George C. Oikonomou

dblp:51/6801 · also George Oikonomou, Georgios Oikonomou · DBLP profile ↗
← Back
54ranked-venue papers
2as first author
17since 2021 · last 2026
0000-0002-1684-6989ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 18 · 1 first-author · 5 since 2021Security and privacy · 10 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3Artificial intelligence and machine learning · 2Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 Multi-Modal Model for Embedding Network and Audit Data for IoT Anomaly Detection
abstract
Current IoT infrastructures generate heterogeneous telemetry and primarily include network (inter-host information) and audit data (intra-host information). Most intrusion detection approaches use network or host information but not both. Specific to resource-constrained environments, like Internet of Things (IoT) systems, there remains a lack of anomaly detection research into multimodal techniques. We propose a multimodal fusion approach that combines network and host telemetry data to improve intrusion detection accuracy while maintaining computational efficiency. To address resource constraints, our approach applies dimensionality reduction to reduce memory and computational requirements. We evaluated our approach on a suitable IoT dataset with network and host (Windows 7 and 10) features already extracted. Our experimental evaluation demonstrates two critical findings. First, multi-modal fusion significantly improved detection accuracy across all evaluated models. The 1D-CNN mod el improved by 17.60 percentage points from 81.72% to 99.32%, while tree ensembles (XGBoost and Random Forest) achieved ideal accuracy. Unsupervised methods also benefited substantially, with Agglomerative Clustering increasing from 0.2173 to 0.6304 Adjusted Rand Index. Second, we demonstrate that the fused feature space can be dimensionally reduced to less than half the features while maintaining comparable accuracy performance, reducing computational requirements. We found that PCA performed as well as UMAP regarding accuracy but was considerably faster (54x speedup) at reducing the feature space. The proposed approach demonstrates robustness to class imbalance and provides practical deployment guidance for resource constrained IoT environments, with comprehensive benchmarking across over 15 model architectures including traditional machine learning, deep learning, and transformer-based approaches.
Pratyush Singh, George C. Oikonomou, James Pope
ICISSP (2)4
2026 xApp distillation: AI-based conflict mitigation in B5G O-RAN
abstract
• The novel xApp distillation method transforms conflicting xApps into a single enhanced model, reducing network outages by up to 83.3% compared to team learning approaches while maintaining consistent service quality. • Unlike conventional O-RAN conflict mitigation that discards valuable information, xApp distillation leverages knowledge from multiple xApps (ML-based and heuristic) to create a comprehensive decision-making model that eliminates inter-xApp conflicts. • The proposed approach enables telecommunication providers to extract value from separately purchased xApps through policy distillation, creating a scalable solution that preserves specialized capabilities while improving overall network. The advancements of machine learning-based xApps in Open Radio Access Network (O-RAN) have created research and industrial opportunities. One of the major advantages of Machine Learning (ML)-based xApps over heuristic methods is the ability to learn the dynamics of the environment and predict upcoming instances. Typically, xApps are trained and fine-tuned for specific objectives. However, telecommunication companies often deploy multiple xApps in overlapping areas. Given the different design objectives of xApps, this deployment strategy can lead to conflicts. Current conflict mitigation schemes proposed by the O-RAN Alliance are rule-based, either ignoring some of the xApps or rolling back their actions. This leads to performing the same action for a different state of the network, resulting in suboptimal mitigation. To prevent this suboptimal mitigation, we propose the xApp distillation method. The proposed method distils historical network state, actions and outcome information from multiple xApps (either heuristic or ML-based xApps) and uses this knowledge to train a single model that has retained the capabilities of previous xApps. The simulation results show that xApp distillation has significantly more consistent performance than conventional conflict mitigation methods. Compared conflict mitigation schemes can cause up to 6 times more network outages than xApp distillation in some cases.
Hakan Erdol, Xiaoyang Wang 0005, Robert J. Piechocki, George C. Oikonomou, Arjun Parekh
Comput. Networks4
2026 An analysis of IoT device update mechanisms
abstract
IoT devices are becoming more embedded within our lives, but the competitive nature of the industry requires quick time to market with security being an afterthought. One way to keep IoT devices secure is to regularly patch them of known vulnerabilities. This relies on knowing what firmware versions IoT devices are running, and when they are updating. In this paper we complete an update analysis for 50 IoT devices within a lab that simulates a smart home. We analyse the passive network traffic of these devices, documenting the prevalence of automatic updates, frequency of updates, and whether encrypted channels are used to send updates. We find that a significant proportion of the devices analysed can only be updated manually; and for those devices that have automatic updates, many typically require user confirmation and can be disabled. We also see that many devices are not updated over periods of several months, and often update insecurely. Based on this analysis, we discuss how the automatic identification of IoT devices — including version identification — can be improved. We also consider what our analysis means for the problem of update detection and provide a step-by-step outline for detecting when a device is updating based on its traffic.
Ashley Andrews, George C. Oikonomou, Simon Armour, Thomas Cattermole
Comput. Secur.2
2026 IoT Firmware Version Identification Using Transfer Learning with Twin Neural Networks
abstract
As the Internet of Things (IoT) becomes more embedded within our daily lives, there is growing concern about the risk ‘smart’ devices pose to network security. To address this, one avenue of research has focused on automated IoT device identification. This research is broadly motivated by the idea that the more we can know about our devices, the more secure the networks they are on can be. Research has however largely neglected the identification of IoT device firmware versions. There is strong evidence that IoT security relies on devices being on the latest version patched for known vulnerabilities. Identifying when a device has updated (has changed version) or not (is on a stable version) is therefore useful for IoT security. Version identification involves challenges beyond those for identifying the model, type, and manufacturer of IoT devices. Most obviously, the differences between versions are more subtle and therefore harder to detect. Moreover, because there has been relatively little research in this area, there are no widely available datasets that track devices’ version changes over time. Consequently, traditional machine learning algorithms are ill-suited for effective version identification due to being limited by the availability of data for training. In this paper, we introduce an effective technique for identifying IoT device versions based on transfer learning. This technique relies on the idea that we can use a Twin Neural Network (TNN) — trained at distinguishing devices — to detect differences between a device on different versions. This facilitates real-world implementation by requiring relatively little training data. In more detail, we extract statistical features from on-wire packet flows, convert these features into greyscale images, pass these images into a TNN to output similarity scores, and determine version changes based on the Hedges’ g effect size of the similarity scores. This allows us to detect the subtle changes present in on-wire traffic when a device changes version. To evaluate our technique, we set up a lab containing 12 IoT devices and recorded their on-wire packet captures for 11 days across multiple firmware versions. For testing data held out from training, our best performing model is shown to be 95.83% and 84.38% accurate at identifying stable versions and version changes respectively.
