EDBT 2026 Demo / reviewers in the wild / expert
Konstantinos Fysarakis
dblp:123/8682
· DBLP profile ↗
23ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0002-6871-8102ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 3 first-author · 1 since 2021Security and privacy · 7 · 1 first-author · 2 since 2021Systems, architecture and hardware · 5 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhanced-LLM extraction of CTI from unstructured threat reports. A tough nut to crack or a walk in the park?
Konstantina Psarrou, Panagiotis Bountakas, Dimitris Eleutheriou, Rafail A. Ellinitakis, Konstantinos Fysarakis, Alexios Lekidis, George Spanoudakis |
Future Gener. Comput. Syst. | 5 |
| 2025 | Operationalizing cybersecurity knowledge: Design, implementation & evaluation of a knowledge management system for CACAO playbooks
Orestis Tsirakis, Konstantinos Fysarakis, Vasileios Mavroeidis, Ioannis Papaefstathiou |
Comput. Secur. | 2 |
| 2024 | SYNAPSE - An Integrated Cyber Security Risk & Resilience Management Platform, With Holistic Situational Awareness, Incident Response & Preparedness Capabilities: SYNAPSEabstractIn an era of escalating cyber threats, the imperative for robust and comprehensive cybersecurity measures has never been more pressing. To address this challenge, SYNAPSE presents a pioneering approach by conceptualising, designing, and delivering an Integrated cybersecurity Risk & Resilience Management Platform. The innovation of this platform lies in the integration of key elements, such as situational awareness, incident response, and preparedness (i.e., cyber range), augmented by advanced AI capabilities. Through its holistic approach, SYNAPSE aims to elevate cyber resilience by not only mitigating threats but also fostering a culture of proactive defence, informed decision-making, and collaborative response within organisations and across industries. Panagiotis Bountakas, Konstantinos Fysarakis, Thomas Kyriakakis, Panagiotis Karafotis, Aristeidis Sotiropoulos, Maria Tasouli, Cristina Alcaraz, George Alexandris, Vassiliki Andronikou, Tzortzia Koutsouri, Romarick Yatagha, George Spanoudakis, Sotiris Ioannidis, Fabio Martinelli, Oleg Illiashenko |
ARES | 2 |
| 2024 | Towards Incident Response Orchestration and Automation for the Advanced Metering InfrastructureabstractThe threat landscape of industrial infrastructures has expanded exponentially over the last few years. Such infrastructures include services such as the smart meter data exchange that should have real-time availability. Smart meters constitute the main component of the Advanced Metering Infrastructure, and their measurements are also used as historical data for forecasting the energy demand to avoid load peaks that could lead to blackouts within specific areas. Hence, a comprehensive Incident Response plan must be in place to ensure high service availability in case of cyber-attacks or operational errors. Currently, utility operators execute such plans mostly manually, requiring extensive time, effort, and domain expertise, and they are prone to human errors. In this paper, we present a method to provide an orchestrated and highly automated Incident Response plan targeting specific use cases and attack scenarios in the energy sector, including steps for preparedness, detection and analysis, containment, eradication, recovery, and post-incident activity through the use of playbooks. In particular, we use the OASIS Collaborative Automated Course of Action Operations (CACAO) standard to define highly automatable workflows in support of cyber security operations for the Advanced Metering Infrastructure. The proposed method is validated through an Advanced Metering Infrastructure testbed where the most prominent cyber-attacks are emulated, and playbooks are instantiated to ensure rapid response for the containment and eradication of the threat, business continuity on the smart meter data exchange service, and compliance with incident reporting requirements. Alexios Lekidis, Vasileios Mavroeidis, Konstantinos Fysarakis |
WFCS | 3 |
| 2024 | Introduction to the Special Issue on Distributed Intelligence on the Internet
Simon Mayer, Arne Bröring, Kimberly García, Konstantinos Fysarakis, Beatriz Soret |
ACM Trans. Internet Techn. | 4 |
| 2022 | A Blueprint for Collaborative Cybersecurity Operations Centres with Capacity for Shared Situational Awareness, Coordinated Response, and Joint PreparednessabstractWith digital technologies now being part of the fabric of our societies, identifying and managing cybersecurity threats becomes imperative. Within the European Union, several initiatives are underway, aiming to motivate, regulate and eventually orchestrate the establishment of capacity and enhancement of situational awareness, incident response, and preparedness capabilities, with an expected emphasis on operators of essential services and state actors entrusted with cybersecurity. In this context, the institution of cooperation and information exchange channels to allow for coordinated cross-border responses to large-scale incidents is particularly prioritized. Motivated by the above, this work presents a conceptual blueprint in support of architecting and establishing interoperable Cyber Security Operations Centres that combine capacity for situational awareness, incident response, and preparedness, also benefiting from the interplay between them, ultimately enhancing national cybersecurity capabilities, cross-border collaboration, and national supervision of their critical sectors, in line with current and upcoming regulatory requirements and the ever-increasing need for national and international cooperation. Konstantinos Fysarakis, Vasileios Mavroeidis, Manos Athanatos, George Spanoudakis, Sotiris Ioannidis |
