Mohamed Elsabagh

dblp:45/7864 · DBLP profile ↗
← Back
14ranked-venue papers
6as first author
3since 2021 · last 2023
0000-0002-5320-4985ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 5 first-author · 3 since 2021Computer networks · 2Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2023 Libra: Library Identification in Obfuscated Android Apps
David A. Tomassi, Kenechukwu Nwodo, Mohamed Elsabagh
ISC3
2022 Detecting and Measuring Misconfigured Manifests in Android Apps
abstract
The manifest file of an Android app is crucial for app security as it declares sensitive app configurations, such as access permissions required to access app components. Surprisingly, we noticed a number of widely-used apps (some with over 500 million downloads) containing misconfigurations in their manifest files that can result in severe security issues. This paper presents ManiScope, a tool to automatically detect misconfigurations of manifest files when given an Android APK. The key idea is to build a manifest XML Schema by extracting ManiScope constraints from the manifest documentation with novel domain-aware NLP techniques and rules, and validate manifest files against the schema to detect misconfigurations. We have implemented ManiScope, with which we have identified 609,428 (33.20%) misconfigured Android apps out of 1,853,862 apps from Google Play, and 246,658 (35.64%) misconfigured ones out of 692,106 pre-installed apps from 4,580 Samsung firmwares, respectively. Among them, 84,117 (13.80%) of misconfigured Google Play apps and 56,611 (22.95%) of misconfigured pre-installed apps have various security implications including app defrauding, message spoofing, secret data leakage, and component hijacking.
Yuqing Yang 0003, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson 0002, Angelos Stavrou, Zhiqiang Lin 0001
CCS2
2021 DEFInit: An Analysis of Exposed Android Init Routines
Yuede Ji, Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou
USENIX Security Symposium2
2020 FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware
Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin 0001
USENIX Security Symposium1
2018 Dazed Droids: A Longitudinal Study of Android Inter-App Vulnerabilities
abstract
Android devices are an integral part of modern life from phone to media boxes to smart home appliances and cameras. With 38.9% of market share, Android is now the most used operating system not just in terms of mobile devices but considering all OSes. As applications' complexity and features increased, Android relied more heavily on code and data sharing among apps for faster response times and richer user experience. To achieve that, Android apps reuse functionality and data by means of inter-app message passing where each app defines the messages it expects to receive. In this paper, we analyze the proliferation of exploitable inter-app communication vulnerabilities using a rich corpus of 1) a representative sample of 32 Android devices, 2) 59 official Google Android versions, and 3) the top 18,583 apps from 2016 to 2017. This corpus covers $91$ Android builds from version 4.4 to present. To the best of our knowledge, ours is the first longitudinal study looking into the propagation of vulnerabilities across AOSP builds, between AOSP and a diverse set of devices, and across app versions over a period of 13 months. To identify inter-app vulnerabilities, we developed Daze as a swift and fully-automated framework for extracting app components and fuzzing all app interfaces. Daze needs only about three hours for full-device analysis or two minutes per app on average. We identified 14,413 vulnerabilities and quantified their exposure time and the number of versions affected. Our findings revealed that $51.7%$ of Android devices and $49%$ of the top $300$ apps on Google Play contained at least one critical inter-app vulnerability. We found that about $15%$ of fixed vulnerabilities lived for more than $100$ days before being patched, more than $20%$ of unpatched vulnerabilities have existed for at least $180$ days, and $45%$ of unpatched vulnerabilities persisted through the latest two to four consecutive app versions in our dataset.
Ryan Johnson 0002, Mohamed Elsabagh, Angelos Stavrou, A. Jefferson Offutt
AsiaCCS2
2018 On early detection of application-level resource exhaustion and starvation
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou
J. Syst. Softw.1
2017 Strict Virtual Call Integrity Checking for C++ Binaries
abstract
Modern operating systems are equipped with defenses that render legacy code injection attacks inoperable. However, attackers can bypass these defenses by crafting attacks that reuse existing code in a program's memory. One of the most common classes of attacks manipulates memory data used indirectly to execute code, such as function pointers. This is especially prevalent in C++ programs, since tables of function pointers (vtables) are used by all major compilers to support polymorphism. In this paper, we propose VCI, a binary rewriting system that secures C++ binaries against vtable attacks. VCI works directly on stripped binary files. It identifies and reconstructs various C++ semantics from the binary, and constructs a strict CFI policy by resolving and pairing virtual function calls (vcalls) with precise sets of target classes. The policy is enforced by instrumenting checks into the binary at vcall sites. Experimental results on SPEC CPU2006 and Firefox show that VCI is significantly more precise than state-of-the-art binary solutions. Testing against the ground truth from the source-based defense GCC VTV, VCI achieved greater than 60% precision in most cases, accounting for at least 48% to 99% additional reduction in the attack surface compared to the state-of-the-art binary defenses. VCI incurs a 7.79% average runtime overhead which is comparable to the state-of-the-art. In addition, we discuss how VCI defends against real-world attacks, and how it impacts advanced vtable reuse attacks such as COOP.
