Stefanos Gritzalis

dblp:83/4094 · DBLP profile ↗
← Back
107ranked-venue papers
8as first author
4since 2021 · last 2025
0000-0002-8037-2191ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 60 · 6 first-author · 3 since 2021Computer networks · 23 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 8 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4Artificial intelligence and machine learning · 3Databases, data management, data science and information retrieval · 3Human-computer interaction and ubiquitous computing · 2Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Assessing the detection of lateral movement through unsupervised learning techniques
Christos Smiliotopoulos, Georgios Kambourakis, Constantinos Kolias, Stefanos Gritzalis
Comput. Secur.4
2024 A Unified Framework for GDPR Compliance in Cloud Computing
abstract
In parallel with the rapid development of Information and Communication technologies and the digitization of information in every aspect of daily life, the enforcement of the GDPR, in May 2018, brought significant changes to the processes that organisations should follow during collecting, processing, and storing personal data and revealed the immediate need for integrating the Regulation’s requirements for integrating into organisational activities that process personal and sensitive data. On the other hand, cloud computing is a cutting-edge technology that is widely used in order to support most, if not every, organisational activities. As a result, such infrastructure constitutes huge pools of personal data and, in this context, a careful consideration and implementation of the rules imposed by the Regulation is considered crucial. In this paper, after highlighting the need to consider the GDPR requirements when designing cloud-based systems, we determined those GDPR compliance controls that should be incorporated at the early stages of the system design process. As a next step, those compliance controls were integrated into a holistic framework that considers both the security and privacy aspects of a cloud-based system as well as the requirements arising from the Regulation during the design of such systems.
Argyri Pattakou, Vasiliki Diamantopoulou, Christos Kalloniatis, Stefanos Gritzalis
ARES4
2024 Leveraging application permissions and network traffic attributes for Android ransomware detection
Sekione Reward Jeremiah, Stefanos Gritzalis, Jong Hyuk Park 0001
J. Netw. Comput. Appl.3
2023 A hands-on gaze on HTTP/3 security through the lens of HTTP/2 and a public dataset
abstract
Following QUIC protocol ratification on May 2021, the third major version of the Hypertext Transfer Protocol, namely HTTP/3, was published around one year later in RFC 9114. In light of these consequential advancements, the current work aspires to provide a full-blown coverage of the following issues, which to our knowledge have received feeble or no attention in the literature so far. First, we provide a complete review of attacks against HTTP/2, and elaborate on if and in which way they can be migrated to HTTP/3. Second, through the creation of a testbed comprising the at present six most popular HTTP/3-enabled servers, we examine the effectiveness of a quartet of attacks, either stemming directly from the HTTP/2 relevant literature or being entirely new. This scrutiny led to the assignment of at least one CVE ID with a critical base score by MITRE. No less important, by capitalizing on a realistic, abundant in devices testbed, we compiled a voluminous, labeled corpus containing traces of ten diverse attacks against HTTP and QUIC services. An initial evaluation of the dataset mainly by means of machine learning techniques is included as well. Given that the 30 GB dataset is made available in both pcap and CSV formats, forthcoming research can easily take advantage of any subset of features, contingent upon the specific network topology and configuration.
Efstratios Chatzoglou, Vasileios Kouliaridis, Georgios Kambourakis, Georgios Karopoulos, Stefanos Gritzalis
Comput. Secur.5
2020 Measuring Users' Socio-contextual Attributes for Self-adaptive Privacy Within Cloud-Computing Environments
Angeliki Kitsiou, Eleni Tzortzaki, Christos Kalloniatis, Stefanos Gritzalis
TrustBus4
2019 A framework for designing cloud forensic-enabled services (CFeS)
Stavros Simou, Christos Kalloniatis, Stefanos Gritzalis, Vasilios Katos
Requir. Eng.3
2018 Never say never: Authoritative TLD nameserver-powered DNS amplification
abstract
DNS amplification attack is a significant and persistent threat to the Internet. Authoritative name servers (ANSes) of popular domains, especially the DNSSEC-enabled ones, give attractive leverage for attackers in distributed denial-of-service (DDoS) attacks. Particularly, the ANS list of top-level domains (TLD) is publicly accessible, including by would-be attackers, in the form of a root.zone file. In this work, we examine the potential of TLD ANSes to be exploited as unknowing agents in DNS amplification attacks. Specifically, over a period of 12 months that covers two different versions of the root.zone file, we assess the amplification factor (AF) that these servers may provide to attackers when replying to both individual and multiple queries. Also, we measure the degree of actual adoption of the recommended response rate limiting (RRL) countermeasure for the ANSes. Our major findings are that (i) 70% of the distinct ANSes and 47% of the possible DNS queries for the TLDs produce a large AF that exceeds 60, (ii) 10% of the distinct ANSes reflect inbound network traffic and magnify it by a factor that exceeds 50, (iii) the number of most useful ANSes for the attacker, in terms of their role as amplifiers, appears increasing during the monitoring period, and (iv) there still exists a significant number of ANSes that do not implement the RRL or leave it inactive.
Marios Anagnostopoulos, Georgios Kambourakis, Stefanos Gritzalis, David K. Y. Yau
NOMS3
2018 An assessment of privacy preservation in crowdsourcing approaches: Towards GDPR compliance
abstract
The increasing use of Social Media has transformed them into valuable tools, able to provide answers and decision support in public policy formulation. This has resulted in the emergence of new e-participation paradigms, such as crowdsourcing approaches, aiming to drive more constructive interactions between governments and citizens or experts, in order to exploit their knowledge, opinions, and ideas when tackling complex societal problems. However, the continuous exposure of the average users, without or with limited awareness of the dangers of the disclosure of sensitive data, remains a threat to the preservation of their information privacy. The upcoming EU General Data Protection Regulation (GDPR) about the protection of personal data is especially well timed, and forces for revision of the processes followed related to the manipulation of personal data within public participation methods. Towards this direction, a thorough examination of three advanced methods of crowdsourcing in public policy-making processes is conducted in the current paper, analysing the data collection and processing methods they encompass. Then, an assessment of their compliance with fundamental privacy requirements is presented. The research contributes to the identification of challenges that crowdsourcing, and in general, e-participation approaches impose with regard to privacy protection. Further research directions include the implementation of techniques that can satisfy the identified requirements.
Vasiliki Diamantopoulou, Aggeliki Androutsopoulou, Stefanos Gritzalis, Yannis Charalabidis
RCIS3
2018 A Decision-Making Approach for Improving Organizations' Cloud Forensic Readiness
Stavros Simou, Ioannis Troumpis, Christos Kalloniatis, Dimitris Kavroudakis, Stefanos Gritzalis
TrustBus5
2018 Assurance of Security and Privacy Requirements for Cloud Deployment Models
abstract
Despite of the several benefits of migrating enterprise critical assets to the cloud, there are challenges specifically related to security and privacy. It is important that cloud users understand their security and privacy needs, based on their specific context and select cloud model best fit to support these needs. The literature provides works that focus on discussing security and privacy issues for cloud systems but such works do not provide a detailed methodological approach to elicit security and privacy requirements neither methods to select cloud deployment models based on satisfaction of these requirements by cloud service providers. This work advances the current state of the art towards this direction. In particular, we consider requirements engineering concepts to elicit and analyze security and privacy requirements and their associated mechanisms using a conceptual framework and a systematic process. The work introduces assurance as evidence for satisfying the security and privacy requirements in terms of completeness and reportable of security incident through audit. This allows perspective cloud users to define their assurance requirements so that appropriate cloud models can be selected for a given context. To demonstrate our work, we present results from a real case study based on the Greek National Gazette.
Shareeful Islam, Moussa Ouedraogo, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis
IEEE Trans. Cloud Comput.5
2018 Interpretability Constraints for Fuzzy Modeling Implemented by Constrained Particle Swarm Optimization
abstract
In this paper certain interpretability criteria are taken into account in order to extract a set of linear inequality constraints for enhancing the fuzzy model interpretability. Among others, the criteria of model distinguishability, completeness, compactness, and fuzzy set sharing between rules are considered. To support distinguishability, the distances between fuzzy set centers are lower bounded and the widths are manipulated as to control the overlap between fuzzy sets. Sufficient conditions are given to satisfy the completeness criterion, whereas the compactness requirement is addressed by comparing models with different number of rules. Finally, fuzzy set sharing between rules is achieved through a model optimization procedure that involves fuzzy set merging. It turns out that the feasible region is a compact and convex set. The tradeoff between interpretability and accuracy is established by minimizing the model's square error over the feasible region through constrained particle swarm optimization. The method is tested using a number of high-dimensional datasets and conducting two kinds of experiments. The first focuses on interpretability. The second studies the accuracy by comparing the method to other algorithms that perform unconstrained optimization, using nonparametric statistics.
George E. Tsekouras, John V. Tsimikas, Christos Kalloniatis, Stefanos Gritzalis
IEEE Trans. Fuzzy Syst.4
2018 Cryptographic Solutions for Industrial Internet-of-Things: Research Challenges and Opportunities
abstract
Industrial Internet of Things (IIoT) is an emerging trend, including in nontraditional technological sector (e.g., oil and gas industry). There are, however, a number of research challenges such using cryptography and other techniques to ensure security and privacy in IIoT applications and services. In this special issue, we present existing state-of-the-art advances reported by the 21 accepted papers. We then conclude the special issue with a number of potential research agenda.
Kim-Kwang Raymond Choo, Stefanos Gritzalis, Jong Hyuk Park 0001
IEEE Trans. Ind. Informatics2
2017 Supporting the design of privacy-aware business processes via privacy process patterns
abstract
Privacy is an increasingly important concern for modern software systems which handle personal and sensitive user information. Privacy by design has been established in order to highlight the path to be followed during a system's design phase ensuring the appropriate level of privacy for the information it handles. Nonetheless, transitioning between privacy concerns identified early during the system's design phase, and privacy implementing technologies to satisfy such concerns at the later development stages, remains a challenge. In order to overcome this issue, mainly caused by the lack of privacy-related expertise of software systems engineers, this work proposes a series of privacy process patterns. The proposed patterns encapsulate expert knowledge and provide predefined solutions for the satisfaction of different types of privacy concerns. The patterns presented in this work are used as a component of an existing privacy-aware system design methodology, through which they are applied to a real life system.
