VLDB 2026 Research / reviewers in the wild / expert
Christos Kalloniatis
dblp:90/6191
· DBLP profile ↗
35ranked-venue papers
5as first author
4since 2021 · last 2024
0000-0002-8844-2596ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 6 · 2 first-authorArtificial intelligence and machine learning · 3Applied, interdisciplinary, general and emerging computing · 3Systems, architecture and hardware · 1Computer networks · 1Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Create, Read, Update, Delete: Implications on Security and Privacy Principles regarding GDPRabstractCreate, Read, Update and Delete operations (CRUD) are a well-established abstraction to model data access in software systems of different architectures. Most system requirements, generated during the specification phase, will be realized by combining these operations on different entities of the system under development. The majority of these requirements will be business operations and objectives. Security requirements come on top of business requirements in a mostly network-connected world and risk the existence of a software system as a business. Through the enforcement of privacy laws, modern systems must also legally comply with privacy requirements or face the possibility of high fines. While there is a great interest in methodologies to elicit security and privacy requirements, little has been done to practically apply those requirements during the software development phase. This paper investigates the implication of those four basic operations regarding security and privacy principles as they are implied by the law. Analysis findings aim to raise awareness among developers about privacy when implementing high-level business requirements, and result in a bottom-up compliance procedure regarding privacy and the GDPR by proposing a systematic approach in this direction. Michail Pantelelis, Christos Kalloniatis |
ARES | 2 |
| 2024 | A Unified Framework for GDPR Compliance in Cloud ComputingabstractIn parallel with the rapid development of Information and Communication technologies and the digitization of information in every aspect of daily life, the enforcement of the GDPR, in May 2018, brought significant changes to the processes that organisations should follow during collecting, processing, and storing personal data and revealed the immediate need for integrating the Regulation’s requirements for integrating into organisational activities that process personal and sensitive data. On the other hand, cloud computing is a cutting-edge technology that is widely used in order to support most, if not every, organisational activities. As a result, such infrastructure constitutes huge pools of personal data and, in this context, a careful consideration and implementation of the rules imposed by the Regulation is considered crucial. In this paper, after highlighting the need to consider the GDPR requirements when designing cloud-based systems, we determined those GDPR compliance controls that should be incorporated at the early stages of the system design process. As a next step, those compliance controls were integrated into a holistic framework that considers both the security and privacy aspects of a cloud-based system as well as the requirements arising from the Regulation during the design of such systems. Argyri Pattakou, Vasiliki Diamantopoulou, Christos Kalloniatis, Stefanos Gritzalis |
ARES | 3 |
| 2024 | Enhancing TrUStAPIS Methodology in the Web of Things with LLM-Generated IoT Trust Semantics
Davide Ferraris, Konstantinos Kotis, Christos Kalloniatis |
ICICS (1) | 3 |
| 2022 | Understanding the role of users' socio-location attributes and their privacy implications on social mediaabstractPurpose The purpose of this paper is to establish reciprocity among socio-location attributes while underlining the additional users’ privacy implications on social media (SM). Design/methodology/approach Digital identity theories, social software engineering theory and the Privacy Safeguard (PriS) methodology were considered while reviewing 32 papers for identifying users’ SM attributes. After proposing interrelations among socio-location attributes, the PriS method was used to match social aspects of privacy in designing case studies to illustrate the associations through potential users’ privacy implications. Findings Eighteen users’ SM attributes were collected and correlated to the Face, Frame, Activity, Time and Stage (FFrATS) 4 W (socio-location attributes), which provoke further privacy implications due to the notions of self-determination and self-disclosure on SM. The authors draw on the PriS methodology to address privacy’s