Kostas G. Anagnostakis

dblp:60/7008 · also Kostas Anagnostakis · DBLP profile ↗
← Back
27ranked-venue papers
9as first author
0since 2021 · last 2010
0009-0000-7139-6661ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 3 first-authorComputer networks · 4 · 2 first-authorSystems, architecture and hardware · 3 · 3 first-authorArtificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Network security · 72% Web and mobile security · 28%
Computer networks
4 papers
Routing and switching · 24% Wireless networking · 23% Datacenter networks · 20%

Topics — the 15 heaviest of 16, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › intrusion detection and prevention
intrusion detection
0.132006
An Active Splitter Architecture for Intrusion Detection and Prevention · IEEE Trans. Dependable Secur. Comput. 2006
Detecting Targeted Attacks Using Shadow Honeypots · USENIX Security Symposium 2005
Puppetnets: misusing web browsers as a distributed attack infrastructure · CCS 2006
Wireless networking
wireless security
0.112007
Proximity Breeds Danger: Emerging Threats in Metro-area Wireless Networks · USENIX Security Symposium 2007
Datacenter networks
load balancing
0.112006
An Active Splitter Architecture for Intrusion Detection and Prevention · IEEE Trans. Dependable Secur. Comput. 2006
Routing and switching
load sharing
0.112006
An Active Splitter Architecture for Intrusion Detection and Prevention · IEEE Trans. Dependable Secur. Comput. 2006
Web and mobile security
browser security
0.112006
Puppetnets: misusing web browsers as a distributed attack infrastructure · CCS 2006
Network security › attack strategy › denial-of-service attack
DDoS attack
0.112006
Puppetnets: misusing web browsers as a distributed attack infrastructure · CCS 2006
Network security › attack strategy
denial-of-service attack
0.112006
Puppetnets: misusing web browsers as a distributed attack infrastructure · CCS 2006
Web and mobile security › web attacks
malicious web content
0.112006
Puppetnets: misusing web browsers as a distributed attack infrastructure · CCS 2006
Physical-layer communications › signal processing for communications › statistical signal processing › estimation theory
delay estimation
0.012004
A hybrid direct-indirect estimator of network internal delays · SIGMETRICS 2004
Network security › intrusion detection and prevention › intrusion detection › network intrusion detection
wireless intrusion detection
0.012007
Proximity Breeds Danger: Emerging Threats in Metro-area Wireless Networks · USENIX Security Symposium 2007
Network security › intrusion detection and prevention › intrusion detection
anomaly detection
0.012006
Puppetnets: misusing web browsers as a distributed attack infrastructure · CCS 2006
Processor architecture and microarchitecture › special-purpose processor
network processor
0.012006
An Active Splitter Architecture for Intrusion Detection and Prevention · IEEE Trans. Dependable Secur. Comput. 2006
Network security › cyber deception
honeypot
0.012005
Detecting Targeted Attacks Using Shadow Honeypots · USENIX Security Symposium 2005
Network measurement and analytics
network tomography
0.012004
A hybrid direct-indirect estimator of network internal delays · SIGMETRICS 2004
Routing and switching
routing
0.012003
cing: Measuring Network-Internal Delays using only Existing Infrastructure · INFOCOM 2003

Methods — techniques the papers use, named apart from their topics

locality buffering · 0.2early filtering · 0.2cumulative acknowledgment · 0.2measurement study · 0.1shadow honeypots · 0.1anomaly detection · 0.1direct-indirect estimation · 0.0clock artifact removal · 0.0TTL response analysis · 0.0
YearPublicationVenuePosition
2010 Comprehensive shellcode detection using runtime heuristics
abstract
A promising method for the detection of previously unknown code injection attacks is the identification of the shellcode that is part of the attack vector using payload execution. Existing systems based on this approach rely on the self-decrypting behavior of polymorphic code and can identify only that particular class of shellcode. Plain, and more importantly, metamorphic shellcode do not carry a decryption routine nor exhibit any self-modifications and thus both evade existing detection systems. In this paper, we present a comprehensive shellcode detection technique that uses a set of runtime heuristics to identify the presence of shellcode in arbitrary data streams. We have identified fundamental machine-level operations that are inescapably performed by different shellcode types, based on which we have designed heuristics that enable the detection of plain and metamorphic shellcode regardless of the use of self-decryption. We have implemented our technique in Gene, a code injection attack detection system based on passive network monitoring. Our experimental evaluation and real-world deployment show that Gene can effectively detect a large and diverse set of shellcode samples that are currently missed by existing detectors, while so far it has not generated any false positives.