Vasiliki Diamantopoulou, Nikolaos Argyropoulos, Christos Kalloniatis, Stefanos Gritzalis
RCIS4
2017 Supporting Privacy by Design Using Privacy Process Patterns
Vasiliki Diamantopoulou, Christos Kalloniatis, Stefanos Gritzalis, Haralambos Mouratidis
SEC3
2017 Modelling Cloud Forensic-Enabled Services
Stavros Simou, Christos Kalloniatis, Stefanos Gritzalis
TrustBus3
2016 Realtime DDoS Detection in SIP Ecosystems: Machine Learning Tools of the Trade
Zisis Tsiatsikas, Dimitris Geneiatakis, Georgios Kambourakis, Stefanos Gritzalis
NSS4
2016 Towards a Model-Based Framework for Forensic-Enabled Cloud Information Systems
Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis
TrustBus4
2016 Challenges and opportunities in next-generation cyberspace security
abstract
The next generation of cyberspace online world of the future should be open, interoperable, reliable, and secure. Through next-generation cyberspace, individuals and communities are able to connect, socialize, and organize together. The goal of next-generation cyberspace is to deliver breakthrough innovation results for enterprises, enabling new products/services/markets, providing better quality for the digital economy and building better governments. However, there is existing challenges (such as growing demands, threats, constrained resources, and heterogeneous environments exist) in establishing next-generation cyberspace. It also calls for security and personal privacy considerations. The starting point for building a next-generation cyberspace can be found in a multitude of wired and wireless communication environments and a new technology or concept to support differentiated human-centric operations. The research efforts should provide innovative solutions in order to deliver resilient, cost-effective capabilities to the next-generation cyberspace and to meet the operational requirements in terms of security and privacy. The main motivation for this special issue is to bring together researchers from academic and industry laboratories to discuss current research issues and advances, which cover diverse aspects of next-generation cyberspace. The aim of our special issue is to provide a platform for discussing relevant research questions and engagement in the growing area of next-generation cyberspace. We have received many manuscripts. However, only 12 manuscripts in high quality were finally selected for this special issue. Each manuscript selected was blind reviewed by at least three reviewers consisting of guest editors and external reviewers. The first paper entitled “Server-based Code Obfuscation Scheme for APK Tamper Detection” by Yuxue Piao et al. analyzes the DexGuard tool from both a static and dynamic points of view. Their analysis reveals that DexGuard has some weaknesses. In this paper, they proposed an obfuscation technique based on a client/server model with one-time secret key delivery using SMS or network protocol. The main concept is to store the core execute class file through obfuscation on the server. When a program needs to execute core routines, it must request these routines from the server. In this way, they can protect Android apps from reverse engineering. The second paper entitled “An Authentication, Authorization, and Accounting Mechanism for 3G/WLAN Networks” by Wei-Chen Wu and Horng-Twu Liaw proposes a practical, efficient, and secure authentication, authorization, and accounting mechanism within the interworking architecture proposed by 3GPP. The next paper entitled “Identifying an OpenID Anti-Phishing Scheme for Cyberspace” by Haider Abbas et al. presents a user authentication scheme. This paper aims at identifying and discussing a solution to OpenID phishing by proposing a user authentication scheme that allows OpenID providers to identify a user using publicly known entities. The research will help in next-generation cyber security innovations by reducing the authentication dependency on user credentials. The authentication scheme is also validated through detailed descriptions of use cases and prototype implementation. “A Histogram-based Method for Efficient Detection of Rewriting Attacks in SOAP Messages” by Aziz Nasridinov et al. presents an efficient method for detecting XML rewriting attacks on SOAP messages using a histogram. With the proposed method, once the source of attacks is identified, it saves in the form of a histogram, which enables us to maintain a statistical information about the location of the attack in the SOAP message. This information can be used to detect attacks in the future and thus avoid unnecessary check of all elements in the SOAP message. Experiments show that the methods outperform those existing methods by several times in many cases. “Implementation of Vessel Traffic System's Mobile Middleware Platform for Secure IVEF Service” by Namje Park and Hyo-Chan Bang presents a vessel traffic service platform for securing inter-VTS data exchange format (IVEF). In this paper, they developed a system enabling IVEF service simulation under a wireless environment made possible by improving IVEF SDK, which is an open source. For this, a mobile phone loaded with Android platform and desktop PC has been used for emulation of a ship on voyage and VTS center. “Optimisation Based Collaborative Determination of Component Trustworthiness in Service Compositions” by Hisain Elshaafi and Dmitri Botvich describes a collaborative trustworthiness determination approach using optimization that can provide a solution to select trustworthy component service constructs based on monitoring and consumer quality of experience reporting of existing composite services from peer providers. “An Enhanced Security Framework for Reliable Android OS” by J. H. Park et al. proposes an enhanced security framework for reliable Android OS. The framework provides means to prevent influx of malware by examining the Android OS and file system. In addition, it recovers data once deleted by security breaches. “A Study on SW-Blackbox to Ensure the Reliability of Content Distribution Using File System Event Monitoring of OSPs” by Sang-Ho Seo et al. presents an SW-Blackbox technical method using file system event monitoring to verify the reliability of online service providers (OSPs) that operate file hosting web hard services. This method prevents the bypassing of filtering solutions and the omission, fabrication, and altering of transaction-related logs for the intentional distribution of illegal content. “Introducing Touchstroke: Keystroke-based Authentication System for Smartphones” by Georgios Kambourakis et al. presents a touchstroke system. They implemented a touchstroke system in the Android platform and executed different scenarios under disparate methodologies to estimate its effectiveness in authenticating the end user. Apart from typical classification features used in legacy keystroke systems, they introduce two novel ones, namely, speed and distance. From the experiments, it can be argued that touchstroke dynamics can be quite competitive, at least when compared with similar results obtained from keystroke evaluation studies. As far as they are aware of, this is the first time this newly arisen behavioral trait is put into focus. “Small Target Detection using Morphology and modified Gaussian Distance Function” by Jong-Ho Kim et al. proposes a new small target detection system that detects small target candidates based on morphology operations and detects actual targets using a modified Gaussian distance function. To reduce clutter on the edges of clouds, a median filter is applied as preprocessing. Two kinds of images are calculated with closing and opening morphological operators, respectively. In the morphology operations, various sizes of structure elements are used to consider the sizes of targets, and candidate targets are extracted from difference images between the two images in the closing and opening operations. With a modified Gaussian distance function, small targets are detected from the candidate targets. The proposed method is less sensitive to clutters than the existing methods and has a detection rate of 98%. “Single Authentication Through (SAT) in Convergence Space using Collaborative Smart Cameras” by Geon Woo Kim et al. suggests a scheme to access any ubiquitous service with single authentication at initial stage for efficiently identifying an object moving multiple convergence spaces by relaying the identifiable information along the movement. This is carried out by enabling distributed smart cameras to deliver identifiable information of the identified moving object. The last paper entitled “Time Synchronization: Pivotal Element in Cloud Forensics” by Nikolaos Marangos et al. investigates the impact that the cloud computing (CC) model has on the trustworthiness of one of the main cloud forensics (CF) sources of information, the log files. More precisely, they bring forth a crucial but rather underestimated problem, the problem of accurate log records timestamping. The synchronization of time (stamps) is of major importance for the investigation logs to be used as source of evidence. They show that this requirement is not easy in the cloud context. They demonstrate that the main features of CC render existing time synchronization techniques inadequate, and they provide a list of guidelines towards a CF aware timekeeping system. Our special thanks go to Professor Hsiao-Hwa Chen and Professor Hamid R. Sharif who are Editors-in-Chief of Security and Communication Networks and all editorial staffs for their valuable supports throughout the preparation and publication of this special issue. We would like to thank all authors for their contributions to this special issue. We also extend our thanks to the external reviewers for their excellent help in reviewing the manuscripts.
Jong Hyuk Park 0001, Stefanos Gritzalis, Bo-Chao Cheng
Secur. Commun. Networks2
2016 A survey on cloud forensics challenges and solutions
abstract
Abstract In recent years, cloud computing has gained popularity, and it is now used to support various areas of human life. Cloud forensics has been introduced to help forensic investigators find potential evidence against cloud criminal activities and maintain the security and integrity of the information stored in the cloud. While great research in the area has been carried out concerning challenges and solutions, the research on methodologies and frameworks is still in its infancy. This article focuses on the methodological aspects of cloud forensics. It critically reviews cloud forensics' existing challenges and solutions, and it explores, based on a detailed review of the area, all the work that has been carried out both in digital and cloud forensic methodologies mainly for supporting the investigation of security incidents in cloud. Furthermore, the detailed comparison reveals similarities and drawbacks of the existing methodologies providing some novel future research directions. Finally, the specific paper can be considered as a starting point for researchers wishing to design cloud‐forensicable services over the cloud. Copyright © 2016 John Wiley & Sons, Ltd.
Stavros Simou, Christos Kalloniatis, Stefanos Gritzalis, Haralambos Mouratidis
Secur. Commun. Networks3
2015 A Meta-model for Assisting a Cloud Forensics Process
Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis
CRiSIS4
2015 Privacy as an Integral Part of the Implementation of Cloud Solutions
abstract
Bridging the gap between design and implementation stages has been a major concern of designers, analysts and developers of information systems (ISs) and a major aspiration of a number of IS engineering approaches. Cloud computing exacerbates the strain on traditional IS engineering approaches that service-oriented computing has started. At the same time, recent research has argued about the importance of security and privacy in a cloud environment and highlighted a number of security and privacy challenges that are not present in traditional environments and need special attention when implementing or migrating ISs into a cloud environment. This paper contributes to this direction. Specifically, it presents a number of privacy-related cloud properties that analysts need to consider when designing privacy-aware systems in a cloud environment. Also it indicates a number of implementation techniques that can assist developers in assuring the respective properties.
Evangelia Kavakli, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis
Comput. J.4
2014 Cloud Forensics: Identifying the Major Issues and Challenges
Stavros Simou, Christos Kalloniatis, Evangelia Kavakli, Stefanos Gritzalis
CAiSE4
2014 Writer Identification Using a Statistical and Model Based Approach
abstract
The state-of-the-art writer identification systems use a variety of different features and techniques in order to identify the writer of the handwritten text. In this paper several statistical and model based features are presented. Specifically, an improvement of a statistical feature, the edge hinge distribution, is attempted. Furthermore, the combination of this feature with a model-based feature is explored, that is based on a codebook of graphemes. For the evaluation, the Fire maker DB was used, which consists of 250 writers, including 4 pages per writer. The best result for the statistical suggested approach, the skeleton hinge distribution, achieved accuracy of 90.8%, while the combination of this method with the codebook of graphemes reached 96%.
