Alexios Lekidis

dblp:166/9219 · DBLP profile ↗
← Back
15ranked-venue papers
9as first author
12since 2021 · last 2026
0000-0002-8243-7075ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 5 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Blockchain architectures for enhancing EV infrastructure security: A unified framework for addressing sophisticated cyber-attacks
abstract
Over the last years the Electric Vehicles (EVs) are gradually adopted by users, as they have environmental, technological and financial benefits with respect to combustion engine vehicles. However, the abundance of connectivity interfaces constitutes them prone to cyber-attack scenarios targeting the entire infrastructure and especially the EVs, the EV Charging Stations as well as the Charging Station Management System that is used for their management, control and configuration. The cyber-attacks have increasing impact and risk as they may further propagate to the electrical grid, causing cascading effects as utility service disruptions or blackouts. The impact analysis though requires a threat taxonomy related to their Tactics, Techniques and Procedures (TTPs) and an associated risk model, allowing to select the most prominent threats in the EV infrastructure. Additionally, such threats are currently detected and mitigated by anomaly detection systems also using Machine Learning systems, which nevertheless do not consider the distributed nature of EV infrastructures. The high level overarching objective of this article is three-fold: 1) to provide an initial security posture assessment of EV ecosystems as a reference point against which a detailed risk model is presented; 2) to identify the best practices and integration patterns in the adoption of blockchain technology to EV ecosystems for addressing EV-oriented attacks; and 3) to propose a blockchain-oriented architecture for the protection of the distributed EV ecosystems against cyber-attacks, which is also validated in a proof-of-concept infrastructure. The proposed approach presents a comprehensive Zero-Trust architecture for securing and unifying EV services across retail EV charging, energy trading, and energy management. The analysis illustrates data models, settlement and control flows, but also the security properties established, via a unified blockchain framework, assuming realistic adversarial capabilities.
Georgios Germanos, Alexios Lekidis, Sotirios Brotsis, Nicholas Kolokotronis
Future Gener. Comput. Syst.2
2026 Enhanced-LLM extraction of CTI from unstructured threat reports. A tough nut to crack or a walk in the park?
Konstantina Psarrou, Panagiotis Bountakas, Dimitris Eleutheriou, Rafail A. Ellinitakis, Konstantinos Fysarakis, Alexios Lekidis, George Spanoudakis
Future Gener. Comput. Syst.6
2024 Anomaly detection mechanisms for in-vehicle and V2X systems
abstract
Modern V2X systems have an increasing number of interfaces that allow remote connectivity but also include the risk of exposure to cyber threats. Hence, the attack surface for such threats is constantly increasing, and combined with privacy issues that may arise through the presence of sensitive user data in the V2X ecosystem, this necessitates the requirement for novel security mechanisms. However, the existing mechanisms to ensure protection against such threats face major hurdles, such as 1) the lack of in-vehicle addressing schemes, 2) the abundance of V2X interfaces, and 3) the manufacturer-specific architecture of each vehicle comprised of various heterogeneous systems. On top of these hurdles, a solution should satisfy the real-time requirements of the resource-constrained in-vehicle architecture by remaining lightweight and highly reliable, as well as by avoiding false positive indications and alarms. This article presents a novel anomaly detection solution for addressing the main challenges of security mechanisms by simultaneously keeping a minimal impact on real-time in-vehicle requirements. The solution is demonstrated through an Electric Vehicle (EV) charging hub testbed that implements anomaly detection schemes to detect proof-of-concept cyber-attacks targeting the EV charging profile and causing cascading effects by zeroing the vehicle speed.
Alexios Lekidis
ARES1
2024 Towards 5G Advanced network slice assurance through isolation mechanisms
abstract
The sixth generation of telecommunication networks (6G) offers even faster data rates, lower latency, greater reliability, and higher device density than the currently available 5G infrastructure. Nevertheless, simultaneously these advancements include several challenges in different domains, slowing substantially the transition to it. Hence, 3GPP opts to gradually tackle these challenges in the second phase 5G Advanced release. One of the most significant challenges amongst them lies in the constantly increasing threat landscape from the use of Network Function Virtualization (NFV) technologies for offering services over a shared mobile infrastructure. A mechanism that allows protection against attacks over established network slices is network isolation. This paper proposes isolation schemes to tackle the threats that arise in 5G slices. Such schemes are integrated into Slice Manager components, responsible for the implementation of a fully automated orchestration and lifecycle management of network slices as well as their network segments. The schemes are implemented through Quality of Service (QoS) policies in an Electric Vehicle (EV) charging infrastructure, which includes the EV charging stations, the management platform, a Slice Manager on the edge segment as well as the orchestration components in an Ultra-Reliable Low Latency Communications (URLLC) network slice.