Michalis Polychronakis, Kostas G. Anagnostakis, Evangelos P. Markatos
ACSAC2
2010 Paranoid Android: versatile protection for smartphones
abstract
Smartphone usage has been continuously increasing in recent years. Moreover, smartphones are often used for privacy-sensitive tasks, becoming highly valuable targets for attackers. They are also quite different from PCs, so that PC-oriented solutions are not always applicable, or do not offer comprehensive security. We propose an alternative solution, where security checks are applied on remote security servers that host exact replicas of the phones in virtual environments. The servers are not subject to the same constraints, allowing us to apply multiple detection techniques simultaneously. We implemented a prototype of this security model for Android phones, and show that it is both practical and scalable: we generate no more than 2KiB/s and 64B/s of trace data for high-loads and idle operation respectively, and are able to support more than a hundred replicas running on a single server.
Georgios Portokalidis, Philip Homburg, Kostas G. Anagnostakis, Herbert Bos
ACSAC3
2008 Antisocial Networks: Turning a Social Network into a Botnet
Elias Athanasopoulos, A. Makridakis, Spiros Antonatos, Demetres Antoniades, Sotiris Ioannidis, Kostas G. Anagnostakis, Evangelos P. Markatos
ISC6
2008 Puppetnets: Misusing Web Browsers as a Distributed Attack Infrastructure
abstract
Most of the recent work on Web security focuses on preventing attacks that directly harm the browser’s host machine and user. In this paper we attempt to quantify the threat of browsers being indirectly misused for attacking third parties. Specifically, we look at how the existing Web infrastructure (e.g., the languages, protocols, and security policies) can be exploited by malicious or subverted Web sites to remotely instruct browsers to orchestrate actions including denial of service attacks, worm propagation, and reconnaissance scans. We show that attackers are able to create powerful botnet-like infrastructures that can cause significant damage. We explore the effectiveness of countermeasures including anomaly detection and more fine-grained browser security policies.
Spiros Antonatos, Periklis Akritidis, Vinh The Lam, Kostas G. Anagnostakis
ACM Trans. Inf. Syst. Secur.4
2007 Emulation-Based Detection of Non-self-contained Polymorphic Shellcode
Michalis Polychronakis, Kostas G. Anagnostakis, Evangelos P. Markatos
RAID2
2007 Proximity Breeds Danger: Emerging Threats in Metro-area Wireless Networks
Periklis Akritidis, Wee-Yung Chin, Vinh The Lam, Stelios Sidiroglou-Douskos, Kostas G. Anagnostakis
USENIX Security Symposium5
2007 Defending against hitlist worms using network address space randomization
Spiros Antonatos, Periklis Akritidis, Evangelos P. Markatos, Kostas G. Anagnostakis
Comput. Networks4
2006 Misusing Unstructured P2P Systems to Perform DoS Attacks: The Network That Never Forgets
Elias Athanasopoulos, Kostas G. Anagnostakis, Evangelos P. Markatos
ACNS2
2006 Puppetnets: misusing web browsers as a distributed attack infrastructure
abstract
Most of the recent work on Web security focuses on preventing attacks that directly harm the browser's host machine and user. In this paper we attempt to quantify the threat of browsers being indirectly misused for attacking third parties. Specifically, we look at how the existing Web infrastructure (e.g., the languages, protocols, and security policies) can be exploited by malicious Web sites to remotely instruct browsers to orchestrate actions including denial of service attacks, worm propagation and reconnaissance scans. We show that, depending mostly on the popularity of a malicious Web site and user browsing patterns, attackers are able to create powerful botnet-like infrastructures that can cause significant damage. We explore the effectiveness of countermeasures including anomaly detection and more fine-grained browser security policies.