multidimensionality while creating case studies to examine privacy issues arising due to socio-location attribute disclosure and users’ trajectories and normativity lines. Research limitations/implications Supplementary case studies and research are needed to enable the design of a socio-spatially and privacy-aware designing methodology. Practical implications Designing proper methodologies and techniques to address users’ privacy implications deriving from socio-location attributes can provide designers with a technical solution to SM platforms. Social implications Socio-location attribute disclosure constructs representative SM profiles; however, the revelation of attributes and their interrelations create additional privacy implications for SM users. Originality/value Deepening the understanding of disclosing socio-location attributes on SM while bridging the socio-technical gap will provide the necessary background for proposing technical solutions to protecting users’ privacy. Katerina Vgena, Angeliki Kitsiou, Christos Kalloniatis |
Inf. Comput. Secur. | 3 |
| 2020 | Measuring Users' Socio-contextual Attributes for Self-adaptive Privacy Within Cloud-Computing Environments
Angeliki Kitsiou, Eleni Tzortzaki, Christos Kalloniatis, Stefanos Gritzalis |
TrustBus | 3 |
| 2019 | The Interrelation of Game Elements and Privacy Requirements for the Design of a System: A Metamodel
Aikaterini-Georgia Mavroeidi, Angeliki Kitsiou, Christos Kalloniatis |
TrustBus | 3 |
| 2019 | Do Identity and Location Data Interrelate? New Affiliations and Privacy Concerns in Social-Driven Sharing
Katerina Vgena, Angeliki Kitsiou, Christos Kalloniatis, Dimitris Kavroudakis |
TrustBus | 3 |
| 2019 | A framework for designing cloud forensic-enabled services (CFeS)
Stavros Simou, Christos Kalloniatis, Stefanos Gritzalis, Vasilios Katos |
Requir. Eng. | 2 |
| 2018 | Modeling Data Center Temperature Profile in Terms of a First Order Polynomial RBF Network Trained by Particle Swarm Optimization
Ioannis A. Troumbis, George E. Tsekouras, Christos Kalloniatis, Panagiotis Papachiou, Dias Haralambopoulos |
ICANN (2) | 3 |
| 2018 | A Decision-Making Approach for Improving Organizations' Cloud Forensic Readiness
Stavros Simou, Ioannis Troumpis, Christos Kalloniatis, Dimitris Kavroudakis, Stefanos Gritzalis |
TrustBus | 3 |
| 2018 | Towards a Security Assurance Framework for Connected VehiclesabstractSecurity assurance is defined as the degree of confidence that the security requirements of an IT system are satisfied. In view of the emerging paradigm of connected vehicles i.e., dynamic Cyber-Physical systems of highly-equipped infrastructure-connected vehicles, specifying the involved assurance becomes highly-critical yet challenging; vehicles increasingly exploit various communication means to exchange rich data of relevance with the infrastructure resulting in a large attack surface. Both the complexity and uncertainty are increased rendering the so-far generic methods for security assurance costly-to-apply. In this position paper we introduce a security assurance framework tailored for connected vehicles, as explored by the EU-funded H2020 SAFERtec project. We put under the microscope two instances of vehicle-to-infrastructure communications and relying on an innovative modeling methodology we identify the involved security and privacy requirements. We then present the way to enhance the processes of the credible yet generic Common Criteria approach to gain evidence that the above requirements are met. The experimental evaluation of the framework is carried-out over a reference implementation of a prototype vehicle connected to road-side units and cloud-based services. The expectations are that our work assists to effectively construct assurance arguments increasing trust in connected vehicles. Panagiotis Pantazopoulos, Sammy Haddad, Costas Lambrinoudakis, Christos Kalloniatis, Konstantinos Maliatsos, Athanasios G. Kanatas, András Varádi, Matthieu Gay, Angelos Amditis |
WOWMOM | 4 |
