Ioannis Mavridis

dblp:33/6741 · DBLP profile ↗
← Back
26ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0001-8724-6801ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3Applied, interdisciplinary, general and emerging computing · 3Human-computer interaction and ubiquitous computing · 2Artificial intelligence and machine learning · 1Computer networks · 1Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 DRIMAX: An intelligence-driven and context-aware dynamic risk assessment methodology for cyber security
Eleftherios Eleftheriadis, Pavlos Cheimonidis, Athanasios Dimitriadis, Konstantinos Rantos, Ioannis Mavridis, Dimitris Gritzalis
Comput. Secur.5
2025 Bolstering IIoT Resilience: The Synergy of Blockchain and CapBAC
Argiro Anagnostopoulou, Eleni Kehrioti, Ioannis Mavridis, Dimitris Gritzalis
SECRYPT3
2023 Risk-Based Illegal Information Flow Detection in the IIoT
Argiro Anagnostopoulou, Ioannis Mavridis, Dimitris Gritzalis
SECRYPT2
2021 Design and Evaluation of COFELET-based Approaches for Cyber Security Learning and Training
Menelaos Katsantonis, Ioannis Mavridis, Dimitris Gritzalis
Comput. Secur.2
2019 Conceptual Framework for Developing Cyber Security Serious Games
abstract
Cyber security education is an emerging field facing many challenges, while demand in skilled cyber security personnel is rising. Serious games and game-based learning approaches constitute a promising opportunity for learning and training in cyber security. However, as game-based learning is a new field, cyber security game-based approaches lack common methodologies and design standards that will provide useful interpretations of the possibilities of such approaches. In this light, we present the Conceptual Framework for e-Learning and Training (COFELET), a framework for the design and implementation of cyber security serious games. The COFELET framework promotes game-based approaches that envisage the improvement of cyber security education pedagogical effectiveness by embracing modern learning theories and innovative teaching approaches. Moreover, the COFELET framework foresees the implementation of a sustainable lifecycle of learning, updating and reinforcing knowledge and skills by adopting multidisciplinary approaches based on sound cyber security methodologies, models and strategies. The COFELET framework realizes cyber security as an attractive and accessible subject endorsing game-based learning and serious games, cyber world simulations, and hacking activities.
Menelaos Katsantonis, Isabella Kotini, Panagiotis E. Fouliras, Ioannis Mavridis
EDUCON4
2018 Towards an Automated Recognition System for Chat-based Social Engineering Attacks in Enterprise Environments
abstract
Increase in usage of electronic communication tools (email, IM, Skype, etc.) in enterprise environments has created new attack vectors for social engineers. Billions of people are now using electronic equipment in their everyday workflow which means billions of potential victims of Social Engineering (SE) attacks. Human is considered the weakest link in cybersecurity chain and breaking this defense is nowadays the most accessible route for malicious internal and external users. While several methods of protection have already been proposed and applied, none of these focuses on chat-based SE attacks while at the same time automation in the field is still missing. Social engineering is a complex phenomenon that requires interdisciplinary research combining technology, psychology, and linguistics. Attackers treat human personality traits as vulnerabilities and use the language as their weapon to deceive, persuade and finally manipulate the victims as they wish. Hence, a holistic approach is required to build a reliable SE attack recognition system. In this paper we present the current state-of-the-art on SE attack recognition systems, we dissect a SE attack to recognize the different stages, forms, and attributes and isolate the critical enablers that can influence a SE attack to work. Finally, we present our approach for an automated recognition system for chat-based SE attacks that is based on Personality Recognition, Influence Recognition, Deception Recognition, Speech Act and Chat History.
Nikolaos Tsinganos, Georgios Sakellariou, Panagiotis E. Fouliras, Ioannis Mavridis
ARES4
2017 Conceptual analysis of cyber security education based on live competitions
abstract
Live competitions, i.e. Capture the Flag, provide noteworthy experiences for the participants while offering both hands-on practice and entertainment. Aiming at performing a conceptual analysis as a basis for improving their pedagogical utilization, we investigate a number of live competition paradigms and analyse their structure by decomposing them into their respective elements and defining their relations. Moreover, we record the possible obstacles related to the pedagogical utilization of live competitions and group them into distinct categories. As a result, we construct a concept map of the technological and pedagogical characteristics of live competitions. Based on the proposed concept map and the recorded obstacles, we present a comparative evaluation scheme that we employ on three live competition approaches from the literature in order to reveal their value with respect to the educational impact. Finally, we discuss the results of our study and suggest directions for its utilization in the phases of analysis, feasibility and assessment towards developing of new live competition approaches for educational purposes. The adopted assumptions can bind the design of new efforts in cyber security education domain such as gamification and game based learning approaches that need to rely on sound learning theories, e.g. cognitive and experiential learning.
