EDBT 2026 Demo / reviewers in the wild / expert
Antonis Papadogiannakis
dblp:82/708
· DBLP profile ↗
15ranked-venue papers
7as first author
0since 2021 · last 2020
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-authorComputer networks · 4 · 3 first-authorSecurity and privacy · 4 · 1 first-authorArtificial intelligence and machine learning · 2Databases, data management, data science and information retrieval · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Systems and software security · 89% Network security · 11% | |
| Computer networks
4 papers |
Network measurement and analytics · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Processor architecture and microarchitecture · 75% Performance modeling and evaluation · 25% |
Topics — the 12 heaviest of 15, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › exploitation mitigation
code injection defense |
0.6 | 2 | 2020 | On Architectural Support for Instruction Set Randomization · ACM Trans. Archit. Code Optim. 2020 ASIST: architectural support for instruction set randomization · CCS 2013 |
Systems and software security › code randomization
instruction set randomization |
0.6 | 2 | 2020 | On Architectural Support for Instruction Set Randomization · ACM Trans. Archit. Code Optim. 2020 ASIST: architectural support for instruction set randomization · CCS 2013 |
Network measurement and analytics
packet capture |
0.4 | 2 | 2014 | Stream-Oriented Network Traffic Capture and Analysis for High-Speed Networks · IEEE J. Sel. Areas Commun. 2014 Scap: stream-oriented network traffic capture and analysis for high-speed networks · Internet Measurement Conference 2013 |
Network measurement and analytics › flow monitoring
flow tracking |
0.2 | 1 | 2014 | Stream-Oriented Network Traffic Capture and Analysis for High-Speed Networks · IEEE J. Sel. Areas Commun. 2014 |
Network measurement and analytics › traffic measurement
traffic monitoring |
0.2 | 1 | 2014 | Stream-Oriented Network Traffic Capture and Analysis for High-Speed Networks · IEEE J. Sel. Areas Commun. 2014 |
Network measurement and analytics
traffic analysis |
0.2 | 1 | 2013 | Scap: stream-oriented network traffic capture and analysis for high-speed networks · Internet Measurement Conference 2013 |
Network measurement and analytics
workload characterization |
0.2 | 1 | 2013 | Rise of the planet of the apps: a systematic study of the mobile app ecosystem · Internet Measurement Conference 2013 |
Processor architecture and microarchitecture
hardware-assisted security |
0.2 | 1 | 2013 | ASIST: architectural support for instruction set randomization · CCS 2013 |
Network security › attack strategy
denial-of-service attack |
0.1 | 1 | 2012 | Tolerating Overload Attacks Against Packet Capturing Systems · USENIX ATC 2012 |
Operating systems › extensible operating systems › kernel extensibility › kernel extensions
kernel module |
0.1 | 1 | 2014 | Stream-Oriented Network Traffic Capture and Analysis for High-Speed Networks · IEEE J. Sel. Areas Commun. 2014 |
Performance modeling and evaluation
high-speed packet processing |
0.0 | 1 | 2013 | Scap: stream-oriented network traffic capture and analysis for high-speed networks · Internet Measurement Conference 2013 |
Performance modeling and evaluation
network performance analysis |
0.0 | 1 | 2013 | Scap: stream-oriented network traffic capture and analysis for high-speed networks · Internet Measurement Conference 2013 |
Methods — techniques the papers use, named apart from their topics
hardware-software co-design · 0.9encryption · 0.9XOR · 0.9AES · 0.9parallel processing · 0.4kernel module design · 0.4parallel stream processing · 0.3emulation · 0.3binary instrumentation · 0.3measurement · 0.2kernel modules · 0.2kernel module · 0.2clustering · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | On Architectural Support for Instruction Set RandomizationabstractInstruction Set Randomization (ISR) is able to protect against remote code injection attacks by randomizing the instruction set of each process. Thereby, even if an attacker succeeds to inject code, it will fail to execute on the randomized processor. The majority of existing ISR implementations is based on emulators and binary instrumentation tools that unfortunately: (i) incur significant runtime performance overheads, (ii) limit the ease of deployment, (iii) cannot protect the underlying operating system kernel, and (iv) are vulnerable to evasion attempts that bypass the ISR protection itself. To address these issues, we present the design and implementation of ASIST, an architecture with both hardware and operating system support for ISR. ASIST uses our extended SPARC processor that is mapped onto a FPGA board and runs our modified Linux kernel to support the new features. In particular, before executing a new user-level process, the operating system loads its randomization key into a newly defined register, and the modified processor decodes the process’s instructions with this key. Besides that, ASIST uses a separate randomization key for the operating system to protect the base system against attacks that exploit kernel vulnerabilities to run arbitrary code with elevated privileges. Our evaluation shows that ASIST can transparently protect both user-land applications and the operating system kernel from code injection and code reuse attacks, with about 1.5% runtime overhead when using simple encryption schemes, such as XOR and Transposition; more secure ciphers, such as AES, even though they are much more complicated for mapping them to hardware, they are still within acceptable margins,with approximately 10% runtime overhead, when efficiently leveraging the spatial locality of code through modern instruction cache configurations. George Christou, Giorgos Vasiliadis, Vassilis Papaefstathiou, Antonis Papadogiannakis, Sotiris Ioannidis |
