VLDB 2026 Research / reviewers in the wild / expert
Razvan Deaconescu
dblp:38/7719
· DBLP profile ↗
12ranked-venue papers
1as first author
5since 2021 · last 2023
0000-0001-8287-1712ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
3 papers |
Operating systems · 78% Program analysis · 22% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Cloud and datacenter computing · 100% | |
| Network and information security
2 papers |
Web and mobile security · 42% Authentication and access control · 29% Systems and software security · 29% | |
| Computer networks
1 paper |
Datacenter networks · 77% Routing and switching · 23% |
Topics — the 15 heaviest of 17, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Operating systems
virtualization |
0.7 | 1 | 2023 | Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMs · EuroSys 2023 |
Cloud and datacenter computing
virtualization |
0.7 | 1 | 2023 | Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMs · EuroSys 2023 |
Cloud and datacenter computing › virtualization › virtual machine management
virtual machine cloning |
0.7 | 1 | 2023 | Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMs · EuroSys 2023 |
Operating systems › operating system design
library operating systems |
0.5 | 1 | 2021 | Unikraft: fast, specialized unikernels the easy way · EuroSys 2021 |
Operating systems › operating system design
unikernel |
0.5 | 1 | 2021 | Unikraft: fast, specialized unikernels the easy way · EuroSys 2021 |
Authentication and access control
access control |
0.4 | 1 | 2020 | Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020 |
Systems and software security › operating system security
inter-process communication security |
0.4 | 1 | 2020 | Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020 |
Web and mobile security › mobile security
iOS security |
0.4 | 2 | 2020 | SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016 Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020 |
Web and mobile security
mobile security |
0.2 | 1 | 2016 | SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016 |
Program analysis › static analysis
logic program analysis |
0.2 | 1 | 2016 | SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016 |
Program analysis
static analysis |
0.2 | 1 | 2016 | SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016 |
Datacenter networks
flow scheduling |
0.2 | 1 | 2015 | Increasing Datacenter Network Utilisation with GRIN · NSDI 2015 |
Cloud and datacenter computing
serverless computing |
0.1 | 1 | 2021 | Unikraft: fast, specialized unikernels the easy way · EuroSys 2021 |
Operating systems › system security › operating system security › protection mechanism › isolation
sandboxing |
0.1 | 1 | 2016 | SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016 |
Routing and switching
traffic engineering |
0.1 | 1 | 2015 | Increasing Datacenter Network Utilisation with GRIN · NSDI 2015 |
Methods — techniques the papers use, named apart from their topics
unikernel design · 1.3POSIX porting · 1.3micro-library OS design · 1.0composable performance-oriented APIs · 1.0prolog · 0.5logic programming · 0.5formal modeling · 0.5decompilation · 0.5static analysis · 0.4dynamic analysis · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMsabstractUnikernels gained an increasing interest in the recent years because they provide efficient resource allocation and high performance for cloud services by bundling the application with a minimal set of OS services in a guest VM. Although a unikernel is by design small and lightweight, fleets of unikernels based on the same image are not necessarily more efficient than containers because the latter can rely upon OS primitives for sharing memory. Futhermore, porting POSIX applications on top of unikernels brings a new challenge: what does fork() mean in the world of unikernels where there is memory isolation within a VM? Lacking fork() support significantly reduces the applicability of unikernels in popular cloud applications. Costin Lupu, Andrei Albisoru, Radu Nichita, Doru-Florin Blânzeanu, Mihai Pogonaru, Razvan Deaconescu, Costin Raiciu |
EuroSys | 6 |
| 2022 | Using Cybersecurity Exercises as Essential Learning Tools in Universities
Razvan Deaconescu, Andra Baltoiu, Tiberiu Georgescu, Alin Puncioiu |
CSEDU (2) | 1 |
| 2022 | Adding Support for Reference Counting in the D Programming Language
Razvan Nitu, Constantin-Eduard Staniloiu, Razvan Deaconescu, Razvan Rughinis |
ICSOFT | 3 |
