis Soupionis, Stelios Dritsas, Dimitris Gritzalis |
ESORICS | 3 |
| 2008 | SPIT Identification Criteria Implementation: Effectiveness and Lessons Learned
Stelios Dritsas, Yannis Soupionis, Marianthi Theoharidou, Yannis Mallios, Dimitris Gritzalis |
SEC | 5 |
| 2008 | A SIP-oriented SPIT Management Framework
Dimitris Gritzalis, Yannis Mallios |
Comput. Secur. | 1 |
| 2007 | Attack Modeling of SIP-Oriented SPIT
John Mallios, Stelios Dritsas, Bill Tsoumas, Dimitris Gritzalis |
CRITIS | 4 |
| 2007 | SIP Vulnerabilities and Anti-SPIT Mechanisms AssessmentabstractAlthough VoIP provides new ways of communication, at the same time it offers new possibilities for transmitting bulk unsolicited messages and calls, enabling spam over internet telephony (SPIT). The VoIP prevailing protocol is SIP, which it is vulnerable to threats that allow SPIT to be deployed. In this paper we assess the risk of identified threats and vulnerabilities of the SIP protocol. Then, we conduct an analytical survey of already proposed anti-SPIT techniques and we evaluate their effectiveness, in terms of how they deal with the threats and vulnerabilities. Finally, we complete our evaluation by presenting a theoretical evaluation framework, based on additional qualitative and quantitative criteria. Giannis F. Marias, Stelios Dritsas, Marianthi Theoharidou, John Mallios, Dimitris Gritzalis |
ICCCN | 5 |
| 2007 | Threat Analysis of the Session Initiation Protocol Regarding SpamabstractVoice over Internet protocol (VoIP) is becoming increasingly popular due to its significant advantages regarding cost and support of enhanced multimedia services. Despite of the substantial advantages of using the Internet as the transmission medium for voice calls, we can foresee many undesirable uses, especially in terms of spam. VoIP technology may provide new means for the transmission of bulk unsolicited messages and calls (spam over Internet telephony - SPIT), mainly due to the reduced cost compared to traditional telephony. Therefore, mechanisms are essential to address the SPIT problem, while maintaining the advantages of VoIP technology. In this paper we conduct a comprehensive threat analysis that addresses the ascendant VoIP protocol, the session initiation protocol, in terms of its vulnerability regarding SPIT deliverance. Our analysis introduces the requirements that the mechanisms dealing with the SPIT phenomenon should take into account, in order to be feasible and efficient. Stelios Dritsas, John Mallios, Marianthi Theoharidou, Giannis F. Marias, Dimitris Gritzalis |
IPCCC | 5 |
| 2007 | Addressing Cultural Dissimilarity in the Information Security Management Outsourcing Relationship
Aggeliki Tsohou, Marianthi Theoharidou, Spyros Kokolakis, Dimitris Gritzalis |
TrustBus | 4 |
| 2006 | Towards an Ontology-based Security ManagementabstractThe paramount complexity of enterprise in formation leads to hard-to-deal security management issues and system configurations. We present a security management framework of an arbitrary information system (IS) which builds upon knowledge-based resources, such as security ontology (SO) providing reusable security knowledge interoperability, aggregation and reasoning exploiting security knowledge from diverse sources; in addition, the separation of security requirements from their technical implementations facilitates the security management. We provide a feasible framework which links the high-level policy statements and deployable security controls and facilitates the security expert's work Bill Tsoumas, Dimitris Gritzalis |
AINA (1) | 2 |
| 2006 | Security-by-Ontology: A Knowledge-Centric ApproachabstractWe present a security ontology (SO), which can be used as a basis of security management of an arbitrary information system. This SO provides capabilities, such as modeling of risk assessment knowledge, abstraction of security requirements, reusable security knowledge interoperability, aggregation and reasoning. The SO is based on the exploitation of security-related knowledge, derived from diverse sources. We demonstrate that the establishment of such a framework is feasible and, furthermore, that a SO can support critical security activities of an expert, e.g. security requirements identification, as well as selection of certain countermeasures. We also present and discuss an implementation of a specific SO. The implementation is accompanied by results regarding how a SO can be built and populated with security information. Bill Tsoumas, Panagiotis Papagiannakopoulos, Stelios Dritsas, Dimitris Gritzalis |
