Emmanouil Magkos

dblp:79/5444 · DBLP profile ↗
← Back
25ranked-venue papers
7as first author
4since 2021 · last 2024
0000-0002-5922-4274ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 4 first-author · 4 since 2021Computer networks · 4 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2024 NITRO: an Interconnected 5G-IoT Cyber Range
abstract
This paper presents NITRO cyber range, which aims at creating a specialized cybersecurity testing and training environment for 5G and IoT networks. NITRO provides a platform for researchers and security professionals to simulate real-world scenarios, assess vulnerabilities, and validate security measures. It focuses on identifying novel cascading attacks that exploit the interdependencies between devices. Another innovation of the NITRO platform is the adversarial AI exercises on 5G and IoT networks, aiming at raising awareness of the vulnerabilities of AI models, how they can be attacked and how robust AI can defend against these vulnerabilities. The overarching goal of NITRO is to enhance security of 5G and IoT networks and serve as a precursor to the development of new cyber ranges within critical infrastructure sectors.
Aristeidis Farao, Christoforos Ntantogian, Stylianos Karagiannis, Emmanouil Magkos, Alexandra Dritsa, Christos Xenakis
ARES4
2024 AI-Powered Penetration Testing using Shennina: From Simulation to Validation
abstract
Artificial intelligence has been greatly improved nowadays, providing innovative approaches in cybersecurity both on offensive and defensive tactics. AI can be specifically utilized to automate and conduct penetration testing, a task that is usually time-intensive, involves high-costs, and requires cybersecurity professionals of high expertise. In this research paper, we utilize an AI penetration testing framework to validate, discover and analyze the techniques that were used. To this end, we conducted a validation process in a realistic environment and to collect the relevant datasets from the execution of the cyberattacks. Finally, the behavior of the AI penetration testing was analyzed in order to adapt and upgrade further. Overall, the research paper provides contributions to dataset generation and a methodology to understand the details of the attack simulation.
Stylianos Karagiannis, Camilla Fusco, Leonidas Agathos, Wissam Mallouli, Valentina Casola, Christoforos Ntantogian, Emmanouil Magkos
ARES7
2021 A Digital Twin-Based Cyber Range for SOC Analysts
Manfred Vielberth, Magdalena Glas, Marietheres Dietz, Stylianos Karagiannis, Emmanouil Magkos, Günther Pernul
DBSec5
2021 Adapting CTF challenges into virtual cybersecurity learning environments
abstract
Purpose This paper aims to highlight the potential of using capture the flag (CTF) challenges, as part of an engaging cybersecurity learning experience for enhancing skills and knowledge acquirement of undergraduate students in academic programs. Design/methodology/approach The approach involves integrating interactivity, gamification, self-directed and collaborative learning attributes using a CTF hosting platform for cybersecurity education. The proposed methodology includes the deployment of a pre-engagement survey for selecting the appropriate CTF challenges in accordance with the skills and preferences of the participants. During the learning phase, storytelling elements were presented, while a behavior rubric was constructed to observe the participants’ behavior and responses during a five-week lab. Finally, a survey was created for getting feedback from the students and for extracting quantitative results based on the attention, relevance, confidence and satisfaction (ARCS) model of motivational design. Findings Students felt more confident about their skills and were highly engaged to the learning process. The outcomes in terms of technical skills and knowledge acquisition were shown to be positive. Research limitations/implications As the number of participants was small, the results and information retrieved from applying the ARCS model only have an indicative value; however, specific challenges to overcome are highlighted which are important for the future deployments. Practical implications Educators could use the proposed approach for deploying an engaging cybersecurity learning experience in an academic program, emphasizing on providing hands-on practice labs and featuring topics from real-world cybersecurity cases. Using the proposed approach, an educator could also monitor the progress of the participants and get qualitative and quantitative statistics regarding the learning impact for each exercise. Social implications Educators could demonstrate modern cybersecurity topics in the classroom, closing further the gap between theory and practice. As a result, students from academia will benefit from the proposed approach by acquiring technical skills, knowledge and experience through hands-on practice in real-world cases. Originality/value This paper intends to bridge the existing gap between theory and practice in the topics of cybersecurity by using CTF challenges for learning purposes and not only for testing the participants’ skills. This paper offers important knowledge for enhancing cybersecurity education programs and for educators to use CTF challenges for conducting cybersecurity exercises in academia, extracting meaningful statistics regarding the learning impact.
