Georgios Kambourakis

dblp:90/2058 · DBLP profile ↗
← Back
71ranked-venue papers
10as first author
17since 2021 · last 2025
0000-0001-6348-5031ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 39 · 6 first-author · 12 since 2021Computer networks · 19 · 4 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Unmasking the hidden credential leaks in password managers and VPN clients
abstract
With the rapid growth of software services and applications, the need to secure digital assets became paramount. The introduction of Password Manager (PM) and Virtual Private Network (VPN) software was established as a prerequisite toolkit to bolster the end-user arsenal. As a matter of fact, these types of artifacts have been around for at least 25 years in various flavors, including desktop and browser-based applications. This work assesses the ability of 12 desktop PM applications, 5 browsers with integrated PM, and 12 PMs in the form of browser plugins, along with 21 VPN client applications, to effectively protect the confidentiality of secret credentials. Our analysis focuses on the period during which an app is loaded into RAM. Despite the sensitive nature of these applications, our results show that across all scenarios the majority of PM applications store plaintext passwords in the system memory; more specifically, 75% (or 9 out of 12) of desktop PM applications, 100% (5 out of 5) of browser PMs and 75% (or 9 out of 12) of PM browser plugins leak such sensitive information. In addition, 33% (or 7 out of 21) of VPN applications leak user credentials. This practice of storing cleartext sensitive information in system memory is widely recognized as a weakness, having also been registered as CWE-316. At the time of writing, merely four vendors have recognized our exploits as vulnerabilities. Three of these vendors have assigned the relevant Common Vulnerabilities and Exposures (CVE) IDs, namely CVE-2023-23349, CVE-2024-9203, and CVE-2024-50570, whereas the fourth one will issue a CVE ID once it implements the relevant fixes. The remaining vendors have either chosen to disregard or downplay the severity of this issue.
Efstratios Chatzoglou, Vyron Kampourakis, Zisis Tsiatsikas, Georgios Karopoulos, Georgios Kambourakis
Comput. Secur.5
2025 Assessing the detection of lateral movement through unsupervised learning techniques
Christos Smiliotopoulos, Georgios Kambourakis, Constantinos Kolias, Stefanos Gritzalis
Comput. Secur.2
2024 Federated Genetic Algorithm: Two-Layer Privacy-Preserving Trajectory Data Publishing
abstract
Nowadays, trajectory data is widely available and used in various real-world applications such as urban planning, navigation services, and location-based services. However, publishing trajectory data can potentially leak sensitive information about identity, personal profiles, and social relationships, and requires privacy protection. This paper focuses on optimizing Privacy-Preserving Trajectory Data Publishing (PP-TDP) problems, addressing the limitations of existing techniques in the trade-off between privacy protection and information preservation. We propose the Federated Genetic Algorithm (FGA) in this paper, aiming to achieve better local privacy protection and global information preservation. FGA consists of multiple local optimizers and a single global optimizer. The parallel local optimizer enables the local data center to retain the original trajectory data and share only the locally anonymized outcomes. The global optimizer collects the local anonymized outcomes and further optimizes the preservation of information while achieving comprehensive privacy protection. To optimize the discrete-domain PP-TDP problems more efficiently, this paper proposes a grouping-based strategy, an intersection-based crossover operation, and a complement-based mutation operation. Experimental results demonstrate that FGA outperforms its competitors in terms of solution accuracy and search efficiency.
Yong-Feng Ge, Hua Wang 0002, Jinli Cao, Yanchun Zhang, Georgios Kambourakis
GECCO5
2024 Keep Your Memory Dump Shut: Unveiling Data Leaks in Password Managers
abstract
Abstract Password management has long been a persistently challenging task. This led to the introduction of password management software, which has been around for at least 25 years in various forms, including desktop and browser-based applications. This work assesses the ability of two dozen password managers, 12 desktop applications, and 12 browser plugins, to effectively protect the confidentiality of secret credentials in six representative scenarios. Our analysis focuses on the period during which a Password Manager (PM) resides in the RAM. Despite the sensitive nature of these applications, our results show that across all scenarios, only three desktop PM applications and two browser plugins do not store plaintext passwords in the system memory. Oddly enough, at the time of writing, only two vendors recognized the exploit as a vulnerability, reserving CVE-2023-23349, while the rest chose to disregard or underrate the issue.
Efstratios Chatzoglou, Vyron Kampourakis, Zisis Tsiatsikas, Georgios Karopoulos, Georgios Kambourakis
SEC5
2024 Hierarchical adaptive evolution framework for privacy-preserving data publishing
abstract
Abstract The growing need for data publication and the escalating concerns regarding data privacy have led to a surge in interest in Privacy-Preserving Data Publishing (PPDP) across research, industry, and government sectors. Despite its significance, PPDP remains a challenging NP-hard problem, particularly when dealing with complex datasets, often rendering traditional traversal search methods inefficient. Evolutionary Algorithms (EAs) have emerged as a promising approach in response to this challenge, but their effectiveness, efficiency, and robustness in PPDP applications still need to be improved. This paper presents a novel Hierarchical Adaptive Evolution Framework (HAEF) that aims to optimizet-closeness anonymization through attribute generalization and record suppression using Genetic Algorithm (GA) and Differential Evolution (DE). To balance GA and DE, the first hierarchy of HAEF employs a GA-prioritized adaptive strategy enhancing exploration search. This combination aims to strike a balance between exploration and exploitation. The second hierarchy employs a random-prioritized adaptive strategy to select distinct mutation strategies, thus leveraging the advantages of various mutation strategies. Performance bencmark tests demonstrate the effectiveness and efficiency of the proposed technique. In 16 test instances, HAEF significantly outperforms traditional depth-first traversal search and exceeds the performance of previous state-of-the-art EAs on most datasets. In terms of overall performance, under the three privacy constraints tested, HAEF outperforms the conventional DFS search by an average of 47.78%, the state-of-the-art GA-based ID-DGA method by an average of 37.38%, and the hybrid GA-DE method by an average of 8.35% in TLEF. Furthermore, ablation experiments confirm the effectiveness of the various strategies within the framework. These findings enhance the efficiency of the data publishing process, ensuring privacy and security and maximizing data availability.
