Stockholm, Stockholms län, Sverige
1 tn följare Fler än 500 kontakter

Bli medlem för att se profilen

Aktivitet

Gå med nu för att se all aktivitet

Erfarenhet och utbildning

  • Filed

Se Stylianos (Stelios)s fullständiga erfarenhet

Se titel, anställningstid med mera.

eller

Genom att klicka på Fortsätt för att gå med eller logga in samtycker du till LinkedIns användaravtal, sekretesspolicy och cookiepolicy.

Publikationer

  • SHIELD: a data verification framework for participatory sensing systems

    WiSec '15 Proceedings of the 8th ACM Conference on Security & Privacy in Wireless and Mobile Networks

    The openness of PS systems renders them vulnerable to malicious users that can pollute the measurement collection process, in an attempt to degrade the PS system data and, overall, its usefulness. Mitigating such adversarial behavior is hard. Cryptographic protection, authentication, authorization, and access control can help but they do not fully address the problem. Reports from faulty insiders (participants with credentials) can target the process intelligently, forcing the PS system to…

    The openness of PS systems renders them vulnerable to malicious users that can pollute the measurement collection process, in an attempt to degrade the PS system data and, overall, its usefulness. Mitigating such adversarial behavior is hard. Cryptographic protection, authentication, authorization, and access control can help but they do not fully address the problem. Reports from faulty insiders (participants with credentials) can target the process intelligently, forcing the PS system to deviate from the actual sensed phenomenon. Filtering out those faulty reports is challenging, with practically no prior knowledge on the participants'​ trustworthiness, dynamically changing phenomena, and possibly large numbers of compromised devices. This paper proposes SHIELD, a novel data verification framework for PS systems that can complement any security architecture. SHIELD handles available, contradicting evidence, classifies efficiently incoming reports, and effectively separates and rejects those that are faulty. As a result, the deemed correct data can accurately represent the sensed phenomena, even when 45% of the reports are faulty, intelligently selected by coordinated adversaries and targeted optimally across the system's coverage area.

    Övriga författare
    Visa publikation
  • Secure and Privacy-Preserving Smartphone-Based Traffic Information Systems

    IEEE Transactions on Intelligent Transportation Systems

    Övriga författare
    Visa publikation
  • Trustworthy People-Centric Sensing: Privacy, Security and User Incentives Road-Map

    IEEE

    The broad capabilities of widespread mobile devices have paved the way for People-Centric Sensing (PCS). This emerging paradigm enables direct user involvement in possibly large-scale and diverse data collection and sharing. Unavoidably, this raises significant privacy concerns, as participants may inadvertently reveal a great deal of sensitive information. In this work, we discuss security, user privacy and incentivization for this sensing paradigm, exploring how to address all aspects of this…

    The broad capabilities of widespread mobile devices have paved the way for People-Centric Sensing (PCS). This emerging paradigm enables direct user involvement in possibly large-scale and diverse data collection and sharing. Unavoidably, this raises significant privacy concerns, as participants may inadvertently reveal a great deal of sensitive information. In this work, we discuss security, user privacy and incentivization for this sensing paradigm, exploring how to address all aspects of this multifaceted problem. We critically survey the security and privacy properties of state-of- the-art research efforts in the area. Based on our findings, we posit open issues and challenges, and discuss possible ways to address them, so that security and privacy do not hinder the deployment of PCS systems.

    Övriga författare
    Visa publikation
  • SEROSA: SERvice oriented security architecture for Vehicular Communications

    IEEE

    Modern vehicles are no longer mere mechanical devices; they comprise dozens of digital computing platforms, coordinated by an in-vehicle network, and have the potential to significantly enhance the digital life of individuals on the road. While this transformation has driven major advancements in road safety and transportation efficiency, significant work remains to be done to support the security and privacy requirements of the envisioned ecosystem of commercial services and applications…

    Modern vehicles are no longer mere mechanical devices; they comprise dozens of digital computing platforms, coordinated by an in-vehicle network, and have the potential to significantly enhance the digital life of individuals on the road. While this transformation has driven major advancements in road safety and transportation efficiency, significant work remains to be done to support the security and privacy requirements of the envisioned ecosystem of commercial services and applications (i.e., Internet access, video streaming, etc.). In the era when “service is everything and everything is a service”, Vehicular Communication (VC) systems cannot escape from this ongoing trend towards multi-service environments accessible from anywhere. To meet the diverse requirements of vehicle operators and Service Providers (SPs), we present SEROSA, a service-oriented security and privacy-preserving architecture for VC. By synthesizing existing VC standards and Web Services (WS), our architecture provides comprehensive identity and service management while ensuring interoperability with existing SPs. We fully implement our system and extensively assess its efficiency, practicality, and dependability. Overall, SEROSA significantly extends the state of the art and serves as a catalyst for the integration of vehicles into the vast domain of Internet-based services.

