Λοιποί Διδάσκοντες

Φακής Αλέξανδρος

Προσωπικά Στοιχεία
Φακής Αλέξανδρος


alfa [at] aegean [dot] gr

22730 82286

Κτήριο Λυμπέρη, 2ος Όροφος, Β9

Προσωπική Ιστοσελίδα

Copyright Notice: Το υλικό αυτό παρουσιάζεται για έγκαιρη διάδοση επιστημονικής και τεχνικής εργασίας. Τα πνευματικά δικαιώματα και όλα τα σχετικά δικαιώματα παραμένουν στους συγγραφείς ή σε άλλους κατόχους πνευματικών δικαιωμάτων. Όσοι αντιγράφουν αυτές τις πληροφορίες αναμένεται να τηρούν τους όρους και τους περιορισμούς που επιβάλλει το πνευματικό δικαίωμα κάθε συγγραφέα. Στις περισσότερες περιπτώσεις, τα έργα αυτά δεν μπορούν να αναδημοσιευτούν ή να αναπαραχθούν μαζικά χωρίς τη ρητή άδεια του κατόχου των πνευματικών δικαιωμάτων.


Επιστημονικά Περιοδικά

[1]
K. Papageorgiou, A. Fakis, G. Spathoulas, A. Kakarountas, An Overview of Security Issues for Blockchain Based Distributed Applications, Security and Privacy in Smart Environments, pp. 187-203, 2024, Springer Nature Switzerland Cham

A. Fakis, G. Karopoulos, G. Kambourakis, Neither Denied nor Exposed: Fixing WebRTC Privacy Leaks, Future Internet, 2020, MDPI, https://www.mdpi.com/1999-5903/12/5/92
Περίληψη:
To establish peer-to-peer connections and achieve realtime web-based communication, the WebRTC framework requires address information of the communicating peers. This means that users behind, say, NAT or firewalls normally rely on the ICE framework for the sake of negotiating information about the connection and media transferring. This typically involves STUN/TURN servers, which assist the peers discover each other's private and public IP:port, and relay traffic if direct connection fails. Nevertheless, these IP:port pieces of data can be easily captured by anyone who controls the corresponding STUN/TURN server, and even more become readily available to the JavaScript application running on the webpage. While this is acceptable for a user that deliberately initiates a WebRTC connection, it becomes a worrisome privacy issue for those being unaware that such a connection is attempted. Furthermore, the application acquires more information on the local network architecture compared to what is exposed in usual HTTP interactions, where only the public IP is visible. Even though this problem is well-known in the related literature, no practical solution has been proposed so far. To this end, and for the sake of detecting and preventing in realtime the execution of STUN/TURN clandestine, privacy-invading requests, we introduce two different kinds of solutions (a) a browser extension, and (b) an HTTP gateway, implemented in C++ as well as in Golang. Both solutions detect any WebRTC API call before it happens and inform accordingly the end-user about the webpage's intentions. We meticulously evaluate the proposed schemes in terms of performance and demonstrate that even in the worst case, the latency introduced is tolerable.

A. Fakis, G. Karopoulos, G. Kambourakis, OnionSIP: Preserving privacy in SIP with Onion Routing, The Journal of Universal Computer Science (J.UCS), Vol. 23, No. 10, pp. 969-991, 2017, Verlag der Technischen Universität Graz, http://www.jucs.org/jucs_23_10/onion_sip..., indexed in SCI-E, IF = 0.696
Περίληψη:
While more and more users turn to IP-based communication technologies, privacy and anonymity remain largely open issues. One of the most prominent VoIP protocols for multimedia session management is SIP which, despite its popularity, suffers from security and privacy flaws. As SIP messages are sent in plain text, user data are exposed to intermediate proxies and eavesdroppers. As a result, information about users participating in a call can leak from header data, which cannot be omitted since they are needed for the correct routing of SIP messages to their final destination. Even more, traffic analysis attacks can be mounted with data stemming from lower layers. To redress this kind of problems, privacy can be achieved either by the construction of a lower level tunnel (via the use of SSL or IPsec protocols) or by employing a custom-tailored solution. However, SSL and IPsec are known for leading to undesirable, non affordable delays, and thus the need for a SIP-oriented solution is preferable. In the context of this article, we evaluate three alternative solutions to encounter the above issues. More specifically, we use two well-known anonymity networks, Tor and I2P, for secluding both caller's and callee's actions by securing SIP messages content. As a third solution, we present our proposal for preserving privacy in SIP signaling, by using an onion-routing approach, where selected sensitive fields of SIP messages are encrypted using either asymmetric or symmetric encryption. We compare these three alternatives in terms of performance, mentioning the pros and cons that come up with each proposal. Our work also presents the reasons why other existing anonymity networks fail to be considered as appropriate for preserving anonymity in SIP.
Επικοινωνία
  • Πρόεδρος: Σκούτας Δημήτριος
  • Προϊσταμένη Γραμματείας: Καραγιάννη Καλλιόπη
  • Γραμματεία Προπτυχιακού: Σχοινάς Αλέξανδρος
  • Γραμματεία Μεταπτυχιακού: Ευγενικού Αργυρώ
  • Email: dicsd [at] aegean [dot] gr
  • Τηλέφωνο: 2273082000
  • Διεύθυνση: Κτήριο Λυμπέρη, Παλαμά 2 & Γοργύρας, Τ.Κ. 83200
  • Ιστοσελίδα: www.icsd.aegean.gr
  • Ωράριο: Δευτέρα - Παρασκευή: 8:00 - 16:00
Στατιστικά Σπουδών
Μέσος Όρος Βαθμού Πτυχίου

7.76

Μέσος χρόνος Απόκτησης Πτυχίου

6.5 έτη

Μαθήματα με εργαστήριο

46

Κύκλοι Σπουδών

6

Μαθήματα Υποχρεωτικά

36

Μαθήματα Κύκλου

8

Σύνολο μαθημάτων για πτυχίο

55

Διπλωματική Εργασία

Υποχρεωτική