EDBT 2026 Demo / reviewers in the wild / expert
George Stergiopoulos
dblp:52/10878
· DBLP profile ↗
22ranked-venue papers
15as first author
7since 2021 · last 2024
0000-0002-5336-6765ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 13 first-author · 5 since 2021Computer networks · 2 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Modeling Networks of Interdependent Infrastructure in Complex Urban Environments Using Open-Data
Antonio Di Pietro, Francesco Cavedon, Vittorio Rosato, George Stergiopoulos |
COMPLEXIS | 4 |
| 2024 | From Plant to Lab: Industrial Emulation Tools for Real-World Security Testing in Industrial Control Systems
Argiro Anagnostopoulou, Thomas Papaloukas, George Stergiopoulos, Dimitris Gritzalis |
SECRYPT | 3 |
| 2024 | Utilizing Machine Learning for Optimizing Cybersecurity Spending in Critical Infrastructures
George Stergiopoulos, Michalis Detsis, Sozon Leventopoulos, Dimitris Gritzalis |
SECRYPT | 1 |
| 2024 | Scaling private proximity testing protocols for geofenced information exchange: A metropolitan-wide case study
George Stergiopoulos, Panagiotis Kotzanikolaou, Konstantinos Adamos, Lilian Mitrou |
Comput. Networks | 1 |
| 2022 | Towards an Automated Business Process Model Risk Assessment: A Process Mining Approach
Panagiotis Dedousis, Melina Raptaki, George Stergiopoulos, Dimitris Gritzalis |
SECRYPT | 3 |
| 2021 | Towards Integrating Security in Industrial Engineering Design Practices
Panagiotis Dedousis, George Stergiopoulos, George Arampatzis, Dimitris Gritzalis |
SECRYPT | 2 |
| 2021 | Dropping malware through sound injection: A comparative analysis on Android operating systems
George Stergiopoulos, Dimitris Gritzalis, Efstratios Vasilellis, Argiro Anagnostopoulou |
Comput. Secur. | 1 |
| 2020 | On a Security-oriented Design Framework for Medical IoT Devices: The Hardware Security PerspectiveabstractAs medical devices more and more use Internet of Things based technologies, serious concerns are raised about their security and the privacy of patient's personal health data. To address these concerns, while maintaining reasonable overheads, designers of medical devices need to take security into account from the beginning until the completion of their designs. In this work we identify the relevant security domains and focus to the Hardware Security perspective. Additionally, we present a secure design and evaluation framework which can assist designers towards more secure medical devices. The framework integrates a complete insulin pump architecture containing all the basic components used in such applications. To illustrate the advantages of the proposed framework we perform a Side Channel Analysis attack against the embedded encryption algorithm of the device to obtain the secret encryption key. Then, we make use of the framework to identify all the components of the system which are either directly or indirectly affected by the attack. This analysis leads us to determine more complex combined attacks which may complement the SCA attack into compromising the overall security of the system. Konstantinos Nomikos, Athanasios Papadimitriou, George Stergiopoulos, Dimitris Koutras, Mihalis Psarakis, Panayiotis Kotzanikolaou |
DSD | 3 |
| 2020 | Automatic network restructuring and risk mitigation through business process asset dependency analysis
George Stergiopoulos, Panagiotis Dedousis, Dimitris Gritzalis |
Comput. Secur. | 1 |
| 2019 | Using side channel TCP features for real-time detection of malware connectionsabstractDuring the past years, deep packet inspection has been prevalent in network intrusion detection systems. Most solutions employ complex algorithms to analyze the intended behaviour and underlying characteristics of packets and their payloads, in an effort to detect and prevent malicious users and software from communicating over business intranets and wider networks. Still, there are multiple issues that inhibit their success rate. Most signature-based security software is plagued by false positives and/or false negatives. On the other hand, behavioral-based solutions achieve better detection rates but need to analyze large amounts of traffic. In this article, we present a real-time network traffic monitoring system that implements machine learning over side channel characteristics of TCP network packets to distinguish normal from malicious TCP sessions, even when encryption is in place. We test in university networks and test multiple different types of traffic. We show that, our approach (i) requires notably less information to achieve similar (if not better) detection rates, (ii) works over encrypted traffic as well, and (iii) has notably low false positives and false negatives in everyday case study scenarios. George Stergiopoulos, Georgia Chronopoulou, Evangelos Bitsikas, Nikolaos Tsalis, Dimitris Gritzalis |
J. Comput. Secur. | 1 |
| 2018 | Cybersecurity Self-assessment Tools: Evaluating the Importance for Securing Industrial Control Systems in Critical Infrastructures
Georgia Lykou, Argiro Anagnostopoulou, George Stergiopoulos, Dimitris Gritzalis |
CRITIS | 3 |