Ashley Andrews, George C. Oikonomou, Simon Armour, Thomas Cattermole
ACM Trans. Internet Techn.2
2023 LE3D: A Lightweight Ensemble Framework of Data Drift Detectors for Resource-Constrained Devices
abstract
Data integrity becomes paramount as the number of Internet of Things (ioT) sensor deployments increases. Sensor data can be altered by benign causes or malicious actions. Mechanisms that detect drifts and irregularities can prevent disruptions and data bias in the state of an IoT application. This paper presents LE3D, an ensemble framework of data drift estimators capable of detecting abnormal sensor behaviours. Working collaboratively with surrounding ioT devices, the type of drift (natural/abnormal) can also be identified and reported to the end-user. The proposed framework is a lightweight and unsupervised implementation able to run on resource-constrained IoT devices. Our framework is also generalisable, adapting to new sensor streams and environments with minimal online reconfiguration. We compare our method against state-of-the-art ensemble data drift detection frameworks, evaluating both the real-world detection accuracy as well as the resource utilisation of the implementation. Experimenting with real-world data and emulated drifts, we show the effectiveness of our method, which achieves up to 97% of detection accuracy while requiring minimal resources to run.
Ioannis Mavromatis, Adrián Sánchez-Mompó, Francesco Raimondo, James Pope, Marcello Bullo, Ingram Weeks, Pietro Edoardo Carnelli, George C. Oikonomou, Theodoros Spyridopoulos, Aftab Khan 0001
CCNC9
2023 Evaluating Concept Drift Detectors on Real-World Data
Ufuk Erol, Francesco Raimondo, James Pope, Sam Gunner, Ioannis Mavromatis, Pietro Edoardo Carnelli, Theodoros Spyridopoulos, Aftab Khan 0001, George C. Oikonomou
EWSN10
2023 CRICKET: A Practical Physical Layer Key Agreement Protocol for IoT Networks
abstract
Physical Layer Key Generation (PLKG) is an attractive method for solving the key distribution problem in IoT networks. Although PLKG has a much lower complexity when compared to public key cryptography, it is not always practical in resource-constrained networks due to a high reconciliation cost. Channel Reciprocity for KEy Transmission (CRicKET) is an ultra-lightweight key agreement method that exploits channel reciprocity for securely transmitting a key generated at one end of a single-hop network. The key disagreement rate can be arbitrarily chosen without increasing the computational complexity. Analytical results allow design optimisation and derive the entropy requirement for perfect secrecy. The practicality of CRicKET is successfully tested on a series of IoT boards connected to a wireless network.
Chrysanthi Paschou, F. Raimondo M. Gugala, Dave McEwan, James Pope, George C. Oikonomou
ICC5
2023 A Conceptual Architecture for Scalable Multi-Application Support in Blockchain-based IoT Environments
abstract
Existing proposals that merge IoT with blockchain technologies have been efficient but often limited to a single application scenario. They require specific hardware setups, thus in case of switching to a new application scenario, they may become ineffective and require a new hardware setup. In this paper, we present a new blockchain-based architecture for IoT environments that addresses one of the fundamental challenges in the area which is the capability of supporting multiple application scenarios. The proposed architecture enables transitioning between various application scenarios via smart contracts and configuration files stored on blockchain. The architecture, additionally, addresses scalability concerns of the blockchain-based IoT systems through a cluster-based approach which provides a more flexible and secure solution.
Akin Eker, Theodore Tryfonas, George C. Oikonomou
INDIN3
2022 Securing Synchronous Flooding Communications: An Atomic-SDN Implementation
Charles Lockie, Ioannis Mavromatis, Aleksandar Stanoev, Yichao Jin 0001, George C. Oikonomou
EWSN5
2022 IoT Key Exchange Performance Analysis
Francesco Raimondo, Ufuk Erol, Sam Gunner, James Pope, Robert Zakrzewski, Mike Faulks, Ryan McConville, Thomas Pasquier, Robert J. Piechocki, George C. Oikonomou
EWSN10
2022 Anomaly Detection in Logical Sub-Views of WSNs
abstract
Wireless sensor networks are often distributed, diverse, and large making their monitoring hard. One way to tackle it is to focus on part of the system by creating logical sub-views which can be seen as proxies of the overall system operations. In this manuscript, logical sub-views consist of traffic aggregators and their topology which are monitored for anomaly. The aggregators are selected based on diversity and importance in the system and they are modelled as graphs to capture aggregation topology and data distributions. The aggregators' selection criteria, the method for comparison of partially overlapping sub-views, normal aggregation profiles acquisition, and measures of anomaly are proposed. A simulated wireless sensor network is used to acquire data at the edge and apply the method to demonstrate that focusing on system sub-views and comparing aggregation profiles facilitates anomaly detection also caused elsewhere in the system and the impact the anomaly has on aggregators.
Robert Zakrzewski, Trevor P. Martin, George C. Oikonomou
ISCC3
2022 Federated Meta-Learning for Traffic Steering in O-RAN
abstract
The vision of 5G lies in providing high data rates, low latency (for the aim of near-real-time applications), significantly increased base station capacity, and near-perfect quality of service (QoS) for users, compared to LTE networks. In order to provide such services, 5G systems will support various combinations of access technologies such as LTE, NR, NR-U and Wi-Fi. Each radio access technology (RAT) provides different types of access, and these should be allocated and managed optimally among the users. Besides resource management, 5G systems will also support a dual connectivity service. The orchestration of the network therefore becomes a more difficult problem for system managers with respect to legacy access technologies. In this paper, we propose an algorithm for RAT allocation based on federated meta-learning (FML), which enables RAN intelligent controllers (RICs) to adapt more quickly to dynamically changing environments. We have designed a simulation environment which contains LTE and 5G NR service technologies. In the simulation, our objective is to fulfil UE demands within the deadline of transmission to provide higher QoS values. We compared our proposed algorithm with a single RL agent, the Reptile algorithm and a rule-based heuristic method. Simulation results show that the proposed FML method achieves higher caching rates at first deployment round 21% and 12% respectively. Moreover, proposed approach adapts to new tasks and environments most quickly amongst the compared methods.