Mingshan You, Yong-Feng Ge, Kate N. Wang 0001, Hua Wang 0002, Jinli Cao, Georgios Kambourakis
World Wide Web (WWW)6
2023 Bypassing antivirus detection: old-school malware, new tricks
abstract
Being on a mushrooming spree since at least 2013, malware can take a large toll on any system. In a perpetual cat-and-mouse chase with defenders, malware writers constantly conjure new methods to hide their code so as to evade detection by security products. In this context, focusing on the MS Windows platform, this work contributes a comprehensive empirical evaluation regarding the detection capacity of popular, off-the-shelf antivirus and endpoint detection and response engines when facing legacy malware obfuscated via more or less uncommon but publicly known methods. Our experiments exploit a blend of seven traditional AV evasion techniques in 16 executables built in C++, Go, and Rust. Furthermore, we conduct an incipient study regarding the ability of the ChatGPT chatbot in assisting threat actors to produce ready-to-use malware. The derived results in terms of detection rate are highly unexpected: approximately half of the 12 tested AV engines were able to detect less than half of the malware variants, four AVs exactly half of the variants, while only two of the rest detected all but one of the variants.
Efstratios Chatzoglou, Georgios Karopoulos, Georgios Kambourakis, Zisis Tsiatsikas
ARES3
2023 Bl0ck: Paralyzing 802.11 Connections Through Block Ack Frames
Efstratios Chatzoglou, Vyron Kampourakis, Georgios Kambourakis
SEC3
2023 TLEF: Two-Layer Evolutionary Framework for t-Closeness Anonymization
Mingshan You, Yong-Feng Ge, Kate N. Wang 0001, Hua Wang 0002, Jinli Cao, Georgios Kambourakis
WISE6
2023 A hands-on gaze on HTTP/3 security through the lens of HTTP/2 and a public dataset
abstract
Following QUIC protocol ratification on May 2021, the third major version of the Hypertext Transfer Protocol, namely HTTP/3, was published around one year later in RFC 9114. In light of these consequential advancements, the current work aspires to provide a full-blown coverage of the following issues, which to our knowledge have received feeble or no attention in the literature so far. First, we provide a complete review of attacks against HTTP/2, and elaborate on if and in which way they can be migrated to HTTP/3. Second, through the creation of a testbed comprising the at present six most popular HTTP/3-enabled servers, we examine the effectiveness of a quartet of attacks, either stemming directly from the HTTP/2 relevant literature or being entirely new. This scrutiny led to the assignment of at least one CVE ID with a critical base score by MITRE. No less important, by capitalizing on a realistic, abundant in devices testbed, we compiled a voluminous, labeled corpus containing traces of ten diverse attacks against HTTP and QUIC services. An initial evaluation of the dataset mainly by means of machine learning techniques is included as well. Given that the 30 GB dataset is made available in both pcap and CSV formats, forthcoming research can easily take advantage of any subset of features, contingent upon the specific network topology and configuration.
Efstratios Chatzoglou, Vasileios Kouliaridis, Georgios Kambourakis, Georgios Karopoulos, Stefanos Gritzalis
Comput. Secur.3
2022 Large-scale empirical evaluation of DNS and SSDP amplification attacks
abstract
Reflection-based volumetric distributed denial-of-service (DDoS) attacks take advantage of the available to all (open) services to flood and possibly overpower a victim’s server or network with an amplified amount of traffic. This work concentrates on two key protocols in the assailants’ quiver regarding DoS attacks, namely domain name system (DNS) and simple service discovery protocol (SSDP). Our contribution spans three axes: (a) We perform countrywide IP address scans (probes) across three countries in two continents to locate devices that run open DNS or SSDP services, and thus can be effectively exploited in the context of amplification attacks, (b) we fingerprint the discovered devices to derive information about their type and operating system, and (c) we estimate the amplification factor of the discovered reflectors through a dozen of diverse, suitably crafted DNS queries and a couple of SSDP ones depending on the case. The conducted scans span fifteen months, therefore comparative conclusions regarding the evolution of the reflectors population over time, as well as indirect ones regarding the security measures in this field, can be deduced. For instance, for DNS, it was calculated that the third quartile of the amplification factor distribution remains more than 30 for customarily exploited queries across all the examined countries, while in the worst case this figure can reach up to 70. The same figures for SSDP range between roughly 41 and 73 for a specific type of query. To our knowledge, this work offers the first full-fledged mapping and assessment of DNS and SSDP amplifiers, and it is therefore anticipated to serve as a basis for further research in this ever-changing and high-stakes network security field.
Marios Anagnostopoulos, Stavros Lagos, Georgios Kambourakis
J. Inf. Secur. Appl.3
2022 How is your Wi-Fi connection today? DoS attacks on WPA3-SAE
abstract
WPA3-Personal renders the Simultaneous Authentication of Equals (SAE) password-authenticated key agreement method mandatory. The scheme achieves forward secrecy and is highly resistant to offline brute-force dictionary attacks. Given that SAE is based on the Dragonfly handshake, essentially a simple password exponential key exchange, it remains susceptible to clogging type of attacks at the Access Point side. To resist such attacks, SAE includes an anti-clogging scheme. To shed light on this contemporary and high-stakes issue, this work offers a full-fledged empirical study on Denial of Service (DoS) against SAE. By utilizing both real-life modern Wi-Fi 6 certified and non-certified equipment and the OpenBSD’s hostapd, we expose a significant number of novel DoS assaults affecting virtually any AP. No less important, more than a dozen of vendor-depended and severe zero-day DoS assaults are manifested, showing that the implementation of the protocol by vendors is not yet mature enough. The fallout of the introduced attacks to the associated stations ranges from a temporary loss of Internet connectivity to outright disconnection. To our knowledge, this work provides the first wholemeal appraisal of SAE’s mechanism endurance against DoS, and it is therefore anticipated to serve as a basis for further research in this timely and intriguing area.
