VLDB 2026 Research / reviewers in the wild / expert
Andrei Mogage
dblp:222/6948 · also Andrei-Catalin Mogage
· DBLP profile ↗
5ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0002-3533-7573ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 1 since 2021Theory of computation · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Malware Analysis through Behavior FormalizationabstractMalware analysis represents a difficult task due to its ever-changing nature, where attackers invent new techniques for avoiding or counter-attacking analysis and prevention mechanisms. During fast-response investigations, a vital element is extracting or checking information, in order to take proper action. One key aspect that is currently missing, in a general sense, is a system which security researchers can query in order to obtain a quick verdict about the capabilities of a malware. The proposed solution is a framework for formal analysis of applications’ behavior, called Formal Tainting-Based Framework, that uses a combination of binary instrumentation, taint analysis, and runtime verification in order to selectively extract behavioral properties of a malware. These are then formalized in order to check if the application expresses certain capabilities. The formal aspect also represents a significant contribution, as we introduce a specific temporal logic, which overcomes obstacles for expressing program events. The findings are accompanied by a concrete implementation, which proved effective and efficient against real-life malware, as highlighted by an evaluation. Furthermore, the framework has been evaluated in realistic cyber forensics scenarios, demonstrating its potential to assist security researchers by reducing analysis time and effort. Andrei Mogage, Dorel Lucanu |
Formal Aspects Comput. | 1 |
| 2024 | A Formal Tainting-Based Framework for Malware Analysis
Andrei Mogage, Dorel Lucanu |
IFM | 1 |
| 2024 | A.I. Assisted Malware Capabilities CapturingabstractMalware analysis is a demanding task regarding techniques, time and creativity. On multiple occasions, however, security researchers are interested in checking if the analyzed threat possesses specific capabilities, disregarding the overall picture. In this paper, we combine our malware expertise with the results of a Large Language Model, in order to expand the knowledge and creativity in generating specific rules that encode these capabilities. The rules, along with malicious applications, are then used as inputs for a malware analysis framework created by us, in order to determine if the application has those specific capabilities. The findings show promising results, sustained by synthetic and real-life experiments. Andrei Mogage |
KES | 1 |
| 2022 | Malware in the SGX Supply Chain: Be Careful When Signing Enclaves!abstractMalware attacks are a significant part of the new software security threats detected each year. Intel Software Guard Extensions (SGX) are a set of hardware instructions introduced by Intel in their recent lines of processors that are intended to provide a secure execution environment for user-developed applications. To our knowledge, there was no serious attempt yet to overcome the SGX protection by exploiting the weaknesses in the software supply chain infrastructure, namely at the level of the development, build or signing servers. While SGX protection does not specifically take into consideration such threats, we show in the current paper that a simple malware attack exploiting a separation between the build and signing processes can have a serious damaging impact, practically nullifying SGX integrity protection measures. We also explore two possible mitigations against the attack, one centralized leveraging SGX itself, and one distributed that relies on a smart contract deployed on a blockchain infrastructure. Our evaluation shows that both methods are feasible in practice and their added costs are acceptable for the offered protection. Vlad Constantin Craciun, Pascal Felber, Andrei Mogage, Emanuel Onica, Rafael Pires 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2019 | Supply Chain Malware Targets SGX: Take Care of what you SignabstractMalware attacks represent a significant part of today's security threats. Software guard extensions (SGX) are a set of hardware instructions introduced by Intel in their recent lines of processors that are intended to provide a secure execution environment for user-developed applications. To our knowledge, there was no serious attempt yet to overcome the SGX protection by leveraging the software supply chain infrastructure, such as weaknesses in the development, build or signing servers. While SGX protection does not specifically take into consideration such threats, we show in the current paper that a simple malware attack exploiting a separation between the build and signing processes can have a serious damaging impact, practically nullifying the SGX integrity protection measures. Finally, we also suggest some possible mitigations against the attack. Andrei Mogage, Rafael Pires 0001, Vlad Constantin Craciun, Emanuel Onica, Pascal Felber |
SRDS | 1 |