VLDB 2026 Research / reviewers in the wild / expert
Christoforos Ntantogian
dblp:86/6966 · also Christoforos Dadoyan
· DBLP profile ↗
27ranked-venue papers
11as first author
6since 2021 · last 2026
0000-0002-1575-4572ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 8 first-author · 5 since 2021Computer networks · 3 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Poison to Antidote: Advancing Cybersecurity Education with AI Attack and Defense Training
Angelos Spyridon Kourtesis, Christian Leka, Konstantinos Lazaros, Aristidis G. Vrahatis, Christoforos Ntantogian |
ICISSP (1) | 5 |
| 2024 | NITRO: an Interconnected 5G-IoT Cyber RangeabstractThis paper presents NITRO cyber range, which aims at creating a specialized cybersecurity testing and training environment for 5G and IoT networks. NITRO provides a platform for researchers and security professionals to simulate real-world scenarios, assess vulnerabilities, and validate security measures. It focuses on identifying novel cascading attacks that exploit the interdependencies between devices. Another innovation of the NITRO platform is the adversarial AI exercises on 5G and IoT networks, aiming at raising awareness of the vulnerabilities of AI models, how they can be attacked and how robust AI can defend against these vulnerabilities. The overarching goal of NITRO is to enhance security of 5G and IoT networks and serve as a precursor to the development of new cyber ranges within critical infrastructure sectors. Aristeidis Farao, Christoforos Ntantogian, Stylianos Karagiannis, Emmanouil Magkos, Alexandra Dritsa, Christos Xenakis |
ARES | 2 |
| 2024 | AI-Powered Penetration Testing using Shennina: From Simulation to ValidationabstractArtificial intelligence has been greatly improved nowadays, providing innovative approaches in cybersecurity both on offensive and defensive tactics. AI can be specifically utilized to automate and conduct penetration testing, a task that is usually time-intensive, involves high-costs, and requires cybersecurity professionals of high expertise. In this research paper, we utilize an AI penetration testing framework to validate, discover and analyze the techniques that were used. To this end, we conducted a validation process in a realistic environment and to collect the relevant datasets from the execution of the cyberattacks. Finally, the behavior of the AI penetration testing was analyzed in order to adapt and upgrade further. Overall, the research paper provides contributions to dataset generation and a methodology to understand the details of the attack simulation. Stylianos Karagiannis, Camilla Fusco, Leonidas Agathos, Wissam Mallouli, Valentina Casola, Christoforos Ntantogian, Emmanouil Magkos |
ARES | 6 |
| 2022 | EKnad: Exploit Kits' network activity detection
Panagiotis Bountakas, Christoforos Ntantogian, Christos Xenakis |
Future Gener. Comput. Syst. | 2 |
| 2022 | A large-scale analysis of Wi-Fi passwords
Eleni Veroni, Christoforos Ntantogian, Christos Xenakis |
J. Inf. Secur. Appl. | 2 |
| 2021 | NodeXP: NOde.js server-side JavaScript injection vulnerability DEtection and eXPloitation
Christoforos Ntantogian, Panagiotis Bountakas, Dimitris Antonaropoulos, Constantinos Patsakis, Christos Xenakis |
J. Inf. Secur. Appl. | 1 |
| 2020 | Distributed Key Management in MicrogridsabstractSecurity for smart industrial systems is prominent due to the proliferation of cyber threats threatening national critical infrastructures. Smart grid comes with intelligent applications that can utilize the bidirectional communication network among its entities. Microgrids are small-scale smart grids that enable machine-to-machine (M2M) communications as they can operate with some degree of independence from the main grid. In addition to protecting critical microgrid applications, an underlying key management scheme is needed to enable secure M2M message transmission and authentication. Existing key management schemes are not adequate due to microgrid special features and requirements. In this article, we propose the Micro sElf-orgaNiSed mAnagement (MENSA), which is the first hybrid key management and authentication scheme that combines public key infrastructure and web-of-trust concepts in microgrids. Our experimental results demonstrate the efficiency of MENSA in terms of scalability and swiftness. Vaios Bolgouras, Christoforos Ntantogian, Emmanouil A. Panaousis, Christos Xenakis |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | SealedGRID: A Secure Interconnection of Technologies for Smart Grid Applications
Aristeidis Farao, Juan E. Rubio, Cristina Alcaraz, Christoforos Ntantogian, Christos Xenakis, Javier López 0001 |
CRITIS | 4 |