Hakan Erdol, Xiaoyang Wang 0005, Peizheng Li, Jonathan D. Thomas, Robert J. Piechocki, George C. Oikonomou, Rui Inacio, Abdelrahim Kasem Ahmad, Keith Briggs, Shipra Kapoor
VTC Fall6
2021 A Reference Implemenation for RPL Attacks Using Contiki-NG and COOJA
abstract
RPL-based IoT networks are vulnerable to routing attacks as well as flooding attacks. Developing security countermeasures requires knowledge of possible attacks, their timing, and combinations. Most implementations of RPL related attacks only consider individual attacks triggered when their simulation starts. Furthermore, nodes which to be compromised are preselected before a simulation starts and cannot later be changed. In this paper, we present a Contiki-NG implementation of most known RPL attacks all of which is shared on a public Github repository. In addition, we designed a framework in COOJA to facilitate simulating hybrid RPL attacks with different settings in terms of duration and severity.
Faya Algahtani, Theodore Tryfonas, George C. Oikonomou
DCOSS3
2021 Anomaly detection of data and topology patterns in WSNs
abstract
Wireless sensor networks are often distributed which makes detection of cyber-attacks or misconfiguration hard. Topology and data patterns change may result from attacks leading to the compromise of data and service availability or indicate operational problems. Graphs are often used to model topology and data paths to describe and compare state of a system. For anomaly detection, the definition of normal patterns, deviation from normal, and criteria when to declare anomaly are required. In this contribution the process of acquisition of normal patterns (ground truth), and criteria when to declare anomaly based on graph comparison are proposed. The anomaly detection is suitable for deployment at the edge of a network. Finally, the inability to define all security threats is addressed by a custom tree-based classifier which only requires normal patterns for training. A simulated wireless sensor network was used to acquire data and apply the method. Our experiments show that data and topology change can be detected at the edge of a network.
Robert Zakrzewski, Trevor P. Martin, George C. Oikonomou
DCOSS3
2021 6TiSCH++ with Bluetooth 5 and Concurrent Transmissions
Michael Baddeley, Adnan Aijaz, Usman Raza, Aleksandar Stanoev, Yichao Jin 0001, Markus Schuss, Carlo Alberto Boano, George C. Oikonomou
EWSN8
2021 Towards Multi-Criteria Heuristic Optimization for Computational Offloading in Multi-Access Edge Computing
abstract
In recent years, there has been considerable interest in computational offloading algorithms. The interest is mainly driven by the potential savings that offloading offers in task completion time and mobile device energy consumption. This paper builds on authors' previous work on computational offloading and describes a multi-objective optimization model that optimizes time and energy in a network with multiple Multi-Access Edge Computing servers (MECs) and Mobile Devices (MDs). Each MD has multiple computational jobs to process, and each task can be processed locally or offloaded to one of the MEC servers. Several heuristic offloading policies are proposed and tested with an objective function with a range of weightings for optimizing time and energy. The approaches are illustrated with the help of three test cases of varying complexity. The objective function shows a continuous variation as the emphasis is placed on either time or energy saving by the weighting factors. The numerical tests demonstrate that the proposed heuristic algorithms produce near-optimal computational offloading solutions while considering a combined weighted score for schedule task completion time and energy.
Raghubir Singh, Simon Armour, Aftab Khan 0001, Mahesh Sooriyabandara, George C. Oikonomou
HPSR5
2021 Container Escape Detection for Edge Devices
abstract
Edge computing is rapidly changing the IoT-Cloud landscape. Various testbeds are now able to run multiple Docker-like containers developed and deployed by end-users on edge devices. However, this capability may allow an attacker to deploy a malicious container on the host and compromise it. This paper presents a dataset based on the Linux Auditing System, which contains malicious and benign container activity. We developed two malicious scenarios, a denial of service and a privilege escalation attack, where an adversary uses a container to compromise the edge device. Furthermore, we deployed benign user containers to run in parallel with the malicious containers. Container activity can be captured through the host system via system calls. Our time series auditd dataset contains partial labels for the benign and malicious related system calls. Generating the dataset is largely automated using a provided AutoCES framework. We also present a semi-supervised machine learning use case with the collected data to demonstrate its utility. The dataset and framework code are open-source and publicly available.
James Pope, Francesco Raimondo, Ryan McConville, Robert J. Piechocki, George C. Oikonomou, Thomas Pasquier, Bo Luo, Dan Howarth, Ioannis Mavromatis, Pietro Edoardo Carnelli, Adrián Sánchez-Mompó, Theodoros Spyridopoulos, Aftab Khan 0001
SenSys6
2020 Wearable Devices for Digital Health: The SPHERE Wearable 3
Antonis Vafeas, Md Israfil Biswas, Xenofon Fafoutis, Atis Elsts, Ian Craddock, Robert J. Piechocki, George C. Oikonomou
EWSN7
2020 Radio Resource Allocation Between Massive MIMO and LTE Using SDN
abstract
Massive multiple-input, multiple-output (Ma-MIMO) is currently being deployed in the fifth generation (5G) networks. It has increased the capacity for sub-6GHz wireless access. However, the ongoing development is a critical step in enhancing this technology in order to deliver the capacity gains and the Quality of Service (QoS) requirements in 5G. Here, a novel spatial Software-Defined Networking (SDN) controller framework for radio resource allocation between a single cell long-term evolution (LTE) and a single cell Ma-MIMO is proposed and shown to further enhance performance. For the first time, an SDN-based radio resource management (SDN-RRM) framework for multiple radio access technologies (multi-RATs) is introduced. The methodologies in this framework address the interference caused by the user channel vectors as well as hardware impairments in Ma-MIMO by mainly relying on the Error Vector Magnitude (EVM) and channel state information (CSI). The handover between the LTE Access Point (AP) and the Ma-MIMO AP is decided by the wireless SDN controller. This has led to maximize the throughput and to achieve the QoS requirement. The proposed framework has been built and evaluated in real-time by using a massive Ma-MIMO testbed and an LTE testbed controlled by an SDN controller.