Alexios Lekidis
ARES1
2024 Open V2X Management Platform Cyber-Resilience and Data Privacy Mechanisms
abstract
Vehicle-to-Everything (V2X) technologies have been recently introduced to provide enhanced connectivity between the different smart grid segments as well as Electric Vehicles (EVs). The EVs draw power to the grid and may be used as an energy flexibility resource for households and buildings. The increased number of interconnections though, is augmenting substantially the cyber-security and data privacy threats that may occur in the V2X ecosystem. In this paper, such threats are categorized into cyber-attack classes which serve as a basis for deriving Tactics, Techniques, and Procedures (TTPs) for the V2X ecosystem. Additionally, the sensitive data that are exchanged in charging and discharging scenarios are reviewed. Then, an analysis of the existing cyber-security mechanisms is provided and further mechanisms/tools are proposed for detecting/preventing the categorized threats, which are being developed in an Open V2X Management Platform (O-V2X-MP) within the EV4EU project. These mechanisms will provide security-by-design in O-V2X-MP, as well as ensure protection in the V2X interactions.
Alexios Lekidis, Hugo Morais
ARES1
2024 Towards Incident Response Orchestration and Automation for the Advanced Metering Infrastructure
abstract
The threat landscape of industrial infrastructures has expanded exponentially over the last few years. Such infrastructures include services such as the smart meter data exchange that should have real-time availability. Smart meters constitute the main component of the Advanced Metering Infrastructure, and their measurements are also used as historical data for forecasting the energy demand to avoid load peaks that could lead to blackouts within specific areas. Hence, a comprehensive Incident Response plan must be in place to ensure high service availability in case of cyber-attacks or operational errors. Currently, utility operators execute such plans mostly manually, requiring extensive time, effort, and domain expertise, and they are prone to human errors. In this paper, we present a method to provide an orchestrated and highly automated Incident Response plan targeting specific use cases and attack scenarios in the energy sector, including steps for preparedness, detection and analysis, containment, eradication, recovery, and post-incident activity through the use of playbooks. In particular, we use the OASIS Collaborative Automated Course of Action Operations (CACAO) standard to define highly automatable workflows in support of cyber security operations for the Advanced Metering Infrastructure. The proposed method is validated through an Advanced Metering Infrastructure testbed where the most prominent cyber-attacks are emulated, and playbooks are instantiated to ensure rapid response for the containment and eradication of the threat, business continuity on the smart meter data exchange service, and compliance with incident reporting requirements.
Alexios Lekidis, Vasileios Mavroeidis, Konstantinos Fysarakis
WFCS1
2023 ELECTRON: An Architectural Framework for Securing the Smart Electrical Grid with Federated Detection, Dynamic Risk Assessment and Self-Healing
abstract
The electrical grid has significantly evolved over the years, thus creating a smart paradigm, which is well known as the smart electrical grid. However, this evolution creates critical cybersecurity risks due to the vulnerable nature of the industrial systems and the involvement of new technologies. Therefore, in this paper, the ELECTRON architecture is presented as an integrated platform to detect, mitigate and prevent potential cyberthreats timely. ELECTRON combines both cybersecurity and energy defence mechanisms in a collaborative way. The key aspects of ELECTRON are (a) dynamic risk assessment, (b) asset certification, (c) federated intrusion detection and correlation, (d) Software Defined Networking (SDN) mitigation, (e) proactive islanding and (f) cybersecurity training and certification.