Stylianos Karagiannis, Emmanouil Magkos
Inf. Comput. Secur.2
2020 DEFeND DSM: A Data Scope Management Service for Model-Based Privacy by Design GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Michalis Pavlidis, Haralambos Mouratidis, Aggeliki Tsohou, Emmanouil Magkos, Andrea Praitano, Annarita Iodice, Beatriz Gallego-Nicasio
TrustBus6
2020 An Analysis and Evaluation of Open Source Capture the Flag Platforms as Cybersecurity e-Learning Tools
Stylianos Karagiannis, Elpidoforos Maragkos-Belmpas, Emmanouil Magkos
WISE3
2020 Privacy, security, legal and technology acceptance elicited and consolidated requirements for a GDPR compliance platform
abstract
Purpose General data protection regulation (GDPR) entered into force in May 2018 for enhancing personal data protection. Even though GDPR leads toward many advantages for the data subjects it turned out to be a significant challenge. Organizations need to implement long and complex changes to become GDPR compliant. Data subjects are empowered with new rights, which, however, they need to become aware of. GDPR compliance is a challenging matter for the relevant stakeholders calls for a software platform that can support their needs. The aim of data governance for supporting GDPR (DEFeND) EU project is to deliver such a platform. The purpose of this paper is to describe the process, within the DEFeND EU project, for eliciting and analyzing requirements for such a complex platform. Design/methodology/approach The platform needs to satisfy legal and privacy requirements and provide functionalities that data controllers request for supporting GDPR compliance. Further, it needs to satisfy acceptance requirements, for assuring that its users will embrace and use the platform. In this paper, the authors describe the methodology for eliciting and analyzing requirements for such a complex platform, by analyzing data attained by stakeholders from different sectors. Findings The findings provide the process for the DEFeND platform requirements’ elicitation and an indicative sample of those. The authors also describe the implementation of a secondary process for consolidating the elicited requirements into a consistent set of platform requirements. Practical implications The proposed software engineering methodology and data collection tools (i.e. questionnaires) are expected to have a significant impact for software engineers in academia and industry. Social implications It is reported repeatedly that data controllers face difficulties in complying with the GDPR. The study aims to offer mechanisms and tools that can assist organizations to comply with the GDPR, thus, offering a significant boost toward the European personal data protection objectives. Originality/value This is the first paper, according to the best of the authors’ knowledge, to provide software requirements for a GDPR compliance platform, including multiple perspectives.
Aggeliki Tsohou, Emmanouil Magkos, Haralambos Mouratidis, George Chrysoloras, Luca Piras 0003, Michalis Pavlidis, Julien Debussche, Marco Rotoloni, Beatriz Gallego-Nicasio
Inf. Comput. Secur.2
2019 DEFeND Architecture: A Privacy by Design Platform for GDPR Compliance
Luca Piras 0003, Mohammed Al-Obeidallah, Andrea Praitano, Aggeliki Tsohou, Haralambos Mouratidis, Beatriz Gallego-Nicasio, Jean Baptiste Bernard, Marco Fiorani, Emmanouil Magkos, Andrès Castillo Sanz, Michalis Pavlidis, Roberto D'Addario, Giuseppe Giovanni Zorzino
TrustBus9
2016 Lightweight private proximity testing for geospatial social networks
Panayiotis Kotzanikolaou, Constantinos Patsakis, Emmanouil Magkos, Michalis Korakakis
Comput. Commun.3
2016 SCN-SI-021 achieving privacy and access control in pervasive computing environments
abstract
Abstract This paper focuses on the inherent trade‐off between privacy and access control in pervasive computing environments (PCEs). On one hand, service providers require user authentication and authorization for the provision of a service, while at the same time end users require untraceability and unlinkability for their transactions. There are also cases where the anonymity of a specific credential must be revoked and a real identity be traced, in order to establish accountability. We analyze privacy and security requirements for PCEs and we show that existing privacy‐preserving access control schemes do not fully satisfy these requirements. Then we propose two approaches towards privacy‐preserving access control in PCEs. Our goal is twofold: (a) to enhance privacy by achieving untraceability and unlinkability even against malicious insiders and (b) to enhance security by achieving conditional traceability of user credentials, and if possible, non‐repudiation of evidence concerning the user's participating in a transaction. Finally, we analyze and compare the proposed schemes against existing schemes. Copyright © 2011 John Wiley & Sons, Ltd.