Efstratios Chatzoglou, Georgios Kambourakis, Constantinos Kolias
J. Inf. Secur. Appl.2
2022 Your WAP Is at Risk: A Vulnerability Analysis on Wireless Access Point Web-Based Management Interfaces
abstract
This work provides an answer to the following key question: Are the Web-based management interfaces of the contemporary off-the-shelf wireless access points (WAP) free of flaws and vulnerabilities? The short answer is not very much. That is, after performing a vulnerability assessment on the Web interfaces of six different WAPs by an equal number of diverse renowned vendors, we reveal a significant number of assorted medium-to-high severity vulnerabilities that are straightforwardly or indirectly exploitable. Overall, 13 categories of vulnerabilities translated to 28 zero-day attacks are exposed. Our findings range from legacy path traversal, cross-site scripting, and clickjacking attacks to HTTP request smuggling and splitting, replay, denial of service, and information leakage among others. In the worst-case scenario, the attacker can acquire the administrator’s (admin) credentials and the WAP’s Wi-Fi passphrases or permanently lock the admin out of accessing the WAP’s Web interface. On top of everything else, we identify the already applied hardening measures by these devices and elaborate on extra countermeasures that are required to tackle the identified weaknesses. To our knowledge, this work contributes the first wholemeal appraisal of the security level of this kind of Web-based interfaces that go hand in glove with the myriads of WAPs out there, and it is therefore anticipated to serve as a basis for further research in this timely and challenging field.
Efstratios Chatzoglou, Georgios Kambourakis, Constantinos Kolias
Secur. Commun. Networks2
2021 AISGA: Multi-objective parameters optimization for countermeasures selection through genetic algorithm
abstract
Cyberattacks targeting modern network infrastructures are increasing in number and impact. This growing phenomenon emphasizes the central role of cybersecurity and, in particular, the reaction against ongoing threats targeting assets within the protected system. Such centrality is reflected in the literature, where several works have been presented to propose full-fledged reaction methodologies to tackle offensive incidents’ consequences. In this direction, the work in [18] developed an immuno-based response approach based on the application of the Artificial Immune System (AIS) methodology. That is, the AIS-powered reaction is able to calculate the optimal set of atomic countermeasure to enforce on the asset within the monitored system, minimizing the risk to which those are exposed in a more than adequate time. To further contribute to this line, the paper at hand presents AISGA, a multi-objective approach that leverages the capabilities of a Genetic Algorithm (GA) to optimize the selection of the input parameters of the AIS methodology. Specifically, AISGA selects the optimal ranges of inputs that balance the tradeoff between minimizing the global risk and the execution time of the methodology. Additionally, by flooding the AIS-powered reaction with a wide range of possible inputs, AISGA intends to demonstrate the robustness of such a model. Exhaustive experiments are executed to precisely compute the optimal ranges of parameters, demonstrating that the proposed multi-objective optimization prefers a fast-but-effective reaction.
Pantaleone Nespoli, Félix Gómez Mármol, Georgios Kambourakis
ARES3
2021 Neither Good nor Bad: A Large-Scale Empirical Analysis of HTTP Security Response Headers
Georgios Karopoulos, Dimitris Geneiatakis, Georgios Kambourakis
TrustBus3
2021 At Your Service 24/7 or Not? Denial of Service on ESInet Systems
Zisis Tsiatsikas, Georgios Kambourakis, Dimitris Geneiatakis
TrustBus2
2021 An extrinsic random-based ensemble approach for android malware detection
abstract
Malware detection is a fundamental task and associated with significant applications in humanities, cybersecurity, and social media analytics. In some of the relevant studies, there is substantial evidence that heterogeneous ensembles can provide very reliable solutions, better than any individual verification model. However, so far, there is no systematic study of examining the application of ensemble methods in this task. This paper introduces a sophisticated Extrinsic Random-based Ensemble (ERBE) method where in a predetermined set of repetitions, a subset of external instances (either malware or benign) as well as classification features are randomly selected, and an aggregation function is adopted to combine the output of all base models for each test case separately. By utilising static analysis only, we demonstrate that the proposed method is capable of taking advantage of the availability of multiple external instances of different size and genre. The experimental results in AndroZoo benchmark corpora verify the suitability of a random-based heterogeneous ensemble for this task and exhibit the effectiveness of our method, in some cases improving the hitherto best reported results by more than 5%.
Nektaria Potha, Vasileios Kouliaridis, Georgios Kambourakis
Connect. Sci.3
2021 Sharing Pandemic Vaccination Certificates through Blockchain: Case Study and Performance Evaluation
abstract
During 2021, different worldwide initiatives have been established for the development of digital vaccination certificates to alleviate the restrictions associated with the COVID‐19 pandemic to vaccinated individuals. Although diverse technologies can be considered for the deployment of such certificates, the use of blockchain has been suggested as a promising approach due to its decentralization and transparency features. However, the proposed solutions often lack realistic experimental evaluation that could help to determine possible practical challenges for the deployment of a blockchain platform for this purpose. To fill this gap, this work introduces a scalable, blockchain‐based platform for the secure sharing of COVID‐19 or other disease vaccination certificates. As an indicative use case, we emulate a large‐scale deployment by considering the countries of the European Union. The platform is evaluated through extensive experiments measuring computing resource usage, network response time, and bandwidth. Based on the results, the proposed scheme shows satisfactory performance across all major evaluation criteria, suggesting that it can set the pace for real implementations. Vis‐à‐vis the related work, the proposed platform is novel, especially through the prism of a large‐scale, full‐fledged implementation and its assessment.