Diamantatos Paraskevas, Stefanos Gritzalis, Ergina Kavallieratou
ICFHR2
2014 Privacy-Aware Cloud Deployment Scenario Selection
Kristian Beckers, Stephan Faßbender, Stefanos Gritzalis, Maritta Heisel, Christos Kalloniatis, Rene Meis
TrustBus3
2014 Exposing mobile malware from the inside (or what is your mobile app really doing?)
Dimitrios Damopoulos, Georgios Kambourakis, Stefanos Gritzalis, Sang Oh Park
Peer-to-Peer Netw. Appl.3
2014 Protecting the internet of things
abstract
The vision of the Internet of Things (IoT), supported by industrial companies and governments all over the world, marks an evolution that will surely have a great impact on our environments and our lives. The central element of this vision is the existence of a network of interconnected objects (electrical appliances, wearable devices, industrial machinery, etc). Under the context of the IoT, these objects not only can exchange data anytime and anywhere, but also collaborate in the provisioning of novel services. In fact, some of these services are already available: web-based portals that enable the creation of aggregated services using world-wide sensor data, industrial systems that enable the development of preventive maintenance processes, and many others. However, protecting the IoT is a complex and difficult task. The current Internet is already under constant attack due to a mixture of several factors: technical (e.g. vulnerable systems, unsecure protocols), legal (e.g. jurisdiction problems), and human (e.g. targeted attacks, usability problems).The Internet of Things will not only inherit these problems, but will also have some important issues of its own. The heterogeneity of protocols and devices will make the development of interoperable, fault-tolerant security services a daunting task. The connectivity that is crucial to the IoT will make critical infrastructures extremely vulnerable against cascade failures. Moreover, as the IoT will process countless bits of personal data, the management of personal privacy might become a nightmare. The purpose of this special issue is to introduce six research articles whose goal is to provide solutions to some of the most urgent problems related to IoT security: secure communications, authentication and authorization, user privacy, and security assessment. Moreover, in line with the inherent heterogeneity of the IoT, this special issue will not focus on one single technology, but will provide an analysis of several protocols and systems (RFID systems, sensor networks, critical infrastructures). The contributions of these papers are outlined in the succeeding text. As Radio Frequency Identification (RFID) systems can be considered as one of the foundational stones of the IoT, it is important to develop a communication system that enables RFID tags to securely connect to the Internet. That is precisely the goal of the article entitled “Secure communication with RFID tags in the internet of things”, by Dominikus and Kraxberger. In this article, the authors develop Mobile-IPv6 enabled RFID tags, which can connect to the Internet through RFID readers. Moreover, these tags can also integrate end-to-end IPsec security services, effectively protecting the information exchange between the tags and the remote servers. Wireless sensor networks, or WSN, can also be considered as one of the essential elements of the IoT. These resource-constrained networks usually make use of the IPv6 over Low-power Wireless Personal Area Networks (6LoWPAN) protocol to connect to external Internet hosts. However, this protocol does not explicitly define an IPsec extension. Therefore, Shahid et al. analyzed how IPsec could be successfully integrated in 6LoWPAN in their article “Secure communication for the Internet of Things - A comparison of Link-Layer security and IPsec for 6LoWPAN”. Their analysis shows how IPsec can be a feasible option for securing the IoT in terms of performance and scalability. As aforementioned, privacy is one of the most important research challenges in the context of the IoT. More specifically, in the case of RFID systems, it is essential to develop security mechanisms that avoid user data to be leaked to unauthorized parties. This special issue introduces two mechanisms that provide efficient solutions to this particular problem. In “How to protect security and privacy in the IoT: A policy-based RFID tag management protocol”, Rekleitis, Rizomiliotis and Gritzalis provide a desirable set of management operations (from delegation of querying rights to ownership transfer) that allow users to manage their own set of RFID tags. On the other hand, in “A context-aware approach to defend against unauthorized reading and relay attacks in RFID systems”, Ma and Saxena make use of on-board sensors to provide contextual information to the RFID tags. This contextual information can be used to develop enhanced authorization policies, such as selective unlocking according to location. These two functions, authorization and context awareness, are also studied by Bai et al. in “Context-Aware Usage Control for Web of Things”. In this article, the authors develop a model that enables users to define their own context-aware security policies. Such policies are then applied to Internet-connected “intranet of things” environments, like smart homes. In fact, the authors provide an example of a working prototype, which enables users to control the appliances of their smart home in an intelligent and secure way. Finally, in “Assessing the Security of Internet Connected Critical Infrastructures”, Ghani et al. develop a set of security metrics that can be used to monitor the integrity of Internet-connected Critical Infrastructures (CIs). In particular, the authors first define a set of metric-based Service-Level Agreements (SLAs), which capture the user requirements of all CIs. Afterwards, a metrics monitoring system receives the measures from various sensors, which are then compared to the SLAs. Consequently, the system can detect potential problems before they happen – and act before a cascade event further damages the integrity of the CIs. We would like to express our gratitude to Professor Hsiao-Hwa Chen and Professor Hamid R. Sharif, Editors-in-Chief of the Security and Communication Networks journal, for their support before and during the development of this special issue. We would also like to thank the authors that chose to publish their research findings in this special issue. The Internet of Things is in dire need of strong security foundations, and we believe these research results will help to build a more secure future. Finally, we would like to thank all the reviewers that, with their time and their comments, helped the authors to strengthen their security protocols and mechanisms.
James Clarke, Stefanos Gritzalis, Jianying Zhou 0001, Rodrigo Roman
Secur. Commun. Networks2
2014 Security in a completely interconnected world
abstract
The convergence of multiple paradigms, visions, and technologies – Internet of Things (IoT) and Web of Things (WoT); Ambient Intelligence (AmI); Machine-to-Machine (M2M); and many others – is giving birth to a world of interconnected things. A world where any entity (be it a machine, an object, a person, or anything) can collaborate with each other, anytime and anywhere, in the provisioning of services. This concept of a truly interconnected world is at its infancy, yet there are various commercial players pushing previously envisioned services to the real world: from centralized Big Data repositories to “intranet of things” systems, from industrial information services to personal wearable sensor systems. Moreover, this evolution does not stop here, as the scientific community is constantly researching new advances in this area. Additionally, there is a factor that must not be overlooked in the development of this interconnected world: security. To truly understand the importance of this factor, we just need to check the state of another interconnected infrastructure: the current Internet. While functional and resilient, the current Internet is still a target of malicious attacks that affect both its users and its infrastructure. However, the scope of a truly interconnected world goes well beyond the current Internet: encompassing a global interoperable connectivity and accessibility by a myriad of heterogeneous entities, with countless data streams that can be aggregated and processed when necessary. Without the proper fault-tolerant security mechanisms, all this wealth of services and information might be not only accessed by users but also manipulated by malicious attackers. Precisely, due to the existence of such information flows, we also cannot let privacy go unnoticed in the development of security solutions for this particular context. Not only are the personal data of users at stake (e.g. daily life, medical records, private information), but also the confidential information managed by larger entities. Consequently, the purpose of this special issue is to introduce six research articles that study how to protect users and devices in the context of an interconnected world, with a special emphasis on privacy-preserving solutions. The contributions of these papers are outlined in the succeeding text. The privacy challenges are not only daunting, but also uncharted. Who are the stakeholders? What concrete threats exist, and how can they be defined? What is the impact of these threats? How can the stakeholders react against these threats? The goal of the article entitled “Privacy in the Internet of Things: Threats and Challenges”, by Ziegeldorf, Garcia-Monchon, and Wehrle, is to provide detailed answers to all these questions. Note that, even if the article focuses specifically on the Internet of Things, most of its analysis can be applied to all the other paradigms that compose this interconnected vision – as they share various underlying principles such as heterogeneous connectivity. In an interconnected world, it is essential for the devices to route the information to each other. One possible solution, which has been studied for years in the area of big distributed infrastructures, are P2P overlay networks. Still, there are several challenges in this area, such as how to manage the users’ identities while preserving their anonymity, and the existence of various attacks that can manipulate how identities are assigned (e.g. Sybil, Eclipse, MITM). The purpose of the paper entitled “RIAPPA: a Robust Identity Assignment Protocol for P2P overlays”, by Caubet et al., is to provide a generic, not algorithm-dependant protocol that can deal with these challenges. In the exchange of information between things, it is not only important to provide anonymity when necessary, but also to maintain a certain Quality of Service (QoS) to avoid excessive service degradation. The goal of the paper entitled “On Collaborative Anonymous Communications in Lossy Networks”, by Rebollo-Monedero et al., is to introduce a Crowds-like protocol for anonymous communication that establishes quantifiable metrics of anonymity and QoS. Such metrics enable the authors to perform a detailed mathematical analysis of the protocol, effectively improving the scope of the original Crowds protocol while achieving a reasonable balance between anonymity and QoS. In fact, due to the importance of maintaining a reasonable QoS while applying the security protocols, this special issue includes the paper entitled “Analysis and Taxonomy of Security/QoS tradeoff solutions for the Future Internet”, by Nieto and Lopez. This paper provides a thorough analysis of the coexistence of security and QoS mechanisms within the context of Future Internet scenarios. The paper analyses existing solutions and identifies potential problems, and also describes the major pitfalls in the integration of existing networking models such as Wireless Sensor Networks (WSN) and Cellular networks. Most of the previous papers focus on anonymity. But there are other privacy issues that must be taken into vaccount. For example, by continuously querying the network about several topics, users can be profiled – which in some cases might reveal bits of information even more important and private than our identities. The paper entitled “Enhancing Information Lookup Privacy through Homomorphic Encryption”, by Fotiou et al., provides a broker-based solution to this problem. Such a solution is also optimized, achieving a balance between the complexity of the computations and the communication overhead between the involved parties. Finally, if the networked embedded systems that comprise our interconnected world are not properly designed to comply with various security properties, attackers will surely find their way to break into them – no matter what security and privacy protocols are developed. The article entitled “Integrating security mechanisms into embedded systems by domain-specific modeling”, by Vasilevskaya et al., combine security and software engineering solutions (e.g. Model-based development (MBD), information security ontology) in order to allow system designers to easily integrate security requirements during the design process. We would like to express our gratitude to Professor Hsiao-Hwa Chen and Professor Hamid R. Sharif, Editors-in-Chief of the Security and Communication Networks journal, for their support before and during the development of this special issue. We would also like to thank the authors that chose to publish their research findings in this special issue, as a truly interconnected world is within our grasp – but we must find ways to protect it before it becomes a liability rather than a blessing. Finally, we would like to thank all the reviewers that, with their time, efforts, and their comments, helped the authors to strengthen their security protocols and mechanisms.
