EDBT 2026 Demo / reviewers in the wild / expert
Spyros Kokolakis
dblp:29/4917
· DBLP profile ↗
27ranked-venue papers
4as first author
6since 2021 · last 2024
0000-0001-6255-1922ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 4 first-author · 6 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Security, Privacy and the "Human Factor": Making Sense of the Paradoxes of Security and Privacy Behaviour
Spyros Kokolakis |
ICISSP | 1 |
| 2024 | Exploring users' attitude towards privacy-preserving search engines: a protection motivation theory approachabstractPurpose Search engines, the most popular online services, are associated with several concerns. Users are concerned about the unauthorized processing of their personal data, as well as about search engines keeping track of their search preferences. Various search engines have been introduced to address these concerns, claiming that they protect users’ privacy. The authors call these search engines privacy-preserving search engines (PPSEs). This paper aims to investigate the factors that motivate search engine users to use PPSEs. Design/methodology/approach This study adopted protection motivation theory (PMT) and associated its constructs with subjective norms to build a comprehensive research model. The authors tested the research model using survey data from 830 search engine users worldwide. Findings The results confirm the interpretive power of PMT in privacy-related decision-making and show that users are more inclined to take protective measures when they consider that data abuse is a more severe risk and that they are more vulnerable to data abuse. Furthermore, the results highlight the importance of subjective norms in predicting and determining PPSE use. Because subjective norms refer to perceived social influences from important others to engage or refrain from protective behavior, the authors reveal that the recommendation from people that users consider important motivates them to take protective measures and use PPSE. Research limitations/implications Despite its interesting results, this research also has some limitations. First, because the survey was conducted online, the study environment was less controlled. Participants may have been disrupted or affected, for example, by the presence of others or background noise during the session. Second, some of the survey items could possibly be misinterpreted by the respondents in the study questionnaire, as they did not have access to clarifications that a researcher could possibly provide. Third, another limitation refers to the use of the Amazon Turk tool. According Paolacci and Chandler (2014) in comparison to the US population, the MTurk workers are more educated, younger and less religiously and politically diverse. Fourth, another limitation of this study could be that Actual Use of PPSE is self-reported by the participants. This could cause bias because it is argued that internet users’ statements may be in contrast with their actions in real life or in an experimental scenario (Berendt et al., 2005, Jensen et al., 2005); Moreover, some limitations of this study emerge from the use of PMT as the background theory of the study. PMT identifies the main factors that affect protection motivation, but other environmental and cognitive factors can also have a significant role in determining the way an individual’s attitude is formed. As Rogers (1975) argued, PMT as proposed does not attempt to specify all of the possible factors in a fear appeal that may affect persuasion, but rather a systematic exposition of a limited set of components and cognitive mediational processes that may account for a significant portion of the variance in acceptance by users. In addition, as Tanner et al. (1991) argue, the ‘PMT’s assumption that the subjects have not already developed a coping mechanism is one of its limitations. Finally, another limitation is that the sample does not include users from China, which is the second most populated country. Unfortunately, DuckDuckGo has been blocked in China, so it has not been feasible to include users from China in this study. Practical implications The proposed model and, specifically, the subjective norms construct proved to be successful in predicting PPSE use. This study demonstrates the need for PPSE to exhibit and advertise the technology and measures they use to protect users’ privacy. This will contribute to the effort to persuade internet users to use these tools. Social implications This study sought to explore the privacy attitudes of search engine users using PMT and its constructs’ association with subjective norms. It used the PMT to elucidate users’ perceptions that motivate them to privacy adoption behavior, as well as how these perceptions influence the type of search engine they use. This research is a first step toward gaining a better understanding of the processes that drive people’s motivation to, or not to, protect their privacy online by means of using PPSE. At the same time, this study contributes to search engine vendors by revealing that users’ need to be persuaded not only about their policy toward privacy but also by considering and implementing new strategies of diffusion that could enhance the use of the PPSE. Originality/value This research is a first step toward gaining a better understanding of the processes that drive people’s motivation to, or not to, protect their privacy online by means of using PPSEs. Andreas Skalkos, Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis |
