VLDB 2026 Research / reviewers in the wild / expert
Haralambos Mouratidis
dblp:58/5370 · also Haris Mouratidis
· DBLP profile ↗
75ranked-venue papers
18as first author
8since 2021 · last 2026
0000-0002-2599-0712ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 27 · 7 first-author · 3 since 2021Security and privacy · 25 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 10 · 8 first-authorArtificial intelligence and machine learning · 9 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Speak in Context: Multilingual ASR with Speech-Context Alignment via Contrastive Learning
Haralambos Mouratidis, Ravi Shekhar |
LREC | 2 |
| 2025 | Multi-Partner Project: CyberSecDome - Framework for Secure, Collaborative, and Privacy-Aware Incident Handling for Digital InfrastructureabstractDigital infrastructure is vital for the economy, democracy, and everyday life, yet it is becoming increasingly vulnerable to strategic cyber-attacks. These attacks can lead to significant disruptions, resulting in widespread service outages, financial losses, and a decline in public trust. Ensuring resilience is difficult due to the infrastructure's complexity, the large volume of data involved, and the growing need for quick, coordinated responses. In the EU Horizon project CyberSecDome, we propose a multi-layered framework that provides AI-driven solutions for incident prediction and detection, automated testing, risk assessment, and rapid incident response, supporting continuity amid complex, large-scale cyber threats. Additionally, Cyber-SecDome introduces a virtual reality interface to enhance AI model explainability and provide real-time contextual awareness of ongoing attacks and defense mechanisms. It also enables privacy-aware model sharing across AI systems, fostering secure collaboration among different domes. Mohammad Hamad, Michael Kühr, Haralambos Mouratidis, Eleni-Maria Kalogeraki, Christos-Antonios Gizelis, Dimitrios Papanikas, Athanasios Bountioukos-Spinaris, Charilaos Skandylas, Evangelos Raptis, Andreas Alexopoulos, Grigorios Chrysos 0001, Mina Marmpena, Sevasti Politi, Konstantinos Lieros, Nikolaos Papagiannopoulos, Iordanis Xanthopoulos, Spyridon Papastergiou, Sotiris Ioannidis, Mikael Asplund, Marc-Oliver Pahl, Sebastian Steinhorst |
DATE | 3 |
| 2024 | Towards an integrated risk analysis security framework according to a systematic analysis of existing proposalsabstractAbstract The information society depends increasingly on risk assessment and management systems as means to adequately protect its key information assets. The availability of these systems is now vital for the protection and evolution of companies. However, several factors have led to an increasing need for more accurate risk analysis approaches. These are: the speed at which technologies evolve, their global impact and the growing requirement for companies to collaborate. Risk analysis processes must consequently adapt to these new circumstances and new technological paradigms. The objective of this paper is, therefore, to present the results of an exhaustive analysis of the techniques and methods offered by the scientific community with the aim of identifying their main weaknesses and providing a new risk assessment and management process. This analysis was carried out using the systematic review protocol and found that these proposals do not fully meet these new needs. The paper also presents a summary of MARISMA, the risk analysis and management framework designed by our research group. The basis of our framework is the main existing risk standards and proposals, and it seeks to address the weaknesses found in these proposals. MARISMA is in a process of continuous improvement, as is being applied by customers in several European and American countries. It consists of a risk data management module, a methodology for its systematic application and a tool that automates the process. Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, David Garcia Rosado, Manuel A. Serrano, Carlos Blanco 0001, Haralambos Mouratidis, Eduardo Fernández-Medina |
Frontiers Comput. Sci. | 6 |
| 2023 | Goal-Modeling Privacy-by-Design Patterns for Supporting GDPR Compliance
Mohammed Al-Obeidallah, Luca Piras 0003, Onyinye Iloanugo, Haralambos Mouratidis, Duaa Alkubaisy, Daniele Dellagiacoma |
ICSOFT | 4 |
| 2023 | Modelling language for cyber security incident handling for critical infrastructuresabstractCyber security incident handling is a consistent methodology with which to ensure overall business continuity. However, specifically handling incidents for critical information infrastructures is challenging owing to the inherent complexity and evolving nature of the threat. Despite the number of contributions made to cyber incident handling, there is little evidence of literature that focuses on modelling activities that will enhance developers’ abilities to model incident handling processes and activities according to different views. Modelling languages of this nature should integrate essential concepts and a descriptive implementation process in order to enable developers to analyse, represent and reason about the crucial incident handling efforts required to support critical information infrastructures. The aim of this paper is, as part of the CyberSANE EU project, to develop a Cyber Incident Handling Modelling Language (CIHML) that focuses explicitly on modelling incident handling in the context of a critical information infrastructure. The work is innovative in its approach because it consolidates concepts from various domains such as security requirements, forensics, threat intelligence, critical infrastructures and cyber incident handling. The approach will allow the phases of the incident handling lifecycle to be modelled from three different views (critical information infrastructures, threat and risk analysis, and incident response). An implementation process is also proposed, which will serve as a comprehensive guide for developers in order to create these modelling views. Finally, CIHML is evaluated using a real-life scenario from the CyberSANE project to demonstrate its applicability. The incident observed had a severe impact on the overall business continuity of the context studied. The results obtained from the study show that CIHML can help critical information infrastructure operators to identify, evaluate, represent and model cyber incidents in critical information systems, in addition to providing the support required to determine the response strategies needed in order to mitigate these cyber-attacks. Haralambos Mouratidis, Shareeful Islam, Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, Umar Mukhtar Ismail |