ACM Trans. Archit. Code Optim. | 4 |
| 2015 | Revealing the relationship network behind link spamabstractAccessing the large volume of information that is available on the Web is more important than ever before. Search engines are the primary means to help users find the content they need. To suggest the most closely related and the most popular Web pages for a user's query, search engines assign a ranking to each Web page, which typically increases with the number and ranking of other Web sites that link to this page. However, link spammers have developed several techniques to exploit this algorithm and improve the ranking of their Web pages. These techniques are commonly based on underground forums for collaborative link exchange; building a relationship network among spammers to favor their Web pages in search engine results. In this study, we provide a systematic analysis of the spam link exchange performed through 15 Search Engine Optimization (SEO) forums. We design a system, which is able to capture the activity of link spammers in SEO forums, identify spam link exchange, and visualize the link spam ecosystem. The outcomes of this study shed light on a different aspect of link spamming that is the collaboration among spammers. Apostolis Zarras, Antonis Papadogiannakis, Sotiris Ioannidis, Thorsten Holz |
PST | 2 |
| 2014 | Automated generation of models for fast and precise detection of HTTP-based malwareabstractMalicious software and especially botnets are among the most important security threats in the Internet. Thus, the accurate and timely detection of such threats is of great importance. Detecting machines infected with malware by identifying their malicious activities at the network level is an appealing approach, due to the ease of deployment. Nowadays, the most common communication channels used by attackers to control the infected machines are based on the HTTP protocol. To evade detection, HTTP-based malware adapt their behavior to the communication patterns of the benign HTTP clients, such as web browsers. This poses significant challenges to existing detection approaches like signature-based and behavioral-based detection systems. In this paper, we propose BO THO U N D: a novel approach to precisely detect HTTP-based malware at the network level. The key idea is that implementations of the HTTP protocol by different entities have small but perceivable differences. Building on this observation, BO THO U N D automatically generates models for malicious and benign requests and classifies at real time the HTTP traffic of a monitored network. Our evaluation results demonstrate that BO THO U N D outperforms prior work on identifying HTTP-based botnets, being able to detect a large variety of real-world HTTP-based malware, including advanced persistent threats used in targeted attacks, with a very low percentage of classification errors. Apostolis Zarras, Antonis Papadogiannakis, Robert Gawlik, Thorsten Holz |
PST | 2 |
| 2014 | Stream-Oriented Network Traffic Capture and Analysis for High-Speed NetworksabstractIntrusion detection, traffic classification, and other network monitoring applications need to analyze the captured traffic beyond the network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. Existing network traffic capture frameworks, however, provide applications with raw packets and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap, between what applications need and what systems provide, leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet capture subsystem and the stream processing module. This paper presents the Stream capture library (Scap), a network monitoring framework built from the ground up for stream-oriented traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern network cards. Our experimental evaluation shows that Scap can capture all streams for traffic rates two times higher than other stream reassembly libraries. Finally, we present the implementation and performance evaluation of four popular network traffic monitoring applications built on top of Scap. Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P. Markatos |
IEEE J. Sel. Areas Commun. | 1 |