José Luis Hernández-Ramos, Georgios Karopoulos, Dimitris Geneiatakis, Tania Martin, Georgios Kambourakis, Igor Nai Fovino
Wirel. Commun. Mob. Comput.5
2020 Feature importance in Android malware detection
abstract
The topic of mobile malware detection on the Android platform has attracted significant attention over the last several years. However, while much research has been conducted toward mobile malware detection techniques, little attention has been devoted to feature selection and feature importance. That is, which app feature matters more when it comes to machine learning classification. After succinctly surveying all major, dated from 2012 to 2020, datasets used by state-of-the-art malware detection works in the literature, we analyse a critical mass of apps from the most contemporary and prevailing datasets, namely Drebin, VirusShare, and AndroZoo. Next, we rank the importance of app classification features pertaining to permissions and intents using the Information Gain algorithm for all the three above-mentioned datasets.
Vasileios Kouliaridis, Georgios Kambourakis, Tao Peng 0011
TrustCom2
2020 Demystifying COVID-19 Digital Contact Tracing: A Survey on Frameworks and Mobile Apps
abstract
The coronavirus pandemic is a new reality, and it severely affects the modus vivendi of the international community. In this context, governments are rushing to devise or embrace novel surveillance mechanisms and monitoring systems to fight the outbreak. The development of digital tracing apps, which among others are aimed at automatising and globalising the prompt alerting of individuals at risk in a privacy-preserving manner, is a prominent example of this ongoing effort. Very promptly, a number of digital contact tracing architectures have been sprouted, followed by relevant app implementations adopted by governments worldwide. Bluetooth, specifically its Low Energy (BLE) power-conserving variant, has emerged as the most promising short-range wireless network technology to implement the contact tracing service. This work offers the first to our knowledge full-fledged review of the most concrete contact tracing architectures proposed so far in a global scale. This endeavour does not only embrace the diverse types of architectures and systems, namely, centralised, decentralised, or hybrid, but also equally addresses the client side, i.e., the apps that have been already deployed in Europe by each country. There is also a full-spectrum adversary model section, which does not only amalgamate the previous work in the topic but also brings new insights and angles to contemplate upon.
Tania Martin, Georgios Karopoulos, José Luis Hernández-Ramos, Georgios Kambourakis, Igor Nai Fovino
Wirel. Commun. Mob. Comput.4
2019 Hands-Free one-Time and continuous authentication using glass wearable devices
Dimitrios Damopoulos, Georgios Kambourakis
J. Inf. Secur. Appl.2
2019 Security, Privacy, and Trust on Internet of Things
Constantinos Kolias, Weizhi Meng 0001, Georgios Kambourakis, Jiageng Chen
Wirel. Commun. Mob. Comput.3
2018 Never say never: Authoritative TLD nameserver-powered DNS amplification
abstract
DNS amplification attack is a significant and persistent threat to the Internet. Authoritative name servers (ANSes) of popular domains, especially the DNSSEC-enabled ones, give attractive leverage for attackers in distributed denial-of-service (DDoS) attacks. Particularly, the ANS list of top-level domains (TLD) is publicly accessible, including by would-be attackers, in the form of a root.zone file. In this work, we examine the potential of TLD ANSes to be exploited as unknowing agents in DNS amplification attacks. Specifically, over a period of 12 months that covers two different versions of the root.zone file, we assess the amplification factor (AF) that these servers may provide to attackers when replying to both individual and multiple queries. Also, we measure the degree of actual adoption of the recommended response rate limiting (RRL) countermeasure for the ANSes. Our major findings are that (i) 70% of the distinct ANSes and 47% of the possible DNS queries for the TLDs produce a large AF that exceeds 60, (ii) 10% of the distinct ANSes reflect inbound network traffic and magnify it by a factor that exceeds 50, (iii) the number of most useful ANSes for the attacker, in terms of their role as amplifiers, appears increasing during the monitoring period, and (iv) there still exists a significant number of ANSes that do not implement the RRL or leave it inactive.
Marios Anagnostopoulos, Georgios Kambourakis, Stefanos Gritzalis, David K. Y. Yau
NOMS2
2018 Dendron : Genetic trees driven rule induction for network intrusion detection systems
Dimitrios Papamartzivanos, Félix Gómez Mármol, Georgios Kambourakis
Future Gener. Comput. Syst.3
2017 Why Snoopy Loves Online Services: An Analysis of (Lack of) Privacy in Online Services
abstract
Over the last decade online services have penetrated the market and for many of us became an integral part of our software portfolio.On the one hand online services offer flexibility in every sector of the social web, but on the other hand these pros do not come without a cost in terms of privacy.This work focuses on online services, and in particular on the possible inherent design errors which make these services an easy target for privacy invaders.We demonstrate the previous fact using a handful of real-world cases pertaining to popular online web services.More specifically, we show that despite the progress made in raising security/privacy awareness amongst all the stakeholders (developers, admins, users) and the existence of mature security/privacy standards and practices, there still exist a plethora of poor implementations that may put user's privacy at risk.We particularly concentrate on cases where a breach can happen even if the aggressor has limited knowledge about their target and/or the attack can be completed with limited resources.In this context, the main contribution of the paper at hand revolves around the demonstration of effortlessly exploiting privacy leaks existing in widely-known online services due to software development errors.