Comput. Secur. | 1 |
| 2022 | An integrated cyber security risk management framework and risk predication for the critical infrastructure protection
Halima Ibrahim Kure, Shareeful Islam, Haralambos Mouratidis |
Neural Comput. Appl. | 3 |
| 2021 | The landscape of cybersecurity vulnerabilities and challenges in healthcare: Security standards and paradigm shift recommendationsabstractDigital technology provides unique opportunities to revolutionize the healthcare ecosystem and health research. However, this comes with serious security, safety, and privacy threats. The healthcare sector has been proven unequipped and unready to face cyberattacks while its vulnerabilities are being systematically exploited by attackers. The growing need and use of medical devices and smart equipment, the complexity of operations and the incompatible systems are leaving healthcare organizations exposed to various malware, including ransomware, which result in compromised healthcare access, quality, safety and care. To fully benefit from the advantages of technology, cybersecurity issues need to be resolved. Cybersecurity measures are being suggested via a number of healthcare standards which are often contradicting and confusing, making these measures ineffective and difficult to implement. To place a solid foundation for the healthcare sector, in improving the understanding of complex cybersecurity issues, this paper explores the existing vulnerabilities in the health care critical information infrastructures which are used in cyberattacks and discusses the reasons why this sector is under attack. Furthermore, the existing security standards in healthcare are presented alongside with their implementation challenges. The paper also discusses the use of living labs as a novel way to discover how to practically implement cybersecurity measures and also provides a set of recommendations as future steps. Finally, to our knowledge this is the first paper that analyses security in the context of living labs and provides suggestions relevant to this context. Kitty Kioskli, Theo Fotis, Haralambos Mouratidis |
ARES | 3 |
| 2021 | ConfIs: A Tool for Privacy and Security Analysis and Conflict Resolution for Supporting GDPR Compliance through Privacy-by-DesignabstractPrivacy and security requirements, and their potential conflicts, are increasingly having more and more importance. It is becoming a necessary part to be considered, starting from the very early stages of requirements engineering, and in the entire software engineering cycle, for the design of any software system. In the last few years, this has been even more emphasized and required by the law. A relevant example is the case of the General Data Protection Regulation (GDPR), which requires organizations, and their software engineers, to enforce and guarantee privacy-by-design to make their platforms compliant with the regulation. In this context, complex activities related to privacy and security requirements elicitation, analysis, mapping and identification of potential conflicts, and the individuation of their resolution, become crucial. In the literature, there is not available a comprehensive requirement engineering oriented tool for supporting the requirements analyst. In this paper, we propose ConfIs, a tool for supporting the analyst in performing a process covering these phases in a systematic and interactive way. We present ConfIs and its process with a realistic example from DEFeND, an EU project aiming at supporting organizations in achieving GDPR compliance. In this context, we evaluated ConfIs by involving privacy/security requirements experts, which recognized our tool and method as supportive, concerning these complex activities. Duaa Alkubaisy, Luca Piras 0003, Mohammed Al-Obeidallah, Karl Cox, Haralambos Mouratidis |
ENASE | 5 |
| 2020 | DEFeND DSM: A Data Scope Management Service for Model-Based Privacy by Design GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Michalis Pavlidis, Haralambos Mouratidis, Aggeliki Tsohou, Emmanouil Magkos, Andrea Praitano, Annarita Iodice, Beatriz Gallego-Nicasio |
TrustBus | 4 |
| 2020 | Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platformabstractPurpose General data protection regulation (GDPR) entered into force in May 2018 for enhancing personal data protection. Even though GDPR leads toward many advantages for the data subjects it turned out to be a significant challenge. Organizations need to implement long and complex changes to become GDPR compliant. Data subjects are empowered with new rights, which, however, they need to become aware of. GDPR compliance is a challenging matter for the relevant stakeholders calls for a software platform that can support their needs. The aim of data governance for supporting GDPR (DEFeND) EU project is to deliver such a platform. The purpose of this paper is to describe the process, within the DEFeND EU project, for eliciting and analyzing requirements for such a complex platform. Design/methodology/approach The platform needs to satisfy legal and privacy requirements and provide functionalities that data controllers request for supporting GDPR compliance. Further, it needs to satisfy acceptance requirements, for assuring that its users will embrace and use the platform. In this paper, the authors describe the methodology for eliciting and analyzing requirements for such a complex platform, by analyzing data attained by stakeholders from different sectors. Findings The findings provide the process for the DEFeND platform requirements’ elicitation and an indicative sample of those. The authors also describe the implementation of a secondary process for consolidating the elicited requirements into a consistent set of platform requirements. Practical implications The proposed software engineering methodology and data collection tools (i.e. questionnaires) are expected to have a significant impact for software engineers in academia and industry. Social implications It is reported repeatedly that data controllers face difficulties in complying with the GDPR. The study aims to offer mechanisms and tools that can assist organizations to comply with the GDPR, thus, offering a significant boost toward the European personal data protection objectives. Originality/value This is the first paper, according to the best of the authors’ knowledge, to provide software requirements for a GDPR compliance platform, including multiple perspectives. Aggeliki Tsohou, Emmanouil Magkos, Haralambos Mouratidis, George Chrysoloras, Luca Piras 0003, Michalis Pavlidis, Julien Debussche, Marco Rotoloni, Beatriz Gallego-Nicasio |