Inf. Comput. Secur. | 4 |
| 2023 | Continuous authentication with feature-level fusion of touch gestures and keystroke dynamics to solve security and usability issues
Ioannis Stylios, Sotirios Chatzis, Olga Thanou, Spyros Kokolakis |
Comput. Secur. | 4 |
| 2022 | BioGames: a new paradigm and a behavioral biometrics collection tool for research purposesabstractPurpose The purpose of this paper is to present a new paradigm, named BioGames, for the extraction of behavioral biometrics (BB) conveniently and entertainingly. To apply the BioGames paradigm, the authors developed a BB collection tool for mobile devices named BioGames App. The BioGames App collects keystroke dynamics, touch gestures, and motion modalities and is available on GitHub. Interested researchers and practitioners may use it to create their datasets for research purposes. Design/methodology/approach One major challenge for BB and continuous authentication (CA) research is the lack of actual BB datasets for research purposes. The compilation and refinement of an appropriate set of BB data constitute a challenge and an open problem. The issue is aggravated by the fact that most users are reluctant to participate in long demanding procedures entailed in the collection of research biometric data. As a result, they do not complete the data collection procedure, or they do not complete it correctly. Therefore, the authors propose a new paradigm and introduce a BB collection tool, which they call BioGames, for the extraction of biometric features in a convenient way. The BioGames paradigm proposes a methodology where users play games without participating in an experimental painstaking process. The BioGames App collects keystroke dynamics, touch gestures, and motion modalities. Findings The authors proposed a new paradigm for the collection of BB on mobile devices and created the BioGames application. The BioGames App is an Android application that collects BB data on mobile devices and sends them to a database. The database design allows multiple users to store their sensor data at any time. Thus, there is no concern about data separation and synchronization. BioGames App is General Data Protection Regulation (GDPR) compliant as it collects and processes only anonymous data. Originality/value The BioGames App is a publicly available tool that combines the keystroke dynamics, touch gestures, and motion modalities. In addition, it uses a methodology where users play games without participating in an experimental painstaking process. Ioannis Stylios, Spyros Kokolakis, Andreas Skalkos, Sotirios Chatzis |
Inf. Comput. Secur. | 2 |
| 2022 | Key factors driving the adoption of behavioral biometrics and continuous authentication technology: an empirical researchabstractPurpose For the success of future investments in the implementation of continuous authentication systems, we should explore the key factors that influence technology adoption. The authors investigate the effect of various factors of behavioral intention through the new incorporation of a modified technology acceptance model (TAM) and diffusion of innovation theory (DOI). Also, the authors have created a new theoretical framework with constructs such as security and privacy risks (SPR), biometrics privacy concerns (BPC) and perceived risk of using the technology (PROU). In this paper, the authors conducted a structural equation modeling empirical research. This research is designed in such a way to respond to the trade-off between users’ concern for the protection of their biometrics privacy and their protection from risks. Design/methodology/approach The authors provide an extensive conceptual framework for both existing models (TAM and DOI) and the new constructs that the authors have added to the model. In addition, this research explores external factors, such as trust in technology (TT) and innovativeness (Innov). In addition, the authors have introduced significant constructs, to overcome the limitations of the TAM and to adapt it to the needs of the present research. The new theoretical framework the authors introduce in the present research concerns the constructs SPR, BPC and PROU. Findings The authors found that the main facilitators of behavioral intention to adopt the technology (BI) are TT, followed by compatibility (COMP), perceived usefulness (PU) and Innov. This research also shows that individuals are less interested in the ease of use of the technology and are willing to sacrifice it to achieve greater security. COMP and Innov also play a significant role. Individuals who believe that the usage of the behavioral biometrics continuous authentication (BBCA) technology would fit into their lifestyle and would like to experiment with new technologies have a positive intention to adopt the BBCA technology. The new constructs the authors have added are SPR, BPC and PROU. The authors’ results support the hypotheses that SPR is a facilitator to PU and PU acts as a facilitator to BI. Consequently, the hypothesis that individuals do not feel adequately protected by classical methods will consider the usefulness of the BBCA as a technology for their extra protection against risks is confirmed by the model. Also, with the constructs BPC and PROU, the authors examined if individuals’ concerns regarding their biometrics privacy act as inhibitors in the BI. The authors concluded that individuals consider that the benefits of using BBCA technology are much more important than the risks for their biometrics privacy since the hypothesis that the major inhibitor of BI is PROU is not supported by the model. Originality/value To the best of the authors’ knowledge, this research is among the first in the field that examines the factors that influence the individuals’ decision to adopt BBCA technology. Ioannis Stylios, Spyros Kokolakis, Olga Thanou, Sotirios Chatzis |