Vittoria Cozza, Zisis Tsiatsikas, Mauro Conti, Georgios Kambourakis
ICISSP4
2017 Botnet Command and Control Architectures Revisited: Tor Hidden Services and Fluxing
Marios Anagnostopoulos, Georgios Kambourakis, Drakatos Panagiotis, Michail Karavolos, Sarantis Kotsilitis, David K. Y. Yau
WISE (2)2
2016 Realtime DDoS Detection in SIP Ecosystems: Machine Learning Tools of the Trade
Zisis Tsiatsikas, Dimitris Geneiatakis, Georgios Kambourakis, Stefanos Gritzalis
NSS3
2016 Introducing touchstroke: keystroke-based authentication system for smartphones
abstract
Abstract Keystroke dynamics is a well‐investigated behavioural biometric based on the way and rhythm in which someone interacts with a keyboard or keypad when typing characters. This paper explores the potential of this modality but for touchscreen‐equipped smartphones. The main research question posed is whether ‘touchstroking’ can be effective in building the biometric profile of a user, in terms of typing pattern, for future authentication. To reach this goal, we implemented a touchstroke system in the Android platform and executed different scenarios under disparate methodologies to estimate its effectiveness in authenticating the end‐user. Apart from typical classification features used in legacy keystroke systems, we introduce two novel ones, namely, speed and distance. From the experiments, it can be argued that touchstroke dynamics can be quite competitive, at least when compared to similar results obtained from keystroke evaluation studies. As far as we are aware of, this is the first time this newly arisen behavioural trait is put into focus. Copyright © 2014 John Wiley & Sons, Ltd.
Georgios Kambourakis, Dimitrios Damopoulos, Dimitrios Papamartzivanos, Emmanouil Pavlidakis
Secur. Commun. Networks1
2015 Battling Against DDoS in SIP - Is Machine Learning-based Detection an Effective Weapon?
abstract
This paper focuses on network anomaly-detection and especially the effectiveness of Machine Learning (ML) techniques in detecting Denial of Service (DoS) in SIP-based VoIP ecosystems. It is true that until now several works in the literature have been devoted to this topic, but only a small fraction of them have done so in an elaborate way. Even more, none of them takes into account high and low-rate Distributed DoS (DDoS) when assessing the efficacy of such techniques in SIP intrusion detection. To provide a more complete estimation of this potential, we conduct extensive experimentations involving 5 different classifiers and a plethora of realistically simulated attack scenarios representing a variety of (D)DoS incidents. Moreover, for DDoS ones, we compare our results with those produced by two other anomaly-based detection methods, namely Entropy and Hellinger Distance. Our results show that ML-powered detection scores a promising false alarm rate in the general case, and seems to outperform similar methods when it comes to DDoS.
Zisis Tsiatsikas, Alexandros Fakis, Dimitrios Papamartzivanos, Dimitris Geneiatakis, Georgios Kambourakis, Constantinos Kolias
SECRYPT5
2015 Hidden in Plain Sight. SDP-Based Covert Channel for Botnet Communication
Zisis Tsiatsikas, Marios Anagnostopoulos, Georgios Kambourakis, Sozon Lambrou, Dimitris Geneiatakis
TrustBus3
2015 Security and privacy in unified communications: Challenges and solutions
Georgios Karopoulos, Georgios Portokalidis, Josep Domingo-Ferrer, Ying-Dar Lin, Dimitris Geneiatakis, Georgios Kambourakis
Comput. Commun.6
2015 An efficient and easily deployable method for dealing with DoS in SIP services
Zisis Tsiatsikas, Dimitris Geneiatakis, Georgios Kambourakis, Angelos D. Keromytis
Comput. Commun.3
2015 Special issue on Security, Privacy and Trust in network-based Big Data
Hua Wang 0002, Xiaohong Jiang 0001, Georgios Kambourakis
Inf. Sci.3
2014 Complete SIP Message Obfuscation: PrivaSIP over Tor
abstract
Anonymity on SIP signaling can be achieved either by the construction of a lower level tunnel (via the use of SSL or IPSec protocols) or by employing a custom-tailored solution. Unfortunately, the former category of solutions present significant impediments including the requirement for a PKI and the hop-by-hop fashioned protection, while the latter only concentrate on the application layer, thus neglecting sensitive information leaking from lower layers. To remediate this problem, in the context of this paper, we employ the well-known Tor anonymity system to achieve complete SIP traffic obfuscation from an attacker's standpoint. Specifically, we capitalize on Tor for preserving anonymity on network links that are considered mostly untrusted, i.e., those among SIP proxies and the one between the last proxy in the chain and the callee. We also, combine this Tor-powered solution with PrivaSIP to achieve an even greater level of protection. By employing PrivaSIP we assure that: (a) the first hop in the path (i.e., between the caller and the outbound proxy) affords anonymity, (b) the callee does not know the real identity of the caller, and (c) no real identities of both the caller and the callee are stored in log files. We also evaluate this scheme in terms of performance and show that even in the worst case, the latency introduced is not so high as it might be expected due to the use of Tor.
Georgios Karopoulos, Alexandros Fakis, Georgios Kambourakis
ARES3
2014 Anonymity and closely related terms in the cyberspace: An analysis by example
Georgios Kambourakis
J. Inf. Secur. Appl.1
2014 Editorial: Developments in Security and Privacy-Preserving Mechanisms for Future Mobile Communication Networks
Georgios Kambourakis, Gregorio Martínez Pérez, Félix Gómez Mármol
Mob. Networks Appl.1
2014 Exposing mobile malware from the inside (or what is your mobile app really doing?)
Dimitrios Damopoulos, Georgios Kambourakis, Stefanos Gritzalis, Sang Oh Park
Peer-to-Peer Netw. Appl.2
2013 A Privacy-Preserving Entropy-Driven Framework for Tracing DoS Attacks in VoIP
abstract
Network audit trails, especially those composed of application layer data, can be a valuable source of information regarding the investigation of attack incidents. Nevertheless, the analysis of log files of large volume is usually both complex (slow) and privacy-neglecting. Especially, when it comes to VoIP, the literature on how audit trails can be exploited to identify attacks remains scarce. This paper provides an entropy-driven, privacy preserving, and practical framework for detecting resource consumption attacks in VoIP ecosystems. We extensively evaluate our framework under various attack scenarios involving single and multiple assailants. The results obtained show that the proposed scheme is capable of identifying malicious traffic with a false positive alarm rate up to 3.5%.
