EDBT 2026 Demo / reviewers in the wild / expert
Leandros Maglaras
dblp:06/7838 · also Leandros A. Maglaras
· DBLP profile ↗
46ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0001-5360-9782ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 1 first-author · 5 since 2021Computer networks · 16 · 2 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Iot Architecture for Enhancing Safety in Supply Chain SystemsabstractABSTRACT Supply chain processes are essential for managing the distribution of goods from suppliers to consumers. In light of the globalization of the economy, the distances involved in delivery have significantly increased, often spanning thousands of kilometers across various countries and continents, utilizing multiple modes of transportation, including land, maritime, and air. The primary objective of the supply chain process is to ensure the quality and safety of goods during transit, thereby mitigating the risks of damage, deterioration, and spoilage. This requires real‐time monitoring of various environmental conditions, such as temperature and humidity, to which goods are subjected. This paper tackles the critical challenge of monitoring real‐time conditions in goods transportation by innovatively designing and implementing an Internet of Things (IoT) system, together with a set of customized evaluation metrics. Unlike conventional approaches, our work introduces a practical and scalable prototype that takes advantage of readily available low‐cost technologies: temperature and light sensors integrated with a Raspberry Pi. This device continuously collects and transmits environmental data to a database server. Metrics will be defined to evaluate the quality of the goods. In addition, a dedicated web application will be developed that enables the complete analysis and visualization of the collected data. By establishing a quantifiable framework and providing a cost‐effective end‐to‐end monitoring solution, our study fills a significant gap in the current cold chain logistics landscape. Wen Zeng 0002, Nicholas Kit Lam Wan, Vasileios Germanos, Leandros Maglaras, Carlos Molina-Jiménez |
Concurr. Comput. Pract. Exp. | 5 |
| 2025 | JamShield: A Machine Learning Detection System for Over-the-Air Jamming AttacksabstractWireless networks are vulnerable to jamming attacks due to the shared communication medium, which can severely degrade performance and disrupt services. Despite extensive research, current jamming detection methods often rely on simulated data or proprietary over-the-air datasets with limited cross-layer features, failing to accurately represent the real state of a network and thus limiting their effectiveness in real-world scenarios. To address these challenges, we introduce JamShield, a dynamic jamming detection system trained on our own collected over-the-air and publicly available dataset. It utilizes hybrid feature selection to prioritize relevant features for accurate and efficient detection. Additionally, it includes an autoclassification module that dynamically adjusts the classification algorithm in real-time based on current network conditions. Our experimental results demonstrate significant improvements in detection rate, precision, and recall, along with reduced false alarms and misdetections compared to state-of-the-art detection algorithms, making JamShield a robust and reliable solution for detecting jamming attacks in real-world wireless networks. Ioannis Panitsas, Yagmur Yigit, Leandros Tassiulas, Leandros Maglaras, Berk Canberk |
ICC | 4 |
| 2025 | Digital Twin-Enabled Lightweight Attack Detection for Software-Defined Edge NetworksabstractWith the development of software-defined edge networks, network management has become more flexible and realtime. However, this advancement has also led to critical security concerns, especially when detecting attacks efficiently in resourceconstraint environments. Existing solutions often suffer from high computational load, making them unsuitable for the fast, dynamic environments of resource-constrained edge environments. To tackle this issue, we introduce a lightweight attack detection system that combines digital twins with advanced machine learning techniques. Our approach uses a stacked sparse autoencoder (ssAE) for feature extraction and reduction and a hybrid CNNGRU model for accurate attack classification. The simulation results show that our solution significantly outperforms existing models, which are ANOVA-DNN, AE-MLP and CNN-LSTM. It achieves the highest detection accuracy at$\mathbf{9 9. 7 2 \%}$and a suitable low time-cost at 0.215 ms, providing a good balance between accuracy and speed. Moreover, it delivers the lowest computational load compared to others, which makes it ideal for deployment in real-time resource-limited environments. Yagmur Yigit, Kerem Gursu, Ahmed Yassin Al-Dubai, Leandros Maglaras, Berk Canberk |
WCNC | 4 |
| 2025 | Post-Quantum ZKP for Privacy-Preserving Authentication and Model Verification in Decentralized CAVabstractDecentralized and Connected Autonomous Vehicle (CAV) networks offer promising advances in safety, efficiency, and real-time decision-making. However, they face significant challenges in authentication, privacy, and scalability—especially in the face of quantum adversaries. This paper proposes a novel post-quantum secure framework that integrates lattice-based Zero-Knowledge Proofs (ZKPs), optimized Binius proofs, and Multi-Layer Compressed Counting Bloom Filters (ML-CCBF) to enable privacy-preserving authentication and model verification in decentralized CAV environments. Our lattice-based ZKP scheme achieves cryptographic commitments in under 5μs, while Binius proofs verify model integrity in less than 0.17 seconds per update. ML-CCBF ensures scalable membership filtering with 0% false positives across 1000 nodes. Experimental results confirm 100% ZKP soundness, strong resilience against simulated quantum and adaptive attacks, and stable latency under increasing network load. These findings demonstrate that our framework delivers quantum-resilient security, real-time efficiency, and robust scalability, offering a viable solution for trustworthy decentralized intelligence in next-generation vehicular systems. Ny Hasina Andriambelo, Naghmeh Moradpoor Sheykhkanloo, Leandros Maglaras |
