Critical National Infrastructures (CNIs) have evolved over the last years through the digitization of their services, which simultaneously led to an increase of their threat surface. Meanwhile the exponential rise of Artificial Intelligence (AI) technologies has given the means to adversaries to perform targeted attacks against high impact systems as the ones found in CNIs. Current regulation directives as the NIS2 or the Cyber Resilience Act (CRA) focus on the presence of Security Operation Centers (SOC), which include different security technologies for the detection and response to cyber-attacks. Nevertheless, such baseline SOCs do not provide the ability to perform a coordinated and orchestrated detection and response cycle for existing cyber threats, but also do not provide proactive measures for zero-day threats. To this end, this paper presents a new approach for automating the orchestration of the incident lifecycle through Next Generation SOC services able to detect/mitigate sophisticated attacks against CNIs, but also implement proactive detection measures against zero-day threats.
The construction of highly informative and pertinent Cyber Threat Intelligence (CTI) requires a significant amount of resources, including security analysts, processing power, and large storage. This has rendered the access to CTI data cost-ineffective, resulting in unprotected organizations and supply chains, which can lead to severe security issues, especially in domains like Industry 4.0; the consequences can be catastrophic. This paper aims to facilitate the democratization of CTI information by minimizing both production costs and time. To accomplish this, an enhanced LLM-based approach, named eLLM-CTI, is proposed to extract threat intelligence information from unstructured threat reports and convert it to standard-based CTI, following the Structured Threat Information Expression (STIX) 2.1 standard. eLLM-CTI exploits reasoning LLMs (GPT-OSS:20B) enhanced with a Retrieval Augmented Generation (RAG) that serves as a security and threat related knowledge base, assisting the LLM to effectively identify the threat-related information and generate the STIX bundle. The evaluation results indicated that integrating an LLM with RAG can not only enhance its performance in identifying and categorizing unstructured threat-related information as STIX Domain Objects (SDOs), but also in correlating the SDOs according to STIX Relationship Objects (SROs). In this way, eLLM-CTI contributes to the automated generation of CTI feeds that are ready to be deployed without additional processing by security analysts, significantly reducing the manual effort of threat analysts and enabling faster access to critical threat intelligence.
iSOCaaS aims to boost European cyber-security resilience across all levels-organizational, sectoral, national, cross-border, and EU-by creating a standards-based, interoperable Security Operations Center (SOC) cluster. This initiative will empower EU member states to better tackle evolving cyber threats and meet the continent's cybersecurity needs.
This paper reveals the transformative potential of the RETENTION Project in revolutionising remote patient monitoring for individuals with heart failure (HF). Examining the detailed architectural design of the RETENTION platform, we uncover a complex ecosystem designed to redefine HF management. The platform includes the Global Insights Cloud (GIC), Clinical Site Backend (CSB), and Patient Edge (PE) components, integrating advanced technologies and data analytics methods. From continuous data collection to personalised interventions based on evidence-based insights, the RETENTION platform stands out as an innovation in HF care. With a strong commitment to ethical standards and data privacy, along with a user-centric design, the platform aims to empower both clinicians and patients. This abstract provides a glimpse into the significant impact of the RETENTION Project, set to reshape HF management and lead to a new era of patient-focused healthcare.
The increasing frequency, sophistication, and impact of cyberattacks have exposed critical gaps in the preparedness of organizations to detect, respond to, and recover from evolving threats. Traditional training approaches often lack realism, adaptability, and alignment with organizational risks, making them insufficient for today’s dynamic threat landscape. There is a pressing need for cybersecurity training solutions that are not only technically robust but also context-aware and risk-driven. This paper presents an integrated cybersecurity training and assurance framework that combines advanced cyber range capabilities with dynamic risk assessment tools to deliver tailored, organization-specific Training Programmes, that will be realized in four, critical infrastructure pilots, namely healthcare, energy, telecommunication, and maritime, in Greece, and Cyprus. Central to the proposed solution is a federated environment utilizing two Cyber Range platforms, enabling both domain-specific and cross-domain scenarios of varying complexity and difficulty, alongside a risk assessment tool, enabling the assurance to training approach offering a scalable, interoperable, and operationally relevant cybersecurity training ecosystem.
In an era of escalating cyber threats, the imperative for robust and comprehensive cybersecurity measures has never been more pressing. To address this challenge, SYNAPSE presents a pioneering approach by conceptualising, designing, and delivering an Integrated cybersecurity Risk & Resilience Management Platform. The innovation of this platform lies in the integration of key elements, such as situational awareness, incident response, and preparedness (i.e., cyber range), augmented by advanced AI capabilities. Through its holistic approach, SYNAPSE aims to elevate cyber resilience by not only mitigating threats but also fostering a culture of proactive defence, informed decision-making, and collaborative response within organisations and across industries.