| 2018 | Assurance of Security and Privacy Requirements for Cloud Deployment ModelsabstractDespite of the several benefits of migrating enterprise critical assets to the cloud, there are challenges specifically related to security and privacy. It is important that cloud users understand their security and privacy needs, based on their specific context and select cloud model best fit to support these needs. The literature provides works that focus on discussing security and privacy issues for cloud systems but such works do not provide a detailed methodological approach to elicit security and privacy requirements neither methods to select cloud deployment models based on satisfaction of these requirements by cloud service providers. This work advances the current state of the art towards this direction. In particular, we consider requirements engineering concepts to elicit and analyze security and privacy requirements and their associated mechanisms using a conceptual framework and a systematic process. The work introduces assurance as evidence for satisfying the security and privacy requirements in terms of completeness and reportable of security incident through audit. This allows perspective cloud users to define their assurance requirements so that appropriate cloud models can be selected for a given context. To demonstrate our work, we present results from a real case study based on the Greek National Gazette. Shareeful Islam, Moussa Ouedraogo, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
IEEE Trans. Cloud Comput. | 3 |
| 2018 | Interpretability Constraints for Fuzzy Modeling Implemented by Constrained Particle Swarm OptimizationabstractIn this paper certain interpretability criteria are taken into account in order to extract a set of linear inequality constraints for enhancing the fuzzy model interpretability. Among others, the criteria of model distinguishability, completeness, compactness, and fuzzy set sharing between rules are considered. To support distinguishability, the distances between fuzzy set centers are lower bounded and the widths are manipulated as to control the overlap between fuzzy sets. Sufficient conditions are given to satisfy the completeness criterion, whereas the compactness requirement is addressed by comparing models with different number of rules. Finally, fuzzy set sharing between rules is achieved through a model optimization procedure that involves fuzzy set merging. It turns out that the feasible region is a compact and convex set. The tradeoff between interpretability and accuracy is established by minimizing the model's square error over the feasible region through constrained particle swarm optimization. The method is tested using a number of high-dimensional datasets and conducting two kinds of experiments. The first focuses on interpretability. The second studies the accuracy by comparing the method to other algorithms that perform unconstrained optimization, using nonparametric statistics. George E. Tsekouras, John V. Tsimikas, Christos Kalloniatis, Stefanos Gritzalis |
IEEE Trans. Fuzzy Syst. | 3 |
| 2017 | Supporting the design of privacy-aware business processes via privacy process patternsabstractPrivacy is an increasingly important concern for modern software systems which handle personal and sensitive user information. Privacy by design has been established in order to highlight the path to be followed during a system's design phase ensuring the appropriate level of privacy for the information it handles. Nonetheless, transitioning between privacy concerns identified early during the system's design phase, and privacy implementing technologies to satisfy such concerns at the later development stages, remains a challenge. In order to overcome this issue, mainly caused by the lack of privacy-related expertise of software systems engineers, this work proposes a series of privacy process patterns. The proposed patterns encapsulate expert knowledge and provide predefined solutions for the satisfaction of different types of privacy concerns. The patterns presented in this work are used as a component of an existing privacy-aware system design methodology, through which they are applied to a real life system. Vasiliki Diamantopoulou, Nikolaos Argyropoulos, Christos Kalloniatis, Stefanos Gritzalis |
RCIS | 3 |
| 2017 | Supporting Privacy by Design Using Privacy Process Patterns
Vasiliki Diamantopoulou, Christos Kalloniatis, Stefanos Gritzalis, Haralambos Mouratidis |
SEC | 2 |
| 2017 | Modelling Cloud Forensic-Enabled Services
Stavros Simou, Christos Kalloniatis, Stefanos Gritzalis |
TrustBus | 2 |
| 2017 | Incorporating privacy in the design of cloud-based systems: a conceptual meta-modelabstractPurpose The purpose of this paper is to extend PriS (privacy safeguard), a privacy requirements engineering method for eliciting and modelling privacy requirements during system design, with the addition of privacy-aware cloud-based concepts to assist analysts to reason and model about privacy in cloud environments. Design/methodology/approach An analysis of previous findings on the file of cloud privacy based on previous work has been conducted and a set of privacy-related concepts that need to be considered during privacy analysis for cloud-based systems have been revealed. These concepts were used for