EDBT 2026 Demo / reviewers in the wild / expert
Vyron Kampourakis
dblp:337/0876
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2025
0000-0003-4492-5104ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unmasking the hidden credential leaks in password managers and VPN clientsabstractWith the rapid growth of software services and applications, the need to secure digital assets became paramount. The introduction of Password Manager (PM) and Virtual Private Network (VPN) software was established as a prerequisite toolkit to bolster the end-user arsenal. As a matter of fact, these types of artifacts have been around for at least 25 years in various flavors, including desktop and browser-based applications. This work assesses the ability of 12 desktop PM applications, 5 browsers with integrated PM, and 12 PMs in the form of browser plugins, along with 21 VPN client applications, to effectively protect the confidentiality of secret credentials. Our analysis focuses on the period during which an app is loaded into RAM. Despite the sensitive nature of these applications, our results show that across all scenarios the majority of PM applications store plaintext passwords in the system memory; more specifically, 75% (or 9 out of 12) of desktop PM applications, 100% (5 out of 5) of browser PMs and 75% (or 9 out of 12) of PM browser plugins leak such sensitive information. In addition, 33% (or 7 out of 21) of VPN applications leak user credentials. This practice of storing cleartext sensitive information in system memory is widely recognized as a weakness, having also been registered as CWE-316. At the time of writing, merely four vendors have recognized our exploits as vulnerabilities. Three of these vendors have assigned the relevant Common Vulnerabilities and Exposures (CVE) IDs, namely CVE-2023-23349, CVE-2024-9203, and CVE-2024-50570, whereas the fourth one will issue a CVE ID once it implements the relevant fixes. The remaining vendors have either chosen to disregard or downplay the severity of this issue. Efstratios Chatzoglou, Vyron Kampourakis, Zisis Tsiatsikas, Georgios Karopoulos, Georgios Kambourakis |
Comput. Secur. | 2 |
| 2025 | Cracks in the chain: A technical analysis of real-life supply chain security incidentsabstractAs Industry 5.0 drives greater digitalization and interconnectivity, supply chains have become vital to global commerce, ensuring the seamless flow of goods, services, and data. However, this reliance has also swelled the attack surface, rendering supply chains a prime target for evildoers. Meanwhile, the inherent complexity of supply chain ecosystems prevents defenders from fully applying contemporary security controls promptly and effectively. Clearly, the combination of these hindering factors has led to some of the most severe cybersecurity incidents of the past years. This study is the first to our knowledge that undertakes a comprehensive technical analysis of reported supply chain security incidents. Our analysis is done both from offensive and defensive prisms, leveraging well-established cybersecurity frameworks and guidelines, namely, the ATT&CK MITRE knowledge base matrix and the NIST SP 800-161, respectively. Furthermore, to consolidate our findings and facilitate future research initiatives, we compiled a fundamental dataset that can be used as the basis for automated analysis and potential integration with cybersecurity workflows. The key observations of a 33-incident analysis through the lens of an ATT&CK MITRE- and NIST SP 800-161-based taxonomies we propose can be wrapped up into two key points. First, the attack surface continues to expand, following an upward spiral due to the mushrooming of tactics and techniques that can facilitate the early or late stages of attacks, highlighting their complexity, sophistication, and widespread impact. Second, our findings underscore the necessity of a multifaceted approach to strengthening supply chain resilience. This includes implementing robust cybersecurity controls, comprehensive risk assessment methodologies, and transparent collaboration among suppliers, customers, and vendors to ensure adherence to state-of-the-art cybersecurity best practices. Vyron Kampourakis, Georgios Kavallieratos, Vasileios Gkioulos, Sokratis K. Katsikas |
Comput. Secur. | 1 |