Panagiotis I. Radoglou-Grammatikis, Thanasis Liatifis, Christos Dalamagkas, Alexios Lekidis, Konstantinos Voulgaridis, Thomas Lagkas, Nikolaos Fotos, Sofia-Anna Menesidou, Thomas Krousarlis, Pedro Ruzafa Alcazar, Juan Francisco Martinez, Antonio F. Skarmeta, Alberto Molinuevo Martín, Iñaki Angulo, Jesus Villalobos Nieto, Hristo Koshutanski, Rodrigo Diaz Rodriguez, Ilias Siniosoglou, Orestis Mavropoulos, Konstantinos Kyranou, Theocharis Saoulidis, Allon Adir, Ramy Masalha, Emanuele Bellini 0001, Nicholas Kolokotronis, Stavros Shiaeles, Jose Garcia Franquelo, George Lalas, Andreas Zalonis, Antonis Voulgaridis, Angelina D. Bintoudi, Konstantinos Votis, David Pampliega, Panagiotis G. Sarigiannidis
ARES4
2023 AMINet: An Industrial Honeynet for AMI Systems
abstract
Advanced Metering Infrastructure (AMI) systems constitute a vital part for the interconnection of the electrical grid towards enabling the smart grid area. They enable real-time electrical measurement exchange through a utility platform, in order to activate billing and load demand forecasting processes. However, the cyber-attack surface of such systems has increased over the latest years. The attacks are becoming highly sophisticated and cannot be detected by the existing cyber-security mechanisms. To cope with this challenge, these mechanisms should start incorporating knowledge about adversarial Tactics, Techniques are Procedures (TTPs). To achieve this, deception tools are used to lure adversaries by introducing an environment that resembles the actual system. In this paper we propose AMINet, which builds on a composition of well-known deception tools as honeypots to form a honeynet for AMI systems. Specifically, this work focuses on AMINet first architectural design with an emphasis on its emulation capabilities on the behavior and interactions between smart meters and the utility platform using the DLMS/COSEM protocol. Furthermore, AMINet is deployed in an production-level AMI infrastructure and compared against the actual AMI system that is available on the utility business side. The comparison results demonstrate a similar behavior, which is validated through initial tests on functional and non-functional requirements. Additionally, the existing small set of static attacks running in the infrastructure is enriched by more sophisticated attacks and AMINet aids towards the development of dedicated detection tools by logging the adversarial interactions.
Alexios Lekidis, George Daniil, Panagiotis Mavrommatis, Konstantinos Lampropoulos 0001, Odysseas G. Koufopavlou
IEEE Big Data1
2022 Cyber-security measures for protecting EPES systems in the 5G area
abstract
The recent technological advance in the fifth generation of telecommunication networks (5G) has led to a evolutions in many domains, including connected cars, manufacturing and electricity. A technological domain that had large benefits from this advance is the Electrical Power and Energy System (EPES). Despite the simplicity and efficiency that 5G brings there are also underlying risks that are slowing down its adoption. These risks are caused by the presence of convergence connectivity interfaces in legacy infrastructures that were built with no security in mind. Specifically, EPES systems are often targeted by cyber criminals to cause massive blackouts in entire cities or countries that in turn lead to societal impact, such as consumer discomfort. In this work we propose a cyber-security measures for 1) early-stage detection of cyber-security incidents and 2) protecting against them through applicable security measures. The proposed measures are applied to a Hydroelectric Power Plant (HPP) of the Public Power Corporation (PPC). The cyber-attacks are performed in a 5G-enabled smart meter that measures power production and transmits measurements to PPC’s control center through the use of 5G Network Function Virtualization (NFV) technologies, such as network slicing. To protect against the attacks, cyber-security measures are applied and incorporated in a cyber-security platform, that was developed within the PHOENIX H2020 project. The measures are used to detect the attacks and perform necessary mitigation actions for restoring the HPP operation.
Alexios Lekidis
ARES1
2021 Dynamic Slice Scaling Mechanisms for 5G Multi-domain Environments
abstract
Network slicing is an essential 5G innovation whereby the network is partitioned into logical segments, so that Communication Service Providers (CSPs) can offer differentiated services for verticals and use cases. In many 5G use cases, network requirements vary over time and CSPs must dynamically adapt network slices to satisfy the contractual network slice QoS, cooperating and using each others’ resources, e.g. when resources of a single CSP are not sufficient or suitable to maintain all it’s current SLAs. While this need for dynamic cross-CSP cooperation is widely recognized, realization of this need is not yet possible due to gaps both in business processes and in technical capabilities.In this paper, we present a 5GZORRO approach to dynamic cross-CSP slice scaling. Our approach both enables CSPs to collaborate, providing security and trust with smart multi-party contracts, and facilitates thus achieved collaboration to enable resource sharing across multiple administrative domains, either during slice establishment or when already existing slice needs to expand or shrink. Our approach allows automating both business and technical processes involved in dynamic lifecycle management of cross-CSP network slices, following ETSI’s Zero-Touch Network and Service Management (ZSM) closed-loop architecture, and relying on resource-sharing Marketplace, Distributed Ledger (DL), and Operational Data Lake. We show how this approach is realized in truly Cloud Naive way, with Kubernetes as both business and technical cross-domain orchestrator. We then showcase applicability of the proposed solution for dynamic scaling of Content Delivery Network (CDN) service.