Menelaos Katsantonis, Panagiotis E. Fouliras, Ioannis Mavridis
EDUCON3
2015 Access Control Issues in Utilizing Fog Computing for Transport Infrastructure
Stavros Salonikias, Ioannis Mavridis, Dimitris Gritzalis
CRITIS2
2015 Information infrastructure risk prediction through platform vulnerability analysis
Aristeidis Chatzipoulidis, Dimitrios Michalopoulos, Ioannis Mavridis
J. Syst. Softw.3
2014 GARS: Real-time system for identification, assessment and control of cyber grooming attacks
Dimitrios Michalopoulos, Ioannis Mavridis, Marija Jankovic
Comput. Secur.2
2013 A method to calculate social networking hazard probability in definite time
abstract
Purpose The purpose of this paper is to investigate hazards for minor users while they are exposed to social networks. In particular, it provides the statistical relationship of these hazards with the exposure time as well as the amount of published personal information. Design/methodology/approach An experiment was conducted that has revealed a huge number of personal information exposed by users of social network applications. Moreover, a significant amount of suspicious activity against minors has been recorded. Experimental data led to the hypothesis that online hazards can be modeled with known statistical distributions. In order to examine this hypothesis, survival analysis techniques, which involve the estimation of certain functions that reflect the relation of a disastrous event with time, were applied. Findings The results show that the incoming hazards for minor female profiles follow the Logistic distribution, while the corresponding hazards for minor male profiles follow the Normal distribution. Originality/value The findings of this work are crucial for developing an effective system for automated grooming recognition in real time by optimizing the detection threshold as a function of time. Thus, the threshold sensitivity can be appropriately adjusted such that lower frequencies of occurrence lead to lower threshold sensitivities, and higher frequencies of occurrence lead to higher threshold sensitivities.
Dimitrios Michalopoulos, Ioannis Mavridis
Inf. Manag. Comput. Secur.2
2012 Towards Use-Based Usage Control
Christos Grompanopoulos, Ioannis Mavridis
SEC2
2012 domRBAC: An access control model for modern collaborative systems
Antonios Gouglidis, Ioannis Mavridis
Comput. Secur.2
2012 Quantifying and measuring metadata completeness
abstract
Abstract Completeness of metadata is one of the most essential characteristics of their quality. An incomplete metadata record is a record of degraded quality. Existing approaches to measure metadata completeness limit their scope in counting the existence of values in fields, regardless of the metadata hierarchy as defined in international standards. Such a traditional approach overlooks several issues that need to be taken into account. This paper presents a fine‐grained metrics system for measuring metadata completeness, based on field completeness. A metadata field is considered to be a container of multiple pieces of information. In this regard, the proposed system is capable of following the hierarchy of metadata as it is set by the metadata schema and admeasuring the effect of multiple values of multivalued fields. An application of the proposed metrics system, after being configured according to specific user requirements, to measure completeness of a real‐world set of metadata is demonstrated. The results prove its ability to assess the sufficiency of metadata to describe a resource and provide targeted measures of completeness throughout the metadata hierarchy.
Merkourios Margaritopoulos, Thomas Margaritopoulos, Ioannis Mavridis, Athanasios Manitsaris
J. Assoc. Inf. Sci. Technol.3
2011 Utilizing document classification for grooming attack recognition
abstract
Grooming attack recognition is a complex issue that is difficult to address using simple word matching in order to identify potential hazard for minor users. In this paper, the utilization of document classification to create patterns from real dialogs is proposed. Furthermore, a decision making method that results in generating proper warning signals based on the classification results is introduced. The decision making method is then applied using the best ranked algorithm with a comparative evaluation which conducted on seven document classification algorithms.