Wael Boukley Hasan, George C. Oikonomou, Mark A. Beach
PIMRC3
2020 Heuristic Approaches for Computational Offloading in Multi-Access Edge Computing Networks
abstract
Computational offloading is a strategy by which mobile device (MD) users can access the superior processing power of a Multi-Access Edge Computing (MEC) server network. In this paper, we contribute a model of a system that consists of multiple MEC servers and multiple MD users. Each MD has multiple computational tasks to perform, and each task can either be computed locally on the MD, or it can be offloaded to one of the MEC servers. For this system and having global knowledge, we compute the theoretical optimal allocation that minimises the time required to complete the computation of all tasks. Subsequently, we contribute a distributed heuristic algorithm that allows each MD to independently, and using local knowledge only, decide how to handle each individual job. Furthermore, we propose three approaches to decide whether to offload each individual job, and three mechanisms to determine which MEC server each task should be offloaded to. We use simulations to evaluate those approaches in terms of how well they can approximate the theoretical optimum. The proposed heuristic algorithm is tested on a range of experiments, and the results demonstrate that the heuristic algorithm can produce reasonable quality solutions.
Raghubir Singh, Simon Armour, Aftab Khan 0001, Mahesh Sooriyabandara, George C. Oikonomou
PIMRC5
2020 TSCH Networks for Health IoT: Design, Evaluation, and Trials in the Wild
abstract
The emerging Internet of Things has the potential to solve major societal challenges associated with healthcare provision. Low-power wireless protocols for residential Health Internet of Things applications are characterized by high reliability requirements, the need for energy-efficient operation, and the need to operate robustly in diverse environments in the presence of external interference. We enhance and experimentally evaluate the Time-Slotted Channel Hopping protocol from the IEEE 802.15.4 standard to address these challenges. Our contributions are a new schedule and an adaptive channel selection mechanism to increase the performance of time-slotted channel hopping in this domain. Evaluation in a test house shows that the enhanced system is suitable for our e-Health application and compares favorably with state-of-the-art options. The schedule provides higher reliability compared with the minimal scheduling function from the IETF 6TiSCH Working Group and has a better energy-efficiency/reliability tradeoff than the Orchestra scheduler. Results from 29 long-term residential deployments confirm the suitability for the application and show that the system is able to adapt and avoid channels used by WiFi. In these uncontrolled environments, the system achieves 99.96% average reliability for networks that generate 7.5 packets per second on average.
Atis Elsts, Xenofon Fafoutis, George C. Oikonomou, Robert J. Piechocki, Ian Craddock
ACM Trans. Internet Things3
2019 Poster: Atomic-SDN: A Synchronous Flooding Framework for SDN Control of Low-Power Wireless
Michael Baddeley, Usman Raza, Mahesh Sooriyabandara, George C. Oikonomou, Reza Nejabati, Dimitra Simeonidou
EWSN4
2019 Instant: A TSCH Schedule for Data Collection from Mobile Nodes
Atis Elsts, James Pope, Xenofon Fafoutis, Robert J. Piechocki, George C. Oikonomou
EWSN5
2019 An SDN Agent-Enabled Rate Adaptation Framework for WLAN
abstract
Rate or link adaptation is the determination of the optimal modulation and coding scheme (MCS) that will maximize the performance under the current wireless channel conditions. A Software-Defined Networking (SDN) agent is a software element bridging an SDN controller and any legacy wireless network elements by providing the abstraction of these elements. In this paper, we present the work of an SDN approach for designing and implementing a Rate/Link Adaptation (RA) framework for wireless local area networks (WLAN). The framework provides support for real-time RA applications and flexibility to satisfy various degrees of Quality of Service (QoS) or Quality of Experience (QoE) requirements. We implement the proposed framework as an extension to the Wireless Open-Access Research Platform (WARP), an FPGA based Software-Defined Radio (SDR) platform, with evaluation results indicating the feasibility of using SDN-RA under the stringent time constraints posed by the WLAN. To demonstrate the effectiveness of decoupling rate decision functions from the underlying wireless interface card and to highlight its applicability for a diverse set of scenarios, we present a use case deployed over the framework focusing on rate adaptation for individual traffic, and display optimization in different aspects, such as the reduction transmission errors.
George C. Oikonomou, Mark A. Beach, Reza Nejabati, Dimitra Simeonidou
ICC2
2019 EVM Prediction for Massive MIMO
abstract
Signal to interference plus noise ratio (SINR) is a widely common performance metric used in the majority of massive multiple-input, multiple-output (Ma-MIMO) research. This metric requires prior knowledge of the user channel vectors and the interference caused by inaccurate channel state information (CSI). However, the interference caused by inaccurate CSI can't be calculated for real-world scenarios. On the other hand, a comprehensive performance indicator can be achieved by the Error Vector Magnitude (EVM) metric in real-world scenarios. This considers all impairments upon the transmitted symbol as seen at the receiver. However, measuring the EVM values for a subset of users requires each user to retransmit data symbols. This paper presents an estimation method with high accuracy by associating EVM to SINR values for Ma-MIMO with zero-forcing (ZF) and Minimum Mean Square Error (MMSE). Also introduced is a novel EVM prediction method for subset of users taken from the original set of simultaneous users in a single cell Ma-MIMO. This method jointly relies on the channel correlation between users and the EVM performance to predict the EVM values for a subset of the available users without the need to retransmit data symbols. This method considers the user channel vector and the interference caused by inaccurate CSI, which makes it suitable for Ma-MIMO algorithms, such as user grouping and power control. Real-world experimental data-sets with real-time results are carried out to validate the EVM prediction method using software-defined radio Ma-MIMO testbed.
Wael Boukley Hasan, Angela Doufexi, George C. Oikonomou, Mark A. Beach
PIMRC3
2019 Efficient DCT-based secret key generation for the Internet of Things
abstract
Cryptography is one of the most widely employed means to ensure confidentiality in the Internet of Things (IoT). Establishing cryptographically secure links between IoT devices requires the prior consensus to a secret encryption key. Yet, IoT devices are resource-constrained and cannot employ traditional key distribution schemes. As a result, there is a growing interest in generating secret random keys locally, using the shared randomness of the communicating channel. This article presents a secret key generation scheme, named SKYGlow, which is targeted at resource-constrained IoT platforms and tested on devices that employ IEEE 802.15.4 radios. We first examine the practical upper bounds of the number of secret bits that can be extracted from a message exchange. We contrast these upper bounds with the current state-of-the-art, and elaborate on the workings of the proposed scheme. SKYGlow applies the Discrete Cosine Transform (DCT) on channel observations of exchanged messages to reduce mismatches and increase correlation between the generated secret bits. We validate the performance of SKYGlow in both indoor and outdoor scenarios, at 2.4 GHz and 868 MHz respectively. The results suggest that SKYGlow can create secret 128-bit keys of 0.9978 bits entropy with just 65 packet exchanges, outperforming the state-of-the-art in terms of energy efficiency.