Digitalization is continuing facilitating our daily lives. The world is interconnected as never before, bringing close people, businesses, or other organizations. However, hackers are also coming close. New business and operational models require the collection and processing of massive amounts of data in real-time, involving utilization of complex information systems, large supply-chains, personal devices, etc. These impose several advantages for adversaries on the one hand (e.g., poorly protected or monitored elements, slow fashion of security updates/upgrades in components that gain little attention, etc.), and many difficulties for defenders on the other hand (e.g., administrate large and complex systems with high dynamicity) in this cyber-security interplay. Impactful attacks on ICT systems, critical infrastructures, and supply networks, as well as cyber-warfare are deriving the necessity for more effective defensives. This paper presents a swarm-intelligence solution for incident handling and response. Cyber Threat Intelligence (CTI) is continuously integrated in the system (i.e., MISP, CVEs, STIX, etc.), and Artificial Intelligence (AI)/Machine Learning (ML) are incorporated in the risk assessment and event evaluation processes. Several incident handling and response sub-procedures are automated, improving effectiveness and decreasing response time. Information concerning identified malicious activity is circulated back to the community (i.e., via the MISP information sharing platform) in an open loop. The proposal is applied in the supply-chain of healthcare organizations in Europe (considering also EU data protection regulations). Nevertheless, it is a generic solution that can be applied in any domain.
The cyber-threat landscape is constantly and rapidly expanding, overwhelming human analysts in their effort to keep track of the latest threats. This affects both organisations that produce threat intelligence to be consumed by third parties, but also the end consumers of this threat intelligence, who want, for example, to configure proactive defences to protect their infras-tructure. This paper presents a novel, Machine Learning-based, solution able to discover & ingest Cyber Threat Intelligence (CTI) data from unstructured online sources, such as dark web forums, social media and online chatrooms, producing a stream of standardised, structured STIX CTI data at its output. Further, a proof-of-concept is developed and assessed, to investigate its effectiveness with real-life data sources, but also to offer insights into the large amount of potentially useful threat intelligence -relevant information that lies unused in online sources, and the positive impact that the discovery and structuring of this information in a standardised, easily shareable manner can have in terms of providing cyber defenders with an up-to-date and comprehensive view of the threat landscape.
Cyber ranges have gained significant importance in cybersecurity training in recent years, and they are still playing a role of paramount importance, thanks to their ability to give trainees hands-on experience with real-world exercises. This paper presents the motivation and objective of the AERAS project, including a thorough analysis of data from ad hoc interviews and surveys specifically designed and administered for the project’s goals. AERAS aims to apply the cyber range concept to the critical healthcare sector. The AERAS platform will be a virtual cyberwarfare solution that will simulate the operation and effects of security controls and offer hands-on training on their development, assessment, use, and management.
Recent cyber-attacks targeting healthcare organizations underscore the growing prevalence of the sector as a prime target for malicious activities. As healthcare systems manage and store sensitive personal health information, the imperative for robust cyber security and privacy protocols becomes increasingly evident. Consequently, healthcare institutions are compelled to actively address the intricate cyber security risks inherent in their digital ecosystems. In response, we present RAMA, a risk assessment solution designed to evaluate the security status of cyber systems within critical domain, such as the healthcare one. By leveraging RAMA, both local stakeholders, such as the hospital’s IT personnel, and global actors, including external parties, can assess their organization’s cyber risk profile. Notably, RAMA goes beyond risk quantification; it facilitates a comparative analysis by enabling organizations to measure their performance against average aggregated mean scores, fostering a culture of continuous improvement in cyber security practices. The practical efficacy of RAMA is demonstrated through its deployment across four real-world healthcare IT infrastructures. This study not only underscores the significance of addressing cyber security risks within healthcare but also highlights the value of innovative solutions like RAMA in safeguarding sensitive health information and enhancing the sector’s overall cyber resilience.
The paper describes a cloud-based platform that utilizes Artificial Intelligence (AI) and Explainable AI techniques to deliver evidence-based, personalized interventions to individuals over 65 suffering or at risk of hearing loss, cardiovascular disease, cognitive impairments, balance disorders, or mental health issues, while supporting efficient remote monitoring and clinician-driven guidance. As part of the SMART BEAR integrated project, this platform has been developed to support its large-scale clinical trials. The platform consists of a standards-based data harmonization and management layer, as well as a security component, a Big Data Analytics system, a Clinical Decision Support system, and a dashboard component to facilitate efficient data collection across pilot sites.