David Breitgand, Alexios Lekidis, Rasoul Behravesh, Avi Weit, Pietro G. Giardina, Vasileios Theodorou, Cristina Emilia Costa, Katherine Barabash
NetSoft2
2021 C-V2X network slicing framework for 5G-enabled vehicle platooning applications
abstract
The fifth generation (5G) of mobile networks is steering the technological evolution of many application domains, including many demanding automotive scenarios, such as platooning. Such evolution combines softwarization enablers (e.g., Network Function Virtualization (NFV) and Software-Defined Networking (SDN)) with Cellular Vehicle-to-Everything (C-V2X) communication to form end-to-end network slices with 5G infrastructure resources. Unlike the currently used 802.11p standard, the adoption of these technologies would support Ultra-Reliable Low-Latency Communication (URLLC) between the platoon members and would offer better network coverage, which in turn would allow faster remote monitoring and operation of the entire platoons. In this paper, we present a novel C-V2X network slicing framework for platooning applications. The proposed framework includes a library of C-V2X Virtual Network Functions (VNFs) that can be used to customize network slices spanning over the entire 5G infrastructure. The implementation also includes edge computing functions to provide further latency and performance improvements as well as network security monitoring functions to provide cyber-resilience for the platoon. We have conducted implementation tests on a real 5G infrastructure forming a truck platoon in an automotive campus. The results demonstrate the support of URLLC on the C-V2X connectivity between trucks, which opens new horizons towards the adoption of C-V2X network slices in future platooning applications.
Alexios Lekidis, Faouzi Bouali
VTC Spring1
2021 Energy characterization of IoT systems through design aspect monitoring
Alexios Lekidis, Panagiotis Katsaros
Int. J. Softw. Tools Technol. Transf.1
2020 Security and Privacy in Smart Grids: Challenges, Current Solutions and Future Opportunities
abstract
Smart grids are a promising upgrade to legacy power grids due to enhanced cooperation of involved parties, such as consumers and utility providers. These newer grids improve the efficiency of electricity generation and distribution by leveraging communication networks to exchange information between those different parties. However, the increased connection and communication also expose the control networks of the power grid to the possibility of cyber-attacks. Therefore, research on cybersecurity for smart grids is crucial to ensure the safe operation of the power grid and to protect the privacy of consumers. In this paper, we investigate the security and privacy challenges of the smart grid; present current solutions to these challenges, especially in the light of intrusion detection systems; and discuss how future grids will create new opportunities for cybersecurity.
Ismail Butun, Alexios Lekidis, Daniel Ricardo dos Santos
ICISSP2
2019 Access control in Internet-of-Things: A survey
Sowmya Ravidas, Alexios Lekidis, Federica Paci, Nicola Zannone
J. Netw. Comput. Appl.2
2018 Model-based design of IoT systems with the BIP component framework
abstract
Summary The design of software for networked systems with nodes running an Internet of things operating system faces important challenges due to the heterogeneity of interacting things and the constraints stemming from the often limited amount of available resources. In this context, it is hard to build confidence that a design solution fulfills the application's requirements. This paper introduces a design flow for web service applications of the representational state transfer style that is based on a formal modeling language, the behaviour, interaction, priority (BIP) component framework. The proposed flow applies the principles of separation of concerns in a component‐based design process that supports the modular design and reuse of model artifacts. The BIP tools for state‐space exploration allow verifying qualitative properties for service responsiveness, ie, the timely handling of events. Moreover, essential quantitative properties are validated through statistical model checking of a stochastic BIP model. All properties are preserved in actual implementation by ensuring that the deployed code is consistent with the validated model. We illustrate the design of a representational state transfer sense‐compute‐control application for a Wireless Personal Area Network architecture with nodes running the Contiki operating system. The results validate qualitative and quantitative properties for the system and include the study of error behaviours.
Alexios Lekidis, Emmanouela Stachtiari, Panagiotis Katsaros, Marius Bozga, Christos K. Georgiadis
Softw. Pract. Exp.1