George Margelis, Xenofon Fafoutis, George C. Oikonomou, Robert J. Piechocki, Theodore Tryfonas
Ad Hoc Networks3
2018 Energy-Efficient, Noninvasive Water Flow Sensor
abstract
We are interested in hot and cold water flow detection in domestic kitchen and bathroom taps for smart home environments. Water flow monitoring is particularly valuable for long-term behavioural monitoring systems for health-related applications, as it enables the collection of long-term data on the hydration levels of the house residents, and it is associated with several activities of daily life, such as cooking and cleaning. This paper presents a water flow sensing device that is based on sensing the vibrations on the pipe when water is flowing through them. The proposed solution is noninvasive and energy efficient, as it does not require cutting the water pipes or altering the plumbing system, and consumes less then 2 uA in continuous operation. The proposed water flow sensor has been integrated to SPHERE, a sensing platform of non-medical sensors for healthcare monitoring and behavioural analytics in a home environment, and deployed to more than 15 residential properties.
Antonis Vafeas, Atis Elsts, James Pope, Xenofon Fafoutis, George C. Oikonomou, Robert J. Piechocki, Ian Craddock
SMARTCOMP5
2018 Temperature-Resilient Time Synchronization for the Internet of Things
abstract
Networks deployed in real-world conditions have to cope with dynamic, unpredictable environmental temperature changes. These changes affect the clock rate on network nodes, and can cause faster clock de-synchronization compared to situations where devices are operating under stable temperature conditions. Wireless network protocols, such as time-slotted channel hopping (TSCH) from the IEEE 802.15.4-2015 standard, are affected by this problem, since they require tight clock synchronization among all nodes for the network to remain operational. This paper proposes a method for autonomously compensating temperature-dependent clock rate changes. After a calibration stage, nodes continuously perform temperature measurements to compensate for clock drifts at runtime. The method is implemented on low-power Internet of Things (IoT) nodes and evaluated through experiments in a temperature chamber, indoor and outdoor environments, as well as with numerical simulations. The results show that applying the method reduces the maximum synchronization error more than ten times. In this way, the method allows reduction in the total energy spent for time synchronization, which is practically relevant concern for low data rate, low energy budget TSCH networks, especially those exposed to environments with changing temperature.
Atis Elsts, Xenofon Fafoutis, Simon Duquennoy, George C. Oikonomou, Robert J. Piechocki, Ian Craddock
IEEE Trans. Ind. Informatics4
2017 TSCH and 6TiSCH for Contiki: Challenges, Design and Evaluation
abstract
Synchronized communication has recently emerged as a prime option for low-power critical applications. Solutions such as Glossy or Time Slotted Channel Hopping (TSCH) have demonstrated end-to-end reliability upwards of 99.99%. In this context, the IETF Working Group 6TiSCH is currently standardizing the mechanisms to use TSCH in low-power IPv6 scenarios. This paper identifies a number of challenges when it comes to implementing the 6TiSCH stack. It shows how these challenges can be addressed with practical solutions for locking, queuing, scheduling and other aspects. With this implementation as an enabler, we present an experimental validation and comparison with state-of-the-art MAC protocols. We conduct fine-grained energy profiling, showing the impact of link-layer security on packet transmission. We evaluate distributed time synchronization in a 340-node testbed, and demonstrate that tight synchronization (hundreds of microseconds) can be achieved at very low cost (0.3% duty cycle, 0.008% channel utilization). We finally compare TSCH against traditional MAC layers: low-power listening (LPL) and CSMA, in terms of reliability, latency and energy. We show that with proper scheduling, TSCH achieves by far the highest reliability, and outperforms LPL in both energy and latency.
Simon Duquennoy, Atis Elsts, Beshr Al Nahas, George C. Oikonomou
DCOSS4
2017 Scheduling High-Rate Unpredictable Traffic in IEEE 802.15.4 TSCH Networks
abstract
The upcoming Internet of Things (IoT) applications include real-time human activity monitoring with wearable sensors. Compared to the traditional environmental sensing with low-power wireless nodes, these new applications generate a constant stream of a much higher rate. Nevertheless, the wearable devices remain battery powered and therefore restricted to low-power wireless standards such as IEEE 802.15.4 or Bluetooth Low Energy (BLE). Our work tackles the problem of building a reliable autonomous schedule for forwarding this kind of dynamic data in IEEE 802.15.4 TSCH networks. Due to the a priori unpredictability of these data source locations, the quality of the wireless links, and the routing topology of the forwarding network, it is wasteful to reserve the number of slots required for the worst-case scenario, under conditions of high expected datarate, it is downright impossible. The solution we propose is a hybrid approach where dedicated TSCH cells and shared TSCH slots coexist in the same schedule. We show that under realistic assumptions of wireless link diversity, adding shared slots to a TSCH schedule increases the overall packet delivery rate and the fairness of the system.
Atis Elsts, Xenofon Fafoutis, James Pope, George C. Oikonomou, Robert J. Piechocki, Ian Craddock
DCOSS4
2017 Competition: Adaptive Time-Slotted Channel Hopping
Atis Elsts, Xenofon Fafoutis, Adeyinka Adeleke, Robert J. Piechocki, George C. Oikonomou, Simon Duquennoy, Antonio Liñán, Marc Fàbregas
EWSN5
2017 Demo: SPES-2 - A Sensing Platform for Maintenance-Free Residential Monitoring
Xenofon Fafoutis, Atis Elsts, Antonis Vafeas, George C. Oikonomou, Robert J. Piechocki
EWSN4
2017 Physical layer secret-key generation with discreet cosine transform for the Internet of Things
abstract
The confidentiality of communications in the Internet of Things (IoT) is critical, with cryptography currently being the most widely employed method of ensuring it. Establishing cryptographically secure communication links between two transceivers requires the pre-agreement on some key, unknown to an external attacker. In recent years there has been growing attention in techniques that generate a shared random key through observation of the channel and its effects on the exchanged messages. In this work we present SKYGlow, a novel scheme for secret-key generation, designed for IoT devices, such as IEEE 802.15.4 and Bluetooth Low Energy (BLE) transceivers. SKYGlow employs the Discreet Cosine Transform (DCT) of channel observations and Slepian-Wolf coding for information reconciliation. Real-life experiments have resulted in the creation of 128-bit secret keys with only 65 packet exchanges and with an entropy of 0.9978 bits, making our scheme much more energy-efficient compared with others in the existing literature.