IEEE Big Data | 1 |
| 2021 | WARDOG: Awareness Detection Watchdog for Botnet Infection on the Host DeviceabstractBotnets constitute nowadays one of the most dangerous security threats worldwide. High volumes of infected machines are controlled by a malicious entity and perform coordinated cyber-attacks. The problem will become even worse in the era of the Internet of Things (IoT) as the number of insecure devices is going to be exponentially increased. This paper presents WARDOG - an awareness and digital forensic system that informs the end-user of the botnet's infection, exposes the botnet infrastructure, and captures verifiable data that can be utilized in a court of law. The responsible authority gathers all information and automatically generates a unitary documentation for the case. The document contains undisputed forensic information, tracking all involved parties and their role in the attack. The deployed security mechanisms and the overall administration setting ensures non-repudiation of performed actions and enforces accountability. The provided properties are verified through theoretic analysis. In simulated environment, the effectiveness of the proposed solution, in mitigating the botnet operations, is also tested against real attack strategies that have been captured by the FORTHcert honeypots, overcoming state-of-the-art solutions. Moreover, a preliminary version is implemented in real computers and IoT devices, highlighting the low computational/communicational overheads of WARDOG in the field. George Hatzivasilis, Othonas Sultatos, Panos Chatziadam, Konstantinos Fysarakis, Ioannis G. Askoxylakis, Sotiris Ioannidis, George Alexandris, Vasilios Katos, George Spanoudakis |
IEEE Trans. Sustain. Comput. | 4 |
| 2019 | The CE-IoT Framework for Green ICT Organizations: The interplay of CE-IoT as an enabler for green innovation and e-waste management in ICTabstractThe growth of the global middle class provokes significant increment in product consumption. As the available resources are limited, Circular Economy (CE) raises as a promising initiative towards the sustainable development. Except from the traditional approaches of reusing or recycling products, the current trend utilizes modern computer technologies and involves a data-driven aspect. The Internet of Things (IoT) is the main enabler for the integration of CE with technology. This paper proposes a framework for implementing the cooperative vision of CE and IoT. Via this solution, a pilot system is developed in a medium size telecommunication company for administrating the lifecycle of the deployed electronic equipment and the management of the related supply chains. Mechanisms and devices are maintained/repaired/fabricated in a regular basis, green computing techniques are efficiently applied, and the productive period is prolonged. When the business upgrades the system, the retired counterparts can be sold in start-ups or gifted in third-world countries. The overall approach extends the working period of the well-maintained electronic assets not only for the examined business but for the collaborating organizations as well. Recycling companies can then trace this supply chain and the assets' status in order to define their investment strategy at the end-consumer, contributing in the reduction of the electronic waste problem in the third-world. George Hatzivasilis, Nikos Christodoulakis, Christos Tzagkarakis, Sotiris Ioannidis, Giorgos Demetriou, Konstantinos Fysarakis, Marios Panayiotou |
DCOSS | 6 |
| 2019 | Towards IoT Orchestrations with Security, Privacy, Dependability and Interoperability GuaranteesabstractThe advent of the Internet of Things opens a plethora of possibilities, provided the research and industry communities are able to overcome a number of challenges such as the dynamicity, scalability, heterogeneity and end-to-end security and privacy requirements of such environments. Motivated by these challenges, this paper proposes leveraging architectural patterns to provide, in an integrated manner, security, dependability, privacy, and interoperability guarantees, across horizontal and vertical compositional structures of IoT applications. The pattern language design process and definition is presented, along with an implementation enabling the automated, pattern- driven property verification and adaptation of IoT orchestrations. Konstantinos Fysarakis, Manos Papoutsakis, Nikos Petroulakis, George Spanoudakis |
GLOBECOM | 1 |