    Övriga författare
    Visa publikation
  • Allocation Adversarial Resources in Sensor Networks

    21st European Signal Processing Conference

    So far, a plethora of security set-ups for wireless sensor networks (WSNs) has been analyzed and resilience to sophisticated attacks has been investigated. Nevertheless, the critical aspect of how the adversary can deploy her resources to maximally affect the attacked system should be further studied. The basic problem statement in this case is: Given a number of compromised entities (nodes) and cryptographic keys, how can the adversary devise a close-to-optimal attack tactic? Considering an…

    So far, a plethora of security set-ups for wireless sensor networks (WSNs) has been analyzed and resilience to sophisticated attacks has been investigated. Nevertheless, the critical aspect of how the adversary can deploy her resources to maximally affect the attacked system should be further studied. The basic problem statement in this case is: Given a number of compromised entities (nodes) and cryptographic keys, how can the adversary devise a close-to-optimal attack tactic? Considering an abstract model for a mission-critical WSN and the adversary, it has been recently shown that an optimal attack is computationally hard. The heuristic approaches have been proposed to address this problem introduce a significant amount of computational overhead. In this paper, we try to address this problem more efficiently and we show that the problem can be relaxed either by combining a genetic algorithm with a convex relaxation (CR) stage or by formulating it in a compressed sensing (CS) framework. This way, near-optimal resource allocation strategies can be efficiently computed even in the case of dynamically changing networks.

  • Towards a Secure and Privacy-preserving Multi-service Vehicular Architecture

    4th IEEE International Workshop on Data Security and Privacy in Wireless Networks: D-SPAN

    To secure vehicular services and to protect the privacy of individuals, it is necessary to revisit
    and extend the vehicular Public Key Infrastructure (VPKI) approach towards a multi-service security architecture. This is exactly what this work does, providing a design and a proof-of-concept
    implementation that supports anonymous Authentication, Authorization and Accountability according to the long-standing standards. Moreover, we elaborate on the VPKI operation
    across multiple VC…

    To secure vehicular services and to protect the privacy of individuals, it is necessary to revisit
    and extend the vehicular Public Key Infrastructure (VPKI) approach towards a multi-service security architecture. This is exactly what this work does, providing a design and a proof-of-concept
    implementation that supports anonymous Authentication, Authorization and Accountability according to the long-standing standards. Moreover, we elaborate on the VPKI operation
    across multiple VC system domains, and craft a roadmap for further developments and extensions
    that leverage Web-based approaches.

    Övriga författare
  • VeSPA: vehicular security and privacy-preserving architecture

    Proceedings of the 2nd ACM workshop on Hot topics on wireless network security and privacy

    Vehicular Communications (VC) are reaching a near deployment phase and will play an important role in improving road safety, driving efficiency and comfort. The industry and the academia have reached a consensus for the need of a Public Key Infrastructure (PKI), in order to achieve security, identity management, vehicle authentication, as well as preserve vehicle privacy. Moreover, a gamut of proprietary and safety applications, such as location-based services and pay-as-you-drive systems, are…

    Vehicular Communications (VC) are reaching a near deployment phase and will play an important role in improving road safety, driving efficiency and comfort. The industry and the academia have reached a consensus for the need of a Public Key Infrastructure (PKI), in order to achieve security, identity management, vehicle authentication, as well as preserve vehicle privacy. Moreover, a gamut of proprietary and safety applications, such as location-based services and pay-as-you-drive systems, are going to be offered to the vehicles. The emerging applications are posing new challenges for the existing Vehicular Public Key Infrastructure (VPKI) architectures to support Authentication, Authorization and Accountability (AAA), without exposing vehicle privacy. In this work we present an implementation of a VPKI that is
    compatible with the VC standards. We propose the use of tickets as cryptographic tokens to provide AAA and also preserve vehicle privacy against adversaries and the VPKI. Finally, we present the efficiency results of our implementation
    to prove its applicability.

    Övriga författare
    Visa publikation
  • VeSPA: Vehicular Security and Privacy Architecture

    2nd ACM Workshop on Hot Topics on Wireless Network Security and Privacy Co-located with ACM WiSec 2013

    The emerging vehicle applications are posing new challenges for
    the existing Public Key Infrastructures (PKI) to support Authentication,
    Authorization and Accountability (AAA) in the Vehicular Communications context. In this work an implementation of a Vehicular-PKI that is compatible with the VC standards is presented. Tickets are proposed as cryptographic tokens to provide AAA for vehicles and preserve privacy and security against adversaries.