George Margelis, Xenofon Fafoutis, George C. Oikonomou, Robert J. Piechocki, Theodore Tryfonas
ICC3
2017 Link quality and path based clustering in IEEE 802.15.4-2015 TSCH networks
abstract
Advance clustering techniques have been widely used in Wireless Sensor Networks (WSNs) since they can potentially reduce latency, improve scheduling, decrease end-to-end delay and optimise energy consumption within a dense network topology. In this paper, we present a novel clustering algorithm for high density IEEE 802.15.4-2015 Time-Slotted Channel Hopping (TSCH). In particular, the proposed methodology merges a variety of solutions into an integrated clustering design. Assuming an homogeneous network distribution, the proposed configuration deploys a hierarchical down-top approach of equally numbered sub-groups, in which the formation of the separate sub-groups is adapted to the network density and the node selection metric is based on the link quality indicator. The presented algorithm is implemented in Contiki Operating System (OS) and several test vectors have been designed in order to evaluate the performance of the proposed algorithm in a COOJA simulation environment. Performance results demonstrate the capability of the clustering structure since compared to the default scheme it significantly improves the energy efficiency up to 35%, packet drops more than 40% as well the packet retransmission rate. Last but not least, the outcome of this study indicates a major increase in the network lifetime, i.e., up to 50%.
Alexandros Mavromatis, Georgios Z. Papadopoulos, Xenofon Fafoutis, Angelos A. Goulianos, George C. Oikonomou, Periklis Chatzimisios, Theodore Tryfonas
ISCC5
2017 Privacy Leakage of Physical Activity Levels in Wireless Embedded Wearable Systems
abstract
With the ubiquity of sensing technologies in our personal spaces, the protection of our privacy and the confidentiality of sensitive data becomes a major concern. In this letter, we focus on wearable embedded systems that communicate data periodically over the wireless medium. In this context, we demonstrate that private information about the physical activity levels of the wearer can leak to an eavesdropper through the physical layer. Indeed, we show that the physical activity levels strongly correlate with changes in the wireless channel that can be captured by measuring the signal strength of the eavesdropped frames. We practically validate this correlation in several scenarios in a real residential environment, using data collected by our prototype wearable accelerometer-based sensor. Finally, we propose a privacy enhancement algorithm that mitigates the leakage of this private information.
Xenofon Fafoutis, Letizia Marchegiani, Georgios Z. Papadopoulos, Robert J. Piechocki, Theodore Tryfonas, George C. Oikonomou
IEEE Signal Process. Lett.6
2016 A Mobility-Supporting MAC Scheme for Bursty Traffic in IoT and WSNs
abstract
Recent boom of mobile applications has become an essential class of mobile Internet of Things (IoT), whereby large amounts of sensed data are collected and shared by mobile sensing devices for observing phenomena such as traffic or the environmental. Currently, most of the proposed Medium Access Control (MAC) protocols mainly focus on static networks. However, mobile sensor nodes may pose many communication challenges during the design and development of a MAC protocol. These difficulties first require an efficient connection establishment between a mobile and static node, and then an efficient data packet transmissions. In this study, we propose MobIQ, an advanced mobility-handling MAC scheme for low-power MAC protocols, which achieves for efficient neighbour(hood) discovery and low-delay communication. Our thorough performance evaluation, conducted on top of Contiki OS, shows that MobIQ outperforms state-of-the-art solutions such as MoX-MAC, MOBINET and ME-ContikiMAC, in terms of significantly reducing delay, contention to the medium and energy consumption.
Georgios Z. Papadopoulos, Vasileios Kotsiou, Antoine Gallais, George C. Oikonomou, Periklis Chatzimisios, Theodore Tryfonas, Thomas Noël
GLOBECOM4
2016 Impact of Guard Time Length on IEEE 802.15.4e TSCH Energy Consumption
abstract
The IEEE 802.15.4-2015 standard defines a number of Medium Access Control (MAC) layer protocols for low-power wireless communications in the IoT. Originally defined in the IEEE 802.15.4e amendment, TSCH (Time Slotted Channel Hopping) is among the proposed mechanisms. TSCH is a scheme aiming to guarantee network reliability by keeping nodes time-synchronised at the MAC layer. In order to ensure successful communication between a sender and a receiver, the latter starts listening shortly before the expected time of a MAC layer frame's arrival. The offset between the time a node starts listening and the estimated time of frame arrival is called guard time and it aims to reduce the probability of missed frames due to clock drift. In this poster, we investigate the effect of the guard time duration on energy consumption. We identify that, when using the 6tisch minimal schedule, the most significant cause of energy consumption is idle listening during guard time. Therefore, the energy-efficiency of TSCH can be significantly improved by guard time optimisation. Our performance evaluation results, conducted using the Contiki operating system, show that an efficient configuration of guard time may reduce energy consumption by up to 30%, without compromising network reliability.
Alexandros Mavromatis, Georgios Z. Papadopoulos, Xenofon Fafoutis, Atis Elsts, George C. Oikonomou, Theodore Tryfonas
SECON5
2016 Classification and suitability of sensing technologies for activity recognition
Przemyslaw Woznowski, Dritan Kaleshi, George C. Oikonomou, Ian Craddock
Comput. Commun.3
2016 A study on usability and security features of the Android pattern lock screen
abstract
Purpose – The Android pattern lock screen (or graphical password) is a popular user authentication method that relies on the advantages provided by the visual representation of a password, which enhance its memorability. Graphical passwords are vulnerable to attacks (e.g. shoulder surfing); thus, the need for more complex passwords becomes apparent. This paper aims to focus on the features that constitute a usable and secure pattern and investigate the existence of heuristic and physical rules that possibly dictate the formation of a pattern. Design/methodology/approach – The authors conducted a survey to study the users’ understanding of the security and usability of the pattern lock screen. The authors developed an Android application that collects graphical passwords, by simulating user authentication in a mobile device. This avoids any potential bias that is introduced when the survey participants are not interacting with a mobile device while forming graphical passwords (e.g. in Web or hard-copy surveys). Findings – The findings verify and enrich previous knowledge for graphical passwords, namely, that users mostly prefer usability than security. Using the survey results, the authors demonstrate how biased input impairs security by shrinking the available password space. Research limitations/implications – The sample’s demographics may affect our findings. Therefore, future work can focus on the replication of our work in a sample with different demographics. Originality/value – The authors define metrics that measure the usability of a pattern (handedness, directionality and symmetry) and investigate their impact to its formation. The authors propose a security assessment scheme using features in a pattern (e.g. the existence of knight moves or overlapping nodes) to evaluate its security strengths.