James Clarke, Stefanos Gritzalis, Jianying Zhou 0001, Rodrigo Roman
Secur. Commun. Networks2
2014 How to protect security and privacy in the IoT: a policy-based RFID tag management protocol
abstract
ABSTRACT Radio‐frequency identification (RFID) technology constitutes an important part of what has become known as the Internet of Things (IoT) that is accessible and interconnected machines and everyday objects that form a dynamic and complex environment. To secure the IoT in a cost‐efficient manner, we need to build security and privacy into the design of its components. Moreover, mechanisms should be constructed that will allow both individuals and organizations to actively manage their “things” and information in a highly flux environment. The contributions of this paper are twofold: We first discuss the use of security and privacy policies that can offer fine granularity and context‐aware information control in RFID systems. Second, we propose a novel secure and privacy‐preserving tag management protocol that can support such policies. Our protocol has a modular design that allows it to support a set of desirable management operations (viz. tag authentication, delegation, and ownership transfer) while imposing minimal hardware and computational requirements on the tag side. Furthermore, inspired by the European Network and Information Security Agency's Flying 2.0 study, we describe a near‐future air travel scenario to further explain and demonstrate the inner workings of our proposal. Copyright © 2011 John Wiley & Sons, Ltd.
Evangelos Rekleitis, Panagiotis Rizomiliotis, Stefanos Gritzalis
Secur. Commun. Networks3
2013 Trustworthy Selection of Cloud Providers Based on Security and Privacy Requirements: Justifying Trust Assumptions
Michalis Pavlidis, Haralambos Mouratidis, Christos Kalloniatis, Shareeful Islam, Stefanos Gritzalis
TrustBus5
2013 Revisiting lightweight authentication protocols based on hard learning problems
abstract
At the 2011 Eurocrypt, Kiltz et al., in their best paper price awarded paper, proposed an ultra-lightweight authentication protocol, called AUTH. This new protocol is supported by a delegated security proof, against passive and active attacks, based on the conjectured hardness of the Learning Parity with Noise (LPN) problem. However, AUTH has two shortcomings. The security proof does not include man-in-the-middle (MIM) attacks and the communication complexity is high. The weakness against MIM attacks was recently verified as a very efficient key recovery MIM attack was introduced with only linear complexity with respect to the length of the secret key. Regarding the communication overhead, Kiltz et al. proposed a modified version of AUTH where the communication complexity is reduced at the expense of higher storage complexity. This modified protocol was shown to be at least as secure as AUTH.
Panagiotis Rizomiliotis, Stefanos Gritzalis
WISEC2
2013 DNS amplification attack revisited
Marios Anagnostopoulos, Georgios Kambourakis, Panagiotis Kopanos, Georgios Louloudakis, Stefanos Gritzalis
Comput. Secur.5
2013 From keyloggers to touchloggers: Take the rough with the smooth
Dimitrios Damopoulos, Georgios Kambourakis, Stefanos Gritzalis
Comput. Secur.3
2013 A framework to support selection of cloud providers based on security and privacy requirements
Haralambos Mouratidis, Shareeful Islam, Christos Kalloniatis, Stefanos Gritzalis
J. Syst. Softw.4
2013 User privacy and modern mobile services: are they on the same path?
Dimitrios Damopoulos, Georgios Kambourakis, Marios Anagnostopoulos, Stefanos Gritzalis
Pers. Ubiquitous Comput.4
2013 Requirements Engineering for Security, Privacy and Services in Cloud Environments
Stefanos Gritzalis, Lin Liu 0001
Requir. Eng.1
2012 GHB #: A Provably Secure HB-Like Lightweight Authentication Protocol
Panagiotis Rizomiliotis, Stefanos Gritzalis
ACNS2
2012 Privacy Preservation by k-Anonymization of Weighted Social Networks
abstract
Privacy preserving analysis of a social network aims at a better understanding of the network and its behavior, while at the same time protecting the privacy of its individuals. We propose an anonymization method for weighted graphs, i.e., for social networks where the strengths of links are important. This is in contrast with many previous studies which only consider unweighted graphs. Weights can be essential for social network analysis, but they pose new challenges to privacy preserving network analysis. In this paper, we mainly consider prevention of identity disclosure, but we also touch on edge and edge weight disclosure in weighted graphs. We propose a method that provides k-anonymity of nodes against attacks where the adversary has information about the structure of the network, including its edge weights. The method is efficient, and it has been evaluated in terms of privacy and utility on real word datasets.
Maria Eleni Skarkala, Manolis Maragoudakis, Stefanos Gritzalis, Lilian Mitrou, Hannu Toivonen, Pirjo Moen
ASONAM3
2012 Evaluation of anomaly-based IDS for mobile devices using machine learning classifiers
abstract
ABSTRACT Mobile devices have evolved and experienced an immense popularity over the last few years. This growth however has exposed mobile devices to an increasing number of security threats. Despite the variety of peripheral protection mechanisms described in the literature, authentication and access control cannot provide integral protection against intrusions. Thus, a need for more intelligent and sophisticated security controls such as intrusion detection systems (IDSs) is necessary. Whilst much work has been devoted to mobile device IDSs, research on anomaly‐based or behaviour‐based IDS for such devices has been limited leaving several problems unsolved. Motivated by this fact, in this paper, we focus on anomaly‐based IDS for modern mobile devices. A dataset consisting of iPhone users data logs has been created, and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. Specifically, the experimental procedure includes and cross‐evaluates four machine learning algorithms (i.e. Bayesian networks, radial basis function,K‐nearest neighbours and random Forest), which classify the behaviour of the end‐user in terms of telephone calls, SMS and Web browsing history. In order to detect illegitimate use of service by a potential malware or a thief, the experimental procedure examines the aforementioned services independently as well as in combination in a multimodal fashion. The results are very promising showing the ability of at least one classifier to detect intrusions with a high true positive rate of 99.8%. Copyright © 2011 John Wiley & Sons, Ltd.
Dimitrios Damopoulos, Sofia-Anna Menesidou, Georgios Kambourakis, Maria Papadaki, Nathan L. Clarke, Stefanos Gritzalis
Secur. Commun. Networks6
2012 Security and privacy in emerging information technologies
abstract
Advances in communication and information technologies including pervasive computer applications, rapid deployments of new wireless networks like 3G, Wifi, WiMAX and their tight coupling to the Internet, have revolutionised our society and really changed every aspect of our lives through a variety of new applications. The rapidly evolving technologies have become ubiquitous, for example, allowing people to stay connected anywhere, anytime via social media services accessed by smartphones, such as Facebook and Twitter. While we experience tremendous benefits from adopting the new technologies, we also continue to face challenges and the biggest challenge is always: how to address security and privacy issues, which may be caused by new technology adoption. This special issue consists of seven papers addressing the security and privacy issues in emerging information technologies such as delay tolerant networking, vehicular communication systems and smartphones and mobile devices. In the first paper, D. Damopoulos, S.A. Menesidou, G. Kambourakis, M. Papadaki, N. Clarke and S. Gritzalis present an evaluation study of anomaly-based IDS for mobile devices using machine learning classifiers. A dataset consisting of iPhone users data log files has been created and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. The experimental procedure includes and cross-evaluates four machine learning algorithms (i.e. Bayesian Networks, Radial Basis Function, K-Nearest Neighbours and Random Forest), which classify the behaviour of the end-user in terms of Telephone calls, SMS and Web browsing history. The results acquired are very promising, showing the ability of at least one classifier to detect intrusions with a high True Positive Rate of 99.8%. The second paper, “User Identification and Anonymization in 802.11 Wireless LANs” by D. Xu, Y. Wang, X. Shi, and X. Yin, deals with privacy issues for 802.11 Wireless LAN users. It first proposes a new 802.11 user identification approach through enhanced feature selection and generation. Then, it further studies how to provide user anonymity by introducing a set of 802.11 user anonymisation approaches based on bogus traffic injection. Accountability is a very important topic for computer and networking systems, and a key to achieve accountability is a better logging system, which can capture not only the activities but also their relationships. The third paper, “Accountability using Flow-net: Design, Implementation, and Performance Evaluation” by Y. Xiao, K. Meng and D. Takahashi extends the flow-net methodology, which is a logging mechanism for accountability previously proposed by the authors, and presents its design and implementation in wireless networks. They also evaluate the performance of flow-net and compare it to that of audit log files. The fourth paper, “Modelling Security Message Propagation in Delay Tolerant Networks ” by Z. Jia, S. Li, H. Peng, Y. Yang and S. Guo, proposes a security message propagation model for delay tolerant networks formed by vehicles on the road. The goal of the paper is to evaluate how many public keys should be maintained by each node in order to achieve fast message propagation while single hop authentication scheme is used. Network coding provides an excellent solution to maximise throughput in various networks. Because of its simplicity and high efficiency, the idea of network coding can also be used for designing lightweight key distribution schemes for wireless ad hoc network. The fifth paper, “A key distribution scheme using network coding for mobile ad hoc network” by J. Liu, R. Du, J. Chen and K. He, presents a key distribution scheme that exploits the inherent security properties of network coding. The new scheme relies on simple XOR network coding operations to provide data confidentiality and as well use message authentication codes to guarantee the integrity of the distributed keys. Recently, vehicular ad-hoc network (VANET) has emerged as a promising approach to increasing road safety and efficiency. However, the attractive features of VANET inevitably incur higher risks for abuse if we do not take into account security and privacy considerations before the wide deployment of such network. It would jeopardise the public safety and become the main barrier to the acceptance of such a new technology. The last two papers focus on the security and privacy issues in VANETs. In the sixth paper, “LPA: A New Location-based Privacy-preserving Authentication Protocol in VANET” by X. Xue and J. Ding, a novel location-based authentication protocol for conditional privacy preservation in VANETs is proposed. By utilising location information and layered security scheme, the large storage overhead problem in anonymous certificates-based protocols and the long verification time problem in group signature-based protocols are solved. The seventh paper, “An Efficient Distributed Key Management Scheme for Group Signature based Anonymous Authentication in VANET” by Y. Sun, Z. Feng, Q. Hu and J. Su, proposes a distributed key management (DKM) scheme based on Group Signature for anonymous authentication in VANETs. The goal of the paper is to prevent vehicles from leaking the value of the updated group secret key to the regional group manager during the group key updating process. Subsequently, it can avoid the buck-passing between vehicles and regional group managers when the malicious messages are detected. In closing, we would like to thank all the authors who have submitted their research work to this special issue. We would also like to acknowledge the contribution of many experts in the field who have participated in the review process and provided helpful suggestions to the authors on improving the content and presentation of the papers. We would also like to express our gratitude to the Editor-in-Chief, Dr. Hsiao-Hwa Chen for his support and help in bringing forward this special issue. We hope you will enjoy the papers in this collection. Prof. Xiaodong Lin received the Ph.D. degree in information engineering from Beijing University of Posts and Telecommunications, Beijing, China, in 1998 and the Ph.D. degree (with Outstanding Achievement in Graduate Studies Award) in electrical and computer engineering from the University of Waterloo, Waterloo, ON, Canada, in 2008. He is currently an assistant professor of information security with the Faculty of Business and Information Technology, University of Ontario Institute of Technology, Oshawa, ON, Canada. His research interests include wireless network security, computer forensics, software security, and applied cryptography. Dr. Lin was the recipient of a Natural Sciences and Engineering Research Council of Canada (NSERC) Canada Graduate Scholarships (CGS) Doctoral and the Best Paper Awards of the 18th International Conference on Computer Communications and Networks (ICCCN 2009), the 5th International Conference on Body Area Networks (BodyNets 2010), the 3rd International Conference on Forensic Applications and Techniques in Telecommunications, Information and Multimedia (e-Forensics 2010), and IEEE International Conference on communications (ICC 2007). He is a member of IEEE. Prof. Jianwei Liu received his Ph.D. in communication engineering from Xidian University, China in 1998, and his B.S. and M.S. degrees in electronic engineering from Shandong University, China in 1985 and 1988. He is currently a professor and vice dean of School of Electronic and Information Engineering of Beihang University. His current research interests include the security of wireless and mobile communication network and computer network. He is a senior member of the Chinese Institute of Electronics and director of the Chinese Association for Cryptologic Research. Prof. Stefanos Gritzalis is a Professor at the Dept. of Information and Communication Systems Engineering, University of the Aegean, Greece and the Director of the Lab. of Information and Communication Systems Security. He also serves as the Special Secretary at the Greek Ministry of Administrative Reform and Electronic Governance. He holds a BSc in Physics, an MSc in Electronic Automation, and a PhD in Information and Communications Security from the Dept. of Informatics and Telecommunications, University of Athens, Greece. He has been involved in several national and EU funded R&D projects. His published scientific work includes 30 books or book chapters, 90 journals and more than 120 international refereed conference and workshop papers. The focus of these publications is on Information and Communications Security and Privacy. His most highly cited papers have more than 1,000 citations. He has been involved in more than 30 international conferences and workshops as General Chair or Program Committee Chair. He has served on more than 230 Program Committees of international conferences and workshops. He is an Editor-in-Chief or Editor or Editorial Board member for 15 journals. He has supervised 10 PhD dissertations. He was an elected Member of the Board (Secretary General, Treasurer) of the Greek Computer Society. His professional experience includes senior consulting and researcher positions in a number of private and public institutions. He is a Member of the ACM, and the IEEE.