Inf. Comput. Secur. | 3 |
| 2020 | Enhancing secure business process design with security process patterns
Nikolaos Argyropoulos, Haralambos Mouratidis, Andrew Fish |
Softw. Syst. Model. | 2 |
| 2020 | A security requirements modelling language for cloud computing environments
Haralambos Mouratidis, Shaun Shei, Aidan J. Delaney |
Softw. Syst. Model. | 1 |
| 2020 | Modelling the interplay of security, privacy and trust in sociotechnical systems: a computer-aided design approach
Mattia Salnitri, Konstantinos Angelopoulos, Michalis Pavlidis, Vasiliki Diamantopoulou, Haralambos Mouratidis, Paolo Giorgini |
Softw. Syst. Model. | 5 |
| 2019 | Cyber Security Incident Handling, Warning and Response System for the European Critical Information Infrastructures (CyberSANE)
Spyridon Papastergiou, Haralambos Mouratidis, Eleni-Maria Kalogeraki |
EANN | 2 |
| 2019 | Towards Detecting and Mitigating Conflicts for Privacy and Security RequirementsabstractRequirement engineering live in a world were contradiction is the norm. Hence, development of software engineering is usually an adjustable and upgrading cyclical process. We found in the literature that some requirements conflict with other requirements. We will focus in this study on identification and resolution of conflicts between security and privacy requirements. Although, most the recent studies focus on identifying conflicts without proposing a solution to resolve it. This paper presents an approach to identifying and resolving conflicting privacy and security requirements as patterns. By using patterns to describe the problem we can propose a solution for each conflict. Duaa Alkubaisy, Karl Cox, Haralambos Mouratidis |
RCIS | 3 |
| 2019 | DEFeND Architecture: A Privacy by Design Platform for GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Andrea Praitano, Aggeliki Tsohou, Haralambos Mouratidis, Beatriz Gallego-Nicasio, Jean Baptiste Bernard, Marco Fiorani, Emmanouil Magkos, Andrès Castillo Sanz, Michalis Pavlidis, Roberto D'Addario, Giuseppe Giovanni Zorzino |
TrustBus | 5 |
| 2019 | Apparatus: A framework for security analysis in internet of things systems
Orestis Mavropoulos, Haralambos Mouratidis, Andrew Fish, Emmanouil A. Panaousis |
Ad Hoc Networks | 2 |
| 2019 | Practical evaluation of a reference architecture for the management of privacy level agreementsabstractPurpose The enforcement of the General Data Protection Regulation imposes specific privacy- and -security related requirements that any organisation that processes European Union citizens’ personal data must comply with. The application of privacy- and security-by-design principles are assisting organisation in achieving compliance with the Regulation. The purpose of this study is to assist data controllers in their effort to achieve compliance with the new Regulation, by proposing the adoption of the privacy level agreement (PLA). A PLA is considered as a formal way for the data controllers and the data subjects to mutually agree the privacy settings of a service provisioned. A PLA supports privacy management, by analysing privacy threats, vulnerabilities and information systems’ trust relationships. Design/methodology/approach However, the concept of PLA has only been proposed on a theoretical level. To this aim, two different domains have been selected acting as real-life case studies, the public administration and the health care, where special categories of personal data are processed. Findings The results of the evaluation of the adoption of the PLA by the data controllers are positive. Furthermore, they indicate that the adoption of such an agreement facilitates data controllers in demonstrating transparency of their processes. Regarding data subjects, the evaluation process revealed that the use of the PLA increases trust levels on data controllers. Originality/value This paper proposes a novel reference architecture to enable PLA management in practice and reports on the application and evaluation of PLA management. Vasiliki Diamantopoulou, Haralambos Mouratidis |
Inf. Comput. Secur. | 2 |
| 2018 | Towards the Definition of a Security Incident Response Modelling Language
Myrsini Athinaiou, Haralambos Mouratidis, Theo Fotis, Michalis Pavlidis, Emmanouil A. Panaousis |
TrustBus | 2 |
| 2018 | Risk-aware decision support with constrained goal modelsabstractPurpose The selection of security configurations for complex information systems is a cumbersome process. Decision-making regarding the choice of security countermeasures has to take into consideration a multitude of, often conflicting, functional and non-functional system goals. Therefore, a structured method to support crucial security decisions during a system’s design that can take account of risk whilst providing feedback on the optimal decisions within specific scenarios would be valuable. Design/methodology/approach Secure Tropos is a well-established security requirements engineering methodology, but it has no concepts of Risk, whilst Constrained Goal Models are an existing method to support relevant automated reasoning tasks. Hence we bridge these methods, by extending Secure Tropos to incorporate the concept of Risk, so that the elicitation and analysis of security requirements can be complimented by a systematic risk assessment process during a system’s design time and supporting the reasoning regarding the selection of optimal security configurations with respect to multiple system objectives and constraints, via constrained goal models. Findings As a means of conceptual evaluation, to give an idea of the applicability of the approach and to check if alterations may be desirable, a case study of its application to an e-government information system is presented. The proposed approach is able to generate security mechanism configurations for multiple optimisation scenarios that are provided, whilst there are limitations in terms of a natural trade-off of information levels of risk assessment that are required to be elicited. Originality/value The proposed approach adds additional value via its flexibility in permitting the consideration of different optimisation scenarios by prioritising different system goals and the automated reasoning support. Nikolaos Argyropoulos, Konstantinos Angelopoulos, Haralambos Mouratidis, Andrew Fish |
Inf. Comput. Secur. | 3 |