| 2021 | Unikraft: fast, specialized unikernels the easy wayabstractUnikernels are famous for providing excellent performance in terms of boot times, throughput and memory consumption, to name a few metrics. However, they are infamous for making it hard and extremely time consuming to extract such performance, and for needing significant engineering effort in order to port applications to them. We introduce Unikraft, a novel micro-library OS that (1) fully modularizes OS primitives so that it is easy to customize the unikernel and include only relevant components and (2) exposes a set of composable, performance-oriented APIs in order to make it easy for developers to obtain high performance. Simon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam, Alexander Jung 0002, Gaulthier Gain, Cyril Soldani, Costin Lupu, Stefan Teodorescu, Costi Raducanu, Cristian Banu, Laurent Mathy, Razvan Deaconescu, Costin Raiciu, Felipe Huici |
EuroSys | 13 |
| 2021 | FlexOS: making OS isolation flexibleabstractOS design is traditionally heavily intertwined with protection mechanisms. OSes statically commit to one or a combination of (1) hardware isolation, (2) runtime checking, and (3) software verification early at design time. Changes after deployment require major refactoring; as such, they are rare and costly. In this paper, we argue that this strategy is at odds with recent hardware and software trends: protections break (Meltdown), hardware becomes heterogeneous (Memory Protection Keys, CHERI), and multiple mechanisms can now be used for the same task (software hardening, verification, HW isolation, etc). In short, the choice of isolation strategy and primitives should be postponed to deployment time. Hugo Lefeuvre, Vlad-Andrei Badoiu, Stefan Teodorescu, Pierre Olivier, Tiberiu Mosnoi, Razvan Deaconescu, Felipe Huici, Costin Raiciu |
HotOS | 6 |
| 2020 | Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOSabstractApple uses several access control mechanisms to prevent third party applications from directly accessing security sensitive resources, including sandboxing and file access control. However, third party applications may also indirectly access these resources using inter-process communication (IPC) with system daemons. If these daemons fail to properly enforce access control on IPC, confused deputy vulnerabilities may result. Identifying such vulnerabilities begins with an enumeration of all IPC services accessible to third party applications. However, the IPC interfaces and their corresponding access control policies are unknown and must be reverse engineered at a large scale. In this paper, we present the Kobold framework to study NSXPC-based system services using a combination of static and dynamic analysis. Using Kobold, we discovered multiple NSXPC services with confused deputy vulnerabilities and daemon crashes. Our findings include the ability to activate the microphone, disable access to all websites, and leak private data stored in iOS File Providers. Luke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu, William Enck |
SP | 4 |
| 2018 | iOracle: Automated Evaluation of Access Control Policies in iOSabstractModern operating systems, such as iOS, use multiple access control policies to define an overall protection system. However, the complexity of these policies and their interactions can hide policy flaws that compromise the security of the protection system. We propose iOracle, a framework that logically models the iOS protection system such that queries can be made to automatically detect policy flaws. iOracle models policies and runtime context extracted from iOS firmware images, developer resources, and jailbroken devices, and iOracle significantly reduces the complexity of queries by modeling policy semantics. We evaluate iOracle by using it to successfully triage executables likely to have policy flaws and comparing our results to the executables exploited in four recent jailbreaks. When applied to iOS 10, iOracle identifies previously unknown policy flaws that allow attackers to modify or bypass access control policies. For compromised system processes, consequences of these policy flaws include sandbox escapes (with respect to read/write file access) and changing the ownership of arbitrary files. By automating the evaluation of iOS access control policies, iOracle provides a practical approach to hardening iOS security by identifying policy flaws before they are exploited. Luke Deshotels, Razvan Deaconescu, Costin Carabas, Iulia Manda, William Enck, Mihai-Daniel Chiroiu, Ninghui Li 0001, Ahmad-Reza Sadeghi |