extending the conceptual model of PriS. Findings The main finding of the paper is the design of a new, novel conceptual model that assists analysts and designers in reasoning about privacy in cloud environments. A new template using the JSON (Javascript notation object) format has been introduced for better expressing the privacy requirements along with the related concepts presented through the conceptual model, thus letting the developers to better understand the findings during the design stage and better guide them to the implementation of the respective solution. Research limitations/implications The design of a cloud-based process that will guide analysts in detail for eliciting and modelling the identified privacy-related requirements is the limitation and in parallel the next step of the specific work presented here. Practical implications The conceptual model has been applied on a real case scenario regarding its efficiency on capturing and mapping all necessary concepts for assisting analysts proceed with the design of the privacy-aware system. The results were positive, all concepts were easy to use and totally understandable from the design team and the stakeholders and the use of the JSON template received very positive comments, especially from the developer’s team. Originality/value The paper presents a novel conceptual model for reasoning about privacy requirements in the cloud. The applicability of the proposed model has also been tested on a real case study. Christos Kalloniatis |
Inf. Comput. Secur. | 1 |
| 2016 | Incorporating privacy patterns into semi-automatic business process derivationabstractThe design of systems capable of protecting users' privacy is a challenging endeavour. Since users are becoming more concerned about the amounts of their personal data handled, stored and shared by such systems it is imperative to identify methods for developing privacy-aware information systems. Current approaches either focus on the elicitation of user requirements at an abstract high level or approach the issue of privacy exclusively from a technical point of view. As a result, privacy implementations are often misaligned with the overarching system goals. This work improves the current situation by presenting an approach for the design of privacy-aware business processes. Goal models are created as a first step, for privacy requirements elicitation, and are then transformed into process models, thus bridging the gap between high level goals and low level processes. Privacy process patterns are utilised for the final instantiation of process models, achieving the satisfaction of the identified privacy objectives through the integration of privacy enhancing technologies. The main advantage of the proposed approach is its ability to map privacy from the strategic to the operational level through a semi-automatic process while offering designers adequate guidance to its operationalisation via the use of process patterns. Nikolaos Argyropoulos, Christos Kalloniatis, Haralambos Mouratidis, Andrew Fish |
RCIS | 2 |
| 2016 | Modelling Secure Cloud Computing Systems from a Security Requirements Perspective
Shaun Shei, Christos Kalloniatis, Haralambos Mouratidis, Aidan J. Delaney |
TrustBus | 2 |
| 2016 | Towards a Model-Based Framework for Forensic-Enabled Cloud Information Systems
Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
TrustBus | 2 |
| 2016 | A survey on cloud forensics challenges and solutionsabstractAbstract In recent years, cloud computing has gained popularity, and it is now used to support various areas of human life. Cloud forensics has been introduced to help forensic investigators find potential evidence against cloud criminal activities and maintain the security and integrity of the information stored in the cloud. While great research in the area has been carried out concerning challenges and solutions, the research on methodologies and frameworks is still in its infancy. This article focuses on the methodological aspects of cloud forensics. It critically reviews cloud forensics' existing challenges and solutions, and it explores, based on a detailed review of the area, all the work that has been carried out both in digital and cloud forensic methodologies mainly for supporting the investigation of security incidents in cloud. Furthermore, the detailed comparison reveals similarities and drawbacks of the existing methodologies providing some novel future research directions. Finally, the specific paper can be considered as a starting point for researchers wishing to design cloud‐forensicable services over the cloud. Copyright © 2016 John Wiley & Sons, Ltd. Stavros Simou, Christos Kalloniatis, Stefanos Gritzalis, Haralambos Mouratidis |