Xiaodong Lin 0001, Jianwei Liu 0001, Stefanos Gritzalis
Secur. Commun. Networks3
2012 SIPA: generic and secure accounting for SIP
abstract
ABSTRACT Authentication, authorization, and accounting services provide the framework on top of which a reliable, secure, and robust accounting system can be built. In a previous work of ours, we have presented a flexible and, most importantly, generic accounting scheme for next generation networks. In this paper, we substantially improve our previous work by providing the required Diameter application namely SIP‐Accounting (SIPA) that enables the use of our accounting scheme for Session Initiation Protocol (SIP) services. Additionally, in an effort to protect the service providers and the end users against accounting frauds, we implement an add‐on mechanism referred to as SIPA+ to combat attacks targeting the core accounting functions and the integrity of the respective accounting messages. Using the implemented SIPA and SIPA+ prototypes, we conducted a complete set of experiments testing several configurations and two distinct scenarios. The results reveal that the proposed accounting system and its security add‐on are fully operable in SIP environments without incurring much cost in terms of performance and overhead. Copyright © 2011 John Wiley & Sons, Ltd.
Alexandros Tsakountakis, Georgios Kambourakis, Stefanos Gritzalis
Secur. Commun. Networks3
2011 Designing secure RFID authentication protocols is (still) a non-trivial task
abstract
In the last few years, a plethora of RFID authentication protocols have been proposed and several security analyses have been published creating the impression that designing such a protocol must be, more or less, a straightforward task. In this paper, we investigate the security of two recently proposed schemes, showing that designing a secure RFID authentication protocol is still a demanding process. One is a mature work; in the sense that it has predecessors that have been extensively analyzed, while the other is a fresh proposal. Our security analysis demonstrates that both are weak, as they suffer from a similar desychronization attack. In addition we prove the existence of a fatal tag impersonation attack against the second one.
Panagiotis Rizomiliotis, Evangelos Rekleitis, Stefanos Gritzalis
NSS3
2011 iSAM: An iPhone Stealth Airborne Malware
Dimitrios Damopoulos, Georgios Kambourakis, Stefanos Gritzalis
SEC3
2011 Privacy Preserving Tree Augmented Naïve Bayesian Multi-party Implementation on Horizontally Partitioned Databases
Maria Eleni Skarkala, Manolis Maragoudakis, Stefanos Gritzalis, Lilian Mitrou
TrustBus3
2011 DoS attacks exploiting signaling in UMTS and IMS
Georgios Kambourakis, Constantinos Kolias, Stefanos Gritzalis, Jong Hyuk Park 0001
Comput. Commun.3
2011 PrivaKERB: A user privacy framework for Kerberos
Fernando Pereñíguez-Garcia, Rafael Marín López, Georgios Kambourakis, Stefanos Gritzalis, Antonio F. Skarmeta
Comput. Secur.4
2011 On the Typical Statistic Features for Image Blind Steganalysis
abstract
Multimedia content is a suitable carrier for secret communication. This paper focuses on the steganalysis technique which aims to get the forensic of secrecy existing in multimedia carriers. A key concern for designing a blind steganalysis algorithm is the selection of statistic features. The Probability Density Function (PDF) moment and Characteristic Function (CF) moment are two typical kinds of statistic features commonly used in blind steganalysis. And generally, the features are computed from the subbands of transform domains, such as the wavelet coefficient subbands, the prediction subbands of wavelet coefficients, the prediction error subbands of wavelet coefficients, the wavelet coefficient subbands of image noise, and the log prediction error subbands of wavelet coefficients. To decide which feature is more sensitive to message embedding and useful for steganalysis is important and urgent. Till now, few works have focused on this topic, and they can only give some experimental results without theoretical analysis. Additionally, few frequency subbands have been investigated. To solve this problem, this paper reviews existing feature computing algorithms, compares the two kinds of features, the PDF moments and the CF moments, by analyzing the change trends of the statistic distribution parameters of various frequency subbands before and after message embedding, and so that provides a theoretical basis for the steganalysis feature selection and extraction. These theoretical results are further confirmed by experimental results. This is the first work to provide thorough theoretical analysis on so many feature computing algorithms. It is expected to provide valuable information to researchers or engineers working in the field of steganography forensics or steganalysis.
Xiangyang Luo 0001, Fenlin Liu, Shiguo Lian, Chunfang Yang, Stefanos Gritzalis
IEEE J. Sel. Areas Commun.5
2011 Digital privacy: theory, policies and technologies
Annie I. Antón, Travis D. Breaux, Stefanos Gritzalis, John Mylopoulos
Requir. Eng.3
2011 Network security and digital forensics in next generation communications
abstract
Next Generation Communications (NGC) represent advanced communication environments featuring objects that are focused on users. NGC has rapidly emerged as an exciting new paradigm that includes ubiquitous, grid, and P2P computing. It provides computing and communication services in a much more convenient and pleasurable way, anytime, and anywhere. That is, a user will be able to remotely access and control all information and appliances used in the workplace, as well as at home and office, utilizing in an easy and convenient way various services without any limitations on space and time. In order to tackle the more sophisticated and powerful attack mechanisms that nowadays exist, it is crucial to build active and smart defence systems. Finding effective and efficient ways to protect information and digital forensics for NGC are very challenging research topics. This special issue aims to address network security and digital forensics for NGC and to encourage researchers to publish their results in WCMC journal. It will accept both original research papers and review articles that enhance the state-of-the-art in NGC security issues, including topics like security and digital forensics theory, services, business models, and novel applications that are associated with NGC utilization. The papers will be peer reviewed and will be selected on the basis of their quality and relevance to the theme of this special issue. This special issue brings together 12 contributions, with both theoretical and practical results of significance on aspects of network security and digital forensics in next generation communications. The contributions vary from themes like secure network middleware interactions to privacy and authentication schemes for next generation communications. Misra et al. present a Mobile Ad hoc Key Revocation Server (MAKeRS) scheme for key revocation in Mobile Ad Hoc Networks (MANETs). The scheme proposes to improve the performance and reliability of the existing system. Simulations show that the concept presented in the paper is more reliable, faster, and scalable than the existing usage of PKI over ad hoc networks. The various scenarios of mobility of nodes and servers are considered and the scheme is designed to suit such scenarios in an optimum way. The paper “Security analysis and improvements of IEEE standard 802.16 in next generation wireless metropolitan access network” is authored by Xiong Naixue. The paper “Secure handover for Proxy Mobile IPv6 in next-generation communications: scenarios and performance” by Jong-Hyouk Lee and Tai-Myoung Chung introduces two fast handover authentication scenarios for Proxy Mobile IPv6: namely, handover re-authentication (HORA) and handover early-authentication (HOEA). The introduced scenarios are based on the Handover Keying (HOKEY) working group in the IETF. In HORA, a mobile node utilizes the previously obtained root key for its handover so that the number of round trips for exchanging of authentication data and keying materials is reduced during its handover. In HOEA, the proactive signaling supported by link layer technologies is used to fast discover a candidate access network where a mobile node potentially attaches to so that the mobile node could perform authentication procedures before the mobile node attaches to the candidate access network. The paper “A secure and efficient RSU-aided bundle forwarding protocol for vehicular delay tolerant networks” by Xiaodong Lin and Hsiao-Hwa Chen studies data forwarding in vehicular delay tolerant networks. By using unique characteristics of vehicular delay tolerant networks, particularly, hybrid communication between the vehicles (V2V communications) and the roadside infrastructure (V2I communications), the authors propose a secure and efficient roadside unit (RSU) aided bundle forwarding protocol for vehicular delay tolerant networks. The paper “Security mechanism for voice over multipath mobile ad hoc networks” by Binod Vaidya, Meiso K. Denko, and Joel J.P.C Rodrigues not only presents a framework for secure voice transmission over multipath MANET but also proposes an efficient traffic allocation approach for it, then the proposed security mechanism was evaluated and its correctness was proved using formal verification. Hai-Cheng Chu, Der-Jiunn Deng, and Han-Chieh Chao present the paper whose scope encompasses the live data collection and analysis trying to disclose the digital trails that might be accidentally left behind with respect to the internal memory and the registry based on the IM session of Skype. A case review was conducted to illustrate the hidden digital trails within the PDA from the Registry of the Windows Mobile and volatile data in the RAM to discover the possible network security leakage scenarios that resulted in the vandalism of intangible digital assets of the organization. The paper “Authenticated key exchange protocol with selectable identities” by Hua Guo, Yi Mu, Xiyong Zhang, and Zhoujun Li deals with a key agreement protocol which allows a single private key to map multiple public keys (identities) that are selectable by the user. In the new protocol, the established session key is associated with an arbitrary subset of identities held by the user, while the unselected identities remain secret to other participants. The paper “Development of digital forensics practice and research in Japan” by Liu J., Uehara T., and Sasaki R. provide a nutshell of the Japanese political structures, legal systems, and law