Zisis Tsiatsikas, Dimitris Geneiatakis, Georgios Kambourakis, Angelos D. Keromytis
ARES3
2013 DNS amplification attack revisited
Marios Anagnostopoulos, Georgios Kambourakis, Panagiotis Kopanos, Georgios Louloudakis, Stefanos Gritzalis
Comput. Secur.2
2013 From keyloggers to touchloggers: Take the rough with the smooth
Dimitrios Damopoulos, Georgios Kambourakis, Stefanos Gritzalis
Comput. Secur.2
2013 User privacy and modern mobile services: are they on the same path?
Dimitrios Damopoulos, Georgios Kambourakis, Marios Anagnostopoulos, Stefanos Gritzalis
Pers. Ubiquitous Comput.2
2012 Evaluation of anomaly-based IDS for mobile devices using machine learning classifiers
abstract
ABSTRACT Mobile devices have evolved and experienced an immense popularity over the last few years. This growth however has exposed mobile devices to an increasing number of security threats. Despite the variety of peripheral protection mechanisms described in the literature, authentication and access control cannot provide integral protection against intrusions. Thus, a need for more intelligent and sophisticated security controls such as intrusion detection systems (IDSs) is necessary. Whilst much work has been devoted to mobile device IDSs, research on anomaly‐based or behaviour‐based IDS for such devices has been limited leaving several problems unsolved. Motivated by this fact, in this paper, we focus on anomaly‐based IDS for modern mobile devices. A dataset consisting of iPhone users data logs has been created, and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. Specifically, the experimental procedure includes and cross‐evaluates four machine learning algorithms (i.e. Bayesian networks, radial basis function,K‐nearest neighbours and random Forest), which classify the behaviour of the end‐user in terms of telephone calls, SMS and Web browsing history. In order to detect illegitimate use of service by a potential malware or a thief, the experimental procedure examines the aforementioned services independently as well as in combination in a multimodal fashion. The results are very promising showing the ability of at least one classifier to detect intrusions with a high true positive rate of 99.8%. Copyright © 2011 John Wiley & Sons, Ltd.
Dimitrios Damopoulos, Sofia-Anna Menesidou, Georgios Kambourakis, Maria Papadaki, Nathan L. Clarke, Stefanos Gritzalis
Secur. Commun. Networks3
2012 SIPA: generic and secure accounting for SIP
abstract
ABSTRACT Authentication, authorization, and accounting services provide the framework on top of which a reliable, secure, and robust accounting system can be built. In a previous work of ours, we have presented a flexible and, most importantly, generic accounting scheme for next generation networks. In this paper, we substantially improve our previous work by providing the required Diameter application namely SIP‐Accounting (SIPA) that enables the use of our accounting scheme for Session Initiation Protocol (SIP) services. Additionally, in an effort to protect the service providers and the end users against accounting frauds, we implement an add‐on mechanism referred to as SIPA+ to combat attacks targeting the core accounting functions and the integrity of the respective accounting messages. Using the implemented SIPA and SIPA+ prototypes, we conducted a complete set of experiments testing several configurations and two distinct scenarios. The results reveal that the proposed accounting system and its security add‐on are fully operable in SIP environments without incurring much cost in terms of performance and overhead. Copyright © 2011 John Wiley & Sons, Ltd.
Alexandros Tsakountakis, Georgios Kambourakis, Stefanos Gritzalis
Secur. Commun. Networks2
2011 iSAM: An iPhone Stealth Airborne Malware
Dimitrios Damopoulos, Georgios Kambourakis, Stefanos Gritzalis
SEC2
2011 DoS attacks exploiting signaling in UMTS and IMS
Georgios Kambourakis, Constantinos Kolias, Stefanos Gritzalis, Jong Hyuk Park 0001
Comput. Commun.1
2011 Swarm intelligence in intrusion detection: A survey
Constantinos Kolias, Georgios Kambourakis, Manolis Maragoudakis
Comput. Secur.2
2011 PrivaKERB: A user privacy framework for Kerberos
Fernando Pereñíguez-Garcia, Rafael Marín López, Georgios Kambourakis, Stefanos Gritzalis, Antonio F. Skarmeta
Comput. Secur.3
2011 Privacy preserving context transfer schemes for 4G networks
abstract
Abstract In the near future, wireless heterogeneous networks are expected to interconnect in an all‐IP architecture. An open issue towards this direction is the uninterrupted continuation of the received services during handover between networks employing different access technologies. In this context, Mobile IP (MIP) is a protocol that allows fast and secure handovers. However, MIP per se cannot handle all the issues that surface during handovers in certain services, and more specifically, when the information of the current state of a service requires re‐establishment on the new subnet without having to repeat the entire protocol exchange with the mobile host from the outset. A number of methods have been proposed to solve the aforementioned problem, commonly referred to as secure context transfer. However, while such methods do succeed in minimising the disruption caused by security‐related delays, it seems that little has been done to protect the end‐users' privacy as well. In this paper, a number of privacy enhanced (PE) context transfer schemes are presented. The first two of them have been introduced in a previous work of ours while the other two are novel. All schemes are analysed in terms of message exchange and evaluated through simulations. The performance of our schemes is compared with the standard ones proposed by the Seamoby work group (WG). The results demonstrate that the proposed schemes are very efficient in terms of application handover times, while at the same time guarantee the privacy of the end‐user. Copyright © 2010 John Wiley & Sons, Ltd.