Panagiotis Andriotis, George C. Oikonomou, Alexios Mylonas, Theodore Tryfonas
Inf. Comput. Secur.2
2016 Highlighting Relationships of a Smartphone's Social Ecosystem in Potentially Large Investigations
abstract
Social media networks are becoming increasingly popular because they can satisfy diverse needs of individuals (both personal and professional). Modern mobile devices are empowered with increased capabilities, taking advantage of the technological progress that makes them smarter than their predecessors. Thus, a smartphone user is not only the phone owner, but also an entity that may have different facets and roles in various social media networks. We believe that these roles can be aggregated in a single social ecosystem, which can be derived by the smartphone. In this paper, we present our concept of the social ecosystem in contemporary devices and we attempt to distinguish the different communities that occur from the integration of social networking in our lives. In addition, we propose techniques to highlight major actors within the ecosystem. Moreover, we demonstrate our suggested visualization scheme, which illustrates the linking of entities that live in separate communities using data taken from the smartphone. Finally, we extend our concept to include various parallel ecosystems during potentially large investigations and we link influential entities in a vertical fashion. We particularly examine cases where data aggregation is performed by specific applications, producing volumes of textual data that can be analyzed with text mining methods. Our analysis demonstrates the risks of the rising "bring your own device" trend in enterprise environments.
Panagiotis Andriotis, George C. Oikonomou, Theodore Tryfonas, Shancang Li
IEEE Trans. Cybern.2
2015 A Framework for Describing Multimedia Circulation in a Smartphone Ecosystem
Panagiotis Andriotis, Theodore Tryfonas, George C. Oikonomou, Irwin King
IFIP Int. Conf. Digital Forensics3
2015 Application of a Game Theoretic Approach in Smart Sensor Data Trustworthiness Problems
Konstantinos Maraslis, Theodoros Spyridopoulos, George C. Oikonomou, Theodore Tryfonas, Mo Haghighi
SEC3
2015 Class Based Overall Priority Scheduling for M2M Communications over LTE Networks
abstract
The rapidly increasing demand of M2M (Machine to Machine) communications poses great challenges to the capacity of cellular networks. This paper proposes a new M2M scheduling algorithm, namely, Class Based Overall Priority (CBOP) scheduling, which is designed particularly to improve uplink scheduling for a massive number of MTCDs (Machine Type Communication Devices) in LTE networks. We compare the proposed algorithm with several existing scheduling algorithms via simulations and discuss its advantages and limitations.
Beichen Chen, Zhong Fan, Fengming Cao, George C. Oikonomou, Theodore Tryfonas
VTC Spring4
2014 A Distributed Consensus Algorithm for Decision Making in Service-Oriented Internet of Things
abstract
In a service-oriented Internet of things (IoT) deployment, it is difficult to make consensus decisions for services at different IoT edge nodes where available information might be insufficient or overloaded. Existing statistical methods attempt to resolve the inconsistency, which requires adequate information to make decisions. Distributed consensus decision making (CDM) methods can provide an efficient and reliable means of synthesizing information by using a wider range of information than existing statistical methods. In this paper, we first discuss service composition for the IoT by minimizing the multi-parameter dependent matching value. Subsequently, a cluster-based distributed algorithm is proposed, whereby consensuses are first calculated locally and subsequently combined in an iterative fashion to reach global consensus. The distributed consensus method improves the robustness and trustiness of the decision process.
Shancang Li, George C. Oikonomou, Theodore Tryfonas, Thomas M. Chen
IEEE Trans. Ind. Informatics2
2013 Game Theoretic Approach for Cost-Benefit Analysis of Malware Proliferation Prevention
Theodoros Spyridopoulos, George C. Oikonomou, Theodore Tryfonas
SEC2
2013 A pilot study on the security of pattern screen-lock methods and soft side channel attacks
abstract
Graphical passwords that allow a user to unlock a smartphone's screen are one of the Android operating system's features and many users prefer them instead of traditional text-based codes. A variety of attacks has been proposed against this mechanism, of which notable are methods that recover the lock patterns using the oily residues left on screens when people move their fingers to reproduce the unlock code. In this paper we present a pilot study on user habits when setting a pattern lock and on their perceptions regarding what constitutes a secure pattern. We use our survey's results to establish a scheme, which combines a behaviour-based attack and a physical attack on graphical lock screen methods, aiming to reduce the search space of possible combinations forming a pattern, to make it partially or fully retrievable.
Panagiotis Andriotis, Theodore Tryfonas, George C. Oikonomou, Can Yildiz
WISEC3
2013 Cryptographic Key Exchange in IPv6-Based Low Power, Lossy Networks
Panagiotis Ilia, George C. Oikonomou, Theodore Tryfonas
WISTP2
2013 A game theoretic defence framework against DoS/DDoS cyber attacks
Theodoros Spyridopoulos, G. Karanikas, Theodore Tryfonas, George C. Oikonomou
Comput. Secur.4
2012 RPL router discovery for supporting energy-efficient transmission in single-hop 6LoWPAN
abstract
In Wireless Sensor Networks (WSNs), controlling transmission power is a commonly used technique to extend battery life. This paper describes a novel mechanism using measured RSS (Received Signal Strength) to calculate optimal transmission power. This technique works in multipath environments and with nodes with differing transmission capability. Our technique achieves automatic configuration employing modifications to RPL (Routing Protocol for Low-power and lossy networks) router discovery without requiring extra steps or messages. Consequently, each node can send packets with ideal transmission power, which will usually be lower than maximum power and will help to prolong its lifetime. We evaluate the effectiveness of the proposed scheme, using performance metrics such as energy consumption and packet loss, on an WSN testbed. Several factors that impact the RSS, such as antenna, multipath environment, output power and the node's capabilities are also investigated. Moreover, two RSS estimation techniques are evaluated and compared to the average measured RSS. The experimental results show that energy consumption is reduced by using the proposed technique.