Vinh The Lam, Spiros Antonatos, Periklis Akritidis, Kostas G. Anagnostakis
CCS4
2006 Network-Level Polymorphic Shellcode Detection Using Emulation
Michalis Polychronakis, Kostas G. Anagnostakis, Evangelos P. Markatos
DIMVA2
2006 Robust Reactions to Potential Day-Zero Worms Through Cooperation and Validation
Kostas G. Anagnostakis, Sotiris Ioannidis, Angelos D. Keromytis, Michael B. Greenwald
ISC1
2006 Flexible network monitoring with FLAME
Kostas G. Anagnostakis, Michael B. Greenwald, Sotiris Ioannidis, Jonathan M. Smith
Comput. Networks1
2006 An Active Splitter Architecture for Intrusion Detection and Prevention
abstract
State-of-the-art high-speed network intrusion detection and prevention systems are often designed using multiple intrusion detection sensors operating in parallel coupled with a suitable front-end load-balancing traffic splitter. In this paper, we argue that, rather than just passively providing generic load distribution, traffic splitters should implement more active operations on the traffic stream, with the goal of reducing the load on the sensors. We present an active splitter architecture and three methods for improving performance. The first is early filtering/forwarding, where a fraction of the packets is processed on the splitter instead of the sensors. The second is the use of locality buffering, where the splitter reorders packets in a way that improves memory access locality on the sensors. The third is the use of cumulative acknowledgments, a method that optimizes the coordination between the traffic splitter and the sensors. Our experiments suggest that early filtering reduces the number of packets to be processed by 32 percent, giving an 8 percent increase in sensor performance, locality buffers improve sensor performance by 10-18 percent, while cumulative acknowledgments improve performance by 50-90 percent. We have also developed a prototype active splitter on an IXP1200 network processor and show that the cost of the proposed approach is reasonable.
Konstantinos Xinidis, Ioannis Charitakis, Spiros Antonatos, Kostas G. Anagnostakis, Evangelos P. Markatos
IEEE Trans. Dependable Secur. Comput.4
2005 Efficient content-based detection of zero-day worms
abstract
Recent cybersecurity incidents suggest that Internet worms can spread so fast that in-time human-mediated reaction is not possible, and therefore initial response to cyberattacks has to be automated. The first step towards combating new unknown worms is to be able to detect and identify them at the first stages of their spread. In this paper, we present a novel method for detecting new worms based on identifying similar packet contents directed to multiple destination hosts. We evaluate our method using real traffic traces that contain real worms. Our results suggest that our approach is able to identify novel worms while at the same time the generated false alarms reach as low as zero percent.
Periklis Akritidis, Kostas G. Anagnostakis, Evangelos P. Markatos
ICC2
2005 STRIDE: Polymorphic Sled Detection through Instruction Sequence Analysis
Periklis Akritidis, Evangelos P. Markatos, Michalis Polychronakis, Kostas G. Anagnostakis
SEC4
2005 Piranha: Fast and Memory-Efficient Pattern Matching for Intrusion Detection
Spiros Antonatos, Michalis Polychronakis, Periklis Akritidis, Kostas G. Anagnostakis, Evangelos P. Markatos
SEC4
2005 Design and Implementation of a High-Performance Network Intrusion Prevention System
Konstantinos Xinidis, Kostas G. Anagnostakis, Evangelos P. Markatos
SEC2
2005 Detecting Targeted Attacks Using Shadow Honeypots
Kostas G. Anagnostakis, Stelios Sidiroglou-Douskos, Periklis Akritidis, Konstantinos Xinidis, Evangelos P. Markatos, Angelos D. Keromytis
USENIX Security Symposium1
2004 Exchange-Based Incentive Mechanisms for Peer-to-Peer File Sharing
abstract
Performance of peer-to-peer resource sharing networks depends upon the level of cooperation of the participants. To date, cash-based systems have seemed too complex, while lighter-weight credit mechanisms have not provided strong incentives for cooperation. We propose exchange-based mechanisms that provide incentives for cooperation in peer-to-peer file sharing networks. Peers give higher service priority to requests from peers that can provide a simultaneous and symmetric service in return. We generalize this approach to n-way exchanges among rings of peers and present a search algorithm for locating such rings. We have used simulation to analyze the effect of exchanges on performance. Our results show that exchange-based mechanisms can provide strong incentives for sharing, offering significant improvements in service times for sharing users compared to free-riders, without the problems and complexity of cash- or credit-based systems.