| 2025 | A step-by-step definition of a reference architecture for cyber rangesabstractBeing on the advent of Industry 5.0, organizations have been progressively incorporating information technology into their formerly air-gapped operational technology architectures. This coalescence has nevertheless amplified the attack surface, ringing the bells of preparedness. In this direction, Cyber Ranges (CRs) have cropped up as a valuable and attractive solution, providing a diverse perspective on reinforcing the overall cybersecurity stance. However, there exists a significant literature gap in attempts to define a complete approach for CR design, development, evaluation, and operation as per the up-to-date guidelines. To address this shortcoming, this work introduces the first to our knowledge overarching, fine-grained reference architecture for CR. This is done by adopting a three-step, systematic methodology. First, we scrutinize contemporary guidelines to extract an abstract architectural model that structurally entrenches the foundations of CR reference architecture. Then, we percolate and pinpoint common functionalities and capabilities of existing CRs, towards delineating the functional and informational aspects of the reference architecture. Finally, we devise an evaluation formula that approximates the conformance of a CR with the state-of-the-art. Through the latter step, we impart a unified means of identifying the most appropriate components to implement the structural, functional, and informational aspects of a CR. Overall, this work can be seen as an attempt towards CR unification and standardization, therefore it is anticipated to serve as a basis and point of reference for multiple stakeholders at varying levels. Vyron Kampourakis, Vasileios Gkioulos, Sokratis K. Katsikas |
J. Inf. Secur. Appl. | 1 |
| 2024 | Keep Your Memory Dump Shut: Unveiling Data Leaks in Password ManagersabstractAbstract Password management has long been a persistently challenging task. This led to the introduction of password management software, which has been around for at least 25 years in various forms, including desktop and browser-based applications. This work assesses the ability of two dozen password managers, 12 desktop applications, and 12 browser plugins, to effectively protect the confidentiality of secret credentials in six representative scenarios. Our analysis focuses on the period during which a Password Manager (PM) resides in the RAM. Despite the sensitive nature of these applications, our results show that across all scenarios, only three desktop PM applications and two browser plugins do not store plaintext passwords in the system memory. Oddly enough, at the time of writing, only two vendors recognized the exploit as a vulnerability, reserving CVE-2023-23349, while the rest chose to disregard or underrate the issue. Efstratios Chatzoglou, Vyron Kampourakis, Zisis Tsiatsikas, Georgios Karopoulos, Georgios Kambourakis |
SEC | 2 |
| 2023 | Secure Infrastructure for Cyber-Physical Ranges
Vyron Kampourakis |
RCIS | 1 |
| 2023 | Bl0ck: Paralyzing 802.11 Connections Through Block Ack Frames
Efstratios Chatzoglou, Vyron Kampourakis, Georgios Kambourakis |
SEC | 2 |
| 2023 | A systematic literature review on wireless security testbeds in the cyber-physical realmabstractThe Cyber-Physical System (CPS) lies in the core of Industry 4.0, accelerating the convergence of formerly barricaded operational technology systems with modern information technology ones. Nevertheless, the increased connectivity in terms of both wired and wireless links and associated attack surfaces that comes along, requires higher security for safeguarding critical industrial systems and manufacturing lines from cyberattacks. In this rapidly evolving ecosystem, security testbeds have emerged as a versatile, cost-effective solution for investigating potential attack vectors and devising appropriate countermeasures, without putting the real system at risk. The present work seeks to address a prominent literature gap, namely, the lack of a systematic review regarding the use of wireless-oriented security testbeds in CPS. We contribute an overarching, manifold review on this topic from 2016 onward, examining the various literature works from diverse angles, namely, the wireless technologies used, the implemented attacks, the employed security controls, and more. The analysis is done on a per-sector basis, including water and wastewater systems, healthcare, transportation, agriculture, energy, maritime, unmanned aircraft systems, and others. Finally yet importantly, we discuss key takeaways, open issues, and challenges. The key observations of our analysis, including almost 50 articles, can be wrapped up into two salient points: on the one hand, wireless technologies are increasingly penetrating into the CPS domain as an orthogonal, versatile solution to their wired counterparts, but on the other, they widen the window of opportunity for threat actors targeting wireless links. In this context, testbed thoroughness and security as a trade-off seem to be of major importance, alongside a modular, possibly sector-neutral reference architecture that overarches the peculiarities of CPS. Overall, to our knowledge, this work provides the first full-fledged survey on the use of wireless-oriented security testbeds in CPS, and it is therefore anticipated to serve as a groundwork and touchstone for several stakeholders at different levels. Vyron Kampourakis, Vasileios Gkioulos, Sokratis K. Katsikas |
Comput. Secur. | 1 |