enforcement practice, and then present an overview of updated and new laws, awareness programs, and the research activities in digital forensics. The paper entitled “A lightweight block cipher based on a multiple recursive generator for wireless sensor networks and RFID” by Alina Olteanu, Yang Xiao, Fei Hu, Bo Sun, and Hongmei Deng use a Multiple Recursive Generator (MRG) to generate sequences of numbers with very long periods. The proposed cipher is a light weight cipher, which is very useful for resource limited resources such as sensor nodes in sensor networks and RFID tags. The paper “A cross-layer approach for integrating security mechanisms in sensor networks architectures” by Rodrigo Roman, Pablo Najera, and Javier Lopez analyzes how the security mechanisms used by sensor network applications should be integrated with existing architecture paradigms. The paper considers that a transversal layer is the optimal component forstoring the security mechanisms. Such layer retains the benefits of layered architectures, and adequately controls the disadvantages of cross-layer approaches. The paper “Hybrid security protocol for wireless body area networks” by dealt with the overall security including up to the in/on and out-body, and utilized two heterogeneous cryptosystems (the symmetric and asymmetric) for diverse environments of WBANs. Our protocol shows that it satisfies more security requirements than existing security protocols including the overall coverage of WBANs. The paper “Privacy preserving context transfer schemes for 4G networks” by Iosif Terzis, Georgios Kambourakis, Giorgos Karopoulos, and Costas Lambrinoudakis focuses on user's roaming between different administrative domains location privacy and proposes a number of privacy enhanced context transfer schemes. All the proposed schemes are analyzed in terms of message exchange, evaluated through simulations and compared with the ones been proposed by the Seamoby work group in CXTP RFC 4067. The results show that the proposed schemes are very efficient in terms of application handover times, while at the same time guarantee the privacy of the end-user. We wish to thank all the authors for their great work and for considering Wireless Communications & Mobile Computing journal for submitting their papers. Special thanks go to the anonymous reviewers for their help and dedication in reviewing the papers and providing useful comments to the authors for their papers improvement. Special thanks to the EiC Professor Mohsen Guizani for hosting this special issue in the prestigious John Wiley & Sons' Wireless Communications and Mobile Computing journal, and for their excellent support. We hope that this special issue will represent a timely and significant reference for future researches.
Jong Hyuk Park 0001, Stefanos Gritzalis, Hai Jin 0001, Jenlong Wang
Wirel. Commun. Mob. Comput.2
2010 An Agent Based Back-End RFID Tag Management System
Evangelos Rekleitis, Panagiotis Rizomiliotis, Stefanos Gritzalis
TrustBus3
2010 Special issue on multimedia networking and security in convergent networks
Chang Wen Chen, Stefanos Gritzalis, Pascal Lorenz, Shiguo Lian
Comput. Commun.2
2010 Privacy-enhanced fast re-authentication for EAP-based next generation network
Fernando Pereñíguez-Garcia, Georgios Kambourakis, Rafael Marín López, Stefanos Gritzalis, Antonio F. Skarmeta
Comput. Commun.4
2010 A framework for identity privacy in SIP
Georgios Karopoulos, Georgios Kambourakis, Stefanos Gritzalis, Elisavet Konstantinou
J. Netw. Comput. Appl.3
2010 Towards adaptive security for convergent wireless sensor networks in beyond 3G environments
abstract
Abstract The integration of wireless sensor networks with different network systems gives rise to many research challenges to ensure security, privacy and trust in the overall architecture. The main contribution of this paper is a generic security, privacy and trust framework providing context‐aware adaptability, flexibility and scalability which allows customisation of wireless sensor networks to a diverse set of application spaces. Suitable protocols and mechanisms are identified, which when combined according to the framework form a complete toolbox solution which fits the architecture of Beyond 3G environments. Performance evaluation results demonstrate the feasibility and estimate the benefits of the security framework for a variety of scenarios. Copyright © 2008 John Wiley & Sons, Ltd.
Anelia Mitseva, Efthimia Aivaloglou, Maria Marchitti, Neeli R. Prasad, Charalabos Skianis, Stefanos Gritzalis, Adrian Waller, Timothy Baugé, Sarah Pennington
Wirel. Commun. Mob. Comput.6
2010 Hybrid trust and reputation management for sensor networks
Efthimia Aivaloglou, Stefanos Gritzalis
Wirel. Networks2
2009 Trust-Based Data Disclosure in Sensor Networks
abstract
In sensor networks, privacy can be addressed in different levels of the network stack and at different points of the information flow. This paper presents an application level scheme for controlling information disclosure at the points of data capture. The scheme includes a trust model for facilitating in-network privacy decisions. The trust model exploits the pre-deployment knowledge on the network topology and the information flows, and combines aspects from alternative approaches on trust establishment on common evaluation metrics, in order to allow for flexibility in the trust establishment process. The trust assigned to each data requestor is used to determine if the data or only a sample of it will be disclosed, or if the request will be rejected. The scheme allows the use of various mechanisms, including negative surveys, for publishing samples of data to partially trusted requestors. The proposed scheme has been validated through simulation. The results and analysis demonstrate its effectiveness in managing trust relationships and data disclosure operations.
Efthimia Aivaloglou, Stefanos Gritzalis
ICC2
2009 A Hierarchical Model for Cross-Domain Communication of Health Care Units
abstract
Common practice for healthcare organizations is to maintain locally their own files, thus causing a geographic distribution of healthcare records. On the other hand, healthcare personnel treating a patient needs access to previous diagnosis and treatment data, maintained by various institutions in many different locations. Currently, the lack of a reliable authentication and authorization framework is considered a major obstacle for interchanging electronic healthcare records (EHRs). This paper proposes a hierarchical model for controlling access to EHRs and protecting the privacy of subjects of care and healthcare personnel, while facilitating the exchange of information among healthcare information systems.
Dimitris Geneiatakis, Costas Lambrinoudakis, Stefanos Gritzalis
NSS3
2009 A Cluster-Based Framework for the Security of Medical Sensor Environments
Eleni Klaoudatou, Elisavet Konstantinou, Georgios Kambourakis, Stefanos Gritzalis
TrustBus4
2009 A generic accounting scheme for next generation networks
Alexandros Tsakountakis, Georgios Kambourakis, Stefanos Gritzalis
Comput. Networks3
2009 Accurate and large-scale privacy-preserving data mining using the election paradigm
Emmanouil Magkos, Manolis Maragoudakis, Vassilios Chrissikopoulos, Stefanos Gritzalis
Data Knowl. Eng.4
2009 Applying effective feature selection techniques with hierarchical mixtures of experts for spam classification
abstract
E-mail abuse has been steadily increasing during the last decade. E-mail users find themselves targeted by massive quantities of unsolicited bulk e-mail, which often contains offensive language or has fraudulent intentions. Internet Service Providers (ISPs) on the other hand, have to face a conside rable system overloading as the incoming mail consumes network and storage resources. Among the plethora of solutions, the most prominent in terms of cost efficiency and complexity are the text filtering approaches. Most of the approaches model the problem using linear statistical models. Despite their popularity – due both to their simplicity and relative ease of interpretation – the non-linearity assumption of data samples is inappropriate in practice. This is mainly due to the inability of other approaches to capture the apparent non-linear relationships, which characterize these samples. In this paper, we propose a margin-based feature selection approach integrated with a Hierarchical Mixtures of Experts (HME) system, which attempts to overcome limitations common to other machine-learning based approaches. By reducing the data dimensionality using effective algorithms for feature selection we evaluated our system with publicly available corpora of e-mails, characterized by very high similarity between legitimate and bulk e-mail (and thus low discriminative potential). We experimented with two different architectures, a hierarchical HME and a perceptron HME. As a result, we confirm the domination of our Spam Filtering (SF) – HME method against other machine learning approaches, which present lesser degree of recall, as well as against traditional rule-based approaches, which lack considerably in the achieved degrees of precision.
Petros Belsis, Kostas Fragos, Stefanos Gritzalis, Christos Skourlas
J. Comput. Secur.3
2009 Pandora: An SMS-oriented m-informational system for educational realms
Lambros Boukas, Georgios Kambourakis, Stefanos Gritzalis
J. Netw. Comput. Appl.3
2008 Clustering Oriented Architectures in Medical Sensor Environments
abstract
Wireless sensor networks are expected to make a significant contribution in the healthcare sector by enabling continuous patient monitoring. Since medical services and the associated to them information are considered particularly sensitive, the employment of wireless sensors in medical environments poses many security issues and challenges. However, security services and the underlying key management mechanisms cannot be seen separately from the efficiency and scalability requirements. Network clustering used in both routing and group key management mechanisms can improve the efficiency and scalability and therefore can also be envisioned in medical environments. This paper introduces a general framework for cluster-based wireless sensor medical environments on the top of which efficient security mechanisms can rely. We describe two different scenarios for infrastructure and infrastructure- less application environments, covering this way a wide area of medical applications (in-hospital and medical emergencies). We also examine the existing group-key management schemes for cluster-based wireless networks and discuss which protocols fit best for each proposed scenario.