SEC | 4 |
| 2006 | A Generic Privacy Enhancing Technology for Pervasive Computing Environments
Stelios Dritsas, John Tsaparas, Dimitris Gritzalis |
TrustBus | 3 |
| 2005 | Technical guidelines for enhancing privacy and data protection in modern electronic medical environmentsabstractRaising awareness and providing guidance to on-line data protection is undoubtedly a crucial issue worldwide. Equally important is the issue of applying privacy-related legislation in a coherent and coordinated way. Both these topics gain extra attention when referring to medical environments and, thus, to the protection of patients' privacy and medical data. Electronic medical transactions require the transmission of personal and medical information over insecure communication channels like the Internet. It is, therefore, a rather straightforward task to capture the electronic medical behavior of a patient, thus constructing "patient profiles," or reveal sensitive information related to a patient's medical history. The consequence is clearly a potential violation of the patient's privacy. We performed a risk analysis study for a Greek shared care environment for the treatment of patients suffering from beta-thalassemia, an empirically embedded scenario that is representative of many other electronic medical environments; we capitalized on its results to provide an assessment of the associated risks, focusing on the description of countermeasures, in the form of technical guidelines that can be employed in such medical environments for protecting the privacy of personal and medical information. Dimitris Gritzalis, Costas Lambrinoudakis, Dimitrios Lekkas, S. Deftereos |
IEEE Trans. Inf. Technol. Biomed. | 1 |
| 2004 | Cumulative notarization for long-term preservation of digital signatures
Dimitrios Lekkas, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2004 | Embedding privacy in IT applications developmentabstractA considerable research stream in information systems security has elaborated several propositions as to how privacy and anonymity can be protected, the most prominent of which make use of encryption and digital signing. Since privacy protection is a persistent topic in most electronically performed activities, the icreasing popularity of Internet has driven researchers to approach privacy protection in a holistic way. As a result, privacy‐enhancing technologies have been put forth, aiming at protecting users against privacy and anonymity threats and vulnerabilities. Nowadays, that privacy protection has to be incorporated in most IT applications is one of the least controversial statements. This paper describes Privacy Protector, a technological means for enhancing privacy in an IT application development process. Privacy Protector comprises of a set of software services that have been built upon generic, privacy‐focused user requirements. The paper also describes an API that can be used for incorporating Privacy Protector in the development framework of an IT application. Dimitris Gritzalis |
Inf. Manag. Comput. Secur. | 1 |
| 2003 | ADoCSI: towards a transparent mechanism for disseminating Certificate Status Information
John Iliadis, Stefanos Gritzalis, Dimitris Gritzalis |
Comput. Commun. | 3 |
| 2003 | Towards a framework for evaluating certificate status information mechanisms
John Iliadis, Stefanos Gritzalis, Diomidis Spinellis, Danny De Cock, Bart Preneel, Dimitris Gritzalis |
Comput. Commun. | 6 |
| 2002 | Elaborating Quantitative Approaches for IT Security Evaluation
Dimitris Gritzalis, Maria Karyda 0001, Lazaros Gymnopoulos |
SEC | 1 |
| 2002 | Functional Requirements for a Secure Electronic Voting System
Spyros Ikonomopoulos, Costas Lambrinoudakis, Dimitris Gritzalis, Spyros Kokolakis, K. Vassiliou |
SEC | 3 |
| 2002 | Revisiting Legal and Regulatory Requirements for Secure E-Voting
Lilian Mitrou, Dimitris Gritzalis, Sokratis K. Katsikas |
SEC | 2 |