| 2018 | Applying the physics of notation to the evaluation of a security and privacy requirements engineering methodologyabstractPurpose The purpose of this study is the analysis of a security and privacy requirements engineering methodology. Such methodologies are considered an important part of systems’ development process when they contain and process a large amount of critical information, and thus need to remain secure and ensure privacy. Design/methodology/approach These methodologies provide techniques, methods and norms for tackling security and privacy issues in information systems. In this process, the utilisation of effective, clear and understandable modelling languages with sufficient notation is of utmost importance, as the produced models are used not only among IT experts or among security specialists but also for communication among various stakeholders, in business environments or among novices in an academic environment. Findings The qualitative analysis revealed a partial satisfaction of these principles. Originality/value This paper evaluates the effectiveness of a security and privacy requirements engineering methodology, namely, Secure Tropos, on the nine principles of the theory of notation. Vasiliki Diamantopoulou, Haralambos Mouratidis |
Inf. Comput. Secur. | 2 |
| 2018 | Assurance of Security and Privacy Requirements for Cloud Deployment ModelsabstractDespite of the several benefits of migrating enterprise critical assets to the cloud, there are challenges specifically related to security and privacy. It is important that cloud users understand their security and privacy needs, based on their specific context and select cloud model best fit to support these needs. The literature provides works that focus on discussing security and privacy issues for cloud systems but such works do not provide a detailed methodological approach to elicit security and privacy requirements neither methods to select cloud deployment models based on satisfaction of these requirements by cloud service providers. This work advances the current state of the art towards this direction. In particular, we consider requirements engineering concepts to elicit and analyze security and privacy requirements and their associated mechanisms using a conceptual framework and a systematic process. The work introduces assurance as evidence for satisfying the security and privacy requirements in terms of completeness and reportable of security incident through audit. This allows perspective cloud users to define their assurance requirements so that appropriate cloud models can be selected for a given context. To demonstrate our work, we present results from a real case study based on the Greek National Gazette. Shareeful Islam, Moussa Ouedraogo, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
IEEE Trans. Cloud Comput. | 4 |
| 2018 | A Security Analysis Method for Industrial Internet of ThingsabstractThe industrial Internet of Things (IIoT) provide an opportunity for industries to build large interconnected systems that utilize various technologies, such as personal computers, wireless devices, and sensor devices, and bring together the cyber and the physical worlds. Such systems provide us with huge advantages but they also introduce major security challenges at both the design and runtime stages. The literature argues for the need to introduce security-by-design methods, which enable security analysis and mitigation of security threats. This paper proposes a novel security-by-design method for IIoT environments across two different levels, design/modeling, and runtime/simulation. Our method supports the analysis of security requirements and identification of attack paths and their integration for the mitigation of potential vulnerabilities. We demonstrate its applicability through a real case study on a critical environment from the maritime sector, which demonstrates that our method helps to identify security mechanisms to mitigate attacks on critical assets. Haralambos Mouratidis, Vasiliki Diamantopoulou |
IEEE Trans. Ind. Informatics | 1 |
| 2017 | A Holistic Approach for Privacy Protection in E-GovernmentabstractImproving e-government services by using data more effectively is a major focus globally. It requires Public Administrations to be transparent, accountable and provide trustworthy services that improve citizen confidence. However, despite all the technological advantages on developing such services and analysing security and privacy concerns, the literature does not provide evidence of frameworks and platforms that enable privacy analysis, from multiple perspectives, and take into account citizens' needs with regards to transparency and usage of citizens information. This paper presents the VisiOn (Visual Privacy Management in User Centric Open Requirements) platform, an outcome of a H2020 European Project. Our objective is to enable Public Administrations to analyse privacy and security from different perspectives, including requirements, threats, trust and law compliance. Finally, our platform-supported approach introduces the concept of Privacy Level Agreement (PLA) which allows Public Administrations to customise their privacy policies based on the privacy preferences of each citizen. Konstantinos Angelopoulos, Vasiliki Diamantopoulou, Haralambos Mouratidis, Michalis Pavlidis, Mattia Salnitri, Paolo Giorgini, José Fran. Ruiz |
ARES | 3 |
| 2017 | Are Small Cells and Network Intelligence at the Edge the Drivers for 5G Market Adoption? The SESAME Case
Ioannis Neokosmidis, Theodoros Rokkas, Ioannis P. Chochliouros, Leonardo Goratti, Haralambos Mouratidis, Karim M. Nasr, Seiamak Vahid, Klaus Moessner, Antonino Albanese, Paolo Secondo Crosta, Pietro Paglierani |
EANN | 5 |
| 2017 | Recommender Systems Meeting Security: From Product Recommendation to Cyber-Attack Prediction
Nikolaos Polatidis, Elias Pimenidis, Michalis Pavlidis, Haralambos Mouratidis |
EANN | 4 |
| 2017 | Supporting Privacy by Design Using Privacy Process Patterns
Vasiliki Diamantopoulou, Christos Kalloniatis, Stefanos Gritzalis, Haralambos Mouratidis |
SEC | 4 |
| 2017 | ASTo: A tool for security analysis of IoT systemsabstractIn this paper, a software tool for security analysis of IoT systems is presented. The tool, named ASTo (Apparatus Software Tool) enables the visualization of IoT systems using a domain-specific modeling language. The modeling language provides constructs to express the hardware, software and social concepts of an IoT system along with security concepts. Security issues of IoT systems are identified based on the attributes of the constructs and their relationships. Security analysis is facilitated using the visualization mechanisms of the tool to recognize the secure posture of an IoT system. Orestis Mavropoulos, Haralambos Mouratidis, Andrew Fish, Emmanouil A. Panaousis |
