VLDB 2026 Research / reviewers in the wild / expert
Eliana Stavrou
dblp:90/4455
· DBLP profile ↗
18ranked-venue papers
9as first author
11since 2021 · last 2025
0000-0003-4040-4942ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 6 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 5 since 2021Computer networks · 3 · 3 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Reducing SOC Analysts Alert Fatigue via Real-Time CTI Correlation and Deduplication
Sotiris Koumourou, Adamantini Peratikou, Eliana Stavrou, Savvas Theodoulou, Stavros Stavrou |
CRITIS | 3 |
| 2025 | CY-TRUST: A Sectorial SOC Framework for Enhanced National and Cross-Border Cybersecurity Resilience
Adamantini Peratikou, Evagoras Charalambous, Eliana Stavrou, Panayiota Smyrli, George Hadjichristophi, Stavros Stavrou |
CRITIS | 3 |
| 2025 | Joining the Dots Between Cybersecurity Career Roles, Skills and Knowledge
Eliana Stavrou, Steven Furnell |
CRITIS | 1 |
| 2025 | A Multi-dimensional Cyber Range-Powered Scoring Framework for Evaluating Cyber Resilience of Critical Infrastructures
Savvas Theodoulou, Eliana Stavrou, Adamantini Peratikou, Stavros Stavrou |
CRITIS | 2 |
| 2025 | Balancing Generative AI and Critical Thinking to Develop Written Communication Skills in CybersecurityabstractAs cybersecurity education continues to evolve, the need for curricula that effectively balance the capabilities of generative Artificial Intelligence (AI) tools with the development of critical thinking and active learning skills has become increasingly urgent. This study addresses this challenge by proposing a curriculum for postgraduate cybersecurity education that focuses on developing transferable skills, particularly critical thinking and written communication. These skills are essential for cybersecurity professionals to excel in both their technical and communicationoriented responsibilities, meeting the growing demand of the cybersecurity industry in the age of AI. The proposed curriculum emphasizes the integration of constructivist learning principles and Bloom's taxonomy, two widely applied pedagogical models, to enhance learners' critical thinking and written communication skills. Designed for a penetration testing module, the curriculum follows a structured, step-by-step approach to build the necessary competences and empower aspiring cybersecurity professionals to meet the expectations of the cybersecurity industry. Through targeted activities, learners develop foundational knowledge while refining advanced written communication skills, equipping them to produce professional-level documentation, such as penetration testing reports. Generative AI is incorporated in the curriculum, providing opportunities for learners to experiment with AIgenerated content while fostering the cognitive skills needed to critically assess its accuracy, relevance, and alignment with professional standards. This study contributes to cybersecurity education by presenting a replicable curriculum model that equips learners with vital skills, preparing them to navigate the complexities of written communication responsibilities in cybersecurity roles and adapt to the evolving demands of the AI era. Apostolos Charalambous, Andriani Piki, Joakim Kävrestad, Eliana Stavrou |
EDUCON | 4 |
| 2025 | Towards the Design of Cyber Range Training Programs for Enhanced Preparedness: Investigating the Training Needs in Critical InfrastructuresabstractThe rising complexity of cyber threats demands tailored cybersecurity training, especially for critical infrastructure sectors such as healthcare, energy, telecommunications, and maritime. This paper examines the training needs of professionals in these domains, emphasizing the importance of customized Training Programmes that address sector-specific challenges and workforce diversity. For this study, two tailored questionnaires were developed to address the distinct needs and perspectives of IT and non-IT personnel. This distinction was crucial to capture the diverse challenges and priorities faced by these groups, ensuring a more holistic understanding of organizational training requirements. By incorporating these diverse perspectives, the study aims to bridge critical gaps in training and awareness, enabling organizations to design more inclusive and impactful cybersecurity programs. The findings guide the development of effective Cyber Range training initiatives, providing actionable recommendations to enhance cybersecurity preparedness in critical infrastructures. These include strategies for building competences that contribute to the protection of sector-related supply chains, promoting the reusability of Cyber Range training scenarios to improve resource efficiency, and tailoring scenarios to sector-specific challenges for greater relevance. All efforts should focus on building a cyber resilient ecosystem for critical infrastructures to address the current and future cyber threat landscape. The study was performed in the context of SecAwarenessTruss project, that emphasizes the role of Cyber Ranges in delivering hands-on, realistic training to enhance organizational resilience. Evangelos Floros, Eliana Stavrou, Michail Smyrlis, Nikolaos Nikoloudakis, Georgios Potamos, Athanasios Apostolidis, Panagiotis Bempis, Athanasios Grigoriadis, Konstantinos Magkos, Dimitris Merkouris, Georgios Spanoudakis, Stavros Stavrou, Stelios Trikos, Stelios E. Papadakis |
EDUCON | 2 |
