Vasileios Gkioulos

dblp:189/4758 · DBLP profile ↗
← Back
18ranked-venue papers
2as first author
12since 2021 · last 2025
0000-0001-7304-3835ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 1 first-author · 11 since 2021Artificial intelligence and machine learning · 1Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 Cracks in the chain: A technical analysis of real-life supply chain security incidents
abstract
As Industry 5.0 drives greater digitalization and interconnectivity, supply chains have become vital to global commerce, ensuring the seamless flow of goods, services, and data. However, this reliance has also swelled the attack surface, rendering supply chains a prime target for evildoers. Meanwhile, the inherent complexity of supply chain ecosystems prevents defenders from fully applying contemporary security controls promptly and effectively. Clearly, the combination of these hindering factors has led to some of the most severe cybersecurity incidents of the past years. This study is the first to our knowledge that undertakes a comprehensive technical analysis of reported supply chain security incidents. Our analysis is done both from offensive and defensive prisms, leveraging well-established cybersecurity frameworks and guidelines, namely, the ATT&CK MITRE knowledge base matrix and the NIST SP 800-161, respectively. Furthermore, to consolidate our findings and facilitate future research initiatives, we compiled a fundamental dataset that can be used as the basis for automated analysis and potential integration with cybersecurity workflows. The key observations of a 33-incident analysis through the lens of an ATT&CK MITRE- and NIST SP 800-161-based taxonomies we propose can be wrapped up into two key points. First, the attack surface continues to expand, following an upward spiral due to the mushrooming of tactics and techniques that can facilitate the early or late stages of attacks, highlighting their complexity, sophistication, and widespread impact. Second, our findings underscore the necessity of a multifaceted approach to strengthening supply chain resilience. This includes implementing robust cybersecurity controls, comprehensive risk assessment methodologies, and transparent collaboration among suppliers, customers, and vendors to ensure adherence to state-of-the-art cybersecurity best practices.
Vyron Kampourakis, Georgios Kavallieratos, Vasileios Gkioulos, Sokratis K. Katsikas
Comput. Secur.3
2025 A step-by-step definition of a reference architecture for cyber ranges
abstract
Being on the advent of Industry 5.0, organizations have been progressively incorporating information technology into their formerly air-gapped operational technology architectures. This coalescence has nevertheless amplified the attack surface, ringing the bells of preparedness. In this direction, Cyber Ranges (CRs) have cropped up as a valuable and attractive solution, providing a diverse perspective on reinforcing the overall cybersecurity stance. However, there exists a significant literature gap in attempts to define a complete approach for CR design, development, evaluation, and operation as per the up-to-date guidelines. To address this shortcoming, this work introduces the first to our knowledge overarching, fine-grained reference architecture for CR. This is done by adopting a three-step, systematic methodology. First, we scrutinize contemporary guidelines to extract an abstract architectural model that structurally entrenches the foundations of CR reference architecture. Then, we percolate and pinpoint common functionalities and capabilities of existing CRs, towards delineating the functional and informational aspects of the reference architecture. Finally, we devise an evaluation formula that approximates the conformance of a CR with the state-of-the-art. Through the latter step, we impart a unified means of identifying the most appropriate components to implement the structural, functional, and informational aspects of a CR. Overall, this work can be seen as an attempt towards CR unification and standardization, therefore it is anticipated to serve as a basis and point of reference for multiple stakeholders at varying levels.
Vyron Kampourakis, Vasileios Gkioulos, Sokratis K. Katsikas
J. Inf. Secur. Appl.2
2024 Vulnerability management digital twin for energy systems
abstract
Increasing cyber attacks underscore the importance of addressing system vulnerabilities to reduce security risks. To structure our workflow of vulnerability management, we made use of relevant and widely adopted industrial standards, while also incorporating the concept of digital twins. Therefore, this research suggests a vulnerability management digital twin that aligns with the ISO 23247-2 framework. It specifically emphasizes recommendations for the ‘data collection’ function following the workflow outlined in IEC 62443-2-3, and exemplifying use cases based on a typical automation architecture of energy systems. We evaluated the CVSS framework to prioritize scores and also examined ways to integrate CVSS with other contextual information to develop a mitigation deployment strategy. The goal is to assist asset owners in optimising resource utilization in addressing vulnerabilities.