Emmanouil Magkos, Panayiotis Kotzanikolaou
Secur. Commun. Networks1
2014 Towards Secure and Practical Location Privacy through Private Equality Testing
Emmanouil Magkos, Panayiotis Kotzanikolaou, Marios Magioladitis, Spyros Sioutas, Vassilios S. Verykios
Privacy in Statistical Databases1
2013 T-ABAC: An attribute-based access control model for real-time availability in highly dynamic systems
abstract
In highly dynamic systems resources may have to be accessed in real-time, within the strict time limits of underlying physical processes, with availability becoming critical. Current access control models such as RBAC and ABAC do not address real-time availability in a scalable way for such scenarios. In this paper we propose a real-time attribute-based access control model that extends the functionality of ABAC by using real-time attributes that reflect the requirements of critical applications. We describe two applications of our model: (a) a substation automation system, and (b) a medical cyber-physical system.
Mike Burmester, Emmanouil Magkos, Vassilios Chrissikopoulos
ISCC2
2013 Toward early warning against Internet worms based on critical-sized networks
abstract
ABSTRACT In this paper, we build on a recent worm propagation stochastic model, in which random effects during worm spreading were modeled by means of a stochastic differential equation. On the basis of this model, we introduce the notion of thecritical sizeof a network, which is the least size of a network that needs to be monitored, in order to correctly project the behavior of a worm in substantially larger networks. We provide a method for the theoretical estimation of the critical size of a network in respect to a worm with specific characteristics. Our motivation is the requirement in real systems to balance the needs for accuracy (i.e., monitoring a network of a sufficient size in order to reduce false alarms) and performance (i.e., monitoring a small‐scale network to reduce complexity). In addition, we run simulation experiments in order to experimentally validate our arguments. Finally, based on notion of critical‐sized networks, we propose a logical framework for a distributed early warning system against unknown and fast‐spreading worms. In the proposed framework, propagation parameters of an early detected worm are estimated in real time by studying a critical‐sized network. In this way, security is enhanced as estimations generated by a critical‐sized network may help large‐scale networks to respond faster to new worm threats. Copyright © 2012 John Wiley & Sons, Ltd.
Emmanouil Magkos, Markos Avlonitis, Panayiotis Kotzanikolaou, Michalis Stefanidakis
Secur. Commun. Networks1
2010 Uncertainty for Anonymity and 2-Dimensional Range Query Distortion
Spyros Sioutas, Emmanouil Magkos, Ioannis Karydis, Vassilios S. Verykios
Privacy in Statistical Databases2
2010 A distributed privacy-preserving scheme for location-based queries
abstract
In this paper we deal with security and historical privacy in Location Based Service (LBS) applications where users submit accurate location samples to an LBS provider. Specifically we propose a distributed scheme that establishes access control while protecting the privacy of a user in both sporadic and continuous LBS queries. Our solution employs a hybrid network architecture where LBS users: (a) are able to communicate with an LBS provider through a network (e.g., cellular) operator, and (b) they are also able to create wireless ad-hoc networks with other peers in order to obtain privacy against an adversary that performs traffic analysis. Our threat model considers the network operator, the LBS provider and other peers, as potential privacy adversaries. For historical privacy we adopt the generic approach of using multiple pseudonyms that are changed frequently. In order to establish untraceability against traffic analysis attacks, a message is not sent directly to the cellular operator, but it is distributed among mobile neighbors who act like mixes and re-encrypt a message before sending it to the LBS provider via the cellular operator. As an extension, we also discuss how to aggregate independent data from different mobile peers before sending them to the LBS provider. This approach may be suitable in applications where aggregate location data are useful (e.g., traffic monitoring and control).