| 2025 | What's in a Name? How Cyber Security Masters Degrees CompareabstractCyber security is now a prominent topic in university education, forming the focus of dedicated degrees at both undergraduate and postgraduate levels. However, the way it is perceived and understood by students can vary significantly, depending upon how the university concerned has elected to present their program. While many degrees (particularly at Masters level) can be found that address specialized aspects of cyber security, there are also many programs that are presented as offering general coverage and are titled accordingly. However, the actual topic coverage offered within these degrees has the potential to vary considerably, meaning that students may get a very different perspective on cyber security depending upon their choice of program. Building upon earlier phases of investigation, this paper examines the topic coverage and consistency of a series of Masters degrees in cyber security, drawing upon a sample of ten from the UK (which had been the focus of the earlier work) and a further ten from a series of European countries. Each program was assessed in terms of the technical and non-technical cyber security topics being covered, and the proportion of credits afforded to these in the degree overall. While all twenty programs shared the same title, the findings revealed significant variation between them in terms of the topics receiving coverage. Additionally, it was apparent that some topics were more likely to receive attention than others, with a general skew towards addressing technical themes such as digital forensics and security testing, while significant non-technical themes such as security awareness and business continuity are often overlooked in comparison. The paper discusses these findings, including the implications of having degrees that are offered as general Masters in cyber security but with imbalanced coverage of key topics, and how the resulting graduate qualifications are likely to align with industry needs. Finally, consideration is directed towards the potential for establishing unified frameworks for cyber security syllabi and assessment of coverage. Eliana Stavrou, Steven Furnell |
EDUCON | 1 |
| 2024 | Assessing the Consistency of Cyber Security EducationabstractCyber security is now a well-established topic in higher education contexts internationally. However, while numerous qualifications are available at undergraduate and postgraduate levels, it can be challenging for prospective students and employers to understand the topic coverage that sits under the degree title (and what aspects of cyber security a graduate will have been exposed to as a result). Following an initial illustration of how even the term ‘cyber security’ itself has varying interpretations, this paper evidences the challenge through an examination of the content of ten postgraduate degree programmes. All are titled ‘MSc Cyber Security’ and thus all are ostensibly addressing the same topic. However, a syllabus-level assessment reveals considerable differences in the programme composition (in terms of cyber and non-cyber topic coverage, and the technical and non-technical split within the cyber material). The technical content of the candidate programmes is compared in order to further demonstrate the difference in both the topic emphasis and the resulting student experience. The discussion then proceeds to consider how the actual content of programmes can be communicated and compared in a more informative manner, using mock-ups based on the earlier metrics to illustrate potential approaches. Steven Furnell, Eliana Stavrou |
EDUCON | 2 |
| 2024 | Empowering Professionals: A Generative AI Approach to Personalized Cybersecurity LearningabstractWe are navigating an era of ongoing technological transformations characterized by a growing need for developing digital skills, including cybersecurity and Artificial Intelligence (AI) literacy. The skills gap in cybersecurity has been acknowledged by the academic and business community at large, which faces an ongoing challenge in terms of finding and attaining talents. Even though different initiatives have been launched to upskill and reskill individuals, they are either ineffective in developing the required competencies or fail to motivate participants to learn and advance their competencies in relation to a cybersecurity job role. A key factor hindering these efforts is the adoption of a generic training approach rather than tailoring learning to the needs of individual learners. It is imperative to identify novel ways to motivate and engage learners, fostering a lifelong learning mindset that is essential for cybersecurity professional development and progression. This work aims to investigate how generative AI can be leveraged to empower professionals to take ownership of their learning by assisting them to create a personalized cybersecurity study plan. The objective is to inspire the design of innovative solutions focusing on accelerating skills development and contributing to increasing the supply of skilled cybersecurity professionals. Christos Kallonas, Andriani Piki, Eliana Stavrou |
EDUCON | 3 |