| 2019 | Secure Semantic Interoperability for IoT Applications with Linked DataabstractInteroperability stands for the capacity of a system to interact with the units of another entity. Although it is quite easy to accomplish this within the products of the same brand, it is not facile to provide compatibility for the whole spectrum of the Internet-of-Things (IoT) and the Linked Data (LD) world. Currently, the different applications and devices operate in their own cloud/platform, without supporting sufficient interaction with different vendor-products. As it concerns the meaning of data, which is the main focus of this paper, semantics can settle commonly agreed information models and ontologies for the used terms. However, as there are several ontologies for describing each distinct 'Thing', we need Semantic Mediators (SMs) in order to perform common data mapping across the various utilized formats (i.e. XML or JSON) and ontology alignment (e.g. resolve conflicts). Our goal is to enable end-to-end vertical compatibility and horizontal cooperation at all levels (field/network/backend). Moreover, the implication of security must be taken into consideration as the unsafe adoption of semantic technologies exposes the linking data and the user's privacy, issues that are neglected by the majority of the semantic-web studies. A motivating example of smart sensing is described along with a preliminary implementation on real heterogeneous devices. Two different IoT platforms are integrating in the case study, detailing the main SM features. The proposed setting is secure, scalable, and the overall overhead is sufficient for runtime operation, while providing significant advances over state-of-the-art solutions. George Hatzivasilis, Lukasz Ciechomski, Othonas Sultatos, Darko Anicic, Arne Bröring, Konstantinos Fysarakis, George Spanoudakis, Eftychia Lakka, Sotiris Ioannidis, Mirko Falchetto |
GLOBECOM | 6 |
| 2018 | SeMIBIoT: Secure Multi-Protocol Integration Bridge for the IoTabstractThe Internet of Things (IoT) is gradually becoming a reality, supported by an assortment of heterogeneous devices, varying from resource- starved wireless sensors to embedded devices and resource-rich backend systems, which are supplemented by a range of networking technologies and protocols. Nevertheless, this diverse ecosystem of platforms and protocols, along with the inherent limitations in processing power, energy, memory and communications bandwidth for some of the involved devices, render secure and interoperable interactions a primary concern, and an important obstacle to the introduction of novel applications, and the adoption of IoT in general. Motivated by the above, this work presents SeMIBIoT, a Secure Multi-protocol Integration Bridge for the IoT. Acting as a gateway, SeMIBIoT is able to provide hop-by-hop or end-to-end secure communications between an array of heterogeneous nodes and standardized IoT protocols, guaranteeing seamless interactions and thus alleviating security and interoperability concerns. Using a realistic testbed featuring a number of diverse platforms, the bridge is evaluated in a variety of scenarios, validating the feasibility of the proposed approach. Emmanouil Palavras, Konstantinos Fysarakis, Ioannis Papaefstathiou, Ioannis G. Askoxylakis |
ICC | 2 |
| 2018 | The Industrial Internet of Things as an enabler for a Circular Economy Hy-LP: A novel IIoT protocol, evaluated on a wind park's SDN/NFV-enabled 5G industrial network
George Hatzivasilis, Konstantinos Fysarakis, Othonas Sultatos, Ioannis G. Askoxylakis, Ioannis Papaefstathiou, Giorgos Demetriou |
Comput. Commun. | 2 |
| 2018 | XSACd - Cross-domain resource sharing & access control for smart environments
Konstantinos Fysarakis, Othonas Sultatos, Charalampos Manifavas, Ioannis Papaefstathiou, Ioannis G. Askoxylakis |
Future Gener. Comput. Syst. | 1 |
| 2017 | A Reactive Security Framework for operational wind parks using Service Function ChainingabstractThe innovative application of 5G core technologies, namely Software Defined Networking (SDN) and Network Function Virtualization (NFV), can help reduce capital and operational expenditures in industrial networks. Nevertheless, SDN expands the attack surface of the communication infrastructure, thus necessitating the introduction of additional security mechanisms. A wind park is a good example of an industrial application relying on a network with strict performance, security, and reliability requirements, and was chosen as a representative example of industrial systems. This work highlights the benefit of leveraging the flexibility of SDN/NFV-enabled networks to deploy enhanced, reactive security mechanisms for the protection of the industrial network, via the use of Service Function Chaining. Moreover, a proof of concept implementation of the reactive security framework for an industrial-grade wind park network is presented. The framework is equipped with SDN and Supervisory Control and Data Acquisition (SCADA) honeypots, modelled on (and deployable to) an actual, operating wind park, allowing continuous monitoring of the industrial network and detailed analysis of potential attacks, thus isolating attackers and enabling the assessment of their level of sophistication. Konstantinos Fysarakis, Nikos Petroulakis, Andreas Roos, Khawar Abbasi, Petra Vizarreta, George P. Petropoulos, Ermin Sakic, George Spanoudakis, Ioannis G. Askoxylakis |