Cyber security always forms a significant aspect of ICT infrastructure, with threats on supply-chain networks gaining greater attention nowadays. The secure autonomous driving domain presents a unique set of challenges for supply-chain security. Autonomous vehicles rely on a complex ecosystem of hardware and software components, many of which are sourced from third-party suppliers. Ensuring the security and reliability of this supply-chain is essential to maintain the safety and viability of autonomous driving as a technology. To address these challenges, a continuous security assurance approach is necessary. This involves ongoing monitoring, assessment, and improvement of security measures to detect and mitigate potential vulnerabilities in the supply chain. Key measures may include regular vulnerability assessments, penetration testing, and security awareness training for employees and contractors, as well as the implementation of security controls such as secure communication protocols, access controls, and intrusion detection systems. By adopting a continuous security assurance approach for supply chain security in the secure autonomous driving domain, organizations can safeguard their operations and ensure the safety of passengers and other road users. This paper presents a security assurance and certification solution for supply-chain services. Security elements are continuously assessed based on AI operations. The proposal is implemented under the EU funded project FISHY and applied in the supply-chain of secure autonomous driving (SADE) pilot with REMOTIS smart vehicles. Nevertheless, it is a generic solution that can be applied in any domain.
As digital technologies become more pervasive in society and the economy, cyber-security incidents become more frequent, but also more impactful. Based on the NIS & NIS2 Directives, EU Member States and their Operators of Essential Services (OES) must establish a minimum baseline set of capabilities while providing cross-border coordination and cooperation. But this is only a small step towards European cyber resilience. In this landscape, preparedness, shared situational awareness, and coordinated incident response are essential for effective crisis management and cyber-security resilience. This paper presents PHOENI2X which, motivated by the above, aims to design, develop, and deliver a Cyber Resilience Framework (CRF) providing Artificial Intelligence (AI) - assisted orchestration, automation & response capabilities for business continuity and recovery, incident response, and information exchange, tailored to the needs of OES and of the EU Member State (MS) National Authorities entrusted with cyber-security.
The evolution of emerging technologies that use Radio Frequency Electromagnetic Field (RF-EMF) has increased the interest of the scientific community and society regarding the possible adverse effects on human health and the environment. This article provides NextGEM's vision to assure safety for EU citizens when employing existing and future EMF-based telecommunication technologies. This is accomplished by generating relevant knowledge that ascertains appropriate prevention and control/actuation actions regarding RF-EMF exposure in residential, public, and occupational settings. Fulfilling this vision, NextGEM commits to the need for a healthy living and working environment under safe RF-EMF exposure conditions that can be trusted by people and be in line with the regulations and laws developed by public authorities. NextGEM provides a framework for generating health-relevant scientific knowledge and data on new scenarios of exposure to RF-EMF in multiple frequency bands and developing and validating tools for evidence-based risk assessment. Finally, NextGEM's Innovation and Knowledge Hub (NIKH) will offer a standardized way for European regulatory authorities and the scientific community to store and assess project outcomes and provide access to findable, accessible, interoperable, and reusable (FAIR) data.
Big data management is a key enabling factor for enterprises that want to compete in the global market. Data coming from enterprise production processes, if properly analyzed, can provide a boost in the enterprise management and optimization, guaranteeing faster processes, better customer management, and lower overheads/costs. Guaranteeing a proper big data pipeline is the holy grail of big data, often opposed by the difficulty of evaluating the correctness of the big data pipeline results. This problem is even worse when big data pipelines are provided as a service in the cloud, and must comply with both laws and users' requirements. To this aim, assurance techniques can complete big data pipelines, providing the means to guarantee that they behave correctly, toward the deployment of big data pipelines fully compliant with laws and users' requirements. In this article, we define an assurance solution for big data based on service-level agreements, where a semiautomatic approach supports users from the definition of the requirements to the negotiation of the terms regulating the provisioned services, and the continuous refinement thereof.
Healthcare ecosystems form a critical type of infrastructures that provide valuable services in today societies. However, the underlying sensitive information is also of interest of malicious entities around the globe, with the attack volume being continuously increasing. Safeguarding this complex computerized setting constitutes a major challenge for the involved organizations. This paper presents an incident handling system for healthcare organizations and their supply-chain. The proposed approach utilizes swarm intelligence in order to assess the current security posture in a continuous basis and respond to attacks in real-time. The overall solution is based on the related NIST 800.61 standard and implements the operations of i) preparation, ii) detection and analysis, iii) containment, eradication, and recovery, and iv) post-incident activity. The system is developed under the EU funded project AI4HEALTHSEC and is applied in the relevant healthcare pilots.
This paper describes a cloud-based platform that offers evidence-based, personalised interventions powered by Artificial Intelligence to help support efficient remote monitoring and clinician-driven guidance to people over 65 who suffer or are at risk of hearing loss, cardiovascular diseases, cognitive impairments, balance disorders, and mental health issues.This platform has been developed within the SMART-BEAR integrated project to power its large-scale clinical pilots and comprises a standards-based data harmonisation and management layer, a security component, a Big Data Analytics system, a Clinical Decision Support tool, and a dashboard component for efficient data collection across the pilot sites.
Christos Kloukinas合作论文数Office A306B
Department of Computing
School of Informatics
City University24
Antonio Mana合作论文数University of M??laga;E.T.S.I.Informatica;Computer Science Department15