Andrei Mogage

dblp:222/6948 · also Andrei-Catalin Mogage · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0002-3533-7573ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 1 since 2021Theory of computation · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Malware Analysis through Behavior Formalization
abstract
Malware analysis represents a difficult task due to its ever-changing nature, where attackers invent new techniques for avoiding or counter-attacking analysis and prevention mechanisms. During fast-response investigations, a vital element is extracting or checking information, in order to take proper action. One key aspect that is currently missing, in a general sense, is a system which security researchers can query in order to obtain a quick verdict about the capabilities of a malware. The proposed solution is a framework for formal analysis of applications’ behavior, called Formal Tainting-Based Framework, that uses a combination of binary instrumentation, taint analysis, and runtime verification in order to selectively extract behavioral properties of a malware. These are then formalized in order to check if the application expresses certain capabilities. The formal aspect also represents a significant contribution, as we introduce a specific temporal logic, which overcomes obstacles for expressing program events. The findings are accompanied by a concrete implementation, which proved effective and efficient against real-life malware, as highlighted by an evaluation. Furthermore, the framework has been evaluated in realistic cyber forensics scenarios, demonstrating its potential to assist security researchers by reducing analysis time and effort.
Andrei Mogage, Dorel Lucanu
Formal Aspects Comput.1
2024 A Formal Tainting-Based Framework for Malware Analysis
Andrei Mogage, Dorel Lucanu
IFM1
2024 A.I. Assisted Malware Capabilities Capturing
abstract
Malware analysis is a demanding task regarding techniques, time and creativity. On multiple occasions, however, security researchers are interested in checking if the analyzed threat possesses specific capabilities, disregarding the overall picture. In this paper, we combine our malware expertise with the results of a Large Language Model, in order to expand the knowledge and creativity in generating specific rules that encode these capabilities. The rules, along with malicious applications, are then used as inputs for a malware analysis framework created by us, in order to determine if the application has those specific capabilities. The findings show promising results, sustained by synthetic and real-life experiments.
Andrei Mogage
KES1
2022 Malware in the SGX Supply Chain: Be Careful When Signing Enclaves!
abstract
Malware attacks are a significant part of the new software security threats detected each year. Intel Software Guard Extensions (SGX) are a set of hardware instructions introduced by Intel in their recent lines of processors that are intended to provide a secure execution environment for user-developed applications. To our knowledge, there was no serious attempt yet to overcome the SGX protection by exploiting the weaknesses in the software supply chain infrastructure, namely at the level of the development, build or signing servers. While SGX protection does not specifically take into consideration such threats, we show in the current paper that a simple malware attack exploiting a separation between the build and signing processes can have a serious damaging impact, practically nullifying SGX integrity protection measures. We also explore two possible mitigations against the attack, one centralized leveraging SGX itself, and one distributed that relies on a smart contract deployed on a blockchain infrastructure. Our evaluation shows that both methods are feasible in practice and their added costs are acceptable for the offered protection.
Vlad Constantin Craciun, Pascal Felber, Andrei Mogage, Emanuel Onica, Rafael Pires 0001
IEEE Trans. Dependable Secur. Comput.3
2019 Supply Chain Malware Targets SGX: Take Care of what you Sign
abstract
Malware attacks represent a significant part of today's security threats. Software guard extensions (SGX) are a set of hardware instructions introduced by Intel in their recent lines of processors that are intended to provide a secure execution environment for user-developed applications. To our knowledge, there was no serious attempt yet to overcome the SGX protection by leveraging the software supply chain infrastructure, such as weaknesses in the development, build or signing servers. While SGX protection does not specifically take into consideration such threats, we show in the current paper that a simple malware attack exploiting a separation between the build and signing processes can have a serious damaging impact, practically nullifying the SGX integrity protection measures. Finally, we also suggest some possible mitigations against the attack.
Andrei Mogage, Rafael Pires 0001, Vlad Constantin Craciun, Emanuel Onica, Pascal Felber
SRDS1