WoWMoM | 3 |
| 2025 | Enhancing Cybersecurity Training Efficacy: A Comprehensive Analysis of Gamified Learning, Behavioral Strategies and Digital TwinsabstractThis paper delves into enhancing cybersecurity training efficacy through an in-depth examination of gamified learning, behavioural strategies, and the deployment of digital twins. It identifies the critical role of behavioural strategies in bolstering cybersecurity defences by influencing human behaviour. The study explores the benefits of gamified learning in engaging participants and improving knowledge acquisition, alongside applying digital twins and cyber ranges in offering practical, hands-on experience. By analysing these methodologies, the paper aims to bridge the gap between theoretical knowledge and real-world application, encouraging the researchers to work on a forward-looking approach to cybersecurity training using these innovative methodologies that are both effective and engaging. Our findings suggest that by creating an immersive, interactive learning environment, it is possible to enhance the cybersecurity competencies of individuals, making them better prepared to navigate the complexities of the digital age. This paper contributes to cybersecurity training by offering insights using innovative approaches for effective training programs that are both engaging and informative, ultimately aiming to bolster organisations’ cybersecurity posture. Yagmur Yigit, Kitty Kioskli, Laura Bishop, Nestoras Chouliaras, Leandros Maglaras, Helge Janicke |
WoWMoM | 5 |
| 2025 | Black Hole Prediction in Backbone Networks: A Comprehensive and Type-Independent Forecasting ModelabstractNetwork backbone black holes(BH) pose significant challenges in the Internet by causing disruptions and data loss as routers silently drop packets without notification. These silent BH failures, stemming from issues like hardware malfunctions or misconfigurations, uniquely affect point-to-point packet flows without disrupting the entire network. Unlike cyber attacks and network intrusions, BHs are often untraceable, making early detection vital and challenging. This study addresses the need for an effective forecasting solution for BH occurrences, especially in environments with unlabeled traffic data where traditional anomaly detection methods fall short. The Type-Independent Black Hole Forecasting Model is introduced to predict BH occurrences with high precision across various anomalies, including contextual and collective anomaly types. The three-stage methodology processes unlabeled time-series network data, where the data is not pre-labeled as anomaly or normal, using machine learning and deep learning techniques to identify and forecast potential BH occurrences. The ’Point BH Identification and Segregation’ stage segregates point BH traffic using Density-Based Spatial Clustering of Applications with Noise(DBSCAN), followed by Reintegration and Time Series Smoothing. The final stage, Advanced Contextual and Collective BH Detection leverages Convolutional AutoEncoder(Conv-AE) with window sliding for advanced anomaly detection. Evaluation using a dual-dataset approach, including real backbone network traffic and a time-series adapted public dataset, demonstrates the adaptability of the model to real backbone BH detection systems. Experimental results show superior performance compared to state-of-the-art unsupervised anomaly forecasting models, with a 98% detection rate and 90% F-1 score, outperforming models like MultiHeadSelfAttention, which is the main building block of Transformers. Kiymet Kaya, Elif Ak, Eren Ozaltun, Leandros Maglaras, Trung Quang Duong, Berk Canberk, Sule Gündüz Ögüdücü |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | APOLLO: a proximity-oriented, low-layer orchestration algorithm for resources optimization in mist computing
Messaoud Babaghayou, Noureddine Chaib, Leandros Maglaras, Yagmur Yigit, Mohamed Amine Ferrag, Carol Marsh, Naghmeh Moradpoor Sheykhkanloo |
Wirel. Networks | 3 |
| 2024 | An IoT Architecture for Enhancing Safety in Supply Chain SystemsabstractSupply chain processes are used for controlling the delivery of goods from suppliers to consumers. With the globalization of the economy, delivery distances are on the increase and might involve thousands of kilometers across countries and even continents and different means of transport including land, water, and air transport. The task of the supply chain process is to guarantee the quality and safety of the goods at transportation time to prevent potential damage, deterioration, and decay. This requires real-time monitoring and observance of several conditions (e.g., temperature and humidity) to which the goods are exposed. To address the problem, this paper discusses the implementation of an IoT system and relevant metrics for monitoring, in real-time, the conditions that goods face during transportation. In the prototype that we have implemented, we use conventional low-cost cost widely available technologies, namely, temperature and light sensors connected to a Raspberry Pi device that sends the sensors' data to a database server. We then analyze the data with the help of a web application that we have also implemented. Wen Zeng 0002, Nicholas Kit Lam Wan, Vasileios Germanos, Leandros Maglaras, Carlos Molina-Jiménez |
ICIS | 5 |