Iosif Terzis, Georgios Kambourakis, Georgios Karopoulos, Costas Lambrinoudakis
Wirel. Commun. Mob. Comput.2
2010 Privacy-enhanced fast re-authentication for EAP-based next generation network
Fernando Pereñíguez-Garcia, Georgios Kambourakis, Rafael Marín López, Stefanos Gritzalis, Antonio F. Skarmeta
Comput. Commun.2
2010 A framework for identity privacy in SIP
Georgios Karopoulos, Georgios Kambourakis, Stefanos Gritzalis, Elisavet Konstantinou
J. Netw. Comput. Appl.2
2010 Design and implementation of a VoiceXML-driven wiki application for assistive environments on the web
Constantinos Kolias, Vassilis Kolias, Ioannis Anagnostopoulos, Georgios Kambourakis, Eleftherios Kayafas
Pers. Ubiquitous Comput.4
2009 A First Order Logic Security Verification Model for SIP
abstract
It is well known that no security mechanism can provide full protection against a potential attack. There is always a possibility that a security incident may happen, mainly as a result of a new or modified attack that the employed countermeasures cannot handle or identify. It is therefore useful to perform a deferred analysis of logged network data, in an attempt to identify abnormal behavior/traffic that flags some type of security incident that has not been detected by the security countermeasures. Such an analysis of logged data for critical real time applications, like VoIP services, is certainly a valuable tool for enhancing the security level of the provided service. In this paper we introduce a practical tool that can be employed for the analysis of logged VoIP data and thus validate the effectiveness of the security mechanisms and the conformance with the corresponding security policy rules. For the analysis of the data we capitalize on our security model for VoIP services that is based on first order logic concepts, while the Protege API and the semantic Web rule language (SWRL) are also exploited. The proposed tool has been evaluated in terms of an experimental environment, while the results obtained confirm the validity of its operation and demonstrate its effectiveness.
Dimitris Geneiatakis, Costas Lambrinoudakis, Georgios Kambourakis, Aggelos Kafkalas, Sven Ehlert
ICC3
2009 A Cluster-Based Framework for the Security of Medical Sensor Environments
Eleni Klaoudatou, Elisavet Konstantinou, Georgios Kambourakis, Stefanos Gritzalis
TrustBus3
2009 A generic accounting scheme for next generation networks
Alexandros Tsakountakis, Georgios Kambourakis, Stefanos Gritzalis
Comput. Networks2
2009 Pandora: An SMS-oriented m-informational system for educational realms
Lambros Boukas, Georgios Kambourakis, Stefanos Gritzalis
J. Netw. Comput. Appl.2
2008 Clustering Oriented Architectures in Medical Sensor Environments
abstract
Wireless sensor networks are expected to make a significant contribution in the healthcare sector by enabling continuous patient monitoring. Since medical services and the associated to them information are considered particularly sensitive, the employment of wireless sensors in medical environments poses many security issues and challenges. However, security services and the underlying key management mechanisms cannot be seen separately from the efficiency and scalability requirements. Network clustering used in both routing and group key management mechanisms can improve the efficiency and scalability and therefore can also be envisioned in medical environments. This paper introduces a general framework for cluster-based wireless sensor medical environments on the top of which efficient security mechanisms can rely. We describe two different scenarios for infrastructure and infrastructure- less application environments, covering this way a wide area of medical applications (in-hospital and medical emergencies). We also examine the existing group-key management schemes for cluster-based wireless networks and discuss which protocols fit best for each proposed scenario.
Eleni Klaoudatou, Elisavet Konstantinou, Georgios Kambourakis, Stefanos Gritzalis
ARES3
2008 Caller identity privacy in SIP heterogeneous realms: A practical solution
abstract
The growing demand for voice services and multimedia delivery over the Internet has raised SIPpsilas popularity making it a subject of extensive research. SIP is an application layer control signaling protocol, whose main purpose is to create, modify and terminate multimedia sessions. Research has shown that SIP has a number of security issues that must be solved in order to increase its trustworthiness and supersede or coexist with PSTN. In this paper our purpose is to address such a weakness, namely the caller identity privacy issue. While some solutions to this problem do exist, we will show that they are inadequate in a number of situations. Furthermore, we will propose a novel scheme for the protection of callerpsilas identity which can also support roaming between different administrative domains. Finally, we provide some performance results, which demonstrate that the proposed solution is efficient even in low-end mobile devices.
Georgios Karopoulos, Georgios Kambourakis, Stefanos Gritzalis
ISCC2
2008 Privacy Protection in Context Transfer Protocol
abstract
In the future 4G wireless networks will span across different administrative domains. In order to provide secure seamless handovers in such an environment the context transfer protocol is an attractive solution. However, the aforementioned protocol arises some privacy issues concerning the location and movement of users roaming between administrative domains. The purpose of this paper is to present and analyze these privacy issues and propose two privacy enhanced context transfer schemes that alleviate these problems. In the first scheme the Mobile Node (MN) is responsible for the transmission of the context to the new domain. In the second scheme the Home Domain (HD) of the user forwards the context acting as a proxy between the old and the new domain. While the second scheme is expected to be more useful towards realizing seamless handovers, the first one poses less signaling load to the HD. In addition, assuming that the most appropriate form of user identity for the context is the Network Access Identifier (NAI), we show how the employment of temporary NAIs can further increase the privacy of our schemes.
