Antonios Gouglidis

dblp:85/7837 · DBLP profile ↗
← Back
17ranked-venue papers
2as first author
9since 2021 · last 2024
0000-0002-4702-3942ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 3 since 2021Computer networks · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2024 Enabling Multi-Layer Threat Analysis in Dynamic Cloud Environments
abstract
Most Threat Analysis (TA) techniques analyze threats to targeted assets (e.g., components, services) by considering static interconnections among them. However, in dynamic environments, e.g., the Cloud, resources can instantiate, migrate across physical hosts, or decommission to provide rapid resource elasticity to its users. Existing TA techniques are not capable of addressing such requirements. Moreover, complex multi-layer/multi-asset attacks on Cloud systems are increasing, e.g., the Equifax data breach; thus, TA approaches must be able to analyze them. This paper proposes ThreatPro, which supports dynamic interconnections and analysis of multi-layer attacks in the Cloud. ThreatPro facilitates threat analysis by developing a technology-agnostic information flow model, representing the Cloud's functionality through conditional transitions. The model establishes the basis to capture the multi-layer and dynamic interconnections during the life cycle of a Virtual Machine. ThreatPro contributes to (1) enabling the exploration of a threat's behavior and its propagation across the Cloud, and (2) assessing the security of the Cloud by analyzing the impact of multiple threats across various operational layers/assets. Using public information on threats from the National Vulnerability Database, we validate ThreatPro's capabilities, i.e., identify and trace actual Cloud attacks and speculatively postulate alternate potential attack paths.
Salman Manzoor, Antonios Gouglidis, Matthew Bradbury, Neeraj Suri
IEEE Trans. Cloud Comput.2
2023 A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments
Igor Ivkic, Dominik Thiede, Nicholas J. P. Race, Matthew Broadbent, Antonios Gouglidis
CLOSER5
2023 Robust Federated Learning Method Against Data and Model Poisoning Attacks with Heterogeneous Data Distribution
abstract
Federated Learning (FL) is essential for building global models across distributed environments. However, it is significantly vulnerable to data and model poisoning attacks that can critically compromise the accuracy and reliability of the global model. These vulnerabilities become more pronounced in heterogeneous environments, where clients’ data distributions vary broadly, creating a challenging setting for maintaining model integrity. Furthermore, malicious attacks can exploit this heterogeneity, manipulating the learning process to degrade the model or even induce it to learn incorrect patterns. In response to these challenges, we introduce RFCL, a novel Robust Federated aggregation method that leverages CLustering and cosine similarity to select similar cluster models, effectively defending against data and model poisoning attacks even amidst high data heterogeneity. Our experiments assess RFCL’s performance against various attacker numbers and Non-IID degrees. The findings reveal that RFCL outperforms existing robust aggregation methods and demonstrates the capability to defend against multiple attack types.
Ebtisaam Alharbi, Leandro Soriano Marcolino, Antonios Gouglidis, Qiang Ni
ECAI3
2022 Joint Security-vs-QoS Framework: Optimizing the Selection of Intrusion Detection Mechanisms in 5G networks
abstract
The advent of 5G technology introduces new - and potentially undiscovered - cybersecurity challenges, with unforeseen impacts on our economy, society, and environment. Interestingly, Intrusion Detection Mechanisms (IDMs) can provide the necessary network monitoring to ensure - to a big extent - the detection of 5G-related cyberattacks. Yet, how to realize the attack surface of 5G networks with respect to the detected risks, and, consequently, how to optimize the cybersecurity levels of the network, remains an open critical challenge. In respect, this work focuses on deploying multiple distributed Security Agents (SAs) that can run different IDMs over various network components and proposes a cybersecurity mechanism for optimizing the network’s attack surface with respect to the Quality of Service (QoS). The proposed approach relies on a new closed-form utility function to describe the trade-off between cybersecurity and QoS and uses multi-objective optimization to improve the selection of each SA detection level. We demonstrate via simulations that before optimization, an increase in the detection level of SAs brings a direct decrease in QoS as more computational, bandwidth and monetary resources are utilized for IDM processing. Thereby, after optimization, we demonstrate that our mechanism can strike a balance between cybersecurity and QoS while showcasing the impact of the importance of different objectives of the joint optimization.