Jessica B. Heluany, Johannes Götzfried, Bernhard Mehlig, Vasileios Gkioulos
ARES4
2024 NEWSROOM: Towards Automating Cyber Situational Awareness Processes and Tools for Cyber Defence
abstract
Cyber Situational Awareness (CSA) is an important element in both cyber security and cyber defence to inform processes and activities on strategic, tactical, and operational level. Furthermore, CSA enables informed decision making. The ongoing digitization and interconnection of previously unconnected components and sectors equally affects the civilian and military sector. In defence, this means that the cyber domain is both a separate military domain as well as a cross-domain and connecting element for the other military domains comprising land, air, sea, and space. Therefore, CSA must support perception, comprehension, and projection of events in the cyber space for persons with different roles and expertise. This paper introduces NEWSROOM, a research initiative to improve technologies, methods, and processes specifically related to CSA in cyber defence. For this purpose, NEWSROOM aims to improve methods for attacker behavior classification, cyber threat intelligence (CTI) collection and interaction, secure information access and sharing, as well as human computer interfaces (HCI) and visualizations to provide persons with different roles and expertise with accurate and easy to comprehend mission- and situation-specific CSA. Eventually, NEWSROOM’s core objective is to enable informed and fast decision-making in stressful situations of military operations. The paper outlines the concept of NEWSROOM and explains how its components can be applied in relevant application scenarios.
Markus Wurzenberger, Stephan Krenn, Max Landauer, Florian Skopik, Cora Lisa Perner, Jarno Lötjönen, Jani Päijänen, Georgios Gardikis, Nikos Alabasis, Liisa Sakerman, Kristiina Omri, Juha Röning, Kimmo Halunen, Vincent Thouvenot, Martin Weise, Andreas Rauber, Vasileios Gkioulos, Sokratis K. Katsikas, Luigi Sabetta, Jacopo Bonato, Rocío Ortíz, Daniel Navarro, Nikolaos Stamatelatos, Ioannis Avdoulas, Rudolf Mayer, Andreas Ekelhart, Ioannis Giannoulakis, Emmanouil Kafetzakis, Antonello Corsi, Ulrike Lechner, Corinna Schmitt
ARES17
2023 Survey on Digital Twins: from concepts to applications
abstract
This study provides a systematic literature review on surveys across the topic of digital twins. The aim is to understand what have been the use cases, modelling and simulation tools/techniques, and how security is being addressed. To answer these research questions, a rigorous methodology consisting of seven steps was followed. The analysis shows that there is a misconception regarding the digital twin concept that may be leading to its misuse. Moreover, it was found that security is not a top priority, but is often mentioned as a challenge. Besides the lack of standardization, the amount of academic papers published and industrial solutions offered is increasing, showing that the consensus is not a limiting factor and the concept is gaining popularity over the years and being applied in an increasing number of sectors, mainly on manufacturing, energy, aerospace and automotive.
Jessica B. Heluany, Vasileios Gkioulos
ARES2
2023 Towards a DevSecOps-Enabled Framework for Risk Management of Critical Infrastructures
Xhesika Ramaj, Ricardo Colomo-Palacios, Mary-Luz Sánchez-Gordón, Vasileios Gkioulos
EuroSPI (1)4
2023 A systematic literature review on wireless security testbeds in the cyber-physical realm
abstract
The Cyber-Physical System (CPS) lies in the core of Industry 4.0, accelerating the convergence of formerly barricaded operational technology systems with modern information technology ones. Nevertheless, the increased connectivity in terms of both wired and wireless links and associated attack surfaces that comes along, requires higher security for safeguarding critical industrial systems and manufacturing lines from cyberattacks. In this rapidly evolving ecosystem, security testbeds have emerged as a versatile, cost-effective solution for investigating potential attack vectors and devising appropriate countermeasures, without putting the real system at risk. The present work seeks to address a prominent literature gap, namely, the lack of a systematic review regarding the use of wireless-oriented security testbeds in CPS. We contribute an overarching, manifold review on this topic from 2016 onward, examining the various literature works from diverse angles, namely, the wireless technologies used, the implemented attacks, the employed security controls, and more. The analysis is done on a per-sector basis, including water and wastewater systems, healthcare, transportation, agriculture, energy, maritime, unmanned aircraft systems, and others. Finally yet importantly, we discuss key takeaways, open issues, and challenges. The key observations of our analysis, including almost 50 articles, can be wrapped up into two salient points: on the one hand, wireless technologies are increasingly penetrating into the CPS domain as an orthogonal, versatile solution to their wired counterparts, but on the other, they widen the window of opportunity for threat actors targeting wireless links. In this context, testbed thoroughness and security as a trade-off seem to be of major importance, alongside a modular, possibly sector-neutral reference architecture that overarches the peculiarities of CPS. Overall, to our knowledge, this work provides the first full-fledged survey on the use of wireless-oriented security testbeds in CPS, and it is therefore anticipated to serve as a groundwork and touchstone for several stakeholders at different levels.