| 2024 | A Blockchain-based Multi-Factor Honeytoken Dynamic Authentication MechanismabstractThe evolution of authentication mechanisms in ensuring secure access to systems has been crucial for mitigating vulnerabilities and enhancing system security. However, despite advancements in two-factor authentication (2FA) and multi-factor authentication (MFA), authentication mechanisms remain weak in system security, particularly when individuals accessing critical systems are involved. In response to this challenge, we propose a novel blockchain-based multi-factor dynamic authentication mechanism (BMFA) that integrates honeytoken technology to enhance security. Our proposed mechanism leverages Ethereum blockchain technology and smart contracts to provide a decentralized and robust authentication framework. By incorporating honeytokens into smart contracts, we introduce a dynamic layer of security that continuously adapts to prevent potential attacks. Our evaluation demonstrates that our BMFA mechanism effectively addresses various security challenges, including brute force attacks, man-in-the-middle attacks, and smart contract vulnerabilities, while providing robust protection against unauthorized access. Our findings emphasise the efficacy of the BMFA mechanism in enhancing system security and mitigating evolving threats in authentication processes for next-generation critical industrial control systems. Vassilis Papaspirou, Ioanna Kantzavelou, Yagmur Yigit, Leandros Maglaras, Sokratis K. Katsikas |
ARES | 4 |
| 2024 | Cyber-Twin: Digital Twin-Boosted Autonomous Attack Detection for Vehicular Ad-Hoc NetworksabstractThe rapid evolution of Vehicular Ad-hoc NETworks (VANETs) has ushered in a transformative era for intelligent transportation systems (ITS), significantly enhancing road safety and vehicular communication. However, the intricate and dynamic nature of VANETs presents formidable challenges, particularly in vehicle-to-infrastructure (V2I) communications. Roadside Units (RSUs), integral components of VANETs, are increasingly susceptible to cyberattacks, such as jamming and distributed denial of service (DDoS) attacks. These vulnerabilities pose grave risks to road safety, potentially leading to traffic congestion and vehicle malfunctions. Existing methods face difficulties in detecting dynamic attacks and integrating digital twin technology and artificial intelligence (AI) models to enhance VANET cybersecurity. Our study proposes a novel framework that combines digital twin technology with AI to enhance the security of RSUs in VANETs and address this gap. This framework enables real-time monitoring and efficient threat detection while also improving computational efficiency and reducing data transmission delay for increased energy efficiency and hardware durability. Our framework outperforms existing solutions in resource management and attack detection. It reduces RSU load and data transmission delay while achieving an optimal balance between resource consumption and high attack detection effectiveness. This highlights our commitment to secure and sustainable vehicular communication systems for smart cities. Yagmur Yigit, Ioannis Panitsas, Leandros Maglaras, Leandros Tassiulas, Berk Canberk |
ICC | 3 |
| 2024 | EV-IRP Manager: An Electric Vehicle Incident Response Playbook Manager and Visualizer ToolkitabstractIn the rapidly evolving realm of electric vehicle technology, safeguarding the cybersecurity of both electric vehicles and their charging infrastructure has become fundamental. The integration of electric vehicles and their charging stations into the broader grid introduces complex cybersecurity challenges, necessitating robust incident response strategies. Traditional cybersecurity playbooks often fall short in addressing the unique vulnerabilities associated with electric vehicles and their charging systems. The lack of publicly available community playbooks tailored to these needs leaves the electric vehicle ecosystem vulnerable to cyber threats that could compromise user privacy, vehicle functionality, and grid stability. In response to this, the project undertakes the creation of a foundational playbook for electric vehicle and electric vehicle charging station incident response, addressing a significant void in current cybersecurity practices. This paper introduces a Playbook Manager and Visualizer application, called EV-IRP, designed to enable users to upload, manage, and visualize electric vehicle and electric vehicle charging station incident response playbooks efficiently. Utilizing Python, Tkinter for GUI development, SQLite for database management, and Graphviz for visualization, the application facilitates a dynamic and responsive approach to maintaining up- to-date incident response strategies. The application is expected to streamline the management of incident response playbooks through procedure visualization, enhancing the cybersecurity posture of electric vehicle infrastructure. By converting textual playbook procedures into easily understandable diagrams, it facilitates a clearer understanding of response steps among users, thereby enhancing the overall efficiency and efficacy of incident response practices. Additionally, the research and development process, informed by a comprehensive literature review, contributes to the academic and practical understanding of cybersecurity best practices for electric vehicle technologies. Kerem Alpdag, Naghmeh Moradpoor Sheykhkanloo, Ny Hasina Andriambelo, Paul Wooderson, Leandros Maglaras |
SIN | 5 |
| 2024 | AI-Enhanced Digital Twin Framework for Cyber-Resilient 6G Internet of Vehicles NetworksabstractDigital twin technology is crucial to the development of the sixth-generation (6G) Internet of Vehicles (IoV) as it allows the monitoring and assessment of the dynamic and complicated vehicular environment. However, 6G IoV networks have critical challenges in network security and computational efficiency, which need to be addressed. Existing digital twin technologies in 6G IoV networks often suffer from limitations, such as reliance on static models and high computational demands, leading to unstable attack detection and inefficiencies. Their results for attack detection performance metrics, precision, detection rate, and F1-Score are insufficient for 6G IoV. Moreover, these systems concentrate all computational processes within the digital twin’s service layer, leading to inefficiencies. To address these challenges, we introduce a novel artificial intelligence (AI) enhanced digital twin framework designed to significantly improve 6G IoV network security and computational efficiency under dynamic conditions. Our framework employs an advanced feature engineering module that uses feature selection methods and stacked sparse autoencoders (ssAE) to reduce feature dimensions within the cyber twin layer, effectively distributing the overall computational load. It also utilizes an online learning module which enables a network-aware attack detection mechanism for precise attack detection. The proposed solution exhibits a stable performance of around 98% success rate regarding attack detection metrics against two data sets. Specifically, our solution reduces system latency by 12%, energy consumption by 15%, RAM usage by 20%, and improves packet delivery rates by 6.1%. These findings underscore the potential of our framework to enhance the robustness and responsiveness of 6G IoV systems, offering a significant contribution to vehicular network security and management. Yagmur Yigit, Leandros Maglaras, William J. Buchanan, Berk Canberk, Hyundong Shin, Trung Quang Duong |
