VLDB 2026 Research / reviewers in the wild / expert
Mohamed Elsabagh
dblp:45/7864
· DBLP profile ↗
14ranked-venue papers
6as first author
3since 2021 · last 2023
0000-0002-5320-4985ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 5 first-author · 3 since 2021Computer networks · 2Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Libra: Library Identification in Obfuscated Android Apps
David A. Tomassi, Kenechukwu Nwodo, Mohamed Elsabagh |
ISC | 3 |
| 2022 | Detecting and Measuring Misconfigured Manifests in Android AppsabstractThe manifest file of an Android app is crucial for app security as it declares sensitive app configurations, such as access permissions required to access app components. Surprisingly, we noticed a number of widely-used apps (some with over 500 million downloads) containing misconfigurations in their manifest files that can result in severe security issues. This paper presents ManiScope, a tool to automatically detect misconfigurations of manifest files when given an Android APK. The key idea is to build a manifest XML Schema by extracting ManiScope constraints from the manifest documentation with novel domain-aware NLP techniques and rules, and validate manifest files against the schema to detect misconfigurations. We have implemented ManiScope, with which we have identified 609,428 (33.20%) misconfigured Android apps out of 1,853,862 apps from Google Play, and 246,658 (35.64%) misconfigured ones out of 692,106 pre-installed apps from 4,580 Samsung firmwares, respectively. Among them, 84,117 (13.80%) of misconfigured Google Play apps and 56,611 (22.95%) of misconfigured pre-installed apps have various security implications including app defrauding, message spoofing, secret data leakage, and component hijacking. Yuqing Yang 0003, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson 0002, Angelos Stavrou, Zhiqiang Lin 0001 |
CCS | 2 |
| 2021 | DEFInit: An Analysis of Exposed Android Init Routines
Yuede Ji, Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou |
USENIX Security Symposium | 2 |
| 2020 | FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware
Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin 0001 |
USENIX Security Symposium | 1 |
| 2018 | Dazed Droids: A Longitudinal Study of Android Inter-App VulnerabilitiesabstractAndroid devices are an integral part of modern life from phone to media boxes to smart home appliances and cameras. With 38.9% of market share, Android is now the most used operating system not just in terms of mobile devices but considering all OSes. As applications' complexity and features increased, Android relied more heavily on code and data sharing among apps for faster response times and richer user experience. To achieve that, Android apps reuse functionality and data by means of inter-app message passing where each app defines the messages it expects to receive. In this paper, we analyze the proliferation of exploitable inter-app communication vulnerabilities using a rich corpus of 1) a representative sample of 32 Android devices, 2) 59 official Google Android versions, and 3) the top 18,583 apps from 2016 to 2017. This corpus covers $91$ Android builds from version 4.4 to present. To the best of our knowledge, ours is the first longitudinal study looking into the propagation of vulnerabilities across AOSP builds, between AOSP and a diverse set of devices, and across app versions over a period of 13 months. To identify inter-app vulnerabilities, we developed Daze as a swift and fully-automated framework for extracting app components and fuzzing all app interfaces. Daze needs only about three hours for full-device analysis or two minutes per app on average. We identified 14,413 vulnerabilities and quantified their exposure time and the number of versions affected. Our findings revealed that $51.7%$ of Android devices and $49%$ of the top $300$ apps on Google Play contained at least one critical inter-app vulnerability. We found that about $15%$ of fixed vulnerabilities lived for more than $100$ days before being patched, more than $20%$ of unpatched vulnerabilities have existed for at least $180$ days, and $45%$ of unpatched vulnerabilities persisted through the latest two to four consecutive app versions in our dataset. Ryan Johnson 0002, Mohamed Elsabagh, Angelos Stavrou, A. Jefferson Offutt |
AsiaCCS | 2 |
| 2018 | On early detection of application-level resource exhaustion and starvation
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou |
J. Syst. Softw. | 1 |
| 2017 | Strict Virtual Call Integrity Checking for C++ BinariesabstractModern operating systems are equipped with defenses that render legacy code injection attacks inoperable. However, attackers can bypass these defenses by crafting attacks that reuse existing code in a program's memory. One of the most common classes of attacks manipulates memory data used indirectly to execute code, such as function pointers. This is especially prevalent in C++ programs, since tables of function pointers (vtables) are used by all major compilers to support polymorphism. In this paper, we propose VCI, a binary rewriting system that secures C++ binaries against vtable attacks. VCI works directly on stripped binary files. It identifies and reconstructs various C++ semantics from the binary, and constructs a strict CFI policy by resolving and pairing virtual function calls (vcalls) with precise sets of target classes. The policy is enforced by instrumenting checks into the binary at vcall sites. Experimental results on SPEC CPU2006 and Firefox show that VCI is significantly more precise than state-of-the-art binary solutions. Testing against the ground truth from the source-based defense GCC VTV, VCI achieved greater than 60% precision in most cases, accounting for at least 48% to 99% additional reduction in the attack surface compared to the state-of-the-art binary defenses. VCI incurs a 7.79% average runtime overhead which is comparable to the state-of-the-art. In addition, we discuss how VCI defends against real-world attacks, and how it impacts advanced vtable reuse attacks such as COOP. Mohamed Elsabagh, Daniel Fleck, Angelos Stavrou |
