Skip to content

Author

Michail Takaronis

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Review Sep 2026

Using LLMs to Elicit Security Requirements for Service-Oriented Cyber Ranges

Cyber ranges are complex environments comprising many interacting components and stakeholders with different security concerns. The Service-Oriented Cyber Range (SOR) is no exception, particularly when it comes to training scenarios targeting critical infrastructure. Security concerns are translated into security requirements, the elicitation of which is usually difficult and time-consuming. This work examines how large language models can assist in eliciting security requirements for a service-oriented range and help produce a useful baseline for designers and developers. The approach follows a SEBoK-guided process in which security mission objectives and stakeholder needs were first identified and then provided as a prompt context along with architectural guidelines to five LLMs: GPT-5.2, Gemini 3.1 Pro, Grok 4.1, Sonar, and Kimi K2.5. The models generated 84 security requirements in total, which were consolidated into a comprehensive set of 27 requirements and then mapped to the architectural layers of the service-oriented range. The final set was evaluated by five cybersecurity experts against the criteria of necessity, clarity, completeness, feasibility, and testability, with an additional rejection option. The results showed a high acceptance rate, specifically for necessity with 98.5%, clarity with 87.4%, completeness with 85.2%, feasibility with 78.5%, and rejection with 0.7%. Testability was lower at 44.4%, indicating a slight lack of information on how these requirements could be tested. These findings show that LLMs can support early stages of the elicitation of security requirements, although human review is still needed, especially to improve or adjust certain aspects of the requirements.

Michail Takaronis, Athanasia Kollarou, G. Kavallieratos et al. · 0 citations
Review Open access Aug 2026

A Systematic Review of Cybersecurity Testbeds for Smart Environments: Architectures, Attack Coverage, and Defensive Evidence

Smart-environment cybersecurity increasingly depends on experimental platforms that can reproduce attacks against buildings, homes, and cities under realistic conditions. However, the literature remains fragmented across testbed design, attack demonstration, and defensive validation. This makes it particularly difficult to judge what kind of security evidence each study actually provides. This review systematically analyses 28 experimentally grounded studies published from 2020 onwards, focusing on how testbed realism, cyber–physical coupling, and evaluation mode shape the strength of the resulting claims. The corpus spans physical, hybrid, emulated, and dataset-driven environments across smart buildings, smart homes, and smart cities. Through our investigation, we discern a clear asymmetry in the field. Detection-oriented studies dominate, especially those based on emulation or public datasets, while live evidence for prevention, response, containment, and recovery is comparatively scarce. Availability and integrity/control attacks are the most frequently exercised, whereas authentication compromise and software exploitation remain rare because they are harder to stage on real hardware. Moreover, an important observation we arrive at is that physical and hardware-in-the-loop platforms support the strongest cyber–physical evidence, but emulated and replayed environments remain valuable for scale and reproducibility. At the same time, public datasets and offline classification results do not by themselves establish operational resilience in a live smart environment. To make these distinctions explicit, we introduce a cross-domain taxonomy of testbed architectures, attack families, and defensive control coverage, and map the evidence strength of reported mitigations using NIST cybersecurity framework-derived operational functions. Last, we identify open challenges, including weak recovery evaluation, limited reuse of reference testbeds, and the need for live, context-aware datasets, outlining promising future directions.

Vyron Kampourakis, Konstantinos E. Kampourakis, Michail Takaronis et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.