IEEE Internet Things J. | 2 |
| 2023 | Scenario-based incident response training: lessons learnt from conducting an experiential learning virtual incident response tabletop exerciseabstractPurpose This paper aims to discuss the experiences designing and conducting an experiential learning virtual incident response tabletop exercise (VIRTTX) to review a business's security posture as it adapts to remote working because of the Coronavirus 2019 (COVID-19). The pandemic forced businesses to move operations from offices to remote working. Given that this happened quickly for many, some firms had little time to factor in appropriate cyber-hygiene and incident prevention measures, thereby exposing themselves to vulnerabilities such as phishing and other scams. Design/methodology/approach The exercise was designed and facilitated through Microsoft Teams. The approach used included a literature review and an experiential learning method that used scenario-based, active pedagogical strategies such as case studies, simulations, role-playing and discussion-focused techniques to develop and evaluate processes and procedures used in preventing, detecting, mitigating, responding and recovering from cyber incidents. Findings The exercise highlighted the value of using scenario-based exercises in cyber security training. It elaborated that scenario-based incident response (IR) exercises are beneficial because well-crafted and well-executed exercises raise cyber security awareness among managers and IT professionals. Such activities with integrated operational and decision-making components enable businesses to evaluate IR and disaster recovery (DR) procedures, including communication flows, to improve decision-making at strategic levels and enhance the technical skills of cyber security personnel. Practical implications It maintained that the primary implication for practice is that they enhance security awareness through practical experiential, hands-on exercises such as this VIRTTX. These exercises bring together staff from across a business to evaluate existing IR/DR processes to determine if they are fit for purpose, establish existing gaps and identify strategies to prevent future threats, including during challenging circumstances such as the COVID-19 outbreak. Furthermore, the use of TTXs or TTEs for scenario-based incident response exercises was extremely useful for cyber security practice because well-crafted and well-executed exercises have been found to serve as valuable and effective tools for raising cyber security awareness among senior leadership, managers and IT professionals (Ulmanová, 2020). Originality/value This paper underlines the importance of practical, scenario-based cyber-IR training and reports on the experience of conducting a virtual IR/DR tabletop exercise within a large organisation. Giddeon Njamngang Angafor, Iryna Yevseyeva, Leandros Maglaras |
Inf. Comput. Secur. | 3 |
| 2022 | Re-configuration from the Edge: alternative Software Models for time-sensitive IoT ApplicationsabstractIn this paper we examine traditional and novel software models for critical IoT applications. We propose a hybrid cellular IoT model that offers optimizations with respect to automated network management, re-configuration and optimized performance. This hybrid model utilizes the fog/edge computing model and can satisfy better the requirements of time-sensitive IoT applications. Christos Tselikis, Christos Douligeris, Sarandis Mitropoulos, Leandros Maglaras |
ISCC | 4 |
| 2022 | Enhancing Privacy of Online Chat Apps Utilising Secure Node End-to-End Encryption (SNE2EE)abstractSNE2EE is a messaging service that protects indi-viduals in each and every stage of the data transfer process: creation, transmission, and reception. The aim of SNE2EE is to protect user communications not only when their date is being transported to another user via secure ports/protocols, but also while they are being created. Nithish Velagala, Leandros Maglaras, Nicholas Ayres 0001, Sotiris Moschoyiannis, Leandros Tassiulas |
ISCC | 2 |
| 2022 | FELIDS: Federated learning-based intrusion detection system for agricultural Internet of Things
Othmane Friha, Mohamed Amine Ferrag, Lei Shu 0001, Leandros Maglaras, Kim-Kwang Raymond Choo, Mehdi Nafaa |
J. Parallel Distributed Comput. | 4 |
| 2021 | A novel Two-Factor HoneyToken Authentication MechanismabstractThe majority of systems rely on user authentication on passwords, but passwords have so many weaknesses and widespread use that easily raise significant security concerns, regardless of their encrypted form. Users hold the same password for different accounts, administrators never check password files for flaws that might lead to a successful cracking, and the lack of a tight security policy regarding regular password replacement are a few problems that need to be addressed. The proposed research work aims at enhancing this security mechanism, prevent penetrations, password theft, and attempted break-ins towards securing computing systems. The selected solution approach is two-folded; it implements a two-factor authentication scheme to prevent unauthorized access, accompanied by Honeyword principles to detect corrupted or stolen tokens. Both can be integrated into any platform or web application with the use of QR codes and a mobile phone. Vassilis Papaspirou, Leandros Maglaras, Mohamed Amine Ferrag, Ioanna Kantzavelou, Helge Janicke, Christos Douligeris |