| 2018 | Automatic Detection of Various Malicious Traffic Using Side Channel Features on TCP Packets
George Stergiopoulos, Alexander Talavari, Evangelos Bitsikas, Dimitris Gritzalis |
ESORICS (1) | 1 |
| 2018 | Using formal distributions for threat likelihood estimation in cloud-enabled IT risk assessment
George Stergiopoulos, Dimitris Gritzalis, Vasilis Kouktzoglou |
Comput. Networks | 1 |
| 2017 | Program analysis with risk-based classification of dynamic invariants for logical error detection
George Stergiopoulos, Panagiotis Katsaros, Dimitris Gritzalis |
Comput. Secur. | 1 |
| 2016 | Combining Invariant Violation with Execution Path Classification for Detecting Multiple Types of Logical Errors and Race ConditionsabstractContext: Modern automated source code analysis techniques can be very successful in detecting a priori de- fined defect patterns and security vulnerabilities. Yet, they cannot detect flaws that manifest due to erroneous translation of the software’s functional requirements into the source code. The automated detection of logical errors that are attributed to a faulty implementation of applications’ functionality, is a relatively uncharted territory. In previous research, we proposed a combination of automated analyses for logical error detection. In this paper, we develop a novel business-logic oriented method able to filter mathematical depictions of software logic in order to augment logical error detection, eliminate previous limitations in analysis and provide a formal tested logical error detection classification without subjective discrepancies. As a proof of concept, our method has been implemented in a prototype tool called PLATO that can detect various types of logical errors. Potential logical errors are thus detected that are ranked using a fuzzy logic system with two scales characterizing their impact: (i) a Severity scale, based on the execution paths’ characteristics and Information Gain, (ii) a Reliability scale, based on the measured program’s Computational Density. The method’s effectiveness is shown using diverse experiments. Albeit not without restrictions, the proposed automated analysis seems able to detect a wide variety of logical errors, while at the same time limiting the false positives. George Stergiopoulos, Panagiotis Katsaros, Dimitris Gritzalis, Theodore K. Apostolopoulos |
SECRYPT | 1 |
| 2015 | "Water, Water, Every Where": Nuances for a Water Industry Critical Infrastructure Specification Exemplar
Shamal Faily, George Stergiopoulos, Vasilios Katos, Dimitris Gritzalis |
CRITIS | 2 |
| 2015 | Automated Exploit Detection using Path Profiling - The Disposition Should Matter, Not the PositionabstractAbstract: Recent advances in static and dynamic program analysis resulted in tools capable to detect various types of security bugs in the Applications under Test (AUTs). However, any such analysis is designed for a priori specified types of bugs and it is characterized by some rate of false positives or even false negatives and certain scalability limitations. We present a new analysis and source code classification technique, and a pro-totype tool aiming to aid code reviews in the detection of general information flow dependent bugs. Our approach is based on classifying the criticality of likely exploits in the source code using two measuring functions, namely Severity and Vulnerability. For an AUT, we analyse every single pair of input vector and program sink in an execution path, which we call an Information Block (IB). A classification technique is introduced for quantifying the Severity (danger level) of an IB by static analysis and computation of its En-tropy Loss. An IB’s Vulnerability is quantified using a tainted object propagation analysis along with a Fuzzy Logic system. Possible exploits are then characterized with respect to their Risk by combining the computed Severity and Vulnerability measurements through an aggregation operation over two fuzzy sets. An IB is characterized of a high risk, when both its Severity and Vulnerability rankings have been found to be above the low zone. In this case, a detected code exploit is reported by our prototype tool, called Entroine. The effectiveness of our approach has been tested by analysing 45 Java programs of NIST’s Juliet Test Suite, which implement three different common weakness exploits. All existing code exploits were detected without any false positive. 1 George Stergiopoulos, Panagiotis Petsanas, Panagiotis Katsaros, Dimitris Gritzalis |
SECRYPT | 1 |
| 2015 | Hacking and Penetration Testing with Low Power Devices
George Stergiopoulos, Dimitris Gritzalis |
Comput. Secur. | 1 |
| 2014 | Automated Detection of Logical Errors in Programs
George Stergiopoulos, Panagiotis Katsaros, Dimitris Gritzalis |
CRiSIS | 1 |
| 2014 | A Bug Hunter's Diary
George Stergiopoulos, Dimitris Gritzalis |
Comput. Secur. | 1 |
| 2013 | On Business Logic Vulnerabilities Hunting: The APP_LogGIC Framework
George Stergiopoulos, Bill Tsoumas, Dimitris Gritzalis |
NSS | 1 |
| 2013 | Approaching Encryption through Complex Number Logarithms
George Stergiopoulos, Miltiadis Kandias, Dimitris Gritzalis |
SECRYPT | 1 |