ISCC | 1 |
| 2017 | SecRoute: End-to-end secure communications for wireless ad-hoc networksabstractRailways constitute a main means of mass transportation, used by public, private, and military entities to traverse long distances every day. Railway control software must collect spatial information and effectively manage these systems. Wireless sensor networks (WSNs) are an attractive solution to cover the area along-side the railway routes. In-carriage WSNs are also studied in cases of dangerous cargo transportation. The secure communication of all these devices becomes important as successful attacks can harm the railway's business operation or cause serious injuries and deaths. This paper presents SecRoute - an end-to-end secure communications scheme for wireless ad hoc networks. The scheme implements mechanisms for cryptographic communication, trusted-based routing, and policy-based access control. SecRoute and alternative schemes are modelled on the NS-2 network simulator and a comparative analysis is conducted, indicating that the proposed scheme provides enhanced protection. A proof of concept of SecRoute is deployed on real embedded platforms and exhibits good overall performance, demonstrating that attacks on the route and carriage WSNs are effectively countered. George Hatzivasilis, Ioannis Papaefstathiou, Konstantinos Fysarakis, Ioannis G. Askoxylakis |
ISCC | 3 |
| 2017 | Lightweight & secure industrial IoT communications via the MQ telemetry transport protocolabstractMassive advancements in computing and communication technologies have enabled the ubiquitous presence of interconnected computing devices in all aspects of modern life, forming what is typically referred to as the “Internet of Things”. These major changes could not leave the industrial environment unaffected, with “smart” industrial deployments gradually becoming a reality; a trend that is often referred to as the 4th industrial revolution or Industry 4.0. Nevertheless, the direct interaction of the smart devices with the physical world and their resource constraints, along with the strict performance, security, and reliability requirements of industrial infrastructures, necessitate the adoption of lightweight as well as secure communication mechanisms. Motivated by the above, this paper highlights the Message Queue Telemetry Transport (MQTT) as a lightweight protocol suitable for the industrial domain, presenting a comprehensive evaluation of different security mechanisms that could be used to protect the MQTT-enabled interactions on a real testbed of wireless sensor motes. Moreover, the applicability of the proposed solutions is assessed in the context of a real industrial application, analyzing the network characteristics and requirements of an actual, operating wind park, as a representative use case of industrial networks. Sotirios Katsikeas, Konstantinos Fysarakis, Andreas I. Miaoudakis, Amaury Van Bemten, Ioannis G. Askoxylakis, Ioannis Papaefstathiou, Anargyros Plemenos |
ISCC | 2 |
| 2016 | Which IoT Protocol? Comparing Standardized Approaches over a Common M2M ApplicationabstractComputing devices already permeate working and living environments, while researchers and engineers aim to exploit the potential of pervasive systems in order to introduce new types of services and address inveterate and emerging problems. This process will lead us eventually to the era of urban computing and the Internet of Things (IoT). However, the long-promised improvements require overcoming some significant obstacles introduced by these technological advancements. One such obstacle is the lack of interoperable solutions, to facilitate the use, monitoring and management of the plethora of devices and their services. While seamless machine-to-machine (M2M) and human-to-machine (H2M) interactions are a necessity for secure and truly ubiquitous computing, the current status quo is that of a segregated and incompatible assortment of devices. The resource-constraints of the platforms integrated into smart environments, and their heterogeneity in hardware, network and overlaying technologies, only exacerbate these interoperability issues. Motivated by the above, this paper identifies three promising, standardized protocols, each following a different approach in addressing the above concerns. We evaluate the selected protocols in the context of designing and implementing an application requiring various M2M interactions, namely a policy-based access control framework for IoT devices. Thus, three variants of the application are developed, considering each protocol's intrinsic characteristics and features. Finally, the developed applications are evaluated on a common testbed of embedded devices, allowing us to extract useful conclusions concerning the protocols' performance, their intricacies and their applicability in similar applications. Konstantinos Fysarakis, Ioannis G. Askoxylakis, Othonas Sultatos, Ioannis Papaefstathiou, Charalampos Manifavas, Vasilios Katos |
GLOBECOM | 1 |
