Konstantinos Touloumis

dblp:311/0292 · DBLP profile ↗
← Back
2ranked-venue papers in the field
2as first author
2since 2021 · last 2022
0000-0002-8560-7391ORCID · corroborated

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 2 (2 first)
YearPublicationVenuePosition
2022 A tool for assisting in the forensic investigation of cyber-security incidents
abstract
The exponential growth of networking capabilities including the Internet of Things (IoT), has led to an outburst of cyberattacks. Many well-documented cyber-attacks have targeted critical energy infrastructures as well as any kind of cloud-based IT platforms. Early examination of critical systems’ vulnerabilities, as well as previous cyber-security incidents, are of utmost importance to prevent new ones. A thorough investigation to examine the context of the cyber-security breach can reveal facts about the source of the attack, the profile of the attacker, the resources, and the skills required and can further reveal mitigations for preventing the attack from re-appearing in the future. To safeguard critical energy infrastructures, many forensic approaches have been developed to collect, analyze, and digitalize evidence assisting in the in-depth investigation of an incident. However, up to now, the many open-source vulnerability data sources which have been developed to provide valuable information for a cyber-attack are yet to be employed to assist in forensic investigation. This paper introduces the Automated Forensic Tool, a platform that employs machine learning algorithms to combine different vulnerability data sources for facilitating the forensic procedure while minimizing the time and effort needed. A use case is also demonstrated that displays how the tool can be used towards assisting the forensic investigation of cyber-security incidents on an energy infrastructure, but the tool can also be applied to other critical energy and IT infrastructures with minor adaptations.
Konstantinos Touloumis, Ariadni Michalitsi-Psarrou, Anna Georgiadou, Dimitris Askounis
IEEE Big Data1
2021 Vulnerabilities Manager, a platform for linking vulnerability data sources
abstract
In order to get a deeper understanding of security breaches, their severity, impact and ways to mitigate them, many vulnerability databases and dictionaries have been developed. However, all that information on vulnerabilities is scattered all over the web, which makes locating and mitigating vulnerabilities an arduous task. This paper introduces the Vulnerabilities Manager, a tool that automates the process of linking information from well-known external vulnerability data sources. Its goal is to present an enriched vulnerability report to its final users, assisting them in pinpointing software and hardware assets’ defects, categorizing and prioritizing them, thus, contributing to the cyber defense against potential security breaches and adversary actions. To achieve this, the Vulnerabilities Manager exploits current state of the art machine learning and artificial intelligence techniques. The tool may also be enriched with forensic capabilities, detecting cyber threats, unveiling information about the nature of the attacker, and proposing mitigations against them in real-time.
Konstantinos Touloumis, Ariadni Michalitsi-Psarrou, Panagiotis Kapsalis, Anna Georgiadou, Dimitris Askounis
IEEE BigData1