Kostas G. Anagnostakis, Michael B. Greenwald
ICDCS1
2004 Design of an application programming interface for IP network monitoring
abstract
We propose a novel general-purpose network traffic monitoring application programming interface (MAPI) for network monitoring applications. Our work builds on a generalized network flow model that we argue is flexible enough to capture emerging application needs, and expressive enough to allow the system to exploit specialized monitoring hardware, where available. We describe an implementation of MAPI using the DAG 4.2 Gigabit Ethernet monitoring card and a commodity Gigabit Ethernet adapter, we present a set of experiments measuring overheads, and we demonstrate potential applications. Our experimental results suggest that MAPI has more expressive power than competing approaches, while at the same time is able to achieve significant performance improvements.
Michalis Polychronakis, Evangelos P. Markatos, Kostas G. Anagnostakis, Arne Øslebø
NOMS (1)3
2004 A hybrid direct-indirect estimator of network internal delays
abstract
No abstract available.
Kostas G. Anagnostakis, Michael B. Greenwald
SIGMETRICS1
2003 cing: Measuring Network-Internal Delays using only Existing Infrastructure
abstract
Several techniques have been proposed for measuring network-internal delays. However, those that rely on router responses have questionable performance, and all proposed alternatives require either new functionality in routers or the existence of a measurement infrastructure. In this paper we revisit the feasibility of measuring network-internal delays using only existing infrastructure, focusing on the use of ICMP timestamp probes to routers. We present network measurements showing that ICMP timestamp is widely supported and that TTL-responses often perform poorly, and we analyze the effect of path instability and routing irregularities on the performance and applicability of using ICMP timestamp. We also confirm that router responses rarely introduce errors in our measurements. Finally, we present a practical algorithm for clock artifact removal that addresses problems with previous methods and has been found to perform well in our setting.
Kostas G. Anagnostakis, Michael B. Greenwald, Raphael S. Ryger
INFOCOM1
2003 Code Generation for Packet Header Intrusion Analysis on the IXP1200 Network Processor
Ioannis Charitakis, Dionisios N. Pnevmatikatos, Evangelos P. Markatos, Kostas G. Anagnostakis
SCOPES4
2003 E2xB: A Domain-Specific String Matching Algorithm for Intrusion Detection
Kostas G. Anagnostakis, Spiros Antonatos, Evangelos P. Markatos, Michalis Polychronakis
SEC1
2002 Efficient packet monitoring for network management
abstract
Network monitoring is a vital part of modern network infrastructure management. Existing techniques either present a restricted view of network behavior and state, or do not efficiently scale to higher network speeds and heavier monitoring workloads. We present a novel architecture for programmable packet-level network monitoring that addresses these shortcomings. Our approach allows users to customize the monitoring function at the lowest possible level of abstraction to suit a wide range of monitoring needs: we use operating system mechanisms that result in a programming environment providing a high degree of flexibility, retaining fine-grained control over security, and minimizing the associated performance overheads. We present an implementation of this architecture as well as a set of experimental applications.
Kostas G. Anagnostakis, Sotiris Ioannidis, Stefan Miltchev, Michael B. Greenwald, Jonathan M. Smith, John Ioannidis
NOMS1
2002 Direct measurement vs. indirect inference for determining network-internal delays
Kostas G. Anagnostakis, Michael B. Greenwald
Perform. Evaluation1
2001 Application of computational intelligence techniques in active networks
Athanasios V. Vasilakos, Kostas G. Anagnostakis, Witold Pedrycz
Soft Comput.2