Dimitrios Michalopoulos, Ioannis Mavridis
ISCC2
2011 X-EDCA: A cross-layer MAC-centric mechanism for efficient multimedia transmission in congested IEEE 802.11e infrastructure networks
abstract
IEEE 802.11e is the indisputable standard for supporting multimedia traffic in modern Wireless Local Area Networks. However, it has been proven incapable of handling efficiently multimedia flows in congested networks. The main reason for this suboptimal behavior roots from the static nature of resource allocation specified in IEEE 802.11e. Dynamic tuning of the MAC parameters has demonstrated a beneficial performance in terms of application efficiency. Nevertheless, it is of great importance that this adaptation takes place by considering the multimedia traffic characteristics. In this paper, a cross-layer MAC-centric mechanism is introduced, under the name X-EDCA. The mechanism is designed to cope with high load situations in IEEE 802.11e wireless infrastructure networks by selectively prioritizing and protecting sensitive multimedia frames. The proposed scheme is evaluated and its effectiveness is proven by means of simulation.
Anastasios Politis, Ioannis Mavridis, Athanasios Manitsaris, Constantinos S. Hilas
IWCMC2
2011 Role-Based Secure Inter-operation and Resource Usage Management in Mobile Grid Systems
Antonios Gouglidis, Ioannis Mavridis
WISTP2
2010 An ICT Security Management Framework
Aristeidis Chatzipoulidis, Ioannis Mavridis
SECRYPT2
2010 Towards Risk based Prevention of Grooming Attacks
Dimitrios Michalopoulos, Ioannis Mavridis
SECRYPT2
2008 A Conceptual Framework for Metadata Quality Assessment
Thomas Margaritopoulos, Merkourios Margaritopoulos, Ioannis Mavridis, Athanasios Manitsaris
Dublin Core Conference3
2008 Supporting dynamic administration of RBAC in web-based collaborative applications during run-time
abstract
The requirements for the efficient management of authorisations in web-based collaborative applications lead to new access control administration paradigms during run-time. The need for fine-grained and just-in-time access control can effectively be addressed by dynamic administration of authorisations, via either proper role or permission activation. In this paper, an authorisation architecture that is based on the Dynamically Administering Role-based Access Control (DARBAC) model, and provides access control and meta-access control capabilities, is presented. The paper describes the implementation of the components and the structure of the architecture within the .NET framework. The application of the implemented access control system is also demonstrated. Based on the results of this demonstration, a more detailed investigation of the benefits of the proposed approach, which are related to improvements in the administration of Role-based Access Control (RBAC) during run-time, is presented.
Ioannis Mavridis, Andreas K. Mattas, Ioannis Pagkalos, Isabella Kotini, Christos Ilioudis
Int. J. Inf. Comput. Secur.1
2007 A Learner-centered Semantic Web-based Architecture
Tania Kerkiri, Athanasios Manitsaris, Ioannis Mavridis
WEBIST (3)3
2006 A Paradigm for Dynamic and Decentralized Administration of Access Control in Workflow Applications
Andreas K. Mattas, Ioannis Mavridis, Iason Pagkalos
SEC2
2001 Flexible team-based access control using contexts
abstract
We discuss the integration of contextual information with team-based access control. The TMAC model was formulated by Thomas in [1] to provide access control for collaborative activity best accomplished by teams of users. In TMAC, access control revolves around teams, where a "team" is an abstraction that encapsulates a collection of users in specific roles and collaborating with the objective of accomplishing a specific task or goal. Users who belong to a team are given access to resources used by a team. However, the effective permissions of a user are always derived from permission types defined for roles that the user belongs to. TMAC is an example of what we call "active security models". These models are aware of the context associated with an ongoing activity in providing access control and thus distinguish the passive concept of permission assignment from the active concept of context-based permission activation. The ability to integrate contextual information allows models such as TMAC to be flexible and express a variety of access policies that can provide tight and just-in-time permission activation.
Christos K. Georgiadis, Ioannis Mavridis, George Pangalos, Roshan K. Thomas
SACMAT2
1999 eMEDAC: Role-based Access Control Supporting Discretionary and Mandatory Features
Ioannis Mavridis, George Pangalos, Marie Khair
DBSec1
1998 Design of Secure Distributed Medical Database Systems
Marie Khair, Ioannis Mavridis, George Pangalos
DEXA2