| 2013 | k-subscription: privacy-preserving microblogging browsing through obfuscationabstractOver the past few years, microblogging social networking services have become a popular means for information sharing and communication. Besides sharing information among friends, such services are currently being used by artists, politicians, news channels, and information providers to easily communicate with their constituency. Even though following specific channels on a microblogging service enables users to receive interesting information in a timely manner, it may raise significant privacy concerns as well. For example, the microblogging service is able to observe all the channels that a particular user follows. This way, it can infer all the subjects a user might be interested in and generate a detailed profile of this user. This knowledge can be used for a variety of purposes that are usually beyond the control of the users. Panagiotis Papadopoulos, Antonis Papadogiannakis, Michalis Polychronakis, Apostolis Zarras, Thorsten Holz, Evangelos P. Markatos |
ACSAC | 2 |
| 2013 | ASIST: architectural support for instruction set randomizationabstractCode injection attacks continue to pose a threat to today's computing systems, as they exploit software vulnerabilities to inject and execute arbitrary, malicious code. Instruction Set Randomization (ISR) is able to protect a system against remote machine code injection attacks by randomizing the instruction set of each process. This way, the attacker will inject invalid code that will fail to execute on the randomized processor. However, all the existing implementations of ISR are based on emulators and binary instrumentation tools that (i) incur a significant runtime performance overhead, (ii) limit the ease of deployment of ISR, (iii) cannot protect the underlying operating system kernel, and (iv) are vulnerable to evasion attempts trying to bypass ISR protection. Antonis Papadogiannakis, Laertis Loutsis, Vassilis Papaefstathiou, Sotiris Ioannidis |
CCS | 1 |
| 2013 | Scap: stream-oriented network traffic capture and analysis for high-speed networksabstractMany network monitoring applications must analyze traffic beyond the network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. However, existing network traffic capture frameworks provide applications with just raw packets, and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet capture subsystem and the stream processing module. This paper presents the Stream capture library (Scap), a network monitoring framework built from the ground up for stream-oriented traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern network cards. Our experimental evaluation shows that Scap can capture all streams for traffic rates two times higher than other stream reassembly libraries, and can process more than five times higher traffic loads when eight cores are used for parallel stream processing in a pattern matching application. Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P. Markatos |
Internet Measurement Conference | 1 |
| 2013 | Rise of the planet of the apps: a systematic study of the mobile app ecosystemabstractMobile applications (apps) have been gaining rising popularity due to the advances in mobile technologies and the large increase in the number of mobile users. Consequently, several app distribution platforms, which provide a new way for developing, downloading, and updating software applications in modern mobile devices, have recently emerged. To better understand the download patterns, popularity trends, and development strategies in this rapidly evolving mobile app ecosystem, we systematically monitored and analyzed four popular third-party Android app marketplaces. Our study focuses on measuring, analyzing, and modeling the app popularity distribution, and explores how pricing and revenue strategies affect app popularity and developers' income. Our results indicate that unlike web and peer-to-peer file sharing workloads, the app popularity distribution deviates from commonly observed Zipf-like models. We verify that these deviations can be mainly attributed to a new download pattern, to which we refer as the clustering effect. We validate the existence of this effect by revealing a strong temporal affinity of user downloads to app categories. Based on these observations, we propose a new formal clustering model for the distribution of app downloads, and demonstrate that it closely fits measured data. Moreover, we observe that paid apps follow a different popularity distribution than free apps, and show how free apps with an ad-based revenue strategy may result in higher financial benefits than paid apps. We believe that this study can be useful to appstore designers for improving content delivery and recommendation systems, as well as to app developers for selecting proper pricing policies to increase their income. Thanasis Petsas, Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P. Markatos, Thomas Karagiannis |
Internet Measurement Conference | 2 |
| 2012 | Tolerating Overload Attacks Against Packet Capturing Systems
Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P. Markatos |
USENIX ATC | 1 |
| 2012 | Improving the performance of passive network monitoring applications with memory locality enhancements