Eleni Klaoudatou, Elisavet Konstantinou, Georgios Kambourakis, Stefanos Gritzalis
ARES4
2008 Modeling Privacy Insurance Contracts and Their Utilization in Risk Management for ICT Firms
Athanasios N. Yannacopoulos, Costas Lambrinoudakis, Stefanos Gritzalis, Stylianos Z. Xanthopoulos, Sokratis K. Katsikas
ESORICS3
2008 Caller identity privacy in SIP heterogeneous realms: A practical solution
abstract
The growing demand for voice services and multimedia delivery over the Internet has raised SIPpsilas popularity making it a subject of extensive research. SIP is an application layer control signaling protocol, whose main purpose is to create, modify and terminate multimedia sessions. Research has shown that SIP has a number of security issues that must be solved in order to increase its trustworthiness and supersede or coexist with PSTN. In this paper our purpose is to address such a weakness, namely the caller identity privacy issue. While some solutions to this problem do exist, we will show that they are inadequate in a number of situations. Furthermore, we will propose a novel scheme for the protection of callerpsilas identity which can also support roaming between different administrative domains. Finally, we provide some performance results, which demonstrate that the proposed solution is efficient even in low-end mobile devices.
Georgios Karopoulos, Georgios Kambourakis, Stefanos Gritzalis
ISCC3
2008 Privacy Protection in Context Transfer Protocol
abstract
In the future 4G wireless networks will span across different administrative domains. In order to provide secure seamless handovers in such an environment the context transfer protocol is an attractive solution. However, the aforementioned protocol arises some privacy issues concerning the location and movement of users roaming between administrative domains. The purpose of this paper is to present and analyze these privacy issues and propose two privacy enhanced context transfer schemes that alleviate these problems. In the first scheme the Mobile Node (MN) is responsible for the transmission of the context to the new domain. In the second scheme the Home Domain (HD) of the user forwards the context acting as a proxy between the old and the new domain. While the second scheme is expected to be more useful towards realizing seamless handovers, the first one poses less signaling load to the HD. In addition, assuming that the most appropriate form of user identity for the context is the Network Access Identifier (NAI), we show how the employment of temporary NAIs can further increase the privacy of our schemes.
Georgios Karopoulos, Georgios Kambourakis, Stefanos Gritzalis
PDP3
2008 Accuracy in Privacy-Preserving Data Mining Using the Paradigm of Cryptographic Elections
Emmanouil Magkos, Manolis Maragoudakis, Vassilios Chrissikopoulos, Stefanos Gritzalis
Privacy in Statistical Databases4
2008 A new Accounting Mechanism for Modern and Future AAA Services
Alexandros Tsakountakis, Georgios Kambourakis, Stefanos Gritzalis
SEC3
2008 Message from the SecPri Workshop Organizing Technical Co-chairs
abstract
Presents the introductory welcome message from the conference proceedings.
Peter Mueller, Kaisa Nyberg, Stefanos Gritzalis, Costas Lambrinoudakis
WiMob3
2008 Applying effective feature selection techniques with hierarchical mixtures of experts for spam classification
abstract
E-mail abuse has been steadily increasing during the last decade. E-mail users find themselves targeted by massive quantities of unsolicited bulk e-mail, which often contains offensive language or has fraudulent intentions. Internet Service Providers (ISPs) on the other hand, have to face a conside rable system overloading as the incoming mail consumes network and storage resources. Among the plethora of solutions, the most prominent in terms of cost efficiency and complexity are the text filtering approaches. Most of the approaches model the problem using linear statistical models. Despite their popularity – due both to their simplicity and relative ease of interpretation – the non-linearity assumption of data samples is inappropriate in practice. This is mainly due to the inability of other approaches to capture the apparent non-linear relationships, which characterize these samples. In this paper, we propose a margin-based feature selection approach integrated with a Hierarchical Mixtures of Experts (HME) system, which attempts to overcome limitations common to other machine-learning based approaches. By reducing the data dimensionality using effective algorithms for feature selection we evaluated our system with publicly available corpora of e-mails, characterized by very high similarity between legitimate and bulk e-mail (and thus low discriminative potential). We experimented with two different architectures, a hierarchical HME and a perceptron HME. As a result, we confirm the domination of our Spam Filtering (SF) – HME method against other machine learning approaches, which present lesser degree of recall, as well as against traditional rule-based approaches, which lack considerably in the achieved degrees of precision.
Petros Belsis, Kostas Fragos, Stefanos Gritzalis, Christos Skourlas
J. Comput. Secur.3
2008 Examining the significance of high-level programming features in source code author classification
Georgia Frantzeskou, Stephen G. MacDonell, Efstathios Stamatatos, Stefanos Gritzalis
J. Syst. Softw.4
2008 Addressing privacy requirements in system design: the PriS method
Christos Kalloniatis, Evangelia Kavakli, Stefanos Gritzalis
Requir. Eng.3
2008 Enabling the provision of secure web based m-health services utilizing XML based security models
abstract
Abstract It has been generally agreed that the security of electronic patient records and generally e‐health applications must meet or exceed the standard security that should be applied to paper medical records, yet the absence of clarity on the proper goals of protection has led to confusion. The primary purpose of this study was to investigate appropriate security mechanisms, which will help clinical professionals and patients discharge their ethical and legal responsibilities by selecting suitable systems and operating them safely and in short order. Thus, in this paper we propose a security model based on XML with the intention of developing a fast security policy mostly intended for mobile healthcare information systems. The proposed schema consists of a set of principles based on XML security models through the use of partial encryption, signature and integrity services and it was implemented by means of a web‐based m‐health application in a centralized three‐tier architecture utilizing wireless networks environment. Several experiments took place with the aim of measuring the client response time implementing a number of m‐health scenarios. The results showed that the response times required for the fulfilment of a client request with the XML security model are smaller compared to those corresponding to the conventional security mechanisms such as the application of SSL. By selectively applying confidentiality and integrity services either to the medical information as a whole or to some sensitive parts of it, the obtained results clearly demonstrate that XML security mechanisms overwhelm those of SSL and they are suitable for deployment in m‐health applications. Copyright © 2008 John Wiley & Sons, Ltd.
Demosthenes Vouyioukas, Georgios Kambourakis, Ilias Maglogiannis, Angelos N. Rouskas, Constantinos Kolias, Stefanos Gritzalis
Secur. Commun. Networks6
2007 Using Privacy Process Patterns for Incorporating Privacy Requirements into the System Design Process
abstract
In the online world every person has to hold a number of different data sets so as to be able to have access to various e-services and take part in specific economical and social transactions. Such data sets require special consideration since they may convey personal data, sensitive personal data, employee data, credit card data etc. Recent surveys have shown that people feel that their privacy is at risk from identity theft and erosion of individual rights. The result is that privacy violation is becoming an increasingly critical issue in modern societies. To this end, PriS, a new security requirements engineering methodology, has been introduced aiming to incorporate privacy requirements early in the system development process. In this paper, we extend the PriS conceptual framework by introducing privacy process patterns as a way for describing the effect of privacy requirements on business processes. In addition, privacy process patterns facilitate the identification of the system architecture that best supports the privacy-related business processes, thus providing a holistic approach from business goals to `privacy-compliant' IT systems
Christos Kalloniatis, Evangelia Kavakli, Stefanos Gritzalis
ARES3
2007 Securing Medical Sensor Environments: The CodeBlue Framework Case
abstract
Research on wireless sensor networks targeting to medical environments has gathered a great attention. In this context, the most recent and perhaps the most promising complete scheme is the CodeBlue hardware and software combined platform, developed in the context of the self-titled Harvard's University project. CodeBlue relies on miniature wearable sensors to monitor real-time patients' vital activities and collecting data for further processing. Apart from the essential query interface for medical monitoring, CodeBlue offers protocols for hardware discovery and multihop routing. This paper contributes to the CodeBlue security, which until now is considered as pending or left out for future work by its designers. We identify and describe several security issues and attack incidents that can be directly applied on CodeBlue compromising its trustworthiness. We also discuss possible solutions for both internal and external attacks and the key-management mechanisms that these solutions presume
Georgios Kambourakis, Eleni Klaoudatou, Stefanos Gritzalis
ARES3
2007 Detecting DNS Amplification Attacks
Georgios Kambourakis, Tassos Moschos, Dimitris Geneiatakis, Stefanos Gritzalis
CRITIS4
2007 Design and Implementation of Distributed Access Control Infrastructures for Federations of Autonomous Domains
Petros Belsis, Stefanos Gritzalis, Christos Skourlas, Vassilis Tsoukalas
TrustBus2
2007 On Device Authentication in Wireless Networks: Present Issues and Future Challenges
Georgios Kambourakis, Stefanos Gritzalis
TrustBus2
2007 A framework for protecting a SIP-based infrastructure against malformed message attacks
Dimitris Geneiatakis, Georgios Kambourakis, Costas Lambrinoudakis, Tasos Dagiuklas, Stefanos Gritzalis
Comput. Networks5
2006 An ontology for secure e-government applications
abstract
This paper addresses the issue of accommodating security requirements in application development. It proposes the use of ontologies for capturing and depicting the security experts' knowledge. In this way developers can exploit security expertise in order to make design choices that help them fulfil security requirements more effectively. We have developed a security ontology for two different application scenarios to illustrate its use. To validate the ontology we have used queries.
Maria Karyda 0001, Theodoros Balopoulos, Lazaros Gymnopoulos, Spyros Kokolakis, Costas Lambrinoudakis, Stefanos Gritzalis, Stelios Dritsas
ARES6
2006 Performance evaluation of a distributed OCSP protocol over MANETs
abstract
Several methods that rely on public or private cryptographic systems have been proposed for trust establishment in mobile ad hoc networks (MANETs). Such methods aim to provide end-entity authentication, communications integrity and privacy. When public key certificates schemes are deployed in MANETs, they must be accompanied by efficient mechanisms for certificate revocation and validation. In this paper we address this issue, and a distributed, on-demand, OCSP-based scheme is adapted to be applicable over MANETs. This scheme, called ADOPT, uses caches of OCSP responses that are distributed and stored on intermediate nodes. ADOPT takes into account the status of intermediate nodes, such as network topology, energy thresholds, and connectivity, to materialize the caching of OCSP responses. This paper uses different MANET con-figurations to evaluate the efficiency of ADOPT. The simulation results show that ADOPT manages to rapidly identify and locate the status of a certificate without introducing significant communication or storage costs. Keywords-OCSP; MANETs; certificate status information; caching
Konstantinos Papapanagiotou, Giannis F. Marias, Panagiotis Georgiadis 0001, Stefanos Gritzalis
CCNC4
2006 Trust Establishment in Ad Hoc and Sensor Networks
Efthimia Aivaloglou, Stefanos Gritzalis, Charalabos Skianis
CRITIS2
2006 Requirements and Challenges in the Design of Privacy-aware Sensor Networks
abstract
Sensor networks are set to become a truly ubiquitous technology that will affect the lives of the people in their application environment. While providing the opportunity for sophisticated, context-aware services, at the same time sensor networks impose great privacy risks. This paper discusses privacy issues in sensor networks, by identifying the requirements for privacy preserving deployments, analysing the challenges faced when designing them, and discussing the main solutions that have been proposed.