| 2002 | Panoptis: Intrusion Detection Using a Domain-Specific LanguageabstractWe describe the use of a domain-specific language (DSL) for expressing critical design values and constraints in an intrusion detection application. Through the use of this specialised language, information that is critical to the correct operation of the software can be expressed in a form that ca n be easily drafted, verified, and maintained by domain experts (security officers), thus minimising the risk inherent from the mediation of software engineers. Our application, Panoptis, is a DSL-based low-cost, easy-to-use intrusion detection system using the process accounting records kept by most Unix systems. A set of database tables contain resource usage profiles for processes, terminals, users, and time intervals. Panoptis monitors new process data against the recorded profiles and reports on entities diverging from the established resource usage envelopes implying possible data security threats. We demonstrate the operation of Panoptis by a case study of a real attack and subsequent system compromise that occured on a system under our administrative control. Diomidis Spinellis, Dimitris Gritzalis |
J. Comput. Secur. | 2 |
| 2001 | Pythia: Towards Anonymity in Authentication
Dimitris Gritzalis, Konstantinos Moulinos, John Iliadis, Costas Lambrinoudakis, S. Xarhoulacos |
SEC | 1 |
| 2001 | A digital seal solution for deploying trust on commercial transactionsabstractTraditional business practice depends on trust relations between the transacting parties. One of the most important aspects of this trust is the quality of the offered services or products. The Web currently constitutes an enabler for electronic commerce, providing a global transaction platform that does not require physical presence. However, transferring trust from the physical world to the electronic one is a process that requires a trust infrastructure. The current infrastructure, based on trusted third parties can be enhanced. We introduce the notion of digital seals and provide a mechanism for transferring the trust placed by users in companies in the physical world, to the electronic one. Stefanos Gritzalis, Dimitris Gritzalis |
Inf. Manag. Comput. Secur. | 2 |
| 2000 | Evaluating certificate status information mechanismsabstractA wide spectrum of certificate revocation mechanisms is currently in use. A number of them have been proposed by standardisation bodies, while some others have originated from academic or private institutions. What is still missing is a systematic and robust framework for the sound evaluation of these mechanisms. We present a mechanism-neutral framework for the evaluation of mechanisms, which collect, process and distribute certificate status information. A detailed demonstration of its exploitation is also provided. The demonstration is mainly based on the evaluation of Certificate Revocation Lists, as well as of the Online Certificate Status Protocol. John Iliadis, Diomidis Spinellis, Dimitris Gritzalis, Bart Preneel, Sokratis K. Katsikas |
CCS | 3 |
| 2000 | A Qualitative Approach to Information Availability
Theodore Tryfonas, Dimitris Gritzalis, Spyros Kokolakis |
SEC | 2 |
| 1999 | Trusted third party services for deploying secure telemedical applications over the WWW
Diomidis Spinellis, Stefanos Gritzalis, John Iliadis, Dimitris Gritzalis, Sokratis K. Katsikas |
Comput. Secur. | 4 |
| 1997 | A baseline security policy for distributed healthcare information systems
Dimitris Gritzalis |
Comput. Secur. | 1 |
| 1996 | Towards a formal system-to-system authentication protocol
Dimitris Gritzalis, Sokratis K. Katsikas |
Comput. Commun. | 1 |
| 1996 | Model for network behaviour under viral attack
Sokratis K. Katsikas, Thomas Spyrou, Dimitris Gritzalis, John Darzentas |
Comput. Commun. | 3 |
| 1995 | Design of a neural network for recognition and classification of computer viruses
Anastasia Doumas, Konstantinos Mavroudakis, Dimitris Gritzalis, Sokratis K. Katsikas |
Comput. Secur. | 3 |
| 1994 | Intrusion detection: Approach and performance issues of the SECURENET system
Michel Denault, Dimitris Karagiannis, Dimitris Gritzalis, Paul G. Spirakis |
Comput. Secur. | 3 |
| 1992 | A zero knowledge probabilistic login protocol
Dimitris Gritzalis, Sokratis K. Katsikas, Stefanos Gritzalis |
Comput. Secur. | 1 |
| 1992 | Determining access rights for medical information systems
Dimitris Gritzalis, Sokratis K. Katsikas, J. Keklikoglou, A. Tomaras |
Comput. Secur. | 1 |
| 1991 | Data security in medical information systems: The Greek case
Dimitris Gritzalis, A. Tomaras, Sokratis K. Katsikas, J. Keklikoglou |
Comput. Secur. | 1 |