EDBT 2026 Demo / reviewers in the wild / expert
Charalampos Katsis
dblp:274/7829
· DBLP profile ↗
5ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0002-1876-8478ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | IoTDSCreator: A Framework to Create Labeled Datasets for IoT Intrusion Detection SystemsabstractIntrusion detection systems (IDSes) are critical building blocks for securing Internet-of-Things (IoT) devices and networks. Advances in AI techniques are contributing to enhancing the efficiency of IDSes, but their performance typically depends on high-quality training datasets. The scarcity of such datasets is a major concern for the effective use of machine learning for IDSes in IoT networks. To address such a need, we present IoTDSCreator - a tool for the automatic generation of labeled datasets able to support various devices, connectivity technologies, and attacks. IoTDSCreator provides a user with DC-API, an API by which the user can describe a target network and an attack scenario against it. Based on the description, the framework configures the network, leveraging virtualization techniques on user-provided physical machines, performs single or multi-step attacks, and finally returns labeled datasets. Thereby, IoTDSCreator dramatically reduces the manual effort for generating labeled and diverse datasets. We release the source code of IoTDSCreator and 16 generated datasets with 193 features based on 26 types of IoT devices, 2 types of communication links, and 15 types of IoT applications. Hyunwoo Lee 0001, Charalampos Katsis, Alireza Lotfi, Taejun Choi, Soeun Kim, Ashish Kundu, Elisa Bertino |
CODASPY | 2 |
| 2025 | ZT-XPN: An End-to-End Zero-Trust Architecture for Next Generation Programmable NetworksabstractZero-trust architecture (ZTA) mandates strict internal and perimeter defenses, ensuring communication occurs solely on a per-request and need-only basis. Achieving this requires robust access control (AC) policies enforced throughout the network. Software-Defined Networks (SDN) and programmable data planes are crucial in implementing ZTA. SDN's centralized management streamlines access request authorization, while data plane programmability enables the direct execution of various tasks such as error checking and stateful AC. However, significant challenges persist. Administrators must define a comprehensive network-wide security policy that accommodates the communication needs of all endpoints, such as users, IoT and services. Moreover, they must manually design and deploy data plane programs to enforce these policies and separately orchestrate the control plane operations for centralized policy deployment, management, and monitoring. This paper presents ZT-XPN, the first end-to-end framework designed to address these challenges. ZT-XPN consists of three key components: (1) a graph-based policy specification tool that enables the precise and fine-grained definition of complex network-wide policies, allowing for detailed endpoint and protocol-level control; (2) a back-end compiler integrated with ONOS SDN controller that processes these requirements, automatically generating data plane programs and orchestrates the control plane to support those programs and (3) a runtime management system for policy management and runtime monitoring. We evaluate our architecture in an SDN network environment with varying scales, including end systems and BMv2 programmable switches. We also compare the performance of our approach with baseline open-source implementations for packet forwarding and a stateful firewall. Charalampos Katsis, Elisa Bertino |
NetSoft | 1 |
| 2025 | ZT-SDN: An ML-Powered Zero-Trust Architecture for Software-Defined NetworksabstractZero Trust (ZT) is a security paradigm aiming to curtail an attacker’s lateral movements within a network by implementing least-privilege and per-request access control policies. However, its widespread adoption is hindered by the difficulty of generating proper rules owing to the lack of detailed knowledge of communication requirements and the characteristic behaviors of communicating entities under benign conditions. Consequently, manual rule generation becomes cumbersome and error prone. To address these problems, we propose ZT-SDN , an automated framework for learning and enforcing network access control in Software-Defined Networks (SDNs). ZT-SDN collects data from the underlying network and models the network “transactions” performed by communicating entities as graphs. The nodes represent entities, whereas the directed edges represent transactions identified by different protocol stacks observed. It uses novel unsupervised learning approaches to extract transaction patterns directly from the network data, such as the allowed protocol stacks and port numbers and data transmission behavior. Finally, ZT-SDN uses an innovative approach to generate correct access control rules and infer strong associations between them, allowing proactive rule deployment in forwarding devices. We show the framework’s efficacy in detecting abnormal network accesses and abuses of permitted flows in changing network conditions with real network datasets. Additionally, we showcase ZT-SDN’s scalability and the network’s performance when applied in an SDN environment. Charalampos Katsis, Elisa Bertino |
ACM Trans. Priv. Secur. | 1 |
| 2022 | NEUTRON: A Graph-based Pipeline for Zero-trust Network ArchitecturesabstractThe Zero-Trust Architecture (ZTA) security paradigm deploys comprehensive user- and resource-aware defenses both at the network's perimeter and inside the network. However, deploying a ZTA approach requires specifying and managing a large, network spanning set of fine-grained security policies, which will increase administrators' workloads and increase the chance of errors. This paper presents the design and prototype implementation of the NEUTRON policy framework, which provides an automated end-to-end policy pipeline, specification, management, testing, and deployment. NEUTRON uses a flexible, graph-based approach to specify and share complex, fine-grained network security policies. NEUTRON provides a software structure so that policy patterns may be easily shared between organizations, reducing the burden of creating the policy. Administrators assemble the software for their site, and the NEUTRON policy generator creates the entire network-wide security policy. Treating the security policy like software also allows new approaches to policy verification and policy change impact analysis. Thus we designed the Security Policy Regression Tool (SPRT), which uses our novelRuleset Aggregation Algorithm to perform scalable verification of the network-wide security policy across the network model. Moreover, our graph-based framework allows for efficient computation and visualization of the policy change impact. Charalampos Katsis, Fabrizio Cicala, Dan Thomsen, Nathan Ringo, Elisa Bertino |
CODASPY | 1 |
| 2021 | Can I Reach You? Do I Need To? New Semantics in Security Policy Specification and TestingabstractThe zero trust principle only allows authorized and authenticated actions in a computer network. A network policy satisfies the least privilege principle by minimizing the network permissions to only those needed by users and applications. However, administrators face many challenges in creating a least privilege policy since it requires a detailed understanding of the network topology and knowing the communication requirements of every network application and user. This paper addresses those challenges by introducing a graph-based policy specification framework to capture a network's communication requirements and a network compiler that turns those requirements into an enforceable policy. To offset the effort of building such a stringent policy, we incorporate patterns to spread the work of policy creation over time and people. In the paper, we first elaborate on how our framework's semantics enhances network security and resilience. We then introduce a Security Policy Regression Testing tool (SPRT), which leverages our framework's semantics, to test and reason about consistency, correctness, and relevance of network security policies. Finally, we outline relevant research directions. Charalampos Katsis, Fabrizio Cicala, Dan Thomsen, Nathan Ringo, Elisa Bertino |
SACMAT | 1 |