Efthimia Aivaloglou, Stefanos Gritzalis, Charalabos Skianis
GLOBECOM2
2006 Effective identification of source code authors using byte-level information
abstract
Source code author identification deals with the task of identifying the most likely author of a computer program, given a set of predefined author candidates. This is usually .based on the analysis of other program samples of undisputed authorship by the same programmer. There are several cases where the application of such a method could be of a major benefit, such as authorship disputes, proof of authorship in court, tracing the source of code left in the system after a cyber attack, etc. We present a new approach, called the SCAP (Source Code Author Profiles) approach, based on byte-level n-gram profiles in order to represent a source code author's style. Experiments on data sets of different programming-language (Java or C++) and varying difficulty (6 to 30 candidate authors) demonstrate the effectiveness of the proposed approach.A comparison with a previous source code authorship identification study based on more complicated information shows that the SCAP approach is language independent and that n-gram author profiles are better able to capture the idiosyncrasies of the source code authors. Moreover, the SCAP approach is able to deal surprisingly well with cases where only a limited amount of very short programs per programmer is available for training. It is also demonstrated that the effectiveness of the proposed model is not affected by the absence of comments in the source code, a condition usually met in cyber-crime cases.
Georgia Frantzeskou, Efstathios Stamatatos, Stefanos Gritzalis, Sokratis K. Katsikas
ICSE3
2006 A Framework for Exploiting Security Expertise in Application Development
Theodoros Balopoulos, Lazaros Gymnopoulos, Maria Karyda 0001, Spyros Kokolakis, Stefanos Gritzalis, Sokratis K. Katsikas
TrustBus5
2006 Support of subscribers' certificates in a hybrid WLAN-3G environment
Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis, Dimitris Geneiatakis
Comput. Networks3
2006 Efficient heuristic algorithms for correcting the Cascade Vulnerability Problem for interconnected networks
Dimitris Fotakis 0001, Stefanos Gritzalis
Comput. Commun.2
2005 Evaluation of digital certificates acquisition in large-scale 802.11-3GPP hybrid environments
abstract
This paper evaluates the performance of a hybrid WLAN-3GPP network architecture for delivering subscribers' certificates. Two main categories of simulation scenarios are implemented and evaluated based on the underlying access network technology used; 802.11b and UMTS. Each of the scenarios is categorized further in numerous sub-cases. Results showed that AC acquisition when deployed in large scale between several heterogeneous networks is feasible within acceptable time limits.
Nikolaos Doukas, Eleni Klaoudatou, Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis
LANMAN5
2005 A framework for detecting malformed messages in SIP networks
abstract
Internet telephony like any other Internet service suffers from security flaws caused by various implementation errors (e.g. in end-users terminals, protocols, operating systems, hardware, etc). These implementation problems usually lead VoIP subsystems (e.g. SIP servers) to various unstable operations whenever trying to process a message not conforming to the underlying standards. As Internet telephony becomes more and more popular, attackers will attempt to exhaustively "test" implementations' robustness, transmitting various types of malformed messages to them. Since it is almost infeasible to avoid or predict every potential error caused during the developing process of these subsystems, it is necessary to specify an appropriate and robust, from the security point of view, framework that will facilitate the successful detection and handling of any kind of malformed messages aiming to destruct the provided service. In this paper, we adequately present malformed message attacks against SIP network servers and/or SIP end-user terminals and we propose a new detection "framework" of prototyped attacks' signatures that can assist the detection procedure and provide effective defence against this category of attacks
Dimitris Geneiatakis, Georgios Kambourakis, Tasos Dagiuklas, Costas Lambrinoudakis, Stefanos Gritzalis
LANMAN5
2005 Sec-Shield: Security Preserved Distributed Knowledge Management Between Autonomous Domains
Petros Belsis, Stefanos Gritzalis, Apostolos Malatras, Christos Skourlas, Ioannis Chalaris
TrustBus2
2005 A good-practice guidance on the use of PKI services in the public sector of the European Union member states
abstract
Purpose – This paper aims to describe good‐practice guidance on how a secure and efficient public key infrastructure (PKI) can be developed to support secure and efficient government‐to‐government and government‐to‐citizen electronic communication.
Stefanos Gritzalis
Inf. Manag. Comput. Security1
2004 Inter/Intra Core Network Security with PKI for 3G-and-Beyond Systems
Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis
NETWORKING3
2004 Enhancing Web privacy and anonymity in the digital era
abstract
This paper presents a state‐of‐the‐art review of the Web privacy and anonymity enhancing security mechanisms, tools, applications and services, with respect to their architecture, operational principles and vulnerabilities. Furthermore, to facilitate a detailed comparative analysis, the appropriate parameters have been selected and grouped in classes of comparison criteria, in the form of an integrated comparison framework. The main concern during the design of this framework was to cover the confronted security threats, applied technological issues and users' demands satisfaction. GNUnet's Anonymity Protocol (GAP), Freedom, Hordes, Crowds, Onion Routing, Platform for Privacy Preferences (P3P), TRUSTe, Lucent Personalized Web Assistant (LPWA), and Anonymizer have been reviewed and compared. The comparative review has clearly highlighted that the pros and cons of each system do not coincide, mainly due to the fact that each one exhibits different design goals and thus adopts dissimilar techniques for protecting privacy and anonymity.
Stefanos Gritzalis
Inf. Manag. Comput. Secur.1
2003 Security Policy Configuration Issues in Grid Computing Environments
George Angelis, Stefanos Gritzalis, Costas Lambrinoudakis
SAFECOMP2
2003 Introducing PKI to Enhance Security in Future Mobile Networks
Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis
SEC3
2003 ADoCSI: towards a transparent mechanism for disseminating Certificate Status Information
John Iliadis, Stefanos Gritzalis, Dimitris Gritzalis
Comput. Commun.2
2003 Towards a framework for evaluating certificate status information mechanisms
John Iliadis, Stefanos Gritzalis, Diomidis Spinellis, Danny De Cock, Bart Preneel, Dimitris Gritzalis
Comput. Commun.2
2003 Security requirements for e-government services: a methodological approach for developing a common PKI-based security policy
Costas Lambrinoudakis, Stefanos Gritzalis, Fredj Dridi, Günther Pernul
Comput. Commun.2
2001 A digital seal solution for deploying trust on commercial transactions
abstract
Traditional business practice depends on trust relations between the transacting parties. One of the most important aspects of this trust is the quality of the offered services or products. The Web currently constitutes an enabler for electronic commerce, providing a global transaction platform that does not require physical presence. However, transferring trust from the physical world to the electronic one is a process that requires a trust infrastructure. The current infrastructure, based on trusted third parties can be enhanced. We introduce the notion of digital seals and provide a mechanism for transferring the trust placed by users in companies in the physical world, to the electronic one.
Stefanos Gritzalis, Dimitris Gritzalis
Inf. Manag. Comput. Secur.1
2000 Securing The Electronic Market: The KEYSTONE Public Key Infrastructure Architecture
Stefanos Gritzalis, Sokratis K. Katsikas, Dimitrios Lekkas, Konstantinos Moulinos, Eleni Polydoro
Comput. Secur.1
2000 Distributed component software security issues on deploying a secure electronic marketplace
abstract
A secure electronic marketplace involves a significant number of real‐time transactions between remote systems, either for commercial or for authentication purposes. The underlying infrastructure of choice to support these transactions seems to be a distributed component architecture. Distributed component software (DCS) is the natural convergence of client/server network computing and object oriented technology in a mix providing reusability, scaleability and maintainability for software constructs. In DCS a client acquires references to objects provided by components located to remote machines and invokes methods of them as if they were located in its native environment. One implementation also provides the ability to pass objects by value, an approach recently examined also by others. The three major models in the distributed component software industry are OMG’s CORBA, Sun’s Enterprise Java Beans, and Microsoft’s DCOM. Besides these, we will discuss the progress for interoperable DCS systems performed in TINA, an open architecture for telecommunications services based on CORBA distributed components. In this paper the security models of each architecture are described and their efficiency and flexibility are evaluated in a comparative manner. Finally, upcoming extensions are discussed.
Stefanos Gritzalis, John Iliadis, Spyros Oikonomopoulos
Inf. Manag. Comput. Secur.1
1999 Security protocols over open networks and distributed systems: formal methods for their analysis, design, and verification
Stefanos Gritzalis, Diomidis Spinellis, Panagiotis Georgiadis 0001
Comput. Commun.1
1999 Trusted third party services for deploying secure telemedical applications over the WWW
Diomidis Spinellis, Stefanos Gritzalis, John Iliadis, Dimitris Gritzalis, Sokratis K. Katsikas
Comput. Secur.2
1999 Security requirements, risks and recommendations for small enterprise and home-office environments
abstract
The pervasive use of information technology in enterprises of every size and the emergence of widely deployed ubiquitous networking technologies have brought with them a widening need for security. Information system security policy development must begin with a thorough analysis of sensitivity and criticality. Risk analysis methodologies, like CRAMM, provide the ability to analyse and manage the associated risks. By performing a risk analysis on a typical small enterprise and a home‐office set‐up the article identifies the risks associated with availability, confidentiality, and integrity requirements. Although both environments share weaknesses and security requirements with larger enterprises, the risk management approaches required are different in nature and scale. Their implementation requires co‐operation between end users, network service providers, and software vendors.
Diomidis Spinellis, Spyros Kokolakis, Stefanos Gritzalis
Inf. Manag. Comput. Secur.3
1998 Towards Secure Downloadable Executable Content: The Java Paradigm
John Iliadis, Stefanos Gritzalis, V. Oikonomou
SAFECOMP2
1997 Cryptographic Protocols over Open Distributed Systems: A Taxonomy of Flaws and related Protocol Analysis Tools
Stefanos Gritzalis, Diomidis Spinellis
SAFECOMP1
1996 Security profile for interconnected open distributed systems with varying vulnerability
Nikitas V. Nikitakos, Stefanos Gritzalis, Panagiotis Georgiadis 0001
SEC2
1992 A zero knowledge probabilistic login protocol
Dimitris Gritzalis, Sokratis K. Katsikas, Stefanos Gritzalis
Comput. Secur.3