ICCCN | 2 |
| 2021 | EASBF: An efficient authentication scheme over blockchain for fog computing-enabled internet of vehicles
Salah Eddine Merzougui, Mohamed Amine Ferrag, Othmane Friha, Leandros Maglaras |
J. Inf. Secur. Appl. | 4 |
| 2021 | RF Jamming Classification Using Relative Speed Estimation in Vehicular Wireless NetworksabstractWireless communications are vulnerable against radio frequency (RF) interference which might be caused either intentionally or unintentionally. A particular subset of wireless networks, Vehicular Ad-hoc NETworks (VANET), which incorporate a series of safety-critical applications, may be a potential target of RF jamming with detrimental safety effects. To ensure secure communications between entities and in order to make the network robust against this type of attacks, an accurate detection scheme must be adopted. In this paper, we introduce a detection scheme that is based on supervised learning. The k-nearest neighbors (KNN) and random forest (RaFo) methods are used, including features, among which one is the metric of the variations of relative speed (VRS) between the jammer and the receiver. VRS is estimated from the combined value of the useful and the jamming signal at the receiver. The KNN-VRS and RaFo-VRS classification algorithms are able to detect various cases of denial-of-service (DoS) RF jamming attacks and differentiate those attacks from cases of interference with very high accuracy. Dimitrios Kosmanos, Dimitrios Karagiannis, Antonios Argyriou, Spyros Lalis, Leandros Maglaras |
Secur. Commun. Networks | 5 |
| 2020 | A NIS Directive Compliant Cybersecurity Maturity Assessment FrameworkabstractThe EU NIS Directive introduces obligations related to the security of the network and information systems for Operators of Essential Services and for Digital Service Providers. Moreover, National Competent Authorities for cybersecurity are required to assess the compliance to these obligations. This paper describes a novel Cybersecurity Maturity Assessment Framework (CMAF) that is tailored to the NIS Directive requirements. CMAF can be used either as a self assessment tool from Operators of Essential Services and Digital Service Providers or as an audit tool from the National Competent Authorities for cybersecurity George Drivas, Argyro Chatzopoulou, Leandros Maglaras, Costas Lambrinoudakis, Allan Cook, Helge Janicke |
COMPSAC | 3 |
| 2020 | Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study
Mohamed Amine Ferrag, Leandros Maglaras, Sotiris Moschoyiannis, Helge Janicke |
J. Inf. Secur. Appl. | 2 |
| 2020 | Introduction to the special issue of the journal of information security and applications on" cyber security in ICS & SCADA systems"
Kevin I. Jones, Helge Janicke, Leandros Maglaras, Christos Xenakis |
J. Inf. Secur. Appl. | 3 |
| 2020 | On the conference key distribution system with user anonymity
Christos Tselikis, Christos Douligeris, Leandros Maglaras, Sarandis Mitropoulos |
J. Inf. Secur. Appl. | 3 |
| 2019 | A Novel Hierarchical Intrusion Detection System Based on Decision Tree and Rules-Based ModelsabstractThis paper proposes a novel intrusion detection system (IDS) that combines different classifier approaches which are based on decision tree and rules-based concepts, namely, REP Tree, JRip algorithm and Forest PA. Specifically, the first and second method take as inputs features of the data set, and classify the network traffic as Attack/Benign. The third classifier uses features of the initial data set in addition to the outputs of the first and the second classifier as inputs. The experimental results obtained by analyzing the proposed IDS using the CICIDS2017 dataset, attest their superiority in terms of accuracy, detection rate, false alarm rate and time overhead as compared to state of the art existing schemes. Ahmed Ahmim, Leandros Maglaras, Mohamed Amine Ferrag, Makhlouf Derdour, Helge Janicke |
DCOSS | 2 |
| 2019 | HEART-IS: A novel technique for evaluating human error-related information security incidents
Mark Glenn Evans, Ying He 0004, Leandros Maglaras, Helge Janicke |
Comput. Secur. | 3 |
| 2019 | Blockchain Technologies for the Internet of Things: Research Issues and ChallengesabstractThis paper presents a comprehensive survey of the existing blockchain protocols for the Internet of Things (IoT) networks. We start by describing the blockchains and summarizing the existing surveys that deal with blockchain technologies. Then, we provide an overview of the application domains of blockchain technologies in IoT, e.g., Internet of Vehicles, Internet of Energy, Internet of Cloud, Edge computing, etc. Moreover, we provide a classification of threat models, which are considered by blockchain protocols in IoT networks, into five main categories, namely identity-based attacks, manipulation-based attacks, cryptanalytic attacks, reputation-based attacks, and service-based attacks. In addition, we provide a taxonomy and a side-by-side comparison of the state-of-the-art methods toward secure and privacy-preserving blockchain technologies with respect to the blockchain model, specific security goals, performance, limitations, computation complexity, and communication overhead. Based on the current survey, we highlight open research challenges and discuss possible future research directions in the blockchain technologies for IoT. Mohamed Amine Ferrag, Makhlouf Derdour, Mithun Mukherjee 0001, Abdelouahid Derhab, Leandros Maglaras, Helge Janicke |
IEEE Internet Things J. | 5 |
