Razvan Deaconescu

dblp:38/7719 · DBLP profile ↗
← Back
12ranked-venue papers
1as first author
5since 2021 · last 2023
0000-0001-8287-1712ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
3 papers
Operating systems · 78% Program analysis · 22%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Cloud and datacenter computing · 100%
Network and information security
2 papers
Web and mobile security · 42% Authentication and access control · 29% Systems and software security · 29%
Computer networks
1 paper
Datacenter networks · 77% Routing and switching · 23%

Topics — the 15 heaviest of 17, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Operating systems
virtualization
0.712023
Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMs · EuroSys 2023
Cloud and datacenter computing
virtualization
0.712023
Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMs · EuroSys 2023
Cloud and datacenter computing › virtualization › virtual machine management
virtual machine cloning
0.712023
Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMs · EuroSys 2023
Operating systems › operating system design
library operating systems
0.512021
Unikraft: fast, specialized unikernels the easy way · EuroSys 2021
Operating systems › operating system design
unikernel
0.512021
Unikraft: fast, specialized unikernels the easy way · EuroSys 2021
Authentication and access control
access control
0.412020
Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020
Systems and software security › operating system security
inter-process communication security
0.412020
Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020
Web and mobile security › mobile security
iOS security
0.422020
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020
Web and mobile security
mobile security
0.212016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Program analysis › static analysis
logic program analysis
0.212016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Program analysis
static analysis
0.212016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Datacenter networks
flow scheduling
0.212015
Increasing Datacenter Network Utilisation with GRIN · NSDI 2015
Cloud and datacenter computing
serverless computing
0.112021
Unikraft: fast, specialized unikernels the easy way · EuroSys 2021
Operating systems › system security › operating system security › protection mechanism › isolation
sandboxing
0.112016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Routing and switching
traffic engineering
0.112015
Increasing Datacenter Network Utilisation with GRIN · NSDI 2015