Antonis Papadogiannakis, Giorgos Vasiliadis, Demetres Antoniades, Michalis Polychronakis, Evangelos P. Markatos |
Comput. Commun. | 1 |
| 2010 | RRDtrace: Long-term Raw Network Traffic Recording using Fixed-size StorageabstractRecording raw network traffic for long-term periods can be extremely beneficial for a multitude of monitoring and security applications. However, storing all traffic of high volume networks is infeasible even for short-term periods due to the increased storage requirements. Traditional approaches for data reduction like aggregation and sampling either require knowing the traffic features of interest in advance, or reduce the traffic volume by selecting a representative set of packets uniformly over the collecting period. In this work we present RRDtrace, a technique for storing full-payload packets for arbitrary long periods using fixed-size storage. RRDtrace divides time into intervals and retains a larger number of packets for most recent intervals. As traffic ages, an aging daemon is responsible for dynamically reducing its storage space by keeping smaller representative groups of packets, adapting the sampling rate accordingly. We evaluate the accuracy of RRDtrace on inferring the flow size distribution, distribution of traffic among applications, and percentage of malicious population. Our results show that RRDtrace can accurately estimate these properties using the suitable sampling strategy, some of them for arbitrary long time and others only for a recent period. Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P. Markatos |
MASCOTS | 1 |
| 2008 | Proof explanation for a nonmonotonic Semantic Web rules language
Grigoris Antoniou, Antonis Bikakis, Nikos Dimaresis, Manolis Genetzakis, Yannis Georgalis, Guido Governatori, Efie Karouzaki, Nikolaos Kazepis, Dimitris Kosmadakis, Manolis Kritsotakis, Yannis Lilis, Antonis Papadogiannakis, Panagiotis Pediaditis, Constantinos Terzakis, Rena Theodosaki, Dimitris Zeginis |
Data Knowl. Eng. | 12 |
| 2007 | Proof Explanation for the Semantic Web Using Defeasible Logic
Grigoris Antoniou, Antonis Bikakis, Nikos Dimaresis, Manolis Genetzakis, Yannis Georgalis, Guido Governatori, Efie Karouzaki, Nikolaos Kazepis, Dimitris Kosmadakis, Manolis Kritsotakis, Yannis Lilis, Antonis Papadogiannakis, Panagiotis Pediaditis, Constantinos Terzakis, Rena Theodosaki, Dimitris Zeginis |
KSEM | 12 |
| 2007 | Improving the Performance of Passive Network Monitoring Applications using Locality BufferingabstractIn this paper, we present a novel approach for improving the performance of a large class of CPU and memory intensive passive network monitoring applications, such as intrusion detection systems, traffic characterization applications, and NetFlow export probes. Our approach, called locality buffering, reorders the captured packets by clustering packets with the same destination port, before they are delivered to the monitoring application, resulting to improved code and data locality, and consequently to an overall increase in the packet processing throughput and to a decrease in the packet loss rate. We have implemented locality buffering within the widely used libpcap packet capturing library, which allows existing monitoring applications to transparently benefit from the reordered packet stream without the need to change application code. Our experimental evaluation shows that locality buffering improves significantly the performance of popular applications, such as the Snort IDS, which exhibits a 40% increase in the packet processing throughput and a 60% improvement in packet loss rate. Antonis Papadogiannakis, Demetres Antoniades, Michalis Polychronakis, Evangelos P. Markatos |
MASCOTS | 1 |
| 2006 | DiMAPI: An Application Programming Interface for Distributed Network MonitoringabstractNetwork monitoring and measurement is commonly regarded as an essential function for understanding, managing and improving the performance and security of network infrastructures. Traditional passive network monitoring approaches are not adequate for fine-grained performance measurements nor for security applications. In addition, many applications would benefit from monitoring data gathered at multiple vantage points within a network infrastructure. This paper presents the design and implementation of DiMAPI, an application programming interface for distributed passive network monitoring. DiMAPI extends the notion of the network flow with the scope attribute, which enables flow creation and manipulation over a set of local and remote monitoring sensors. Experiments with a number of applications on top of DiMAPI show that it has reasonable performance, while the response latency is very close to the actual round trip time between the monitoring application and the monitoring sensors. A broad range of monitoring applications can benefit from DiMAPI to efficiently perform advanced monitoring tasks over a potentially large number of passive monitoring sensors Panos Trimintzios, Michalis Polychronakis, Antonis Papadogiannakis, Michalis Foukarakis, Evangelos P. Markatos, Arne Øslebø |
NOMS | 3 |