Arash Bozorgchenani, Charilaos C. Zarakovitis, Su Fong Chien, Heng Siong Lim, Qiang Ni, Antonios Gouglidis, Wissam Mallouli
ARES6
2022 Poster: Effectiveness of Moving Target Defense Techniques to Disrupt Attacks in the Cloud
abstract
Moving Target Defense (MTD) can eliminate the asymmetric advantage that attackers have in terms of time to explore a static system by changing a system's configuration dynamically to reduce the efficacy of reconnaissance and increase uncertainty and complexity for attackers. To this extent, a variety of MTDs have been proposed for specific aspects of a system. However, deploying MTDs at different layers/components of the Cloud and assessing their effects on the overall security gains for the entire system is still challenging since the Cloud is a complex system entailing physical and virtual resources, and there exists a multitude of attack surfaces that an attacker can target. Thus, we explore the combination of MTDs, and their deployment at different components (belonging to various operational layers) to maximize the security gains offered by the MTDs.We also propose a quantification mechanism to evaluate the effectiveness of the MTDs against the attacks in the Cloud.
Salman Manzoor, Antonios Gouglidis, Matthew Bradbury, Neeraj Suri
CCS2
2022 Poster: Multi-Layer Threat Analysis of the Cloud
abstract
A variety of Threat Analysis (TA) techniques exist that typically target exploring threats to discrete assets (e.g., services, data, etc.) and reveal potential attacks pertinent to these assets. Furthermore, these techniques assume that the interconnection among the assets is static. However, in the Cloud, resources can instantiate or migrate across physical hosts at run-time, thus making the Cloud a dynamic environment. Additionally, the number of attacks targeting multiple assets/layers emphasizes the need for threat analysis approaches developed for Cloud environments. Therefore, this proposal presents a novel threat analysis approach that specifically addresses multi-layer attacks. The proposed approach facilitates threat analysis by developing a technology-agnostic information flow model. It contributes to exploring a threat's propagation across the operational stack of the Cloud and, consequently, holistically assessing the security of the Cloud.
Salman Manzoor, Antonios Gouglidis, Matthew Bradbury, Neeraj Suri
CCS2
2022 A Security Cost Modelling Framework for Cyber-Physical Systems
abstract
Cyber-Physical Systems (CPS) are formed through interconnected components capable of computation, communication, sensing and changing the physical world. The development of these systems poses a significant challenge, since they have to be designed in a way to ensure cyber-security without impacting their performance. This article presents the Security Cost Modelling Framework (SCMF) and shows supported by an experimental study how it can be used to measure, normalise, and aggregate the overall performance of a CPS. Unlike previous studies, our approach uses different metrics to measure the overall performance of a CPS and provides a methodology for normalising the measurement results of different units to a common Cost Unit . Moreover, we show how the Security Costs can be extracted from the overall performance measurements, which allows us to quantify the overhead imposed by performing security-related tasks. Furthermore, we describe the architecture of our experimental testbed and demonstrate the applicability of SCMF in an experimental study. Our results show that measuring the overall performance and extracting the security costs using SCMF can serve as basis to redesign interactions to achieve the same overall goal at less costs.
Igor Ivkic, Patrizia Sailer, Antonios Gouglidis, Andreas Mauthe, Markus Tauber
ACM Trans. Internet Techn.3
2021 Analysing Design Approaches for the Power Consumption in Cyber-Physical Systems
Patrizia Sailer, Igor Ivkic, Markus Tauber, Andreas Mauthe, Antonios Gouglidis
IM5
2021 Specifying and verifying usage control models and policies in TLA+
Christos Grompanopoulos, Antonios Gouglidis, Anastasia Mavridou
Int. J. Softw. Tools Technol. Transf.2
2019 Communication Standards for Distributed Renewable Energy Sources Integration in Future Electricity Distribution Networks
abstract
Distributed Renewable Energy Sources (DRESs) such as wind and solar are becoming a promising alternative for the energy supply in modern (smart) electricity grids as part of future sustainable smart cities. Successful integration of DRESs requires efficient, resilient, and secure communication in order to satisfy the highly challenging and real-time constraints of smart city applications. Regardless of the various research solutions proposed in this context within the last decade, the relevant standardization is a non-trivial issue and is still in its infancy. In this position paper, we briefly review the currently employed DRES communications standards and identify the gaps in their present status. Finally, we discuss and suggest potential pathways for further improvement.