    Övriga författare
  • On the Optimal Allocation of Adversarial Resources

    ACM

    Security is important for mission-critical wireless sensor networks (WSNs). This is especially so because powerful adversaries could compromise and control a signi?cant fraction of the network nodes. A plethora of schemes has been developed to secure wireless sensor networks and resilience to sophisticated attacks has been analyzed. However, the question of how the adversary could deploy her resources to maximally a?ect the attacked system has remained largely unaddressed. This is the problem…

    Security is important for mission-critical wireless sensor networks (WSNs). This is especially so because powerful adversaries could compromise and control a signi?cant fraction of the network nodes. A plethora of schemes has been developed to secure wireless sensor networks and resilience to sophisticated attacks has been analyzed. However, the question of how the adversary could deploy her resources to maximally a?ect the attacked system has remained largely unaddressed. This is the problem this paper is concerned with: Given a number of compromised entities (nodes) and cryptographic keys, how can the adversary devise a close-to-optimal attack tactic? To the best of our knowledge, this is the ?rst investigation of its kind: while the basic adversarial behavior is well-known, the problem of how the adversary can optimally deploy her resources to maximize the attack impact has not been considered for WSNs. We consider an abstract model of the mission-critical WSN and the adversary, and we ?nd that the determination of an optimal attack is computationally hard, thus, we devise an effcient heuristic approach. An intelligent adversarial resource allocation indeed yields disproportional gains for the attacker. Our analysis is the ?rst necessary step to comprehend how to best address vulnerabilities

    Övriga författare
  • SPPEAR: Security & Privacy-Preserving Architecture for Mobile Crowd-Sensing Applications

    ACM

    Recent advances in sensing, computing, and networking have paved the way for the emerging paradigm of participatory sensing (PS). The openness of such systems and the richness of user data they entail raise significant concerns for their security, privacy and resilience. Prior works addressed different aspects of the problem. But in order to reap the benefits of this new sensing paradigm, we need a comprehensive solution. That is, a secure and accountable PS system that preserves user privacy…

    Recent advances in sensing, computing, and networking have paved the way for the emerging paradigm of participatory sensing (PS). The openness of such systems and the richness of user data they entail raise significant concerns for their security, privacy and resilience. Prior works addressed different aspects of the problem. But in order to reap the benefits of this new sensing paradigm, we need a comprehensive solution. That is, a secure and accountable PS system that preserves user privacy, and enables the provision of incentives to the participants. At the same time, we are after a PS system that is resilient to abusive users and guarantees privacy protection even against multiple misbehaving PS entities (servers). We address these seemingly contradicting requirements with our SPPEAR architecture. Our full blown implementation and experimental evaluation demonstrate that SPPEAR is efficient, practical, and scalable. Last but not least, we formally assess the achieved security and privacy properties. Overall, our system is a comprehensive solution that significantly extends the state-of-the-art and can catalyze the deployment of PS applications.

    Övriga författare
    Visa publikation

Kurser

  • Advanced Internetworking

    -

  • Advanced Networked Systems Security

    -

  • An Efficient Discarding Mechanism of DDoS Traffic Based on QoS.

    Thesis

  • Building Networked Systems Security

    -

  • Data Intensive Computing

    -

  • Data Science and Machine Learning Essentials

    -

  • Network Security

    -

  • Networked Systems Security

    -

  • Principles of Computer Security

    -

  • Research Methodology and Scientific Communication

    -

  • Security Architecture for Open Distributed Systems

    -

  • Security Management

    -

  • Security for Java Environment and Electronic Commerce

    -

  • Security in Mobile and Wireless Networks

    -

  • Software Engineering and Security Architecture

    -

  • Statistical Problems in Simulation

    -

  • Systems Theory and Security

    -

Projekt

  • SHIELD

    In this work I developed a data verification framework for Participatory Sensing systems. More specifically, I developed a reasoning and inference framework which leverages the Dempster-Shafer Theory of evidence and a combination of supervised and unsupervised machine learning techniques to detect and sift invalid and malicious data originating from adversarial users.

