Ivan Vasiliev

dblp:204/3680 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
0since 2021 · last 2020
0000-0003-3824-2753ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Operating systems · 100%

Topics — the 2 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Operating systems › virtualization
virtual machine introspection
0.312017
QEMU-based framework for non-intrusive virtual machine instrumentation and introspection · ESEC/SIGSOFT FSE 2017
Operating systems › operating system interface › system call
system call tracing
0.112017
QEMU-based framework for non-intrusive virtual machine instrumentation and introspection · ESEC/SIGSOFT FSE 2017

Methods — techniques the papers use, named apart from their topics

record/replay · 0.3dynamic binary analysis · 0.3ABI-based introspection · 0.3
YearPublicationVenuePosition
2020 Non-intrusive Virtual Machine Analysis and Reverse Debugging with SWAT
abstract
This paper presents SWAT - System-Wide Analysis Toolkit. It is based on open source emulation and debugging projects and implements the approaches for non-intrusive system-wide analysis and debugging: lightweight OS-agnostic virtual machine introspection, full system execution replay, non-intrusive debugging with WinDbg, and full system reverse debugging. These features are based on novel non-intrusive introspection and reverse debugging methods. They are useful for stealth debugging and analysis of the platforms with custom kernels. SWAT includes multi-platform emulator QEMU with additional instrumentation and debugging features, GUI for convenient QEMU setup and execution, QEMU plugin for non-intrusive introspection, and modified version of GDB. Our toolkit may be useful for the developers of the virtual platforms, emulators, and firmwares/drivers/operating systems. Virtual machine intospection approach does not require loading any guest agents and source code of the OS. Therefore it may be applied to ROM-based guest systems and enables using of record/replay of the system execution. This paper includes the description of SWAT components, analysis methods, and some SWAT use cases.
Pavel Dovgalyuk, Ivan Vasiliev, Natalia Fursova, Denis Dmitriev, Mikhail Abakumov, Vladimir Makarov
QRS2
2018 Introspection of the Linux-based embedded firmwares: work-in-progress
abstract
This paper presents a novel approach for virtual machine introspection of the embedded systems based on the unknown revisions of the known kernels. Existing introspection methods require embedding the code into the guest to capture the data for analysis algorithms. When OS image is extracted from the ROM, usually no analysis code can be loaded into the virtual machine. We propose new non-intrusive method for extracting the kernel- and process-level information from such virtual machines. This method is based on the application binary interface, which is small enough and usually non-volatile. Therefore one analysis configuration may be used for different systems with the kernels from the same family without re-tuning them. We also present the analysis framework based on the simulator QEMU. It includes instrumentation and some tools for extracting the process- and kernel-level information from the guest. Our framework may be applied to ROM-based guest systems and enables using of record/replay of the system execution during the analysis. We applied our framework to some public firmwares to evaluate how our method works on the embedded systems with custom Linux kernel.
Pavel Dovgalyuk, Natalia Fursova, Ivan Vasiliev, Vladimir Makarov
EMSOFT3
2017 QEMU-based framework for non-intrusive virtual machine instrumentation and introspection
abstract
This paper presents the framework based on the emulator QEMU. Our framework provides set of multi-platform analysis tools for the virtual machines and mechanism for creating instrumentation and analysis tools. Our framework is based on a lightweight approach to dynamic analysis of binary code executed in virtual machines. This approach is non-intrusive and provides system-wide analysis capabilities. It does not require loading any guest agents and source code of the OS. Therefore it may be applied to ROM-based guest systems and enables using of record/replay of the system execution. We use application binary interface (ABI) of the platform to be analyzed for creating introspection tools. These tools recover the part of kernel-level information related to the system calls executed on the guest machine.
Pavel Dovgalyuk, Natalia Fursova, Ivan Vasiliev, Vladimir Makarov
ESEC/SIGSOFT FSE3