Secur. Commun. Networks | 2 |
| 2015 | Addressing Privacy and Trust Issues in Cultural Heritage Modelling
Michalis Pavlidis, Haralambos Mouratidis, Cesar Gonzalez-Perez, Christos Kalloniatis |
CRiSIS | 4 |
| 2015 | A Meta-model for Assisting a Cloud Forensics Process
Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
CRiSIS | 2 |
| 2015 | Designing Privacy-Aware Systems in the Cloud
Christos Kalloniatis |
TrustBus | 1 |
| 2015 | Privacy as an Integral Part of the Implementation of Cloud SolutionsabstractBridging the gap between design and implementation stages has been a major concern of designers, analysts and developers of information systems (ISs) and a major aspiration of a number of IS engineering approaches. Cloud computing exacerbates the strain on traditional IS engineering approaches that service-oriented computing has started. At the same time, recent research has argued about the importance of security and privacy in a cloud environment and highlighted a number of security and privacy challenges that are not present in traditional environments and need special attention when implementing or migrating ISs into a cloud environment. This paper contributes to this direction. Specifically, it presents a number of privacy-related cloud properties that analysts need to consider when designing privacy-aware systems in a cloud environment. Also it indicates a number of implementation techniques that can assist developers in assuring the respective properties. Evangelia Kavakli, Christos Kalloniatis, Haralambos Mouratidis, Stefanos Gritzalis |
Comput. J. | 2 |
| 2014 | Cloud Forensics: Identifying the Major Issues and Challenges
Stavros Simou, Christos Kalloniatis, Evangelia Kavakli, Stefanos Gritzalis |
CAiSE | 2 |
| 2014 | Privacy-Aware Cloud Deployment Scenario Selection
Kristian Beckers, Stephan Faßbender, Stefanos Gritzalis, Maritta Heisel, Christos Kalloniatis, Rene Meis |
TrustBus | 5 |
| 2013 | Trustworthy Selection of Cloud Providers Based on Security and Privacy Requirements: Justifying Trust Assumptions
Michalis Pavlidis, Haralambos Mouratidis, Christos Kalloniatis, Shareeful Islam, Stefanos Gritzalis |
TrustBus | 3 |
| 2013 | A framework to support selection of cloud providers based on security and privacy requirements
Haralambos Mouratidis, Shareeful Islam, Christos Kalloniatis, Stefanos Gritzalis |
J. Syst. Softw. | 3 |
| 2013 | Evaluating cloud deployment scenarios based on security and privacy requirements
Christos Kalloniatis, Haralambos Mouratidis, Shareeful Islam |
Requir. Eng. | 1 |
| 2011 | The "Panopticon" of search engines: the response of the European data protection framework
Eleni Kosta, Christos Kalloniatis, Lilian Mitrou, Evangelia Kavakli |
Requir. Eng. | 2 |
| 2009 | Search Engines: Gateway to a New "Panopticon"?
Eleni Kosta, Christos Kalloniatis, Lilian Mitrou, Evangelia Kavakli |
TrustBus | 2 |
| 2008 | Addressing privacy requirements in system design: the PriS method
Christos Kalloniatis, Evangelia Kavakli, Stefanos Gritzalis |
Requir. Eng. | 1 |
| 2007 | Using Privacy Process Patterns for Incorporating Privacy Requirements into the System Design ProcessabstractIn the online world every person has to hold a number of different data sets so as to be able to have access to various e-services and take part in specific economical and social transactions. Such data sets require special consideration since they may convey personal data, sensitive personal data, employee data, credit card data etc. Recent surveys have shown that people feel that their privacy is at risk from identity theft and erosion of individual rights. The result is that privacy violation is becoming an increasingly critical issue in modern societies. To this end, PriS, a new security requirements engineering methodology, has been introduced aiming to incorporate privacy requirements early in the system development process. In this paper, we extend the PriS conceptual framework by introducing privacy process patterns as a way for describing the effect of privacy requirements on business processes. In addition, privacy process patterns facilitate the identification of the system architecture that best supports the privacy-related business processes, thus providing a holistic approach from business goals to `privacy-compliant' IT systems Christos Kalloniatis, Evangelia Kavakli, Stefanos Gritzalis |
ARES | 1 |
| 2005 | A Fuzzy Logic-Based Approach for Detecting Shifting Patterns in Cross-Cultural Data
George E. Tsekouras, Dimitris Papageorgiou, Sotiris B. Kotsiantis, Christos Kalloniatis, Panayiotis E. Pintelas |
IEA/AIE | 4 |