Wilawan Rukpakavong, Iain Phillips 0002, Lin Guan 0001, George C. Oikonomou
ICC4
2012 Adaptive neighbor discovery for mobile and low power wireless sensor networks
abstract
Wireless Sensor Networks are by nature highly dynamic and communication between sensors is completely ad hoc, especially when mobile devices are part of the setup. Numerous protocols and applications proposed for such networks operate on the assumption that knowledge of the neighborhood is a priori available to all nodes. As a result, WSN deployments need to use or implement from scratch a neighborhood discovery mechanism. In this work we present a new protocol based on adaptive periodic beacon exchanges. We totally avoid continuous beaconing by adjusting the rate of broadcasts using the concept of consistency over the understanding of neighborhood that nearby devices share. We propose, implement and evaluate our adaptive neighborhood discovery protocol over our experimental testbed and using large scale simulations. Our results indicate that the new protocol operates more efficiently than existing reference implementations while it provides valid information to applications that use it. Extensive performance evaluation indicates that it successfully reduces generated network traffic by 90% and increases network lifetime by 20% compared to existing mechanisms that rely on continuous beaconing.
Dimitrios Amaxilatis, George C. Oikonomou, Ioannis Chatzigiannakis
MSWiM2
2009 Modeling Human Behavior for Defense Against Flash-Crowd Attacks
abstract
Flash-crowd attacks are the most vicious form of distributed denial of service (DDoS). They flood the victim with service requests generated from numerous bots. Attack requests are identical in content to those generated by legitimate, human users, and bots send at a low rate to appear non-aggressive - these features defeat many existing DDoS defenses. We propose defenses against flash-crowd attacks via human behavior modeling, which differentiate DDoS bots from human users. Current approaches to human-vs-bot differentiation, such as graphical puzzles, are insufficient and annoying to humans, whereas our defenses are highly transparent. We model three aspects of human behavior: a) request dynamics, by learning several chosen features of human interaction dynamics, and detecting bots that exhibit higher aggressiveness in one or more of these features, b) request semantics, by learning transitional probabilities of user requests, and detecting bots that generate valid but low-probability sequences, and c) ability to process visual cues, by embedding into server replies human-invisible objects, which cannot be detected by automated analysis, and flagging users that visit them as bots. We evaluate our defenses' performance on a series of Web traffic logs, interlaced with synthetically generated attacks, and conclude that they raise the bar for a successful, sustained attack to botnets whose size is larger than the size observed in 1-5% of DDoS attacks today.
George C. Oikonomou, Jelena Mirkovic
ICC1
2008 Combining Speak-Up with DefCOM for Improved DDoS Defense
abstract
This work combines two existing defenses against distributed denial-of-service (DDoS) attacks - DefCOM and speak-up - resulting in a synergistic improvement. DefCOM defense organizes existing source-end, victim-end and core defenses into a collaborative overlay to filter DDoS floods. Source networks that do not participate in DefCOM often receive poor service and their traffic is severely rate-limited. This is because core nodes in DefCOM that perform filtering lack cheap algorithms to differentiate legitimate from attack traffic at line speed - they must conservatively assume all high-rate traffic from legacy networks to be attack. Thus, in its attempt to mitigate DDoS, DefCOM ends up denying service during attacks to legitimate hosts that reside in legacy networks. Speak-up is a recently proposed defense, which invites all clients of the DDoS victim to send additional payment traffic, with the assumption that attack machines are already sending close to their full capacity. Clients that send a lot of payment traffic are considered legitimate and whitelisted. Speak-up is relatively cheap to deploy at the clients and the DDoS victim, but since payment traffic needs to be sent continuously, this creates additional congestion at the victim, which is undesirable. We combine speak-up and DefCOM into a synergistic defense that addresses the shortcomings of the individual defenses and confirms the success of collaborative protection against DDoS attacks. Speak-up is integrated with core defenses in DefCOM and whitelists clients based on their payment traffic. Legitimate clients in legacy networks can thus be detected and served. Further, since Speak-up is implemented in the core, payment and attack traffic do not reach the victim and any undesirable congestion effects are localized to the vicinity of legacy networking.
Mohit Mehta, Kanika Thapar, George C. Oikonomou, Jelena Mirkovic
ICC3
2008 A software platform for developing multi-player pervasive games using small programmable object technologies
abstract
In this paper we present a platform for developing mobile, locative and collaborative distributed games comprised of small programmable object technologies (e.g., wireless sensor networks) and traditional networked processors. The platform is implemented using a combination of JAVA Standard and Mobile editions, targeting also mobile phones that have some kind of sensors installed. We briefly present the architecture of our platform and demonstrate its capabilities by reporting two pervasive multiplayer games. The key characteristic of these games is that players interact with each other and their surrounding environment by moving, running and gesturing as a means to perform game related actions, using small programmable object technologies.
Orestis Akribopoulos, Dimitrios Bousis, Dionysios Efstathiou, Haris Koutsouridis, Marios Logaras, Andreas Loukas, Alexandros Nafas, George C. Oikonomou, Irini Thireou, Nikos Vasilakis, Panagiotis C. Kokkinos, Georgios Mylonas, Ioannis Chatzigiannakis
MASS8
2006 A Framework for a Collaborative DDoS Defense
abstract
Increasing use of the Internet for critical services makes flooding distributed denial-of-service (DDoS) a top security threat. A distributed nature of DDoS suggests that a distributed mechanism is necessary for a successful defense. Three main DDoS defense functionalities -- attack detection, rate limiting and traffic differentiation -- are most effective when performed at the victim-end, core and sourceend respectively. Many existing systems are successful in one aspect of defense, but none offers a comprehensive solution and none has seen a wide deployment. We propose to harvest the strengths of existing defenses by organizing them into a collaborative overlay, called DefCOM, and augmenting them with communication and collaboration functionalities. Nodes collaborate during the attack to spread alerts and protect legitimate traffic, while rate limiting the attack. DefCOM can accommodate existing defenses, provide synergistic response to attacks and naturally lead to an Internet-wide response to DDoS threat.
George C. Oikonomou, Jelena Mirkovic, Peter L. Reiher, Max Robinson
ACSAC1