Mohamed Elsabagh, Daniel Fleck, Angelos Stavrou
AsiaCCS1
2017 Detecting ROP with Statistical Learning of Program Characteristics
abstract
Return-Oriented Programming (ROP) has emerged as one of the most widely used techniques to exploit software vulnerabilities. Unfortunately, existing ROP protections suffer from a number of shortcomings: they require access to source code and compiler support, focus on specific types of gadgets, depend on accurate disassembly and construction of Control Flow Graphs, or use hardware-dependent (microarchitectural) characteristics. In this paper, we propose EigenROP, a novel system to detect ROP payloads based on unsupervised statistical learning of program characteristics. We study, for the first time, the feasibility and effectiveness of using microarchitecture-independent program characteristics -- namely, memory locality, register traffic, and memory reuse distance -- for detecting ROP. We propose a novel directional statistics based algorithm to identify deviations from the expected program characteristics during execution. EigenROP works transparently to the protected program, without requiring debug information, source code or disassembly. We implemented a dynamic instrumentation prototype of EigenROP using Intel Pin and measured it against in-the-wild ROP exploits and on payloads generated by the ROP compiler ROPC. Overall, EigenROP achieved significantly higher accuracy than prior anomaly-based solutions. It detected the execution of the ROP gadget chains with 81% accuracy, 80% true positive rate, only 0.8% false positive rate, and incurred comparable overhead to similar Pin-based solutions.
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou
CODASPY1
2017 Practical and Accurate Runtime Application Protection Against DoS Attacks
Mohamed Elsabagh, Daniel Fleck, Angelos Stavrou, Michael Kaplan, Thomas Bowen
RAID1
2016 Why Software DoS Is Hard to Fix: Denying Access in Embedded Android Platforms
Ryan Johnson 0002, Mohamed Elsabagh, Angelos Stavrou
ACNS2
2015 Radmin: Early Detection of Application-Level Resource Exhaustion and Starvation Attacks
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou
RAID1
2011 Synthetic Generation of Radio Maps for Device-Free Passive Localization
abstract
In this paper, we present the design, implementation, and evaluation of a system that automatically constructs accurate radio maps for device-free WLAN localization systems. The system is capable of generating deterministic and probabilistic radio maps for localization systems. Our system uses 3D ray tracing enhanced with the uniform theory of diffraction (UTD) to model the electric field behavior and the human shadowing effect. We present our system architecture and describe the details of its different components. We also propose an optional module, location-0 correction, that can significantly enhances the system accuracy and reduces its dependence on the 3D model details by using just one signal strength sample. Our experiments in a real testbed show that the predicted signal strength differs from the measurements by a maximum average absolute error of 2.77 dB achieving a maximum localization error of 3.13m and 2.84m for both the deterministic and probabilistic radio maps, respectively. In addition, the results show that our system is not sensitive to the 3D model details.
Ahmed Eleryan, Mohamed Elsabagh, Moustafa Youssef 0001
GLOBECOM2
2011 Practical Provably Secure Communication for Half-Duplex Radios
abstract
In this paper, we present a practical and provably secure two-way wireless communication scheme in the presence of a passive eavesdropper. The scheme implements a randomized scheduling and power allocation mechanism, where each legitimate node transmits in random time slots and with random transmit power. Such randomization results in ambiguity at the eavesdropper with regard to the origin of each transmitted frame. The scheme is analyzed in a time-varying binary block erasure channel model and secrecy outage probabilities are derived and empirically evaluated. The scheme is implemented over an IEEE 802.15.4-enabled Sun SPOT sensor motes. The results show that the proposed scheme achieves significant secrecy gains with a vanishing outage probability, at the expense of slight decrease in throughput, even when the eavesdropper is equipped with a receive power based classifier and is located too close to the transmitter node.
Ahmed Elmorsy, Mohamed Yasser, Mohamed Elsabagh, Moustafa Youssef 0001
ICC3
2010 Automatic Generation of Radio Maps for Localization Systems
Ahmed Eleryan, Mohamed Elsabagh, Moustafa Youssef 0001
MobiQuitous2