| 2024 | Merging Policy and Practice: Crafting Effective Social Engineering Awareness-Raising PoliciesabstractCybersecurity policies play a fundamental role in fostering organizational cyber governance and cyber resilience. Cybersecurity awareness-raising and training policies specify upskilling requirements and explicitly address persistent threats such as social engineering attacks. While cybersecurity awareness-raising and training activities complement the objectives of security policies, challenges including stakeholder diversity, budget constraints, generic messaging and low user engagement hinder their effectiveness. For successful policy adoption it is crucial for the workforce to grasp the relevance of these policies within their work context, understand how social engineering attacks are deployed, and apply policy rules appropriately. However, existing awareness-raising and training policies often lack specificity, leading to gaps in employee engagement and behavioural change, especially regarding social engineering threats. To address these issues, the paper proposes a dedicated social engineering awareness-raising policy, guided by Merrill's Principles of Instructions. This work aims to merge policy and practice, offering tailored examples of social engineering attacks, explicitly connecting them to relevant cybersecurity policies and making the content more engaging and relevant to the workforce. This is envisioned as a cost-effective resource for organizations with a limited training budget, which can be utilized as a starting point to enhance employee awareness, engagement, and foster a stronger organizational cyber resilience culture. Eliana Stavrou, Andriani Piki, Panayiotis Varnava |
ICISSP | 1 |
| 2024 | Cultivating self-efficacy to empower professionals' re-up skilling in cybersecurityabstractPurpose The accelerated digital transformation and the growing emphasis on privacy, safety and security present ongoing challenges for cybersecurity experts. Alongside these challenges, the multidisciplinary, everchanging and complex nature of the cybersecurity domain has further challenged the acquisition and retention of cybersecurity talent. Empowering reskilling and upskilling in cybersecurity necessitates efficacious educational endeavours which promote self-confidence and foster a growth mindset. The purpose of this paper is to highlight that cultivating self-efficacy in cybersecurity education can help promote competency development and effectively address the prominent skills gaps. This notion applies equally to both aspiring individuals pursuing a career in cybersecurity and professionals in the field who may wish to better articulate the skills they already possess, the skills they lack and newly surfacing skills that need to be developed. Design/methodology/approach The study discusses the imminent need for adopting a “skills-first” approach in cybersecurity and explores innovative pedagogies and professional frameworks that can inform and frame such an approach. Subsequently, a critical analysis of the importance of self-efficacy towards motivating and supporting upskilling in cybersecurity is performed. A case study is presented, expanding the authors’ previous work on cybersecurity professional development, to demonstrate the mediating role that self-efficacy can play in developing core cybersecurity competencies. The case study presents the design of a new cybersecurity curriculum in the context of postgraduate, synchronous distance cybersecurity education, and it is utilised as a basis to discuss how the proposed curriculum cultivates self-efficacy attitudes. Findings A skills-first approach is becoming the new norm in contemporary workplaces. This work highlights the importance of actively nurturing self-efficacy attitudes through innovative cybersecurity curricula that can be tailored to the learners’ needs, instigating a drive for learning and, ultimately, helping learners effectively upskilling by portraying a self-directed learning path and a professional growth mindset in cybersecurity. Originality/value The authors present the importance of cultivating self-efficacy in higher and lifelong education to foster reskilling and upskilling in cybersecurity. An innovative cybersecurity curriculum was constructed and delivered with a group of learners demonstrating how self-efficacy can be leveraged through interactive, reflective and self-assessment educational activities that enhanced motivation and self-awareness, curiosity, attention to detail and resilience – key skills for a successful career in cybersecurity. Eliana Stavrou, Andriani Piki |
Inf. Comput. Secur. | 1 |
| 2018 | A password generator tool to increase users' awareness on bad password construction strategiesabstractCybersecurity education and training activities are essential to empower end users to take informed decisions and address cyber threats. An ongoing problem that still troubles the cybersecurity community is the selection of weak passwords. Users keep using weak passwords, cultivating the risk of compromisation. Users often choose passwords that appear to be strong. This creates a false sense of security as users have the belief that their passwords cannot be guessed. Unfortunately, given that attackers are aware of the users' habits, they often recover users' passwords. Therefore, it is imperative to educate people about the bad password construction strategies and empower them to select stronger passwords. Educational activities should be enhanced by integrating practical aspects that will assist the users to realize the problem. This work identifies and combines a range of bad password construction strategies and designs a relevant tool to practically demonstrate the strategies to the users. Pieris Tsokkis, Eliana Stavrou |
ISNCC | 2 |