| 2019 | Secure Edge Computing with Lightweight Control-Flow Property-based AttestationabstractThe Internet of Things (IoT) is rapidly evolving, while introducing several new challenges regarding security, resilience and operational assurance. In the face of an increasing attack landscape, it is necessary to cater for the provision of efficient mechanisms to collectively verify software- and device-integrity in order to detect run-time modifications. Towards this direction, remote attestation has been proposed as a promising defense mechanism. It allows a third party, the verifier, to ensure the integrity of a remote device, the prover. However, this family of solutions do not capture the real-time requirements of industrial IoT applications and suffer from scalability and efficiency issues. In this paper, we present a lightweight dynamic control-flow property-based attestation architecture (CFPA) that can be applied on both resource-constrained edge and cloud devices and services. It is a first step towards a new line of security mechanisms that enables the provision of control-flow attestation of only those specific, critical software components that are comparatively small, simple and limited in function, thus, allowing for a much more efficient verification. Our goal is to enhance run-time software integrity and trustworthiness with a scalable and decentralized solution eliminating the need for federated infrastructure trust. Based on our findings, we posit open issues and challenges, and discuss possible ways to address them, so that security do not hinder the deployment of intelligent edge computing systems. Nikos Koutroumpouchos, Christoforos Ntantogian, Sofia-Anna Menesidou, Kaitai Liang, Panagiotis Gouvas, Christos Xenakis, Thanassis Giannetsos |
NetSoft | 2 |
| 2019 | Evaluation of password hashing schemes in open source web platforms
Christoforos Ntantogian, Stefanos Malliaros, Christos Xenakis |
Comput. Secur. | 1 |
| 2019 | Transforming malicious code to ROP gadgets for antivirus evasionabstractThis study advances research in offensive technology by proposing return oriented programming (ROP) as a means to achieve code obfuscation. The key inspiration is that ROP's unique structure poses various challenges to malware analysis compared to traditional shellcode inspection and detection. The proposed ROP‐based attack vector provides two unique features: (i) the ability to automatically analyse and generate equivalent ROP chains for a given code, and (ii) the ability to reuse legitimate code found in an executable in the form of ROP gadgets. To this end, a software tool named ROPInjector was developed which, given any piece of shellcode and any legitimate executable file, it transforms the shellcode to its ROP equivalent re‐using the available code in the executable and finally patches the ROP chain infecting the executable. After trying various combinations of evasion techniques, the results show that ROPInjector can evade nearly and completely all antivirus software employed in the online VirusTotal service, making ROP an effective ingredient for code obfuscation. This attack vector poses a serious threat which malicious actors can take advantage to perform cyber‐attack campaigns. Christoforos Ntantogian, George Poulios, Georgios Karopoulos, Christos Xenakis |
IET Inf. Secur. | 1 |
| 2018 | MASKER: Masking for privacy-preserving aggregation in the smart grid ecosystem
Georgios Karopoulos, Christoforos Ntantogian, Christos Xenakis |
Comput. Secur. | 2 |
| 2017 | Analyzing, quantifying, and detecting the blackhole attack in infrastructure-less networks
Christoforos Panos, Christoforos Ntantogian, Stefanos Malliaros, Christos Xenakis |
Comput. Networks | 2 |
| 2016 | Protecting Sensitive Information in the Volatile Memory from Disclosure AttacksabstractThe protection of the volatile memory data is an issue of crucial importance, since authentication credentials and cryptographic keys remain in the volatile memory. For this reason, the volatile memory has become a prime target for memory scrapers, which specifically target the volatile memory, in order to steal sensitive information, such as credit card numbers. This paper investigates security measures, to protect sensitive information in the volatile memory from disclosure attacks. Experimental analysis is performed to investigate whether the operating systems (Windows or Linux) perform data zeroization in the volatile memory. Results show that Windows kernel zeroize data after a process termination, while the Linux kernel does not. Next, we examine functions and software techniques in C/C++ programming language that can be used by developers to modify at process runtime the contents of the allocated blocks in the volatile memory. We have identified that only the Windows operating system provide a specific function named SecureZeroMemory that can reliably zeroize data. Finally, driven by the fact that malware scrapers primarily target web browsers, we examine whether it is feasible to extract authentication credentials from the volatile memory allocated by web browsers. The presented results show that in most cases we can successfully recover user authentication credentials from all the web browsers except when the user has closed the tab that used to access the website. Stefanos Malliaros, Christoforos Ntantogian, Christos Xenakis |
ARES | 2 |
| 2016 | (U)SimMonitor: A mobile application for security evaluation of cellular networks
Christos Xenakis, Christoforos Ntantogian, Orestis Panos |
Comput. Secur. | 2 |
| 2015 | Attacking GSM Networks as a Script Kiddie Using Commodity Hardware and Software
Christoforos Ntantogian, Grigoris Valtas, Nikos Kapetanakis, Faidon Lalagiannis, Georgios Karopoulos, Christos Xenakis |
TrustBus | 1 |