| 2019 | Authentication and Authorization for Mobile IoT Devices Using Biofeatures: Recent Advances and Future TrendsabstractBiofeatures are fast becoming a key tool to authenticate the IoT devices; in this sense, the purpose of this investigation is to summarise the factors that hinder biometrics models’ development and deployment on a large scale, including human physiological (e.g., face, eyes, fingerprints-palm, or electrocardiogram) and behavioral features (e.g., signature, voice, gait, or keystroke). The different machine learning and data mining methods used by authentication and authorization schemes for mobile IoT devices are provided. Threat models and countermeasures used by biometrics-based authentication schemes for mobile IoT devices are also presented. More specifically, we analyze the state of the art of the existing biometric-based authentication schemes for IoT devices. Based on the current taxonomy, we conclude our paper with different types of challenges for future research efforts in biometrics-based authentication schemes for IoT devices. Mohamed Amine Ferrag, Leandros Maglaras, Abdelouahid Derhab |
Secur. Commun. Networks | 2 |
| 2019 | Estimating the Relative Speed of RF Jammers in VANETsabstractVehicular Ad Hoc Networks (VANETs) aim at enhancing road safety and providing a comfortable driving environment by delivering early warning and infotainment messages to the drivers. Jamming attacks, however, pose a significant threat to their performance. In this paper, we propose a novel Relative Speed Estimation Algorithm (RSEA) of a moving vehicle that approaches a transmitter ( Tx )-receiver ( Rx ) pair that interferes with their radio frequency (RF) communication by conducting a denial of service (DoS) attack. Our scheme is completely passive and uses a pilot-based received signal without hardware or computational cost to, firstly, estimate the combined channel between the transmitter-receiver and jammer-receiver and, secondly, to estimate the jamming signal and the relative speed between the jammer-receiver using the RF Doppler shift. Moreover, the relative speed metric exploits the angle of projection (AOP) of the speed vector of the jammer in the axis of its motion in order to form a two-dimensional representation of the geographical area. Our approach can effectively be applied for any form of the jamming signal and is proven to have quite accurate performance, with a mean absolute error (MAE) value of approximately 10% compared to the optimal zero MAE value under different jamming attack scenarios. Dimitrios Kosmanos, Antonios Argyriou, Leandros Maglaras |
Secur. Commun. Networks | 3 |
| 2018 | Security for 4G and 5G cellular networks: A survey of existing authentication and privacy-preserving schemes
Mohamed Amine Ferrag, Leandros Maglaras, Antonios Argyriou, Dimitrios Kosmanos, Helge Janicke |
J. Netw. Comput. Appl. | 2 |
| 2018 | An introduction to cyber peacekeeping
Michael Robinson 0004, Kevin I. Jones, Helge Janicke, Leandros Maglaras |
J. Netw. Comput. Appl. | 4 |
| 2018 | Editorial: Industrial Internet of Things (I2oT)
Leandros Maglaras, Lei Shu 0001, Athanasios Maglaras, Jianmin Jiang, Helge Janicke, Dimitrios Katsaros 0001, Tiago Cruz 0001 |
Mob. Networks Appl. | 1 |
| 2018 | Vulnerability Analysis of Network Scanning on SCADA SystemsabstractSupervisory Control and Data Acquisition (SCADA) systems and Industrial Control Systems (ICSs) have controlled the regulation and management of Critical National Infrastructure environments for decades. With the demand for remote facilities to be controlled and monitored, industries have continued to adopt Internet technology into their ICS and SCADA systems so that their enterprise can span across international borders in order to meet the demand of modern living. Although this is a necessity, it could prove to be potentially dangerous. The devices that make up ICS and SCADA systems have bespoke purposes and are often inherently vulnerable and difficult to merge with newer technologies. The focus of this article is to explore, test, and critically analyse the use of network scanning tools against bespoke SCADA equipment in order to identify the issues with conducting asset discovery or service detection on SCADA systems with the same tools used on conventional IP networks. The observations and results of the experiments conducted are helpful in evaluating their feasibility and whether they have a negative impact on how they operate. This in turn helps deduce whether network scanners open a new set of vulnerabilities unique to SCADA systems. Kyle Coffey, Richard Smith 0002, Leandros Maglaras, Helge Janicke |
Secur. Commun. Networks | 3 |
| 2017 | The industrial control system cyber defence triage process
Allan Cook, Helge Janicke, Richard Smith 0002, Leandros Maglaras |
Comput. Secur. | 4 |
| 2017 | Architectural and information theoretic perspectives of physical layer intruders for direct sequence spread spectrum systems
Asim Loan, Radu F. Babiceanu, Leandros Maglaras, Onaiza Yousaf |
Comput. Secur. | 4 |
| 2017 | On data leakage from non-production systemsabstractPurpose This study is an exploration of areas pertaining to the use of production data in non-production environments. During the software development life cycle, non-production environments are used to serve various purposes to include unit, component, integration, system, user acceptance, performance and configuration testing. Organisations and third parties have been and are continuing to use copies of production data in non-production environments. This can lead to personal and sensitive data being accidentally leaked if appropriate and rigorous security guidelines are not implemented. This paper aims to propose a comprehensive framework for minimising data leakage from non-production environments. The framework was evaluated using guided interviews and was proven effective in helping organisation manage sensitive data in non-production environments. Design/methodology/approach Authors conducted a thorough literature review on areas related to data leakage from non-production systems. By doing an analysis of advice, guidelines and frameworks that aims at finding a practical solution for selecting and implementing a de-identification solution of sensitive data, the authors managed to highlight the importance of all areas related to sensitive data protection. Based on these areas, a framework was proposed which was evaluated by conducting set of guided interviews. Findings This paper has researched the background information and produced a framework for an organisation to manage sensitive data in its non-production environments. This paper presents a proposed framework that describes a