| 2018 | Global perspectives on cybersecurity educationabstractGlobal cybersecurity crises have compelled universities to address the demand for educated cybersecurity professionals. As no shared framework for cybersecurity as an academic discipline exists, growthhas been unfocused and driven by training materials, which make it harder to create a common body of knowledge. An international perspective is still harder, as different nations use different criteria to define local needs. As a result, new programs entering this space are on their own to conceptualize, design, package and market their programs, as there is no globally accepted reference model for cybersecurity to allow employers or students to understand the extent of a given cybersecurity program. Allen S. Parrish, John Impagliazzo, Rajendra K. Raj, Henrique M. Dinis Santos, Muhammad Rizwan Asghar, Audun Jøsang, Teresa Susana Mendes Pereira, Vítor J. Sá, Eliana Stavrou |
ITiCSE | 9 |
| 2014 | Recovering from the selective forwarding attack in WSNs - enhancing the recovery benefits of blacklisting and rerouting using directional antennasabstractWireless sensor networks (WSNs) face a number of security challenges that can compromise their operation. A typical security attack that can be launched by an adversary, in order to affect the network's communication, is the selective forwarding attack. If compromisation occurs, it is essential to recover the network to a stable state. In the context of mission-critical WSNs the challenge is not just to recover from compromisation but it is vital to restore an enhanced network operation in order to support a reliable decision-making. Sensor nodes usually address the selective forwarding attack by deploying blacklisting and rerouting. These countermeasures have been proposed in the context of omni-directional networks. This research work investigates the utilization of directional antennas in WSNs in order to increase the recovery benefits gained by the blacklisting and rerouting countermeasures in terms of reliability, survivability and responsiveness, attributes that are vital for the operation of mission-critical applications. Eliana Stavrou, Andreas Pitsillides |
IWCMC | 1 |
| 2012 | Security evaluation methodology for intrusion recovery protocols in wireless sensor networksabstractResearchers have designed intrusion recovery protocols in Wireless Sensor Networks (WSN) with the aim of restoring compromised services and promoting a secure and reliable environment in WSNs. Currently, evaluation frameworks in WSNs have been proposed in a generic security context and do not constitute a representative assessment of intrusion recovery protocols. This paper proposes an evaluation methodology to aid the evaluation and comparison of intrusion recovery protocols in WSNs. The methodology defines the intrusion recovery protocol aspects that should be evaluated using a number of evaluation criteria and guides researchers in identifying the evaluation direction they should follow. Eliana Stavrou, Andreas Pitsillides |
MSWiM | 1 |
| 2011 | Vulnerability assessment of intrusion recovery countermeasures in wireless sensor networksabstractWireless sensor networks (WSNs) have become a hot research topic in recent years and are considered to be one of the building blocks of pervasive computing. Many diverse, mission-critical applications are deployed, including military, rescue, healthcare, factory floor, and smart homes. Security is a fundamental requirement in such sensitive applications in order to ensure their reliable and stable operation. However, security is a fairly difficult task to achieve. The open nature of the wireless communication, the unrestricted deployment and limitations of WSNs and the existence of a variety of attacks threaten the security of a sensor network. Currently, research efforts have mainly focused on developing prevention and intrusion detection mechanisms in WSNs. Intrusion recovery is also an important aspect of security provisioning that is not given the same attention. Researchers have proposed intrusion recovery protocols to restore the network's operation when an attack is detected. Their designs are mostly based on simplified threat models, making the intrusion recovery countermeasures vulnerable to advanced threat models. Although the network may recover its operation after an attack is detected, it does not mean that the threat is eliminated. For example, a persistent adversary can adapt his intrusion strategy to compromise the deployed recovery countermeasure. This research work evaluates the robustness and reliability of well-known recovery countermeasures in WSNs against persistent adversaries. Evaluation results have shown that existing intrusion recovery solutions are vulnerable and can be exploited under different attack strategies in order to compromise the applied recovery countermeasures, and thus the network. The vulnerability assessment is carried out using ns-2 simulations in an IEEE 802.15.4 network and within the AODV context. Observations derived from the assessment contribute towards future directions that can drive new designs of intrusion recovery protocols in WSNs. Eliana Stavrou, Andreas Pitsillides |
ISCC | 1 |
| 2010 | Security in Future Mobile Sensor Networks - Issues and Challenges
Eliana Stavrou, Andreas Pitsillides, George C. Hadjichristofi, Christoforos N. Hadjicostis |
SECRYPT | 1 |
| 2010 | A survey on secure multipath routing protocols in WSNs
Eliana Stavrou, Andreas Pitsillides |
Comput. Networks | 1 |