AsiaCCS | 2 |
| 2016 | SandScout: Automatic Detection of Flaws in iOS Sandbox ProfilesabstractRecent literature on iOS security has focused on the malicious potential of third-party applications, demonstrating how developers can bypass application vetting and code-level protections. In addition to these protections, iOS uses a generic sandbox profile called "container" to confine malicious or exploited third-party applications. In this paper, we present the first systematic analysis of the iOS container sandbox profile. We propose the SandScout framework to extract, decompile, formally model, and analyze iOS sandbox profiles as logic-based programs. We use our Prolog-based queries to evaluate file-based security properties of the container sandbox profile for iOS 9.0.2 and discover seven classes of exploitable vulnerabilities. These attacks affect non-jailbroken devices running later versions of iOS. We are working with Apple to resolve these attacks, and we expect that SandScout will play a significant role in the development of sandbox profiles for future versions of iOS. Luke Deshotels, Razvan Deaconescu, Mihai-Daniel Chiroiu, Lucas Davi, William Enck, Ahmad-Reza Sadeghi |
CCS | 2 |
| 2015 | XiOS: Extended Application Sandboxing on iOSabstractUntil very recently it was widely believed that iOS malware is effectively blocked by Apple's vetting process and application sandboxing. However, the newly presented severe malicious app attacks (e.g., Jekyll) succeeded to undermine these protection measures and steal private data, post Twitter messages, send SMS, and make phone calls. Currently, no effective defenses against these attacks are known for iOS. Mihai-Daniel Chiroiu, Lucas Davi, Razvan Deaconescu, Ahmad-Reza Sadeghi |
AsiaCCS | 3 |
| 2015 | Increasing Datacenter Network Utilisation with GRIN
Alexandru Agache, Razvan Deaconescu, Costin Raiciu |
NSDI | 2 |
| 2015 | Smart malware detection on AndroidabstractAbstract Nowadays, because of its increased popularity, Android is target to a growing number of attacks and malicious applications, with the purpose of stealing private information and consuming credit by subscribing to premium services. Most of the current commercial antivirus solutions use static signatures for malware detection, which may fail to detect different variants of the same malware and zero‐day attacks. In this paper, we present a behavior‐based, dynamic analysis security solution, called Android Malware Detection System, for detecting both well‐known and zero‐day malware. The proposed solution uses a machine learning classifier in order to differentiate between the behaviors of legitimate and malicious applications. In addition, it uses the application statistics for determining its reputation. The final decision is based on a combination of the classifier's result and the application reputation. The solution includes a unique and extensive set of data collectors, which gather application‐specific data that describe the behavior of the monitored application. We evaluated our solution on a set of legitimate and malicious applications and obtained a high accuracy of 0.985. Our system is able to detect zero‐day malware samples that are not detected by current commercial solutions. Our solution outperforms other similar solutions running on mobile devices. Copyright © 2015 John Wiley & Sons, Ltd. Laura Gheorghe, Bogdan Marin, Gary Gibson, Lucian Mogosanu, Razvan Deaconescu, Valentin-Gabriel Voiculescu, Mihai Carabas |
Secur. Commun. Networks | 5 |
| 2013 | Teamwork: A Decentralized, Secure and Portable Team Management SystemabstractWe present Teamwork, an easy to use, portable system for team management. The distinguishing key feature of our solution is enhanced privacy provided by two means. First of all, all user content is moved from the cloud directly to users' devices, which share the data through a Peer-to-Peer overlay network for content distribution. Secondly, all content transferred through the network is secured in order to protect it from eavesdropping. Content is stored in files distributed through the Peer-to-Peer file system component named Teamshare. User's cognitive load is reduced by merging abstractions such as groups, organizations and projects into one simple concept teams. The system is tightly integrated with existing mailing protocols, such that any task is an email. Adriana Draghici, Calin-Andrei Burloiu, Razvan Deaconescu, Donat Muller |
ISPDC | 3 |