| 2015 | Gaithashing: A two-factor authentication scheme based on gait features
Christoforos Ntantogian, Stefanos Malliaros, Christos Xenakis |
Comput. Secur. | 1 |
| 2014 | Evaluating the privacy of Android mobile applications under forensic analysis
Christoforos Ntantogian, Giannis Marinakis, Christos Xenakis |
Comput. Secur. | 1 |
| 2014 | An advanced persistent threat in 3G networks: Attacking the home network from roaming networks
Christos Xenakis, Christoforos Ntantogian |
Comput. Secur. | 2 |
| 2013 | A Better Time Approximation Scheme for e-Passports
Charalampos Petrou, Christoforos Ntantogian, Christos Xenakis |
TrustBus | 2 |
| 2012 | Analysis and Modeling of False Synchronizations in 3G-WLAN Integrated Networks
Christoforos Ntantogian, Christos Xenakis, Ioannis Stavrakakis |
SEC | 1 |
| 2011 | A Mobility and Energy-Aware Hierarchical Intrusion Detection System for Mobile Ad Hoc Networks
Eleni Darra, Christoforos Ntantogian, Christos Xenakis, Sokratis K. Katsikas |
TrustBus | 2 |
| 2011 | Reducing False Synchronizations in 3G-WLAN Integrated NetworksabstractAuthentication in 3G encompasses a mechanism, which ensures that the authentication vectors (AVs) are used only once. To achieve this, the employed mechanism maintains counters at both sides (mobile station and network) and verifies that the provided AVs are among the last α generated. However, there are many cases in which the mobile station receives AVs that have not been previously used, but the employed mechanism rejects them as outdated. This phenomenon, called false synchronization, causes signaling overhead and delays, and increases the cost of the network use. False synchronizations are more frequent in 3G-WLAN integrated networks. The frequency of false synchronizations decreases with α, while at the same time the risk of a replay attack increases. This paper aims at analytically determining an appropriate value of α, which balances effectively in 3G-WLANs the tradeoff between the rate of false synchronizations and exposure to adversaries exploiting compromised AVs. This is done by determining a threshold value of α beyond which the further reduction in false synchronizations is marginal, while the potential for a replay attack is constantly increasing and substantial. To this end, an analytical model based on a four dimensional Markov chain is developed whose accuracy is verified through simulations. Christoforos Ntantogian, Christos Xenakis, Ioannis Stavrakakis |
IEEE Trans. Wirel. Commun. | 1 |
| 2010 | A generic mechanism for efficient authentication in B3G networks
Christoforos Ntantogian, Christos Xenakis, Ioannis Stavrakakis |
Comput. Secur. | 1 |
| 2008 | A network-assisted mobile VPN for securing users data in UMTS
Christos Xenakis, Christoforos Ntantogian, Ioannis Stavrakakis |
Comput. Commun. | 2 |
| 2007 | A Security Protocol for Mutual Authentication and Mobile VPN Deployment in B3G NetworksabstractThis paper proposes a security protocol that provides mutual authentication between a user and a WLAN that the first tries to connect to, and deploys a mobile Virtual Private Network (VPN) that protects the user's data conveyed over the wireless network. For the user authentication as well as for the initialization of the VPN and the related key agreement, the EAP-SIM encapsulated within the Internet Key Exchange version 2 (IKEv2) is proposed. The deployed VPN, which is based on IPsec, ensures confidentiality, source authentication and integrity of the data exchanged over the WLAN. At the same time, the user has been subscribed to the 3G-network for charging and billing purposes using the legacy EAP-SIM authentication protocol. The established VPN can seamlessly operate and continuously provide security services as the mobile user moves and roams, materializing the notion of mobile VPN. The proposed security protocol eliminates the required enhancements to the current network infrastructure and operates transparently to the existing network functionality. Christoforos Ntantogian, Christos Xenakis |
PIMRC | 1 |
| 2007 | Reducing Authentication Traffic in 3G-WLAN Integrated NetworksabstractThe security architecture of the 3G-WLAN integrated networks specifies that a WLAN user, in order to get access to the 3G packet switched services or the public internet through the 3G PLMN, he must follow a two-pass EAP-AKA authentication procedure. This involves a double execution of EAP-AKA, which introduces a duplicated authentication overhead. This paper proposes a one-pass EAP-AKA authentication procedure for the 3 G-WLAN integrated networks that reduces significantly the authentication traffic, compared to the two-pass EAP-AKA authentication, without compromising the provided level of security. The proposed procedure has minimal impact on the existing 3 G-WLAN network infrastructure and functionality. A security analysis of the proposed authentication procedure is elaborated that identifies potential attacks and proposes possible countermeasures. In addition, a cost analysis is considered that compares the total number of messages required for user's authentication using the two-pass EAP-AKA and the proposed one-pass EAP-AKA authentication. Christoforos Ntantogian, Christos Xenakis |
PIMRC | 1 |