EDBT 2026 Demo / reviewers in the wild / expert
Anna Georgiadou
dblp:130/2390
· DBLP profile ↗
4ranked-venue papers in the field
2as first author
4since 2021 · last 2022
0000-0002-0078-6969ORCID · corroborated
Domains — venue-derived; a paper can count in several
Big Data, Cloud & Distributed Data Systems · 2Knowledge Engineering, Semantic Web & Information Systems · 2 (2 first)
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | A tool for assisting in the forensic investigation of cyber-security incidentsabstractThe exponential growth of networking capabilities including the Internet of Things (IoT), has led to an outburst of cyberattacks. Many well-documented cyber-attacks have targeted critical energy infrastructures as well as any kind of cloud-based IT platforms. Early examination of critical systems’ vulnerabilities, as well as previous cyber-security incidents, are of utmost importance to prevent new ones. A thorough investigation to examine the context of the cyber-security breach can reveal facts about the source of the attack, the profile of the attacker, the resources, and the skills required and can further reveal mitigations for preventing the attack from re-appearing in the future. To safeguard critical energy infrastructures, many forensic approaches have been developed to collect, analyze, and digitalize evidence assisting in the in-depth investigation of an incident. However, up to now, the many open-source vulnerability data sources which have been developed to provide valuable information for a cyber-attack are yet to be employed to assist in forensic investigation. This paper introduces the Automated Forensic Tool, a platform that employs machine learning algorithms to combine different vulnerability data sources for facilitating the forensic procedure while minimizing the time and effort needed. A use case is also demonstrated that displays how the tool can be used towards assisting the forensic investigation of cyber-security incidents on an energy infrastructure, but the tool can also be applied to other critical energy and IT infrastructures with minor adaptations. Konstantinos Touloumis, Ariadni Michalitsi-Psarrou, Anna Georgiadou, Dimitris Askounis |
IEEE Big Data | 3 |
| 2022 | Detecting Insider Threat via a Cyber-Security Culture FrameworkabstractInsider threat has been recognized by both scientific community and security professionals as one of the gravest security hazards for private companies, institutions, and governmental organizations. Extended research on the types, associated internal and external factors, detection approaches and mitigation strategies has been conducted over the last decades. Various frameworks have been introduced in an attempt to understand and reflect the danger posed by this threat, whereas multiple identified cases have been classified in private or public databases. This paper aims to present how a cyber-security culture framework with a clear focus on the human factor can assist in detecting possible threats of both malicious and unintentional insiders. We link current insider threat categories with specific security domains of the framework and introduce an assessment methodology of the core contributing parameters. Specific approach takes into consideration technical, behavioral, cultural, and personal indicators and assists in identifying possible security perils deriving from privileged individuals. Anna Georgiadou, Spiros Mouzakitis, Dimitris Askounis |
J. Comput. Inf. Syst. | 1 |
| 2022 | A Cyber-Security Culture Framework for Assessing Organization ReadinessabstractThis paper presents a cyber-security culture framework for assessing and evaluating the current security readiness of an organization’s workforce. Having conducted a thorough review of the most commonly used security frameworks, we identify core security human-related elements and classify them by constructing a domain agnostic security model. We then proceed by presenting in detail each component of our model and attempt to quantify them in order to achieve a feasible assessment methodology. The paper thereafter presents the application of this methodology for the design and development of a security culture evaluation tool, that offers recommendations and alternative approaches to workforce training programs and techniques. The model has been designed to easily adapt on various application domains while focusing on their unique characteristics. The paper concludes on applications of our instrument on security-critical domains, and its contribution to current research by providing deeper insights regarding the human factor in cybersecurity. Anna Georgiadou, Spiros Mouzakitis, Kanaris Bounas, Dimitris Askounis |
J. Comput. Inf. Syst. | 1 |
| 2021 | Vulnerabilities Manager, a platform for linking vulnerability data sourcesabstractIn order to get a deeper understanding of security breaches, their severity, impact and ways to mitigate them, many vulnerability databases and dictionaries have been developed. However, all that information on vulnerabilities is scattered all over the web, which makes locating and mitigating vulnerabilities an arduous task. This paper introduces the Vulnerabilities Manager, a tool that automates the process of linking information from well-known external vulnerability data sources. Its goal is to present an enriched vulnerability report to its final users, assisting them in pinpointing software and hardware assets’ defects, categorizing and prioritizing them, thus, contributing to the cyber defense against potential security breaches and adversary actions. To achieve this, the Vulnerabilities Manager exploits current state of the art machine learning and artificial intelligence techniques. The tool may also be enriched with forensic capabilities, detecting cyber threats, unveiling information about the nature of the attacker, and proposing mitigations against them in real-time. Konstantinos Touloumis, Ariadni Michalitsi-Psarrou, Panagiotis Kapsalis, Anna Georgiadou, Dimitris Askounis |
IEEE BigData | 4 |