process flow from the legal and regulatory requirements to data treatment and protection, gained through understanding the organisation’s business, the production system, the purpose and the requirements of the non-production environment. The paper shows that there is some conflict between security and perceived usability, which may be addressed by challenging the perceptions of usability or identifying the compromise required. Non-production environments need not be the sole responsibility of the IT section, they should be of interest to the business area that is responsible for the data held. Originality/value This paper proposes a simplified business model and framework. The proposed model diagrammatically describes the interactions of elements affecting the organisation. It highlights how non-production environments may be perceived as separate from the business systems, but despite the perceptions, these are still subject to the same legal requirements and constraints. It shows the interdependency of data, software, technical infrastructure and human interaction and how the change of one element may affect the others. The proposed framework describes the process flow and forms a practical solution in assisting the decision-making process and providing documentary evidence for assurance and audit purposes. It looks at the requirements of the non-production system in relation to the legal and regulatory constraints, as well as the organisational requirements and business systems. The impact of human factors on the data is also considered to bring a holistic approach to the protection of non-production environments. Jacqueline Cope, François Siewe, Feng Chen 0004, Leandros Maglaras, Helge Janicke |
Inf. Comput. Secur. | 4 |
| 2017 | Introduction to the special issue of the journal of information security and applications on "ICS & SCADA cyber security"
Kevin I. Jones, Helge Janicke, Christian Facchi, Leandros Maglaras |
J. Inf. Secur. Appl. | 4 |
| 2017 | Authentication Protocols for Internet of Things: A Comprehensive SurveyabstractIn this paper, a comprehensive survey of authentication protocols for Internet of Things (IoT) is presented. Specifically more than forty authentication protocols developed for or applied in the context of the IoT are selected and examined in detail. These protocols are categorized based on the target environment: (1) Machine to Machine Communications (M2M), (2) Internet of Vehicles (IoV), (3) Internet of Energy (IoE), and (4) Internet of Sensors (IoS). Threat models, countermeasures, and formal security verification techniques used in authentication protocols for the IoT are presented. In addition a taxonomy and comparison of authentication protocols that are developed for the IoT in terms of network model, specific security goals, main processes, computation complexity, and communication overhead are provided. Based on the current survey, open issues are identified and future research directions are proposed. Mohamed Amine Ferrag, Leandros Maglaras, Helge Janicke, Jianmin Jiang, Lei Shu 0001 |
Secur. Commun. Networks | 2 |
| 2016 | Combining ensemble methods and social network metrics for improving accuracy of OCSVM on intrusion detection in SCADA systems
Leandros Maglaras, Jianmin Jiang, Tiago Cruz 0001 |
J. Inf. Secur. Appl. | 1 |
| 2016 | Cyberterrorism targeting the general public through social mediaabstractAbstract Current literature suggests that critical national infrastructure is the main focus of attack for cyberterrorism, but this research will address the issue of whether a mimetic virus would be a viable cyberterrorist attack against a target population. Statistical data was obtained from questionnaires with 100 random participants regarding their understanding and current levels of fear of a cyberterrorist attack against them; responses indicated that there was a good level of understanding as to what cyberterrorism was and that participants' fear levels of an impending attack were low. The participants were then introduced using a fabricated video clip to what they were led to believe was a real weaponised computer virus that attacked laptop batteries causing them to explode. The data showed that not only had participants' fear levels increased but also would modify future habits and behaviour. This research highlighted that the general public could indeed be a target of cyberterrorism, and a mimetic virus could be an effective method of attack. Copyright © 2016 John Wiley & Sons, Ltd. Nicholas Ayres 0001, Leandros Maglaras |
Secur. Commun. Networks | 2 |
| 2016 | Human behaviour as an aspect of cybersecurity assuranceabstractAbstract There continue to be numerous breaches publicised pertaining to cybersecurity despite security practices being applied within industry for many years. This paper is intended to be the first in a number of papers as research into cybersecurity assurance processes. This paper is compiled based on current research related to cybersecurity assurance and the impact of the human element on it. The objective of this work is to identify elements of cybersecurity that would benefit from further research and development based on the literature review findings. The results outlined in this paper present a need for the cybersecurity field to look in to established industry areas to benefit from effective practices such as human reliability assessment, along with improved methods of validation such as statistical quality control in order to obtain true assurance. The paper proposes the development of a framework that will be based upon defined and repeatable quantification, specifically relating to the range of human aspect tasks that provide or are intended not to negatively affect cybersecurity assurance. Copyright © 2016 John Wiley & Sons, Ltd. Mark Glenn Evans, Leandros Maglaras, Ying He 0004, Helge Janicke |
Secur. Commun. Networks | 2 |