    The prototype implementation was done using python and the scikit-learn library

  • SPPEAR: Security & Privacy-Preserving Architecture for Mobile Crowd-Sensing Applications

    In this work we designed and deployed a IAM framework for IoT systems (sensors, smart-phones). A proof of concept implementation was done:

    - C++ with openSSL for issuing cryptographic credentials. For credential storage we used MySQL.
    - The identity provider was implemented in PHP. For credential storage (on the IdP) we used LDAP. The IdP provided authentication based on group signatures (http://en.wikipedia.org/wiki/Group_signature), implemented in Java. Moreover, for enhanced…

    In this work we designed and deployed a IAM framework for IoT systems (sensors, smart-phones). A proof of concept implementation was done:

    - C++ with openSSL for issuing cryptographic credentials. For credential storage we used MySQL.
    - The identity provider was implemented in PHP. For credential storage (on the IdP) we used LDAP. The IdP provided authentication based on group signatures (http://en.wikipedia.org/wiki/Group_signature), implemented in Java. Moreover, for enhanced privacy-protection an oblivious transfer protocol was implemented (in Java).
    - Mobile clients were also implemented for Android.

  • A Vehicular Public Key Infrastructure

    Design and deployment of a PKI for Vehicular Networks (see publications). The implementation included:

    - C++ with openSSL for issuing cryptographic credentials. For credential storage we used MySQL.
    - The identity provider was implemented in PHP. For credential storage (on the IdP) we used LDAP
    - The testing framework was implemented in Python and JAVA (stress testing was performed with JMeter)

    For authentication, authorization and A.C we leveraged SAML (Security Assertion…

    Design and deployment of a PKI for Vehicular Networks (see publications). The implementation included:

    - C++ with openSSL for issuing cryptographic credentials. For credential storage we used MySQL.
    - The identity provider was implemented in PHP. For credential storage (on the IdP) we used LDAP
    - The testing framework was implemented in Python and JAVA (stress testing was performed with JMeter)

    For authentication, authorization and A.C we leveraged SAML (Security Assertion Markup Language).



  • A framework for allocating adversarial resources

    In the context of this work, we developed a framework for defining optimal adversarial strategies. The framework leveraged genetic algorithms and dynamic programming techniques and was implemented in Java

  • PRESERVE

    -

    The goal of PRESERVE (Preparing Secure Vehicle-to-X Communication Systems) is to bring secure and privacy-protected V2X communication closer to reality by providing and field testing a security and privacy subsystem for V2X systems. PRESERVE will combine and extend results from earlier research projects, integrating and developing them to a pre-deployment stage by enhancing scalability, reducing the cost level, and addressing open deployment issues. It aims at providing comprehensive protection…

    The goal of PRESERVE (Preparing Secure Vehicle-to-X Communication Systems) is to bring secure and privacy-protected V2X communication closer to reality by providing and field testing a security and privacy subsystem for V2X systems. PRESERVE will combine and extend results from earlier research projects, integrating and developing them to a pre-deployment stage by enhancing scalability, reducing the cost level, and addressing open deployment issues. It aims at providing comprehensive protection ranging from the vehicle sensors, through the on-board network and V2V/V2I communication, to the receiving application. As a result, PRESERVE will present a complete, scalable, and cost-efficient V2X security subsystem that is close-to-market and will be provided to other FOT projects and interested parties for ongoing testing.

    Field operational testing will investigate a number of important scalability and feasibility issues. Further, the V2X security subsystem will also be provided to other projects to jointly investigate integration and performance in larger fleets of vehicles. Another strategic objective of PRESERVE is to contribute to on-going harmonization and standardization efforts at the European level.


    PRESERVE is expected to produce the following results:

    - Harmonized V2X Security Architecture
    - Implementation of V2X Security Subsystem
    - Cheap and scalable security ASIC for V2X
    - Testing results VSS under realistic conditions
    - Research results for deployment challenges

Utmärkelser och priser

  • Best Paper Award ACM WiSec

    ACM WiSec

    Best Paper Award for "SPPEAR: Security & Privacy-Preserving Architecture for Mobile Crowd-Sensing Applications"

Språk

  • Greek

    Modersmåls- eller tvåspråkig nivå

  • English

    Fullständig professionell nivå

  • French

    Begränsad yrkeskunskap

  • Swedish

    Begränsad yrkeskunskap

Organisationer

  • Car-to-Car Communication Consortium (C2C-CC)

    -

  • OWASP Sweden

    -

Fler aktiviteter efter Stylianos (Stelios)

Se hela Stylianos (Stelios)s profil

  • Upptäck gemensamma kontakter
  • Bli presenterad
  • Kontakta Stylianos (Stelios) direkt
Bli medlem för att se hela profilen

Andra liknande profiler