SERA | 2 |
| 2017 | Selecting Security Mechanisms in Secure Tropos
Michalis Pavlidis, Haralambos Mouratidis, Emmanouil A. Panaousis, Nikolaos Argyropoulos |
TrustBus | 2 |
| 2017 | Privacy-preserving collaborative recommendations based on random perturbations
Nikolaos Polatidis, Christos K. Georgiadis, Elias Pimenidis, Haralambos Mouratidis |
Expert Syst. Appl. | 4 |
| 2016 | Incorporating privacy patterns into semi-automatic business process derivationabstractThe design of systems capable of protecting users' privacy is a challenging endeavour. Since users are becoming more concerned about the amounts of their personal data handled, stored and shared by such systems it is imperative to identify methods for developing privacy-aware information systems. Current approaches either focus on the elicitation of user requirements at an abstract high level or approach the issue of privacy exclusively from a technical point of view. As a result, privacy implementations are often misaligned with the overarching system goals. This work improves the current situation by presenting an approach for the design of privacy-aware business processes. Goal models are created as a first step, for privacy requirements elicitation, and are then transformed into process models, thus bridging the gap between high level goals and low level processes. Privacy process patterns are utilised for the final instantiation of process models, achieving the satisfaction of the identified privacy objectives through the integration of privacy enhancing technologies. The main advantage of the proposed approach is its ability to map privacy from the strategic to the operational level through a semi-automatic process while offering designers adequate guidance to its operationalisation via the use of process patterns. Nikolaos Argyropoulos, Christos Kalloniatis, Haralambos Mouratidis, Andrew Fish |
RCIS | 3 |
| 2016 | Privacy Requirements: Findings and Lessons Learned in Developing a Privacy PlatformabstractInformation practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience. Mohamad Gharib, Mattia Salnitri, Elda Paja, Paolo Giorgini, Haralambos Mouratidis, Michalis Pavlidis, José Fran. Ruiz, Sandra Fernandez, Andrea Della Siria |
RE | 5 |
| 2016 | Modelling Secure Cloud Computing Systems from a Security Requirements Perspective
Shaun Shei, Christos Kalloniatis, Haralambos Mouratidis, Aidan J. Delaney |
TrustBus | 3 |
| 2016 | Towards a Model-Based Framework for Forensic-Enabled Cloud Information Systems
Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
TrustBus | 3 |
| 2016 | Security Challenges of Small Cell as a Service in Virtualized Mobile Edge Computing Environments
Vassilios G. Vassilakis, Emmanouil A. Panaousis, Haralambos Mouratidis |
WISTP | 3 |
| 2016 | An information security risk-driven investment model for analysing human factorsabstractPurpose The purpose of this paper is to introduce a risk-driven investment process model for analysing human factors that allows information security managers to capture possible risk–investment relationships and to reason about them. The overall success of an information security system depends on analysis of the risks and threats so that appropriate protection mechanism can be in place to protect them. However, lack of appropriate analysis of risks may potentially results in failure of information security systems. Existing literature does not provide adequate guidelines for a systematic process or an appropriate modelling language to support such analysis. This work aims to fill this gap by introducing the process and reason about the risks considering human factors. Design/methodology/approach To develop risk-driven investment model along with the activities that support the process. These objectives were achieved through the collection of quantitative and qualitative data utilising requirements engineering and secure tropos methods. Findings The proposed process and model lead to define a clear relationship between risks, incidents and investment and allows organisations to calculate them based on their own figures. Research limitations/implications One of the major limitations of this model is that it only supports incident-based investment. This creates some sort of difficulties to be presented to the executive board. Secondly, because of the nature of human factors, quantification does not exactly reflect the monetary value of the factors. Practical implications Applying the information security risk-driven investment model in a real case study shows that this can help organisations apply and use it in other incidents, and more importantly, to the incidents which critical human factors are a grave concern of organisations. The importance of providing a financial justification is clearly highlighted and provided for seeking investment in information security. Social implications It has a big social impact that technically could lead for cost justifications and decision-making process. This would impact the whole society by helping individuals to keep their data safe. Originality/value The novel contribution of this work is to analyse specific critical human factors which have subjective natures in an objective and dynamic domain of risk, security and investment. Reza Alavi, Shareeful Islam, Haralambos Mouratidis |
Inf. Comput. Secur. | 3 |
| 2016 | A survey on cloud forensics challenges and solutionsabstractAbstract In recent years, cloud computing has gained popularity, and it is now used to support various areas of human life. Cloud forensics has been introduced to help forensic investigators find potential evidence against cloud criminal activities and maintain the security and integrity of the information stored in the cloud. While great research in the area has been carried out concerning challenges and solutions, the research on methodologies and frameworks is still in its infancy. This article focuses on the methodological aspects of cloud forensics. It critically reviews cloud forensics' existing challenges and solutions, and it explores, based on a detailed review of the area, all the work that has been carried out both in digital and cloud forensic methodologies mainly for supporting the investigation of security incidents in cloud. Furthermore, the detailed comparison reveals similarities and drawbacks of the existing methodologies providing some novel future research directions. Finally, the specific paper can be considered as a starting point for researchers wishing to design cloud‐forensicable services over the cloud. Copyright © 2016 John Wiley & Sons, Ltd. Stavros Simou, Christos Kalloniatis, Stefanos Gritzalis, Haralambos Mouratidis |