Anish Jindal, Angelos K. Marnerides, Antonios Gouglidis, Andreas Mauthe, David Hutchison 0001
ICASSP3
2017 The Extended Cloud: Review and Analysis of Mobile Edge Computing and Fog From a Security and Resilience Perspective
abstract
Mobile edge computing (MEC) and fog are emerging computing models that extend the cloud and its services to the edge of the network. The emergence of both MEC and fog introduce new requirements, which mean their supported deployment models must be investigated. In this paper, we point out the influence and strong impact of the extended cloud (i.e., the MEC and fog) on existing communication and networking service models of the cloud. Although the relation between them is fairly evident, there are important properties, notably those of security and resilience, that we study in relation to the newly posed requirements from the MEC and fog. Although security and resilience have been already investigated in the context of the cloud-to a certain extent-existing solutions may not be applicable in the context of the extended cloud. Our approach includes the examination of models and architectures that underpin the extended cloud, and we provide a contemporary discussion on the most evident characteristics associated with them. We examine the technologies that implement these models and architectures, and analyze them with respect to security and resilience requirements. Furthermore, approaches to security and resilience-related mechanisms are examined in the cloud (specifically, anomaly detection and policy-based resilience management), and we argue that these can also be applied in order to improve security and achieve resilience in the extended cloud environment.
Noor-ul-Hassan Shirazi, Antonios Gouglidis, Arsham Farshad, David Hutchison 0001
IEEE J. Sel. Areas Commun.2
2016 Anomaly Detection in the Cloud Using Data Density
abstract
Cloud computing is now extremely popular because of its use of elastic resources to provide optimized, cost-effective and on-demand services. However, clouds may be subject to challenges arising from cyber attacks including DoS and malware, as well as from sheer complexity problems that manifest themselves as anomalies. Anomaly detection techniques are used increasingly to improve the resilience of cloud environments and indirectly reduce the cost of recovery from outages. Most anomaly detection techniques are computationally expensive in a cloud context, and often require problem-specific parameters to be predefined in advance, impairing their use in real-time detection. Aiming to overcome these problems, we propose a technique for anomaly detection based on data density. The density is computed recursively, so the technique is memory-less and unsupervised, and therefore suitable for real-time cloud environments. We demonstrate the efficacy of the proposed technique on a dataset created in our cloud testbed. The dataset consists of feature vectors obtained from a physical cloud testbed network experiencing migration under controlled traffic conditions modelling scenarios combining normal network use with network-based attacks. The obtained results, which include precision, recall, accuracy, F-score and G-score, show that network level attacks are detectable with high accuracy.
Noor-ul-Hassan Shirazi, Steven Simpson, Antonios Gouglidis, Andreas Mauthe, David Hutchison 0001
CLOUD3
2016 A Multi-commodity Network Flow Model for Cloud Service Environments
Ioannis M. Stephanakis, Noor-ul-Hassan Shirazi, Antonios Gouglidis, David Hutchison 0001
EANN3
2016 Modelling security risk in critical utilities: The system at risk as a three player game and agent society
abstract
It becomes essential when reasoning about the security risks to critical utilities such electrical power and water distribution to recognize that the interests of producers and consumers do not fully coincide. They may have incentives to behave strategically towards each other, as well as toward some third party adversary. We therefore argue for the need to extend the prior literature, which has concentrated on the strategic, adaptive game between adversary and defender, towards 3-player games. But it becomes hard to justify modelling a population of consumers as a single, decision making actor. So we also show how we can model consumers as a group of mutually-influencing, yet not centrally co-ordinated, heterogeneous agents. And we suggest how this representation can be integrated into a game-theoretic framework. This requires a framework in which payoffs are known by the players only stochastically. We present some basic models and demonstrate the nature of the modelling commitments that need to be made in order to reason about utilities' security risk.
Jeremy Busby, Antonios Gouglidis, Stefan Rass, Sandra König
SMC2
2016 Information assurance techniques: Perceived cost effectiveness
Jose M. Such, Antonios Gouglidis, William Knowles, Gaurav Misra, Awais Rashid
Comput. Secur.2
2012 domRBAC: An access control model for modern collaborative systems
Antonios Gouglidis, Ioannis Mavridis
Comput. Secur.1
2011 Role-Based Secure Inter-operation and Resource Usage Management in Mobile Grid Systems
Antonios Gouglidis, Ioannis Mavridis
WISTP1