Inf. Comput. Secur. | 2 |
| 2022 | BioPrivacy: a behavioral biometrics continuous authentication system based on keystroke dynamics and touch gesturesabstractPurpose This research aims to build a system that will continuously. This paper is an extended version of SECPRE 2021 paper and presents a research on the development and validation of a behavioral biometrics continuous authentication (BBCA) system that is based on users keystroke dynamics and touch gestures on mobile devices. This paper aims to build a system that will continuously authenticate the user of a smartphone. Design/methodology/approach Session authentication schemes establish the identity of the user only at the beginning of the session, so they are vulnerable to attacks that tamper with communications after the establishment of the authenticated session. Moreover, smartphones themselves are used as authentication means, especially in two-factor authentication schemes, which are often required by several services. Whether the smartphone is in the hands of the legitimate user constitutes a great concern and correspondingly whether the legitimate user is the one who uses the services. In response to these concerns, BBCA technologies have been proposed on a large corpus of literature. This paper presents a research on the development and validation of a BBCA system (named BioPrivacy), which is based on the user’s keystroke dynamics and touch gestures, using a multi-layer perceptron (MLP). Also, this paper introduces a new BB collection tool and proposes a methodology for the selection of an appropriate set of BB. Findings The system achieved the best results for keystroke dynamics which are 97.18% accuracy, 0.02% equal error rate, 97.2% true acceptance rate and 0.02% false acceptance rate. Originality/value This paper develops a new BB collection tool, named BioPrivacy, by which behavioral data of users on mobile devices can be collected. This paper proposes a methodology for the selection of an appropriate set of BB. This paper presents the development of a BBCA system based on MLP. Ioannis Stylios, Andreas Skalkos, Spyros Kokolakis, Maria Karyda 0001 |
Inf. Comput. Secur. | 3 |
| 2020 | AppAware: a policy visualization model for mobile applicationsabstractPurpose Privacy policies emerge as the main mechanism to inform users on the way their information is managed by online service providers, and still remain the dominant approach for this purpose. The literature notes that users find difficulties in understanding privacy policies because they are usually written in technical or legal language even, although most users are unfamiliar with them. These difficulties have led most users to skip reading privacy policies and blindly accept them. This study aims to address this challenge this paper presents AppAware, a multiplatform tool that intends to improve the visualization of privacy policies for mobile applications. Design/methodology/approach AppAware formulates a visualized report with the permission set of an application, which is easily understandable by a common user. AppAware aims to bridge the difficulty to read privacy policies and android’s obscure permission set with a new privacy policy visualization model. Thus, we propose AppAware parser, a mobile add-on that acts complementary with AppAware and helps mobile device users to monitor the applications they installed to their smart device. Findings To validate AppAware, the authors conducted a survey through questionnaire aiming to evaluate AppAware in terms of installability, usability and viability-purpose. The results demonstrate that AppAware is assessed above average by the users in all categories. Originality/value In the best of the authors’ knowledge, there is no such approach as AppAware as an application nor AppAware parser as add-on. Ioannis Paspatis, Aggeliki Tsohou, Spyros Kokolakis |
Inf. Comput. Secur. | 3 |
| 2017 | Privacy attitudes and privacy behaviour: A review of current research on the privacy paradox phenomenon
Spyros Kokolakis |
Comput. Secur. | 1 |
| 2015 | Analyzing the role of cognitive and cultural biases in the internalization of information security policies: Recommendations for information security awareness programs
Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis |
Comput. Secur. | 3 |