| 2016 | A survey of lightweight stream ciphers for embedded systemsabstractPervasive computing constitutes a growing trend, aiming to embed smart devices into everyday objects. The limited resources of these devices and the ever-present need for lower production costs, lead to the research and development of lightweight cryptographic mechanisms. Block ciphers, the main symmetric key cryptosystems, perform well in this field. Nevertheless, stream ciphers are also relevant in ubiquitous computing applications, as they can be used to secure the communication in applications where the plaintext length is either unknown or continuous, like network streams. This paper provides the latest survey of stream ciphers for embedded systems. Lightweight implementations of stream ciphers in embedded hardware and software are examined as well as relevant authenticated encryption schemes. Their speed and simplicity enable compact and low-power implementations, allow them to excel in applications pertaining to resource-constrained devices. The outcomes of the International Organization for Standardization/International Electrotechnical Commission 29192-3 standard and the cryptographic competitions eSTREAM and Competition for Authenticated Encryption: Security, Applicability, and Robustness are summarized along with the latest results in the field. However, cryptanalysis has proven many of these schemes are actually insecure. From the 31 designs that are examined, only six of them have been found to be secure by independent cryptanalysis. A constrained benchmark analysis is performed on low-cost embedded hardware and software platforms. The most appropriate and secure solutions are then mapped in different types of applications. Copyright © 2015 John Wiley & Sons, Ltd. Charalampos Manifavas, George Hatzivasilis, Konstantinos Fysarakis, Ioannis Papaefstathiou |
Secur. Commun. Networks | 3 |
| 2015 | WSACd - A Usable Access Control Framework for Smart Home Devices
Konstantinos Fysarakis, Charalampos Konstantourakis, Konstantinos Rantos, Charalampos Manifavas, Ioannis Papaefstathiou |
WISTP | 1 |
| 2015 | Secure and Authenticated Access to LLN Resources Through Policy Constraints
Konstantinos Rantos, Konstantinos Fysarakis, Othonas Sultatos, Ioannis G. Askoxylakis |
WISTP | 2 |
| 2015 | Embedded Systems Security: A Survey of EU Research EffortsabstractAbstract Embedded systems security is a recurring theme in current research efforts, brought in the limelight by the wide adoption of ubiquitous devices. Significant funding has been allocated to various European projects on this subject area, in order to investigate and overcome the various security challenges. This paper provides an overview of recent EU research efforts pertaining to embedded systems security, where several prominent security issues and the respective proposed approaches are presented. Surveying relatively recent EU research projects, the authors identify 20 such projects that focus on embedded systems security aspects. The investigated technologies are categorised using a layered approach, to facilitate the presentation of the results; the categories comprise the node, network, and middleware and overlay layers, as well as architectures, frameworks and formal validation of the security of embedded systems. From this survey, certain patterns emerge regarding the issues investigated and the technologies researchers focus on, in order to address the said issues. Finally, the existing open issues are summarised, and directions for future research are given. Copyright © 2014 John Wiley & Sons, Ltd. Charalampos Manifavas, Konstantinos Fysarakis, Alexandros Papanikolaou, Ioannis Papaefstathiou |
Secur. Commun. Networks | 2 |
| 2014 | Policy-based access control for DPWS-enabled ubiquitous devicesabstractAs computing becomes ubiquitous, researchers and engineers aim to exploit the potential of the pervasive systems in order to introduce new types of services and address inveterate and emerging problems. This process will, eventually, lead us to the era of urban computing and the Internet of Things; the ultimate goal being to improve our quality of life. But these concepts typically require direct and constant interaction of computing systems with the physical world in order to be realized, which inevitably leads to the introduction of a range of safety and privacy issues that must be addressed. One such important aspect is the fine-grained control of access to the resources of these pervasive embedded systems, in a secure and scalable manner. This paper presents an implementation of such a secure policy-based access control scheme, focusing on the use of well-established, standardized technologies and considering the potential resource-constraints of the target heterogeneous embedded devices. The proposed framework adopts a DPWS-compliant approach for smart devices and introduces XACML-based access control mechanisms. The proof-of-concept implementation is presented in detail, along with a performance evaluation on typical embedded platforms. Konstantinos Fysarakis, Ioannis Papaefstathiou, Charalampos Manifavas, Konstantinos Rantos, Othonas Sultatos |
ETFA | 1 |
| 2014 | Policy-Based Access Control for Body Sensor Networks
Charalampos Manifavas, Konstantinos Fysarakis, Konstantinos Rantos, Konstantinos Kagiambakis, Ioannis Papaefstathiou |
WISTP | 2 |