Emmanouil Magkos, Panayiotis Kotzanikolaou, Spyros Sioutas
WOWMOM1
2009 Empirical Paraphrasing of Modern Greek Text in Two Phases: An Application to Steganography
Katia Kermanidis, Emmanouil Magkos
CICLing2
2009 Accurate and large-scale privacy-preserving data mining using the election paradigm
Emmanouil Magkos, Manolis Maragoudakis, Vassilios Chrissikopoulos, Stefanos Gritzalis
Data Knowl. Eng.1
2009 Secure and practical key establishment for distributed sensor networks
abstract
Abstract Key establishment in sensor networks is a challenging task, due to the physical constraints of sensor devices and their exposure to several threats. Existing protocols based on symmetric cryptography are very efficient but they are weak against several node impersonation and insider attacks. On the other hand, asymmetric protocols are resilient to such attacks but unfortunately, they are not feasible for sensor networks, even in their most efficient versions (e.g. the elliptic curve (EC) Diffie‐Hellman family of key agreement protocols). In this paper, we present two pairwise key establishment protocols for sensor nodes in unattended distributed sensor networks (DSNs). The first protocol is hybrid and it combines asymmetric (elliptic curve (EC)) cryptography with symmetric key techniques. The second protocol is fully asymmetric. Furthermore, through simulations, we measure the efficiency of the proposed protocols in comparison with existing hybrid protocols. Our results show that under conditions, it is feasible for highly sensitive applications of static sensor networks to employ partial or fully asymmetric key establishment techniques and thus extend their security properties. Copyright © 2009 John Wiley & Sons, Ltd.
Panayiotis Kotzanikolaou, Emmanouil Magkos, Dimitrios D. Vergados, Michalis Stefanidakis
Secur. Commun. Networks2
2008 Accuracy in Privacy-Preserving Data Mining Using the Paradigm of Cryptographic Elections
Emmanouil Magkos, Manolis Maragoudakis, Vassilios Chrissikopoulos, Stefanos Gritzalis
Privacy in Statistical Databases1
2008 Towards Efficient Cryptography for Privacy Preserving Data Mining in Distributed Systems
Emmanouil Magkos, Vassilios Chrissikopoulos
WEBIST (1)1
2008 Strengthening Privacy Protection in VANETs
abstract
In the not so far future, vehicles are expected to be able to communicate with each other and with the road infrastructure, to enhance driving experience and support road safety, among others. Vehicular ad-hoc networks (VANETs) introduce a number of security challenges to the research community, mainly concerning the tradeoff between the privacy of the drivers and the accountability of misbehaving vehicles. Another challenge is how to satisfy privacy in the presence of an adversary that has access to all communication (a global observer), and that can perform traffic analysis in order to link messages and identify vehicles. In this paper we attempt to address such issues and propose a set of cryptographic mechanisms that balance the tradeoff between privacy and accountability in a VANET. Furthermore, we examine techniques for location privacy against adversaries that perform a Bayesian traffic analysis, and propose a strategy to strengthen location privacy in VANETs.
Mike Burmester, Emmanouil Magkos, Vassilios Chrissikopoulos
WiMob2
2008 Secure log management for privacy assurance in electronic communications
Vassilios Stathopoulos 0001, Panayiotis Kotzanikolaou, Emmanouil Magkos
Comput. Secur.3
2006 A Framework for Secure and Verifiable Logging in Public Communication Networks
Vassilios Stathopoulos 0001, Panayiotis Kotzanikolaou, Emmanouil Magkos
CRITIS3
2005 Hybrid Key Establishment for Multiphase Self-Organized Sensor Networks
abstract
Recent work on key establishment for sensor networks has shown that it is feasible to employ limited elliptic curve cryptography in sensor networks through hybrid protocols. We propose a hybrid key establishment protocol for uniform self-organized sensor networks. The proposed protocol combines elliptic curve Diffie-Hellmann key establishment with implicit certificates and symmetric-key cryptographic techniques. The protocol can be implemented on uniform networks comprised of restricted functional devices. Furthermore, due to its public-key nature, the protocol is resilient to a wide range of passive and active attacks, such as known-key attacks, as well as attacks against the confidentiality, integrity and authenticity of the communication. The protocol is scalable and efficient for low-capability devices in terms of storage, communication and computational complexity; the cost per node for a key establishment is reduced to one scalar multiplication with a random point, plus one with a fixed point.
Panayiotis Kotzanikolaou, Emmanouil Magkos, Christos Douligeris, Vassilios Chrissikopoulos
WOWMOM2
2001 Strong Forward Security
Mike Burmester, Vassilios Chrissikopoulos, Panayiotis Kotzanikolaou, Emmanouil Magkos
SEC4