Georgios Karopoulos, Georgios Kambourakis, Stefanos Gritzalis
PDP2
2008 A new Accounting Mechanism for Modern and Future AAA Services
Alexandros Tsakountakis, Georgios Kambourakis, Stefanos Gritzalis
SEC2
2008 A Mechanism for Ensuring the Validity and Accuracy of the Billing Services in IP Telephony
Dimitris Geneiatakis, Georgios Kambourakis, Costas Lambrinoudakis
TrustBus2
2008 Two layer Denial of Service prevention on SIP VoIP infrastructures
Sven Ehlert, Dimitris Geneiatakis, Georgios Kambourakis, Tasos Dagiuklas, Jirí Markl, Dorgham Sisalem
Comput. Commun.4
2008 An ontology-based policy for deploying secure SIP-based VoIP services
Dimitris Geneiatakis, Costas Lambrinoudakis, Georgios Kambourakis
Comput. Secur.3
2008 Enabling the provision of secure web based m-health services utilizing XML based security models
abstract
Abstract It has been generally agreed that the security of electronic patient records and generally e‐health applications must meet or exceed the standard security that should be applied to paper medical records, yet the absence of clarity on the proper goals of protection has led to confusion. The primary purpose of this study was to investigate appropriate security mechanisms, which will help clinical professionals and patients discharge their ethical and legal responsibilities by selecting suitable systems and operating them safely and in short order. Thus, in this paper we propose a security model based on XML with the intention of developing a fast security policy mostly intended for mobile healthcare information systems. The proposed schema consists of a set of principles based on XML security models through the use of partial encryption, signature and integrity services and it was implemented by means of a web‐based m‐health application in a centralized three‐tier architecture utilizing wireless networks environment. Several experiments took place with the aim of measuring the client response time implementing a number of m‐health scenarios. The results showed that the response times required for the fulfilment of a client request with the XML security model are smaller compared to those corresponding to the conventional security mechanisms such as the application of SSL. By selectively applying confidentiality and integrity services either to the medical information as a whole or to some sensitive parts of it, the obtained results clearly demonstrate that XML security mechanisms overwhelm those of SSL and they are suitable for deployment in m‐health applications. Copyright © 2008 John Wiley & Sons, Ltd.
Demosthenes Vouyioukas, Georgios Kambourakis, Ilias Maglogiannis, Angelos N. Rouskas, Constantinos Kolias, Stefanos Gritzalis
Secur. Commun. Networks2
2007 Securing Medical Sensor Environments: The CodeBlue Framework Case
abstract
Research on wireless sensor networks targeting to medical environments has gathered a great attention. In this context, the most recent and perhaps the most promising complete scheme is the CodeBlue hardware and software combined platform, developed in the context of the self-titled Harvard's University project. CodeBlue relies on miniature wearable sensors to monitor real-time patients' vital activities and collecting data for further processing. Apart from the essential query interface for medical monitoring, CodeBlue offers protocols for hardware discovery and multihop routing. This paper contributes to the CodeBlue security, which until now is considered as pending or left out for future work by its designers. We identify and describe several security issues and attack incidents that can be directly applied on CodeBlue compromising its trustworthiness. We also discuss possible solutions for both internal and external attacks and the key-management mechanisms that these solutions presume
Georgios Kambourakis, Eleni Klaoudatou, Stefanos Gritzalis
ARES1
2007 Detecting DNS Amplification Attacks
Georgios Kambourakis, Tassos Moschos, Dimitris Geneiatakis, Stefanos Gritzalis
CRITIS1
2007 On Device Authentication in Wireless Networks: Present Issues and Future Challenges
Georgios Kambourakis, Stefanos Gritzalis
TrustBus1
2007 A framework for protecting a SIP-based infrastructure against malformed message attacks
Dimitris Geneiatakis, Georgios Kambourakis, Costas Lambrinoudakis, Tasos Dagiuklas, Stefanos Gritzalis
Comput. Networks2
2006 Support of subscribers' certificates in a hybrid WLAN-3G environment
Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis, Dimitris Geneiatakis
Comput. Networks1
2005 Evaluation of digital certificates acquisition in large-scale 802.11-3GPP hybrid environments
abstract
This paper evaluates the performance of a hybrid WLAN-3GPP network architecture for delivering subscribers' certificates. Two main categories of simulation scenarios are implemented and evaluated based on the underlying access network technology used; 802.11b and UMTS. Each of the scenarios is categorized further in numerous sub-cases. Results showed that AC acquisition when deployed in large scale between several heterogeneous networks is feasible within acceptable time limits.
Nikolaos Doukas, Eleni Klaoudatou, Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis
LANMAN3
2005 A framework for detecting malformed messages in SIP networks
abstract
Internet telephony like any other Internet service suffers from security flaws caused by various implementation errors (e.g. in end-users terminals, protocols, operating systems, hardware, etc). These implementation problems usually lead VoIP subsystems (e.g. SIP servers) to various unstable operations whenever trying to process a message not conforming to the underlying standards. As Internet telephony becomes more and more popular, attackers will attempt to exhaustively "test" implementations' robustness, transmitting various types of malformed messages to them. Since it is almost infeasible to avoid or predict every potential error caused during the developing process of these subsystems, it is necessary to specify an appropriate and robust, from the security point of view, framework that will facilitate the successful detection and handling of any kind of malformed messages aiming to destruct the provided service. In this paper, we adequately present malformed message attacks against SIP network servers and/or SIP end-user terminals and we propose a new detection "framework" of prototyped attacks' signatures that can assist the detection procedure and provide effective defence against this category of attacks
Dimitris Geneiatakis, Georgios Kambourakis, Tasos Dagiuklas, Costas Lambrinoudakis, Stefanos Gritzalis
LANMAN2
2004 Inter/Intra Core Network Security with PKI for 3G-and-Beyond Systems
Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis
NETWORKING1
2003 Introducing PKI to Enhance Security in Future Mobile Networks
Georgios Kambourakis, Angelos N. Rouskas, Stefanos Gritzalis
SEC1