Vyron Kampourakis, Vasileios Gkioulos, Sokratis K. Katsikas
Comput. Secur.2
2023 Assessing Cyber Risk in Cyber-Physical Systems Using the ATT&CK Framework
abstract
Autonomous transport is receiving increasing attention, with research and development activities already providing prototype implementations. In this article we focus on Autonomous Passenger Ships (APS) , which are being considered as a solution for passenger transport across urban waterways. The ambition of the authors has been to examine the safety and security implications of such a Cyber Physical System (CPS) , particularly focusing on threats that endanger the passengers and the operational environment of the APS. Accordingly, the article presents a new risk assessment approach based on a Failure Modes Effects and Criticality Analysis (FMECA) that is enriched with selected semantics and components of the MITRE ATT&CK framework, in order to utilize the encoded common knowledge and facilitate the expression of attacks. Then, the proposed approach is demonstrated through conducting a risk assessment for a communication architecture tailored to the requirements of APSs that were proposed in earlier work. Moreover, we propose a group of graph theory-based metrics for estimating the impact of the identified risks. The use of this method has resulted in the identification of risks and their corresponding countermeasures, in addition to identifying risks with limited existing mitigation mechanisms. The benefits of the proposed approach are the comprehensive, atomic, and descriptive nature of the identified threats, which reduce the need for expert judgment, and the granular impact estimation metrics that reduce the impact of bias. All these features are provided in a semi-automated approach to reduce the required effort and collectively are argued to enrich the design-level risk assessment processes with an updatable industry threat model standard, namely ATT&CK.
Ahmed Amro, Vasileios Gkioulos, Sokratis K. Katsikas
ACM Trans. Priv. Secur.2
2022 Properties for Cybersecurity Awareness Posters' Design and Quality Assessment
abstract
Posters are widely in practice to communicate cybersecurity awareness (CSA) messages. This popularity could be because it is one of the simplest mechanisms, and most people are accustomed to poster usage. Despite this, very little effort has been made to make the CSA poster design and assessment more systematic. Due to this, there exists a wide variation in CSA poster design. Alarmingly, many of them do not align with the needs and objectives of CSA. This study, therefore, intends to collect and analyze the properties that can guide the production of more uniform and effective posters for CSA purposes. At the same time, the study contributes to making the poster design and quality assessment approach more systematic. In order to do so, this study used a literature review for the elicitation of properties and an online assessment to analyze the relevancy of the elicited properties. As a final result, the study provides six main properties (i.e., topic, information quality, message framing, suggestions quality, content presentation, localization, and style and formatting) and their respective twenty-one sub-properties that can facilitate CSA poster design and its quality assessment.
Sunil Chaudhary, Marko Kompara, Sebastian Pape 0001, Vasileios Gkioulos
ARES4
2022 From Click to Sink: Utilizing AIS for Command and Control in Maritime Cyber Attacks
Ahmed Amro, Vasileios Gkioulos
ESORICS (3)2
2022 Modeling effective cybersecurity training frameworks: A delphi method-based study
abstract
Today, cybersecurity training is commonplace in both large companies and Small & Medium Enterprise (SME). Nonetheless, the effectiveness of many of the current training offerings is put into question by reports of increasing successful cyber-attacks. While a number of models for developing Cybersecurity (CS) training frameworks for industrial personnel or general audience have been proposed, these models often lack consideration for humans aspects of learning (cognitive abilities, learning styles, meta-cognition among others) during development. Additionally, the success of a CS training program highly depends on its ability to engage participants. To develop a CS training framework that is able to motivate participants, we must consider individual-specific factors that can affect the result of training, besides establishing optimal training delivery methods and assessment. For this, in this work we propose a CS training framework based on a revised version of the ADDIE model and more recent research personalised learning theory. The Delphi method was used to both develop and validate our decisions during the development of the training framework model. The results of the decision of the Delphi method have later been compared to recommendations in the literature to create the finalised framework. This work presents two major distinctions from other CS training frameworks models described in the literature. First, the developed model is strongly based in learning theory foundations and takes into consideration differences in learning styles, cognitive abilities and metacognition of individuals, to offer tailored solutions optimized for each group of employees and single individual. Second, the use of the Delphi method and the involvement of experts stakeholders from various sides of academia and industry gave a wide insight into current needs and recommendations for CS training, as well as formal validation for the final development.