| 2015 | Managing the introduction of information security awareness programmes in organisationsabstractSeveral studies explore information security awareness focusing on individual and/or organisational aspects. This paper argues that security awareness processes are associated with interrelated changes that occur at the organisational, the technological and the individual level. We introduce an integrated analytical framework that has been developed through action research in a public sector organisation, comprising actor-network theory (ANT), structuration theory and contextualism. We develop and use this framework to analyse and manage changes introduced by the implementation of a security awareness programme in the research setting. The paper illustrates the limitations of each theory (ANT, structuration theory and contextualism) to study multi-level changes when used individually, demonstrates the synergies of the three theories, and proposes how they can be used to study and manage awareness-related changes at the individual, organisational and technological level. Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
Eur. J. Inf. Syst. | 3 |
| 2010 | Analyzing Information Security Awareness through Networks of Association
Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
TrustBus | 3 |
| 2008 | Process-variance models in information security awareness researchabstractPurpose The purpose of this paper is to study the way information systems (IS) security researchers approach information security awareness and examine whether these approaches are consistent with the organization theory and IS approaches for the study of organizational processes. Design/methodology/approach Open coding analysis was performed on selected publications (articles, surveys, standards, and reports). The chosen publications were classified and the classification results are presented, based on a proposed typology. Findings The proposed typology allows us to identify different types of research models followed by security researchers and practitioners, and to infer a set of practical implications, for the benefit of those interested in empirically studying information security awareness. Research limitations/implications The paper represents a pilot survey, performed in a selected number of publications. Practical implications The paper helps researchers and practitioners to distinguish the research models that can be adopted for the study of information security awareness organizational process, by identifying the key dimensions along which they differ. Originality/value The proposed typology provides a guide to identify the range of options available to researchers and practitioners when they design their work regarding the security awareness topic. Moreover, it can facilitate the communication between scholars in the field of security awareness. Aggeliki Tsohou, Spyros Kokolakis, Maria Karyda 0001, Evangelos A. Kiountouzis |
Inf. Manag. Comput. Secur. | 2 |
| 2007 | Addressing Cultural Dissimilarity in the Information Security Management Outsourcing Relationship
Aggeliki Tsohou, Marianthi Theoharidou, Spyros Kokolakis, Dimitris Gritzalis |
TrustBus | 3 |
| 2006 | An ontology for secure e-government applicationsabstractThis paper addresses the issue of accommodating security requirements in application development. It proposes the use of ontologies for capturing and depicting the security experts' knowledge. In this way developers can exploit security expertise in order to make design choices that help them fulfil security requirements more effectively. We have developed a security ontology for two different application scenarios to illustrate its use. To validate the ontology we have used queries. Maria Karyda 0001, Theodoros Balopoulos, Lazaros Gymnopoulos, Spyros Kokolakis, Costas Lambrinoudakis, Stefanos Gritzalis, Stelios Dritsas |
ARES | 4 |
| 2006 | A Framework for Exploiting Security Expertise in Application Development
Theodoros Balopoulos, Lazaros Gymnopoulos, Maria Karyda 0001, Spyros Kokolakis, Stefanos Gritzalis, Sokratis K. Katsikas |
TrustBus | 4 |
| 2006 | Formulating information systems risk management strategies through cultural theoryabstractPurpose The purpose of this paper is to examine the potential of cultural theory as a tool for identifying patterns in the stakeholders' perception of risk and its effect on information system (IS) risk management. Design/methodology/approach Risk management involves a number of human activities which are based on the way the various stakeholders perceive risk associated with IS assets. Cultural theory claims that risk perception within social groups and structures is predictable according to group and individual worldviews; therefore this paper examines the implications of cultural theory on IS risk management as a means for security experts to manage stakeholders perceptions. Findings A basic theoretical element of cultural theory is the grid/group typology, where four cultural groups with differentiating worldviews are identified. This paper presents how these worldviews affect the process of IS risk management and suggests key issues to be considered in developing strategies of risk management according to the different perceptions cultural groups have. Research limitations/implications The findings of this research are based on theoretical analysis and are not supported by relevant empirical research. Further research is also required for incorporating the identified key issues into information security management systems (ISMS). Originality/value IS security management overlooks stakeholders' risk perception; for example, there is no scheme developed to understand and manage the perception of IS stakeholders. This paper proposes some key issues that should be taken into account when developing strategies for addressing the issue of understanding and managing the perception of IS stakeholders. Aggeliki Tsohou, Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
