VLDB 2026 Research / reviewers in the wild / expert
Nimrod Busany
dblp:167/7836
· DBLP profile ↗
7ranked-venue papers
5as first author
2since 2021 · last 2025
0009-0000-2843-9515ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 5 first-author · 2 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Automating Business Intelligence Requirements with Generative AI and Semantic SearchabstractEliciting Business Intelligence (BI) requirements is challenging, especially in dynamic business environments. This paper introduces AutoBIR, an AI-driven system that uses semantic search and Large Language Models (LLMs) to automate BI specification and prototyping. Through a conversational interface, it translates user inputs into analytic code, descriptions, and data dependencies while generating test-case reports with optional visuals. AutoBIR refines BI reporting via feedback, accelerating data-driven decision-making. We also explore the broader potential of generative AI in transforming BI development, illustrating its role in enhancing data engineering practice for large-scale, evolving systems. Nimrod Busany, Ethan Hadar, Hananel Hadad, Gil Rosenblum, Zofia Maszlanka, Okhaide Akhigbe, Daniel Amyot |
COMPSAC | 1 |
| 2024 | Fast Attack Graph Defense Localization via BisimulationabstractAbstract System administrators, network engineers, and IT managers can learn much about the vulnerabilities of an organization’s cyber system by constructing and analyzing analytical attack graphs (AAGs). An AAG consists of logical rule nodes, fact nodes, and derived fact nodes. It provides a graph-based representation that describes ways by which an attacker can achieve progress towards a desired goal, a.k.a. a crown jewel. Given an AAG, different types of analyses can be performed to identify attacks on a target goal, measure the vulnerability of the network, and gain insights on how to make it more secure. However, as the size of the AAGs representing real-world systems may be very large, existing analyses are slow or practically impossible. In this paper, we introduce and show how to compute an AAG’s defense core: a locally minimal subset of the AAG’s rules whose removal will prevent an attacker from reaching a crown jewel. Most importantly, in order to scale-up the performance of the detection of a defense core, we introduce a novel application of the well-known notion of bisimulation to AAGs. Our experiments show that the use of bisimulation results in significantly smaller graphs and in faster detection of defense cores, making them practical. Nimrod Busany, Rafi Shalom, Daniel Klein 0003, Shahar Maoz |
FM (1) | 1 |
| 2019 | Statistical Log DifferencingabstractRecent works have considered the problem of log differencing: given two or more system's execution logs, output a model of their differences. Log differencing has potential applications in software evolution, testing, and security. In this paper we present statistical log differencing, which accounts for frequencies of behaviors found in the logs. We present two algorithms, s2KDiff for differencing two logs, and snKDiff, for differencing of many logs at once, both presenting their results over a single inferred model. A unique aspect of our algorithms is their use of statistical hypothesis testing: we let the engineer control the sensitivity of the analysis by setting the target distance between probabilities and the statistical significance value, and report only (and all) the statistically significant differences. Our evaluation shows the effectiveness of our work in terms of soundness, completeness, and performance. It also demonstrates its effectiveness compared to previous work via a user-study and its potential applications via a case study using real-world logs. Lingfeng Bao, Nimrod Busany, David Lo 0001, Shahar Maoz |
ASE | 2 |
| 2019 | Size and Accuracy in Model InferenceabstractMany works infer finite-state models from execution logs. Large models are more accurate but also more difficult to present and understand. Small models are easier to present and understand but are less accurate. In this work we investigate the tradeoff between model size and accuracy in the context of the classic k-Tails model inference algorithm. First, we define mk-Tails, a generalization of k-Tails from one to many parameters, which enables fine-grained control over the tradeoff. Second, we extend mk-Tails with a reduction based on past-equivalence, which effectively reduces the size of the model without decreasing its accuracy. We implemented our work and evaluated its performance and effectiveness on real-world logs as well as on models and generated logs from the literature. Nimrod Busany, Shahar Maoz, Yehonatan Yulazari |
ASE | 1 |
| 2018 | Using finite-state models for log differencingabstractMuch work has been published on extracting various kinds of models from logs that document the execution of running systems. In many cases, however, for example in the context of evolution, testing, or malware analysis, engineers are interested not only in a single log but in a set of several logs, each of which originated from a different set of runs of the system at hand. Then, the difference between the logs is the main target of interest. Hen Amar, Lingfeng Bao, Nimrod Busany, David Lo 0001, Shahar Maoz |
ESEC/SIGSOFT FSE | 3 |
| 2016 | Behavioral log analysis with statistical guaranteesabstractScalability is a major challenge for existing behavioral log analysis algorithms, which extract finite-state automaton models or temporal properties from logs generated by running systems. In this paper we present statistical log analysis, which addresses scalability using statistical tools. The key to our approach is to consider behavioral log analysis as a statistical experiment. Rather than analyzing the entire log, we suggest to analyze only a sample of traces from the log and, most importantly, provide means to compute statistical guarantees for the correctness of the analysis result. Nimrod Busany, Shahar Maoz |
ICSE | 1 |
| 2015 | Behavioral log analysis with statistical guaranteesabstractScalability is a major challenge for existing behavioral log analysis algorithms, which extract finite-state automaton models or temporal properties from logs generated by running systems. In this work we propose to address scalability using statistical tools. The key to our approach is to consider behavioral log analysis as a statistical experiment. Rather than analyzing the entire log, we suggest to analyze only a sample of traces from the log and, most importantly, provide means to compute statistical guarantees for the correctness of the analysis result. We present two example applications of our approach as well as initial evidence for its effectiveness. Nimrod Busany, Shahar Maoz |
ESEC/SIGSOFT FSE | 1 |