Nabin Chowdhury, Sokratis K. Katsikas, Vasileios Gkioulos
Comput. Secur.3
2021 Key competencies for critical infrastructure cyber-security: a systematic literature review
abstract
Purpose The purpose of this paper can be encapsulated in the following points: identify the research papers published on the topic: competencies and skills necessary for critical infrastructure (CI) cyber-security (CS) protection; determine main focus areas within the identified literature and evaluate the dependency or lack thereof between them: make recommendations for future research. Design/methodology/approach This study is based on a systematic literature review conducted to identify scientific papers discussing and evaluating competencies, skills and essential attributes needed by the CI workforce for CS and preparedness to attacks and incidents. Findings After a comparative analysis of the articles reviewed in this study, a variety of skills and competencies was found to be necessary for CS assurance in CIs. These skills have been grouped into four categories, namely, technical, managerial, implementation and soft skills. Nonetheless, there is still a lack of agreement on which skills are the most critical and further research should be conducted on the relation between specific soft skills and CS assurance. Research limitations/implications Investigation of which skills are required by industry for specific CS roles, by conducting interviews and sending questionnaire\surveys, would allow consolidating whether literature and industry requirements are equivalent. Practical implications Findings from this literature review suggest that more effort should be taken to conciliate current CS curricula in academia with the skills and competencies required for CS roles in the industry. Originality/value This study provides a previously lacking current mapping and review of literature discussing skills and competencies evidenced as critical for CS assurance for CI. The findings of this research are useful for the development of comprehensive solutions for CS awareness and training.
Nabin Chowdhury, Vasileios Gkioulos
Inf. Comput. Secur.2
2020 Modelling Shipping 4.0: A Reference Architecture for the Cyber-Enabled Ship
Georgios Kavallieratos, Sokratis K. Katsikas, Vasileios Gkioulos
ACIIDS (2)3
2020 Cyber ranges and security testbeds: Scenarios, functions, tools and architecture
Muhammad Mudassar Yamin, Basel Katt, Vasileios Gkioulos
Comput. Secur.3
2019 Threat Analysis in Dynamic Environments: The Case of the Smart Home
abstract
The rapid advancement of information and communication technologies has fostered the development and deployment of complex interrelated systems, many of which also present highly dynamic operational characteristics. These are further integrated within highly connected environments such as smart cities, smart homes, and smart cars, continuously adopting new technological developments. In this article, we focus on the smart home environment, as a case study for such ecosystems, where the integration of IoT devices increases the attack surface, evaluating whether existing risk assessment methods can be utilized for the identification and monitoring of risks, while also capturing the dynamic operational aspects. Accordingly, we review existing dynamic risk assessment methodologies and we leverage a smart home reference architecture to identify the security threats of a smart home's physical and communication viewpoints by leveraging the STRIDE methodology and Microsoft's threat modelling tool.
Georgios Kavallieratos, Vasileios Gkioulos, Sokratis K. Katsikas
DCOSS2
2019 Dynamic setup of IPsec VPNs in service function chaining
Håkon Gunleifsen, Thomas Kemmerich, Vasileios Gkioulos
Comput. Networks3
2017 Security Infrastructure for Service Oriented Architectures at the Tactical Edge
Vasileios Gkioulos, Stephen D. Wolthusen
CISIS1
2017 TACTICS: Validation of the security framework developed for tactical SOA
Vasileios Gkioulos, Erko Risthein, Stephen D. Wolthusen
J. Inf. Secur. Appl.1