VLDB 2026 Research / reviewers in the wild / expert
Georgios Kontaxis
dblp:48/9075
· DBLP profile ↗
6ranked-venue papers
3as first author
0since 2021 · last 2016
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-authorDatabases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Authentication and access control · 45% Network security · 21% Privacy and data protection · 20% | |
| Computer networks
2 papers |
Internet architecture and protocols · 87% Content delivery and video streaming · 13% | |
| Databases, data mining, and information retrieval
1 paper |
Web and social media mining · 100% | |
| Artificial intelligence
1 paper |
Face, body and person analysis · 100% |
Topics — the 9 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Internet architecture and protocols › overlay networks
overlay routing |
0.2 | 1 | 2016 | Protecting Insecure Communications with Topology-aware Network Tunnels · CCS 2016 |
Authentication and access control › knowledge-based authentication › graphical password
image-based authentication |
0.2 | 1 | 2014 | Faces in the Distorting Mirror: Revisiting Photo-based Social Authentication · CCS 2014 |
Authentication and access control › user authentication
social authentication |
0.2 | 1 | 2014 | Faces in the Distorting Mirror: Revisiting Photo-based Social Authentication · CCS 2014 |
Privacy and data protection › data confidentiality
credential protection |
0.2 | 1 | 2013 | SAuth: protecting user accounts from password database leaks · CCS 2013 |
Authentication and access control
password authentication |
0.2 | 1 | 2013 | SAuth: protecting user accounts from password database leaks · CCS 2013 |
Cryptographic primitives and cryptanalysis › hash functions
password hashing |
0.2 | 1 | 2013 | SAuth: protecting user accounts from password database leaks · CCS 2013 |
Privacy and data protection
communication privacy |
0.1 | 1 | 2016 | Protecting Insecure Communications with Topology-aware Network Tunnels · CCS 2016 |
Computer vision › Face, body and person analysis
face recognition |
0.1 | 1 | 2014 | Faces in the Distorting Mirror: Revisiting Photo-based Social Authentication · CCS 2014 |
Content delivery and video streaming
web performance |
0.0 | 1 | 2011 | we.b: the web of short urls · WWW 2011 |
Methods — techniques the papers use, named apart from their topics
overlay routing · 0.5network measurement · 0.5image comparison · 0.4measurement study · 0.2crawl analysis · 0.2one-way hash function · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2016 | Protecting Insecure Communications with Topology-aware Network TunnelsabstractUnencrypted and unauthenticated protocols present security and privacy risks to end-to-end communications. At the same time we observe that only 30% of popular web servers offer HTTPS. Even when services support it, implementation vulnerabilities threaten their security. In this paper we propose an architecture called Topology-aware Network Tunnels (TNT) which minimizes insecure network paths to Internet services without their participation. TNT is not a substitute for TLS. We determine that popular web destinations are collocated in a small set of networks with 10 autonomous systems hosting 66% of traffic. At the same time cloud providers own these networks or are very close to them. Therefore clients can strategically establish secure tunnels to these providers and route their traffic through them. As a result adversaries not able to compromise the web service or its hosting provider are presented with encrypted and authenticated traffic instead of today's plain text. The strategic placement of network tunnels, gathering of network intelligence and routing decisions of the TNT architecture are not found in VPN services, network proxies or Tor. Existing overlay routing systems such as RON and one-hop source routing cannot substitute TNT. We implement our proposal as a routing software suite and evaluate it extensively using diverse cloud and ISP networks. We eliminate plain-text traffic to the Internet for 20% of web servers, reduce it to 1 network hop for an additional 20% and minimize it for the rest. We preserve the original network latency and page load time. TNT is practical and can be deployed by clients today. Georgios Kontaxis, Angelos D. Keromytis |
CCS | 1 |
| 2014 | Faces in the Distorting Mirror: Revisiting Photo-based Social AuthenticationabstractIn an effort to hinder attackers from compromising user accounts, Facebook launched a form of two-factor authentication called social authentication (SA), where users are required to identify photos of their friends to complete a log-in attempt. Recent research, however, demonstrated that attackers can bypass the mechanism by employing face recognition software. Here we demonstrate an alternative attack. that employs image comparison techniques to identify the SA photos within an offline collection of the users' photos. Iasonas Polakis, Panagiotis Ilia, Federico Maggi 0001, Marco Lancini, Georgios Kontaxis, Stefano Zanero, Sotiris Ioannidis, Angelos D. Keromytis |
CCS | 5 |
| 2013 | SAuth: protecting user accounts from password database leaksabstractPassword-based authentication is the dominant form of access control in web services. Unfortunately, it proves to be more and more inadequate every year. Even if users choose long and complex passwords, vulnerabilities in the way they are managed by a service may leak them to an attacker. Recent incidents in popular services such as LinkedIn and Twitter demonstrate the impact that such an event could have. The use of one-way hash functions to mitigate the problem is countered by the evolution of hardware which enables powerful password-cracking platforms. Georgios Kontaxis, Elias Athanasopoulos, Georgios Portokalidis, Angelos D. Keromytis |
CCS | 1 |
| 2012 | All your face are belong to us: breaking Facebook's social authenticationabstractTwo-factor authentication is widely used by high-value services to prevent adversaries from compromising accounts using stolen credentials. Facebook has recently released a two-factor authentication mechanism, referred to as Social Authentication, which requires users to identify some of their friends in randomly selected photos. A recent study has provided a formal analysis of social authentication weaknesses against attackers inside the victim's social circles. In this paper, we extend the threat model and study the attack surface of social authentication in practice, and show how any attacker can obtain the information needed to solve the challenges presented by Facebook. We implement a proof-of-concept system that utilizes widely available face recognition software and cloud services, and evaluate it using real public data collected from Facebook. Under the assumptions of Facebook's threat model, our results show that an attacker can obtain access to (sensitive) information for at least 42% of a user's friends that Facebook uses to generate social authentication challenges. By relying solely on publicly accessible information, a casual attacker can solve 22% of the social authentication tests in an automated fashion, and gain a significant advantage for an additional 56% of the tests, as opposed to just guessing. Additionally, we simulate the scenario of a determined attacker placing himself inside the victim's social circle by employing dummy accounts. In this case, the accuracy of our attack greatly increases and reaches 100% when 120 faces per friend are accessible by the attacker, even though it is very accurate with as little as 10 faces. Iasonas Polakis, Marco Lancini, Georgios Kontaxis, Federico Maggi 0001, Sotiris Ioannidis, Angelos D. Keromytis, Stefano Zanero |
ACSAC | 3 |
| 2011 | SudoWeb: Minimizing Information Disclosure to Third Parties in Single Sign-on Platforms
Georgios Kontaxis, Michalis Polychronakis, Evangelos P. Markatos |
ISC | 1 |
| 2011 | we.b: the web of short urlsabstractShort URLs have become ubiquitous. Especially popular within social networking services, short URLs have seen a significant increase in their usage over the past years, mostly due to Twitter's restriction of message length to 140 characters. In this paper, we provide a first characterization on the usage of short URLs. Specifically, our goal is to examine the content short URLs point to, how they are published, their popularity and activity over time, as well as their potential impact on the performance of the web. Demetres Antoniades, Iasonas Polakis, Georgios Kontaxis, Elias Athanasopoulos, Sotiris Ioannidis, Evangelos P. Markatos, Thomas Karagiannis |
WWW | 3 |