Secur. Commun. Networks | 4 |
| 2015 | Addressing Privacy and Trust Issues in Cultural Heritage Modelling
Michalis Pavlidis, Haralambos Mouratidis, Cesar Gonzalez-Perez, Christos Kalloniatis |
CRiSIS | 2 |
| 2015 | A Meta-model for Assisting a Cloud Forensics Process
Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
CRiSIS | 3 |
| 2015 | Security-Aware Elasticity for NoSQL Databases
Athanasios Naskos, Anastasios Gounaris, Haralambos Mouratidis, Panagiotis Katsaros |
MEDI | 3 |
| 2015 | Privacy as an Integral Part of the Implementation of Cloud SolutionsabstractBridging the gap between design and implementation stages has been a major concern of designers, analysts and developers of information systems (ISs) and a major aspiration of a number of IS engineering approaches. Cloud computing exacerbates the strain on traditional IS engineering approaches that service-oriented computing has started. At the same time, recent research has argued about the importance of security and privacy in a cloud environment and highlighted a number of security and privacy challenges that are not present in traditional environments and need special attention when implementing or migrating ISs into a cloud environment. This paper contributes to this direction. Specifically, it presents a number of privacy-related cloud properties that analysts need to consider when designing privacy-aware systems in a cloud environment. Also it indicates a number of implementation techniques that can assist developers in assuring the respective properties. Evangelia Kavakli, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
Comput. J. | 3 |
| 2015 | Empirical evaluation of a cloud computing information security governance framework
Oscar Rebollo, Daniel Mellado, Eduardo Fernández-Medina, Haralambos Mouratidis |
Inf. Softw. Technol. | 4 |
| 2014 | An empirical study on the implementation and evaluation of a goal-driven software development risk management model
Shareeful Islam, Haralambos Mouratidis, Edgar R. Weippl |
Inf. Softw. Technol. | 2 |
| 2013 | Trustworthy Selection of Cloud Providers Based on Security and Privacy Requirements: Justifying Trust Assumptions
Michalis Pavlidis, Haralambos Mouratidis, Christos Kalloniatis, Shareeful Islam, Stefanos Gritzalis |
TrustBus | 2 |
| 2013 | Selecting a Cloud Service Provider in the age of cybercrime
Moussa Ouedraogo, Haralambos Mouratidis |
Comput. Secur. | 2 |
| 2013 | A framework to support selection of cloud providers based on security and privacy requirements
Haralambos Mouratidis, Shareeful Islam, Christos Kalloniatis, Stefanos Gritzalis |
J. Syst. Softw. | 1 |
| 2013 | Evaluating cloud deployment scenarios based on security and privacy requirements
Christos Kalloniatis, Haralambos Mouratidis, Shareeful Islam |
Requir. Eng. | 2 |
| 2013 | Taxonomy of quality metrics for assessing assurance of security correctness
Moussa Ouedraogo, Reijo Savola, Haralambos Mouratidis, David Preston 0001, Djamel Khadraoui, Eric Dubois 0001 |
Softw. Qual. J. | 3 |
| 2012 | Extracting security requirements from relevant laws and regulationsabstractFor software systems that process and manage sensitive information, compliance with laws has become not an option but a necessity. Analysing relevant laws and aligning them with the system requirements is necessary for attaining compliance issues. But analyzing laws within the context of software system requirements is a difficult task, mainly because the concepts used in legal texts are different compared to the concepts used in requirements engineering. This paper contributes to that direction. In particular it presents a process to model and analyse laws and regulations and to support the elicitation of security requirements based on the relevant legal and system context. Finally a case study is used to demonstrate the applicability of the proposed approach. Fatemeh Zarrabi Jorshari, Haralambos Mouratidis, Shareeful Islam |
RCIS | 2 |
| 2012 | Dealing with trust and control: A meta-model for trustworthy information systems developmentabstractInformation systems exist in every aspect of our life and our society depends on them enormously. Despite this reliance, these systems are often unreliable, prone to errors, and pose vulnerabilities for potential security attacks. We are often faced with a choice between using a valuable (or even an essential) system, which is not fully trustworthy, or else forgoing the services it provides. Developing a trustworthy software system is a challenging task. The system's overall trustworthiness depends on trust relationships that are usually assumed and not properly analysed during the analysis and design of the system. The lack of appropriate analysis of such trust relationships, or the lack of appropriate justification of relevant trust assumptions, usually results in systems that can potentially fail to fully achieve those functionalities that depend on such trust relationships. In this paper, we present a meta-model for a modelling language that allows developers to capture possible trust relationships and to reason about them. The meta-model includes a set of trust based concepts, which support the development of trustworthy systems. A case study from the UK health care sector is used to illustrate the usefulness of the meta-model. Michalis Pavlidis, Haralambos Mouratidis, Shareeful Islam, Paul Kearney |
RCIS | 2 |
| 2012 | Preface
Haralambos Mouratidis |
Inf. Syst. | 1 |
| 2012 | Appraisal and reporting of security assurance at operational systems level
Moussa Ouedraogo, Djamel Khadraoui, Haralambos Mouratidis, Eric Dubois 0001 |
J. Syst. Softw. | 3 |
| 2011 | A new approach to evaluating security assuranceabstractThis paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through tool implementation, and application to another of security components including firewall, DNS and antivirus. Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, Eric Dubois 0001, David Preston 0001 |
IAS | 2 |
| 2011 | A framework to support alignment of secure software engineering with legal regulations
Shareeful Islam, Haralambos Mouratidis, Jan Jürjens |
Softw. Syst. Model. | 2 |
| 2010 | Towards a Framework to Elicit and Manage Security and Privacy Requirements from Laws and Regulations