Inf. Manag. Comput. Secur. | 3 |
| 2005 | Information systems security policies: a contextual perspective
Maria Karyda 0001, Evangelos A. Kiountouzis, Spyros Kokolakis |
Comput. Secur. | 3 |
| 2005 | The insider threat to information systems and the effectiveness of ISO17799
Marianthi Theoharidou, Spyros Kokolakis, Maria Karyda 0001, Evangelos A. Kiountouzis |
Comput. Secur. | 2 |
| 2005 | Information systems security from a knowledge management perspectiveabstractPurpose Information systems security management is a knowledge‐intensive activity that currently depends heavily on the experience of security experts. However, the knowledge dimension of IS security management has been neglected, both by research and industry. This paper aims to explore the sources of IS security knowledge and the potential role of an IS security knowledge management system. Design/methodology/approach The results of this paper are based on field research involving five organizations (public and private) and five security experts and consultants. A model to illustrate the structure of IS security knowledge in an organization is then proposed. Findings Successful security management largely depends on the involvement of users and other stakeholders in security analysis, design, and implementation, as well as in actively defending the IS. However, most stakeholders lack the required knowledge of IS security issues that would allow them to play an important role in IS security management. Originality/value In this paper, the knowledge management aspect of IS security management has been highlighted. Moreover, the basic sources of security‐related knowledge have been identified and a model of IS security knowledge has been created. Also, the activities to be supported by a security‐focused KM system have been identified. Thus, the basis for the development of specialized security KM systems has been set. Petros Belsis, Spyros Kokolakis, Evangelos A. Kiountouzis |
Inf. Manag. Comput. Security | 2 |
| 2003 | Content, Context, Process Analysis of IS Security Policy Formation
Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
SEC | 2 |
| 2002 | Functional Requirements for a Secure Electronic Voting System
Spyros Ikonomopoulos, Costas Lambrinoudakis, Dimitris Gritzalis, Spyros Kokolakis, K. Vassiliou |
SEC | 4 |
| 2001 | Redefining Information Systems Security: Viable Information Systems
Maria Karyda 0001, Spyros Kokolakis, Evangelos A. Kiountouzis |
SEC | 2 |
| 2000 | A Qualitative Approach to Information Availability
Theodore Tryfonas, Dimitris Gritzalis, Spyros Kokolakis |
SEC | 3 |
| 2000 | Achieving Interoperability in a Multiple-Security- Policies Environment
Spyros Kokolakis, Evangelos A. Kiountouzis |
Comput. Secur. | 1 |
| 2000 | The use of business process modelling in information systems security analysis and designabstractThe increasing reliance of organisations on information systems connected to or extending over open data networks has established information security as a critical success factor for modern organisations. Risk analysis appears to be the predominant methodology for the introduction of security in information systems (IS). However, risk analysis is based on a very simple model of IS as consisting of assets, mainly data, hardware and software, which are vulnerable to various threats. Thus, risk analysis cannot provide for an understanding of the organisational environment in which IS operate. We believe that a comprehensive methodology for information systems security analysis and design (IS‐SAD) should incorporate both risk analysis and organisational analysis, based on business process modelling (BPM) techniques. This paper examines the possible contribution of BPM techniques to IS‐SAD and identifies the conceptual and methodological requirements for a technique to be used in this context. Based on these requirements, several BPM techniques have been reviewed. The review reveals the need for either adapting and combining current techniques or developing new, specialised ones. Spyros Kokolakis, A. J. Demopoulos, Evangelos A. Kiountouzis |
Inf. Manag. Comput. Secur. | 1 |
| 1999 | Security requirements, risks and recommendations for small enterprise and home-office environmentsabstractThe pervasive use of information technology in enterprises of every size and the emergence of widely deployed ubiquitous networking technologies have brought with them a widening need for security. Information system security policy development must begin with a thorough analysis of sensitivity and criticality. Risk analysis methodologies, like CRAMM, provide the ability to analyse and manage the associated risks. By performing a risk analysis on a typical small enterprise and a home‐office set‐up the article identifies the risks associated with availability, confidentiality, and integrity requirements. Although both environments share weaknesses and security requirements with larger enterprises, the risk management approaches required are different in nature and scale. Their implementation requires co‐operation between end users, network service providers, and software vendors. Diomidis Spinellis, Spyros Kokolakis, Stefanos Gritzalis |
Inf. Manag. Comput. Secur. | 2 |
| 1996 | An analyst's view of IS security
Evangelos A. Kiountouzis, Spyros Kokolakis |
SEC | 2 |