AsiaCCS | 1 |
| 2017 | Detecting ROP with Statistical Learning of Program CharacteristicsabstractReturn-Oriented Programming (ROP) has emerged as one of the most widely used techniques to exploit software vulnerabilities. Unfortunately, existing ROP protections suffer from a number of shortcomings: they require access to source code and compiler support, focus on specific types of gadgets, depend on accurate disassembly and construction of Control Flow Graphs, or use hardware-dependent (microarchitectural) characteristics. In this paper, we propose EigenROP, a novel system to detect ROP payloads based on unsupervised statistical learning of program characteristics. We study, for the first time, the feasibility and effectiveness of using microarchitecture-independent program characteristics -- namely, memory locality, register traffic, and memory reuse distance -- for detecting ROP. We propose a novel directional statistics based algorithm to identify deviations from the expected program characteristics during execution. EigenROP works transparently to the protected program, without requiring debug information, source code or disassembly. We implemented a dynamic instrumentation prototype of EigenROP using Intel Pin and measured it against in-the-wild ROP exploits and on payloads generated by the ROP compiler ROPC. Overall, EigenROP achieved significantly higher accuracy than prior anomaly-based solutions. It detected the execution of the ROP gadget chains with 81% accuracy, 80% true positive rate, only 0.8% false positive rate, and incurred comparable overhead to similar Pin-based solutions. Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou |
CODASPY | 1 |
| 2017 | Practical and Accurate Runtime Application Protection Against DoS Attacks
Mohamed Elsabagh, Daniel Fleck, Angelos Stavrou, Michael Kaplan, Thomas Bowen |
RAID | 1 |
| 2016 | Why Software DoS Is Hard to Fix: Denying Access in Embedded Android Platforms
Ryan Johnson 0002, Mohamed Elsabagh, Angelos Stavrou |
ACNS | 2 |
| 2015 | Radmin: Early Detection of Application-Level Resource Exhaustion and Starvation Attacks
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou |
RAID | 1 |
| 2011 | Synthetic Generation of Radio Maps for Device-Free Passive LocalizationabstractIn this paper, we present the design, implementation, and evaluation of a system that automatically constructs accurate radio maps for device-free WLAN localization systems. The system is capable of generating deterministic and probabilistic radio maps for localization systems. Our system uses 3D ray tracing enhanced with the uniform theory of diffraction (UTD) to model the electric field behavior and the human shadowing effect. We present our system architecture and describe the details of its different components. We also propose an optional module, location-0 correction, that can significantly enhances the system accuracy and reduces its dependence on the 3D model details by using just one signal strength sample. Our experiments in a real testbed show that the predicted signal strength differs from the measurements by a maximum average absolute error of 2.77 dB achieving a maximum localization error of 3.13m and 2.84m for both the deterministic and probabilistic radio maps, respectively. In addition, the results show that our system is not sensitive to the 3D model details. Ahmed Eleryan, Mohamed Elsabagh, Moustafa Youssef 0001 |
GLOBECOM | 2 |
| 2011 | Practical Provably Secure Communication for Half-Duplex RadiosabstractIn this paper, we present a practical and provably secure two-way wireless communication scheme in the presence of a passive eavesdropper. The scheme implements a randomized scheduling and power allocation mechanism, where each legitimate node transmits in random time slots and with random transmit power. Such randomization results in ambiguity at the eavesdropper with regard to the origin of each transmitted frame. The scheme is analyzed in a time-varying binary block erasure channel model and secrecy outage probabilities are derived and empirically evaluated. The scheme is implemented over an IEEE 802.15.4-enabled Sun SPOT sensor motes. The results show that the proposed scheme achieves significant secrecy gains with a vanishing outage probability, at the expense of slight decrease in throughput, even when the eavesdropper is equipped with a receive power based classifier and is located too close to the transmitter node. Ahmed Elmorsy, Mohamed Yasser, Mohamed Elsabagh, Moustafa Youssef 0001 |
ICC | 3 |
| 2010 | Automatic Generation of Radio Maps for Localization Systems
Ahmed Eleryan, Mohamed Elsabagh, Moustafa Youssef 0001 |
MobiQuitous | 2 |