Shareeful Islam, Haralambos Mouratidis, Stefan Wagner 0001 |
REFSQ | 2 |
| 2010 | From goal-driven security requirements engineering to secure designabstractSecurity of intelligent software systems is an important area of research. Although security is traditionally considered a technical issue; security is, in fact, a two-dimensional problem, which involves technical as well as social challenges. Goal-driven requirements engineering (GDRE) has been proposed in the literature as a suitable paradigm for the analysis of security issues and elicitation of security requirements at both the social and technical level. Nevertheless, there is lack of approaches, which would support the successful transformation of the elicited, using GDRE approaches, security requirements to design. This paper presents work that fills this gap. The presented approach, which is based on the integration of a goal-driven security requirements engineering (GDSRE) methodology and a model-based security engineering (MBSE) method, has some important features: (1) It provides a structured process to translate the results of the GDSRE method to a design, which satisfies these requirements; (2) it allows the simultaneous elicitation and analysis of the security requirements and the functional requirements of the system; (3) it allows consideration of both the social and the technical dimensions of the system's security; (4) it guides software engineers toward a design that is amenable to formal verification with the aid of automated tools. We demonstrate the applicability of the proposed approach at the hand of an application to the electronic purse standard common electronic purse specifications (released by Visa International and others). © 2010 Wiley Periodicals, Inc. Haralambos Mouratidis, Jan Jürjens |
Int. J. Intell. Syst. | 1 |
| 2010 | Guest editorial: security requirements engineering: past, present and future
Eric Dubois 0001, Haralambos Mouratidis |
Requir. Eng. | 2 |
| 2010 | An architectural description language for secure Multi-Agent SystemsabstractMulti-Agent Systems (MAS) architectures are gaining popularity for building open, distributed, and evolving information systems. Unfortunately, despite considerable work in the fields of software architecture and MAS during the last decade, few resea Haralambos Mouratidis, Manuel Kolp, Paolo Giorgini, Stéphane Faulkner |
Web Intell. Agent Syst. | 1 |
| 2009 | Secure Information Systems Engineering: Experiences and Lessons Learned from Two Health Care Projects
Haralambos Mouratidis, Ali Sunyaev, Jan Jürjens |
CAiSE | 1 |
| 2009 | A security-aware metamodel for multi-agent systems (MAS)
Ghassan Beydoun, Graham C. Low, Haralambos Mouratidis, Brian Henderson-Sellers |
Inf. Softw. Technol. | 3 |
| 2009 | FAML: A Generic Metamodel for MAS DevelopmentabstractIn some areas of software engineering research, there are several metamodels claiming to capture the main issues. Though it is profitable to have variety at the beginning of a research field, after some time, the diversity of metamodels becomes an obstacle, for instance to the sharing of results between research groups. To reach consensus and unification of existing metamodels, metamodel-driven software language engineering can be applied. This paper illustrates an application of software language engineering in the agent-oriented software engineering research domain. Here, we introduce a relatively generic agent-oriented metamodel whose suitability for supporting modeling language development is demonstrated by evaluating it with respect to several existing methodology-specific metamodels. First, the metamodel is constructed by a combination of bottom-up and top-down analysis and best practice. The concepts thus obtained and their relationships are then evaluated by mapping to two agent-oriented metamodels: TAO and Islander. We then refine the metamodel by extending the comparisons with the metamodels implicit or explicit within five more extant agent-oriented approaches: Adelfe, PASSI, Gaia, INGENIAS, and Tropos. The resultant FAML metamodel is a potential candidate for future standardization as an important component for engineering an agent modeling language. Ghassan Beydoun, Graham C. Low, Brian Henderson-Sellers, Haralambos Mouratidis, Jorge J. Gómez-Sanz, Juan Pavón, Cesar Gonzalez-Perez |
IEEE Trans. Software Eng. | 4 |
| 2008 | Adapting Secure Tropos for Security Risk Management in the Early Phases of Information Systems Development
Raimundas Matulevicius, Nicolas Mayer, Haralambos Mouratidis, Eric Dubois 0001, Patrick Heymans, Nicolas Genon |
CAiSE | 3 |
| 2008 | Selecting Security Patterns that Fulfill Security RequirementsabstractOver the last few years a large number of security patterns have been proposed. However, this large number of patterns has created a problem in selecting patterns that are appropriate for different security requirements. In this paper, we present a selection approach for security patterns, which allows us to understand in depth the trade-offs involved in the patterns and the implications of a pattern to various security requirements. Moreover, our approach supports the search for a combination of security patterns that will meet given security requirements. Michael Weiss 0001, Haralambos Mouratidis |
RE | 2 |
| 2008 | Management versus security specialists: an empirical study on security related perceptionsabstractPurpose The purpose of this study is to explore the rationale that governs implementation of information systems and network security expenditures through a case study approach. Design/methodology/approach The research method took the form of a mixed‐method assessment of the perceptions of persons of authority in the management and the network security areas of an organization that has implemented network security protocols. Two stages of the research process were completed in order to gather the necessary data for the study. The first stage of the study was the administration of a Likert‐type questionnaire in which respondents answered 30 unique items on network security. In the second phase of the study, a number of responders were contacted to further expand upon the themes presented in the Likert‐type questionnaire. Findings Empirical evidence gathered justifies theoretical claims that personnel from general management have different perspectives towards network security than personnel from the network security management. In particular, the study indicates that such differences are demonstrated on a number of areas such as the effectiveness and the efficiency of the