EDBT 2026 Demo / reviewers in the wild / expert
Pavel Dovgalyuk
dblp:78/11180 · also P. V. Dovgalyuk
· DBLP profile ↗
5ranked-venue papers
5as first author
1since 2021 · last 2025
0000-0003-2483-5718ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 4 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Operating systems · 67% Debugging and program repair · 33% |
Topics — the 3 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Operating systems › virtualization
virtual machine introspection |
0.3 | 1 | 2017 | QEMU-based framework for non-intrusive virtual machine instrumentation and introspection · ESEC/SIGSOFT FSE 2017 |
Debugging and program repair
time-travel debugging |
0.2 | 1 | 2015 | Don't panic: reverse debugging of kernel drivers · ESEC/SIGSOFT FSE 2015 |
Operating systems › operating system interface › system call
system call tracing |
0.1 | 1 | 2017 | QEMU-based framework for non-intrusive virtual machine instrumentation and introspection · ESEC/SIGSOFT FSE 2017 |
Methods — techniques the papers use, named apart from their topics
record/replay · 0.5dynamic binary analysis · 0.3ABI-based introspection · 0.3reverse execution · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Hybrid Introspection for JIT-Compilers and Interpreters in Attack Surface AnalysisabstractFinding the attack surface of the systems and applications is an important phase in secure software development lifecycle. Attack surface usually analyzed with the help of the experts or static and dynamic analysis tools. Most of the analysis tools and methods can be applied only to the single programs and do not cover the systems that consist of several heterogenous components. In this paper we present new hybrid introspection method for analyzing the software which includes interpreted code and just-in-time (JIT) compilers besides the machine code. We show how to inspect such applications when they are executed in the virtual machine. Targeting the virtual machine analysis allows one to recover the attack surface for the complex systems that include web servers, databases, and other backend components. We also present a case study with the analysis of Java application and show how to find bugs in the core dependencies, that reside on the attack surface. Pavel Dovgalyuk, Vladislav Stepanov, Arkadiy Ivanov, Natalia Fursova |
QRS | 1 |
| 2020 | Non-intrusive Virtual Machine Analysis and Reverse Debugging with SWATabstractThis paper presents SWAT - System-Wide Analysis Toolkit. It is based on open source emulation and debugging projects and implements the approaches for non-intrusive system-wide analysis and debugging: lightweight OS-agnostic virtual machine introspection, full system execution replay, non-intrusive debugging with WinDbg, and full system reverse debugging. These features are based on novel non-intrusive introspection and reverse debugging methods. They are useful for stealth debugging and analysis of the platforms with custom kernels. SWAT includes multi-platform emulator QEMU with additional instrumentation and debugging features, GUI for convenient QEMU setup and execution, QEMU plugin for non-intrusive introspection, and modified version of GDB. Our toolkit may be useful for the developers of the virtual platforms, emulators, and firmwares/drivers/operating systems. Virtual machine intospection approach does not require loading any guest agents and source code of the OS. Therefore it may be applied to ROM-based guest systems and enables using of record/replay of the system execution. This paper includes the description of SWAT components, analysis methods, and some SWAT use cases. Pavel Dovgalyuk, Ivan Vasiliev, Natalia Fursova, Denis Dmitriev, Mikhail Abakumov, Vladimir Makarov |
QRS | 1 |
| 2018 | Introspection of the Linux-based embedded firmwares: work-in-progressabstractThis paper presents a novel approach for virtual machine introspection of the embedded systems based on the unknown revisions of the known kernels. Existing introspection methods require embedding the code into the guest to capture the data for analysis algorithms. When OS image is extracted from the ROM, usually no analysis code can be loaded into the virtual machine. We propose new non-intrusive method for extracting the kernel- and process-level information from such virtual machines. This method is based on the application binary interface, which is small enough and usually non-volatile. Therefore one analysis configuration may be used for different systems with the kernels from the same family without re-tuning them. We also present the analysis framework based on the simulator QEMU. It includes instrumentation and some tools for extracting the process- and kernel-level information from the guest. Our framework may be applied to ROM-based guest systems and enables using of record/replay of the system execution during the analysis. We applied our framework to some public firmwares to evaluate how our method works on the embedded systems with custom Linux kernel. Pavel Dovgalyuk, Natalia Fursova, Ivan Vasiliev, Vladimir Makarov |
EMSOFT | 1 |
| 2017 | QEMU-based framework for non-intrusive virtual machine instrumentation and introspectionabstractThis paper presents the framework based on the emulator QEMU. Our framework provides set of multi-platform analysis tools for the virtual machines and mechanism for creating instrumentation and analysis tools. Our framework is based on a lightweight approach to dynamic analysis of binary code executed in virtual machines. This approach is non-intrusive and provides system-wide analysis capabilities. It does not require loading any guest agents and source code of the OS. Therefore it may be applied to ROM-based guest systems and enables using of record/replay of the system execution. We use application binary interface (ABI) of the platform to be analyzed for creating introspection tools. These tools recover the part of kernel-level information related to the system calls executed on the guest machine. Pavel Dovgalyuk, Natalia Fursova, Ivan Vasiliev, Vladimir Makarov |
ESEC/SIGSOFT FSE | 1 |
| 2015 | Don't panic: reverse debugging of kernel driversabstractDebugging of device drivers' failures is a very tough task because of kernel panics, blue screens of death, hardware volatility, long periods of time required to expose the bug, perturbation of the drivers by the debugger, and non-determinism of multi-threaded environment. This paper shows how reverse debugging reduces the influence of these factors to the process of drivers debugging. We present reverse debugger as a practical tool, which was tested for i386, x86-64, and ARM platforms, for Windows and Linux guest operating systems. We show that our tool incurs very low overhead (about 10%), which allows using it for debugging of the time sensitive applications. The paper also presents the case study which demonstrates reverse debugging of the USB kernel drivers for Linux. Pavel Dovgalyuk, Denis Dmitriev, Vladimir Makarov |
ESEC/SIGSOFT FSE | 1 |