Methods — techniques the papers use, named apart from their topics

unikernel design · 1.3POSIX porting · 1.3micro-library OS design · 1.0composable performance-oriented APIs · 1.0prolog · 0.5logic programming · 0.5formal modeling · 0.5decompilation · 0.5static analysis · 0.4dynamic analysis · 0.4
YearPublicationVenuePosition
2023 Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMs
abstract
Unikernels gained an increasing interest in the recent years because they provide efficient resource allocation and high performance for cloud services by bundling the application with a minimal set of OS services in a guest VM. Although a unikernel is by design small and lightweight, fleets of unikernels based on the same image are not necessarily more efficient than containers because the latter can rely upon OS primitives for sharing memory. Futhermore, porting POSIX applications on top of unikernels brings a new challenge: what does fork() mean in the world of unikernels where there is memory isolation within a VM? Lacking fork() support significantly reduces the applicability of unikernels in popular cloud applications.
Costin Lupu, Andrei Albisoru, Radu Nichita, Doru-Florin Blânzeanu, Mihai Pogonaru, Razvan Deaconescu, Costin Raiciu
EuroSys6
2022 Using Cybersecurity Exercises as Essential Learning Tools in Universities
Razvan Deaconescu, Andra Baltoiu, Tiberiu Georgescu, Alin Puncioiu
CSEDU (2)1
2022 Adding Support for Reference Counting in the D Programming Language
Razvan Nitu, Constantin-Eduard Staniloiu, Razvan Deaconescu, Razvan Rughinis
ICSOFT3
2021 Unikraft: fast, specialized unikernels the easy way
abstract
Unikernels are famous for providing excellent performance in terms of boot times, throughput and memory consumption, to name a few metrics. However, they are infamous for making it hard and extremely time consuming to extract such performance, and for needing significant engineering effort in order to port applications to them. We introduce Unikraft, a novel micro-library OS that (1) fully modularizes OS primitives so that it is easy to customize the unikernel and include only relevant components and (2) exposes a set of composable, performance-oriented APIs in order to make it easy for developers to obtain high performance.
Simon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam, Alexander Jung 0002, Gaulthier Gain, Cyril Soldani, Costin Lupu, Stefan Teodorescu, Costi Raducanu, Cristian Banu, Laurent Mathy, Razvan Deaconescu, Costin Raiciu, Felipe Huici
EuroSys13
2021 FlexOS: making OS isolation flexible
abstract
OS design is traditionally heavily intertwined with protection mechanisms. OSes statically commit to one or a combination of (1) hardware isolation, (2) runtime checking, and (3) software verification early at design time. Changes after deployment require major refactoring; as such, they are rare and costly. In this paper, we argue that this strategy is at odds with recent hardware and software trends: protections break (Meltdown), hardware becomes heterogeneous (Memory Protection Keys, CHERI), and multiple mechanisms can now be used for the same task (software hardening, verification, HW isolation, etc). In short, the choice of isolation strategy and primitives should be postponed to deployment time.
Hugo Lefeuvre, Vlad-Andrei Badoiu, Stefan Teodorescu, Pierre Olivier, Tiberiu Mosnoi, Razvan Deaconescu, Felipe Huici, Costin Raiciu
HotOS6
2020 Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS
abstract
Apple uses several access control mechanisms to prevent third party applications from directly accessing security sensitive resources, including sandboxing and file access control. However, third party applications may also indirectly access these resources using inter-process communication (IPC) with system daemons. If these daemons fail to properly enforce access control on IPC, confused deputy vulnerabilities may result. Identifying such vulnerabilities begins with an enumeration of all IPC services accessible to third party applications. However, the IPC interfaces and their corresponding access control policies are unknown and must be reverse engineered at a large scale. In this paper, we present the Kobold framework to study NSXPC-based system services using a combination of static and dynamic analysis. Using Kobold, we discovered multiple NSXPC services with confused deputy vulnerabilities and daemon crashes. Our findings include the ability to activate the microphone, disable access to all websites, and leak private data stored in iOS File Providers.
Luke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu, William Enck
SP4
2018 iOracle: Automated Evaluation of Access Control Policies in iOS
abstract
Modern operating systems, such as iOS, use multiple access control policies to define an overall protection system. However, the complexity of these policies and their interactions can hide policy flaws that compromise the security of the protection system. We propose iOracle, a framework that logically models the iOS protection system such that queries can be made to automatically detect policy flaws. iOracle models policies and runtime context extracted from iOS firmware images, developer resources, and jailbroken devices, and iOracle significantly reduces the complexity of queries by modeling policy semantics. We evaluate iOracle by using it to successfully triage executables likely to have policy flaws and comparing our results to the executables exploited in four recent jailbreaks. When applied to iOS 10, iOracle identifies previously unknown policy flaws that allow attackers to modify or bypass access control policies. For compromised system processes, consequences of these policy flaws include sandbox escapes (with respect to read/write file access) and changing the ownership of arbitrary files. By automating the evaluation of iOS access control policies, iOracle provides a practical approach to hardening iOS security by identifying policy flaws before they are exploited.
Luke Deshotels, Razvan Deaconescu, Costin Carabas, Iulia Manda, William Enck, Mihai-Daniel Chiroiu, Ninghui Li 0001, Ahmad-Reza Sadeghi
AsiaCCS2
2016 SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles
abstract
Recent literature on iOS security has focused on the malicious potential of third-party applications, demonstrating how developers can bypass application vetting and code-level protections. In addition to these protections, iOS uses a generic sandbox profile called "container" to confine malicious or exploited third-party applications. In this paper, we present the first systematic analysis of the iOS container sandbox profile. We propose the SandScout framework to extract, decompile, formally model, and analyze iOS sandbox profiles as logic-based programs. We use our Prolog-based queries to evaluate file-based security properties of the container sandbox profile for iOS 9.0.2 and discover seven classes of exploitable vulnerabilities. These attacks affect non-jailbroken devices running later versions of iOS. We are working with Apple to resolve these attacks, and we expect that SandScout will play a significant role in the development of sandbox profiles for future versions of iOS.
Luke Deshotels, Razvan Deaconescu, Mihai-Daniel Chiroiu, Lucas Davi, William Enck, Ahmad-Reza Sadeghi
CCS2
2015 XiOS: Extended Application Sandboxing on iOS
abstract
Until very recently it was widely believed that iOS malware is effectively blocked by Apple's vetting process and application sandboxing. However, the newly presented severe malicious app attacks (e.g., Jekyll) succeeded to undermine these protection measures and steal private data, post Twitter messages, send SMS, and make phone calls. Currently, no effective defenses against these attacks are known for iOS.
Mihai-Daniel Chiroiu, Lucas Davi, Razvan Deaconescu, Ahmad-Reza Sadeghi
AsiaCCS3
2015 Increasing Datacenter Network Utilisation with GRIN
Alexandru Agache, Razvan Deaconescu, Costin Raiciu
NSDI2
2015 Smart malware detection on Android
abstract
Abstract Nowadays, because of its increased popularity, Android is target to a growing number of attacks and malicious applications, with the purpose of stealing private information and consuming credit by subscribing to premium services. Most of the current commercial antivirus solutions use static signatures for malware detection, which may fail to detect different variants of the same malware and zero‐day attacks. In this paper, we present a behavior‐based, dynamic analysis security solution, called Android Malware Detection System, for detecting both well‐known and zero‐day malware. The proposed solution uses a machine learning classifier in order to differentiate between the behaviors of legitimate and malicious applications. In addition, it uses the application statistics for determining its reputation. The final decision is based on a combination of the classifier's result and the application reputation. The solution includes a unique and extensive set of data collectors, which gather application‐specific data that describe the behavior of the monitored application. We evaluated our solution on a set of legitimate and malicious applications and obtained a high accuracy of 0.985. Our system is able to detect zero‐day malware samples that are not detected by current commercial solutions. Our solution outperforms other similar solutions running on mobile devices. Copyright © 2015 John Wiley & Sons, Ltd.
Laura Gheorghe, Bogdan Marin, Gary Gibson, Lucian Mogosanu, Razvan Deaconescu, Valentin-Gabriel Voiculescu, Mihai Carabas
Secur. Commun. Networks5
2013 Teamwork: A Decentralized, Secure and Portable Team Management System
abstract
We present Teamwork, an easy to use, portable system for team management. The distinguishing key feature of our solution is enhanced privacy provided by two means. First of all, all user content is moved from the cloud directly to users' devices, which share the data through a Peer-to-Peer overlay network for content distribution. Secondly, all content transferred through the network is secured in order to protect it from eavesdropping. Content is stored in files distributed through the Peer-to-Peer file system component named Teamshare. User's cognitive load is reduced by merging abstractions such as groups, organizations and projects into one simple concept teams. The system is tightly integrated with existing mailing protocols, such that any task is an email.
Adriana Draghici, Calin-Andrei Burloiu, Razvan Deaconescu, Donat Muller
ISPDC3