| 2016 | A Cybersecurity Detection Framework for Supervisory Control and Data Acquisition SystemsabstractThis paper presents a distributed intrusion detection system (DIDS) for supervisory control and data acquisition (SCADA) industrial control systems, which was developed for the CockpitCI project. Its architecture was designed to address the specific characteristics and requirements for SCADA cybersecurity that cannot be adequately fulfilled by techniques from the information technology world, thus requiring a domain-specific approach. DIDS components are described in terms of their functionality, operation, integration, and management. Moreover, system evaluation and validation are undertaken within an especially designed hybrid testbed emulating the SCADA system for an electrical distribution grid. Tiago Cruz 0001, Luís Rosa 0001, Jorge Proença, Leandros Maglaras, Matthieu Aubigny, Leonid Lev, Jianmin Jiang, Paulo Simões 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2014 | OCSVM model combined with K-means recursive clustering for intrusion detection in SCADA systemsabstractIntrusion detection in Supervisory Control and Data Acquisition (SCADA) systems is of major importance nowadays. Most of the systems are designed without cyber security in mind, since interconnection with other systems through unsafe channels, is becoming the rule during last years. The de-isolation of SCADA systems make them vulnerable to attacks, disrupting its correct functioning and tampering with its normal operation. In this paper we present a intrusion detection module capable of detecting malicious network traffic in a SCADA (Supervisory Control and Data Acquisition) system, based on the combination of One-Class Support Vector Machine (OCSVM) with RBF kernel and recursive k-means clustering. The combination of OCSVM with recursive k-means clustering leads the proposed intrusion detection module to distinguish real alarms from possible attacks regardless of the values of parameters σ and ν, making it ideal for real-time intrusion detection mechanisms for SCADA systems. The OCSVM module developed is trained by network traces off line and detect anomalies in the system real time. The module is part of an IDS (Intrusion Detection System) system developed under CockpitCI project. Leandros Maglaras, Jianmin Jiang |
QSHINE | 1 |
| 2013 | Enhanced Spring Clustering in VANETs with Obstruction ConsiderationsabstractVehicular networks have a diverse range of applications that varies from safety applications to comfort applications. Clustering in VANETs is of crucial importance for addressing the scalability problems of VANETs. The performance of communication protocols is greatly influenced by the existence of vehicles in the neighborhood; vehicles acting as obstacles change the behavior of protocols when different density, speed and car sizes scenarios are investigated since reliable communication range among vehicles varies. The Enhanced Spring Clustering is a new distributed clustering protocol, which forms stable clusters based on vehicle dimensions. An investigation of the performance of the Enhanced Spring Clustering in realistic environments is presented confirming its superiority over the examined, competing clustering protocol. Leandros Maglaras, Dimitrios Katsaros 0001 |
VTC Spring | 1 |
| 2012 | Distributed Skip Air Index for smart broadcasting in intelligent transportation systemsabstractWireless data broadcast received a lot of attention from industries and academia in recent years. In any form of a push-based broadcast, access latency and tuning time are vital issues, and in order to address the tradeoff among these competing goals, the broadcasting of indices along with the data is the most viable solution. Currently, two broad indexing families exist: those that exploit some form of a tree structure, and those that are based on some `distributed access on the air' mechanism. The latter family is the most popular and viable, because it allows for following `air-pointers' without the need to first find a tree root. The champion method of the distributed air index is the Exponential index which however is not appropriate when the access pattern is skewed, i.e., some data items are more popular than the others. To address this shortcoming, we design a Distributed Skip Air Index (DiSAIn), which exploits access statistics in order to improve average tuning time, while it preserves the access latency equal to that of the original Exponential index. To attest the superiority of the proposed indexing method, we perform a detailed simulation evaluation of the two competing methods. Leandros Maglaras, Dimitrios Katsaros 0001 |
Intelligent Vehicles Symposium | 1 |
| 2012 | Distributed clustering in vehicular networksabstractClustering in vanets is of crucial importance in order to cope with the dynamic features of the vehicular topologies. Algorithms that give good results in Manets fail to create stable clusters since vehicular nodes are characterized by their high mobility and the different mobility patterns that even nodes in proximity may follow. In this paper, we propose a distributed clustering algorithm which forms stable clusters based on force directed algorithms. The simulation results show that our Spring-Clustering (Sp-Cl) scheme has stable performance in randomly generated scenarios on a highway. It forms lesser clusters than Lowest-ID and it is better in terms of Cluster stability compared to Lowest-ID and LPG algorithms in the same scenarios. Leandros Maglaras, Dimitrios Katsaros 0001 |
WiMob | 1 |
| 2011 | Layered backpressure scheduling for delay reduction in ad hoc networksabstractPacket scheduling in wireless ad hoc networks is a fundamental problem for ad hoc networking. Backpressure scheduling is a solid and throughput optimal policy for such networks, but suffers from increased delays. In this article, we present an holistic approach to improve upon the delay problems of backpressure-type algorithms. We develop two scheduling policies, namely Voting-based and Layered backpressure routing which both are throughput optimal. We experimentally compare the proposed policies against all the delay-aware backpressure policies and conclude that Layered backpressure is a high performance policy compromising a little delay for robustness, low computational complexity and simplicity. Leandros Maglaras, Dimitrios Katsaros 0001 |
WOWMOM | 1 |