networked system; control of network security; security‐related decision‐making processes; and users of the network. The latter being the most controversial issue with one side indicating that users should be allowed to use the network in an efficient manner, and the other side emphasizing that users pose one of the greatest security risks to the system. Research limitations/implications The limitations of the study are found in its focus on a specific company and on its perception‐centred nature of risk and risk analysis. No two persons identify and frame risk in an identical manner. This creates potential conflict of interest when the participants within a risk assessment process approach the issues and present their arguments as to how to best identify and respond to risks. Practical implications Through comparing and contrasting the perspectives of the two sample populations, the research assists in demonstrating how, why, and to what extent specific problems are recognized by those within management and those within network security. This allowed the analysis of how these problems are defined and what steps can be taken that would help to reduce or eliminate its impact in the organization used in our case study. Originality/value It has been argued in the literature that there is lack of empirically based research to explore and effectively analyze the perceptions held by management and by security specialists within organizations with respect to security. This paper presents the results of the application of a novel two‐stage framework on an empirical case study focused on a large national bank. The work allowed the identification of the various perceptions held by management and by security specialists, and the degree to which these perceptions are similar. Haralambos Mouratidis, Hamid Jahankhani, Mathews Z. Nkhoma |
Inf. Manag. Comput. Secur. | 1 |
| 2007 | Modelling MAS-Specific Security Features
Ghassan Beydoun, Graham C. Low, Haralambos Mouratidis, Brian Henderson-Sellers |
EMMSAD | 3 |
| 2007 | Information Systems Security: Cases of Network Administrator ThreatsabstractIn today’s business environment it is difficult to obtain senior management approval for the expenditure of valuable resources to “guarantee” that a potentially disastrous event will not occur that could affect the ultimate survivability of the organization. The total information network flexibility achieved depends to a great extent on how network security is implemented. However, this implementation depends on the network designers at the initial stage and the network administrators in the long term. Administrator may pave the way to attacks that could take place either at once where an obvious vulnerability may exist or in several phases where it requires information gathering or scanning in order to enter into the target system. Two studies on real cases given in this paper highlights the influence of such network administrators. To preserve the confidentiality, the names of personnel or organizations are not revealed. Hamid Jahankhani, Shantha Fernando, Mathews Z. Nkhoma, Haralambos Mouratidis |
Int. J. Inf. Secur. Priv. | 4 |
| 2007 | Secure Tropos: a Security-Oriented Extension of the Tropos MethodologyabstractAlthough security plays an important role in the development of multiagent systems, a careful analysis of software development processes shows that the definition of security requirements is, usually considered after the design of the system. One of the reasons is the fact that agent oriented software engineering methodologies have not integrated security concerns throughout their developing stages. The integration of security concerns during the whole range of the development stages can help in the development of more secure multiagent systems. In this paper we introduce extensions to the Tropos methodology to enable it to model security concerns throughout the whole development process. A description of the new concepts and modelling activities is given together with a discussion on how these concepts and modelling activities are integrated to the current stages of Tropos. A real life case study from the health and social care sector is used to illustrate the approach. Haralambos Mouratidis, Paolo Giorgini |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2007 | Security Attack Testing (SAT) - testing the security of information systems at design time
Haralambos Mouratidis, Paolo Giorgini |
Inf. Syst. | 1 |
| 2006 | Towards a Comprehensive Framework for Secure Systems Development
Haralambos Mouratidis, Jan Jürjens, Jorge Fox |
CAiSE | 1 |
| 2006 | Modeling Secure Systems Using an Agent-oriented Approach and Security PatternsabstractIn this paper we describe an approach for modeling security issues in information systems. It is based on an agent-oriented approach, and extends it with the use of security patterns. Agent-oriented software engineering provides advantages when modeling security issues, since agents are often a natural way of conceptualizing an information system, in particular at the requirements stage, when the viewpoints of multiple stakeholders need to be considered. Our approach uses the Tropos methodology for modeling a system as a set of agents and their social dependencies, with specific extensions for representing security constraints. As an extension to the existing methodology we propose the use of security patterns. These patterns capture proven solutions to common security issues, and support the systematic and structured mapping of these constraints to an architectural model of the system, in particular for non-security specialists. Haralambos Mouratidis, Michael Weiss 0001, Paolo Giorgini |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2005 | Security Patterns Meet Agent Oriented Software Engineering: A Complementary Solution for Developing Secure Information Systems
Haralambos Mouratidis, Michael Weiss 0001, Paolo Giorgini |
ER | 1 |
| 2005 | Safety and Security in Multiagent Systems: Report on the 2nd SASEMAS workshop (SASEMAS'05)
Haralambos Mouratidis |
Comput. Secur. | 1 |
| 2005 | When security meets software engineering: a case of modelling secure information systems
Haralambos Mouratidis, Paolo Giorgini, Gordon A. Manson |
Inf. Syst. | 1 |
| 2003 | Integrating Security and Systems Engineering: Towards the Modelling of Secure Information Systems
Haralambos Mouratidis, Paolo Giorgini, Gordon A. Manson |
CAiSE | 1 |
| 2003 | An Ontology for Modelling Security: The Tropos Approach
Haralambos Mouratidis, Paolo Giorgini, Gordon A. Manson |
KES | 1 |