C. Michael Overstreet

56 papers A* 2B 2C 7Misc 16Journal 12Unranked 16
YearRankTypeTitle / Venue / Authors
2017 Misc conf
WSC
Richard E. Nance, C. Michael Overstreet
2015 Misc conf
WSC
Kara A. Olson, C. Michael Overstreet
2011 C conf
SIMULTECH
Kara A. Olson, C. Michael Overstreet
2009 conf
SpringSim
Kara A. Olson, C. Michael Overstreet, E. Joseph Derrick
2009 conf
SpringSim
Kara A. Olson, C. Michael Overstreet, E. Joseph Derrick
2007 Misc conf
WSC
Kara A. Olson, C. Michael Overstreet, E. Joseph Derrick
2006 J jnl
Simul.
C. Michael Overstreet, Alke Martens
2006 J jnl
J. Mobile Multimedia
Stephan Olariu, Kurt Maly, Edwin C. Foudriat, C. Michael Overstreet, Sameh M. Yamany, Thomas Luckenbach
2006 Misc conf
WSC
Robert G. Sargent, Richard E. Nance, C. Michael Overstreet, Stewart Robinson, Jayne Talbot
2004 Misc conf
WSC
C. Michael Overstreet, Richard E. Nance
2003 J jnl
Int. J. Distance Educ. Technol.
Kurt Maly, Hussein M. Abdel-Wahab, C. Michael Overstreet, J. Christian Wild, Ayman A. Abdel-Hamid, Sahar Mohamed Ghanem, Waleed E. Farag
2002 Misc conf
WSC
C. Michael Overstreet
2001 J jnl
ACM J. Educ. Resour. Comput.
Kurt Maly, Hussein M. Abdel-Wahab, J. Christian Wild, C. Michael Overstreet, Ajay Gupta, Ayman Adel Abdel-Hamid, Sahar Mohamed Ghanem, Agustin González, Xiaoqing Zhu
2000 Misc conf
WSC
Paul C. Davis, Paul A. Fishwick, C. Michael Overstreet, Claude Dennis Pegden
1999 J jnl
ACM Trans. Model. Comput. Simul.
Richard E. Nance, C. Michael Overstreet, Ernest H. Page
1998 conf
Teleteaching
Kurt Maly, C. Michael Overstreet, Agustin González, M. Denbar, R. Cutaran, N. Karunaratne
1998 conf
ECOOP Workshops
Robert Cherinka, C. Michael Overstreet, J. Ricci, M. Schrank
1998 conf
ICSM
Robert Cherinka, C. Michael Overstreet, J. Ricci
1998 J jnl
Comput. Networks
Kurt Maly, C. Michael Overstreet, Agustin González, M. Denbar, R. Cutaran, N. Karunaratne, C. J. Srinivas
1997 Misc conf
WSC
David B. Cavitt, C. Michael Overstreet, Kurt Maly
1997 J jnl
IEEE Internet Comput.
Kurt Maly, Hussein M. Abdel-Wahab, C. Michael Overstreet, J. Christian Wild, Ajay K. Gupta, Alaa Youssef, Emilia Stoica, Ehab S. Al-Shaer
1997 C conf
WETICE
Ehab S. Al-Shaer, Alaa Youssef, Hussein M. Abdel-Wahab, Kurt Maly, C. Michael Overstreet
1996 Misc conf
WSC
David B. Cavitt, C. Michael Overstreet, Kurt Maly
1996 B conf
ITiCSE
Kurt Maly, J. Christian Wild, C. Michael Overstreet, Hussein M. Abdel-Wahab, Ajay Gupta, Alaa Youssef, Emilia Stoica, R. Talla, A. Prabhu
1996 Misc conf
WSC
Richard E. Nance, C. Michael Overstreet, Ernest H. Page
1996 C conf
WETICE
Hussein M. Abdel-Wahab, Kurt Maly, Alaa Youssef, Emilia Stoica, C. Michael Overstreet, J. Christian Wild, Ajay Gupta
1995 conf
CSEE
Kurt Maly, Dennis E. Ray, J. Christian Wild, Irwin B. Levinstein, Stephan Olariu, C. Michael Overstreet, Nageswara S. V. Rao, Deane Sibol, George Panayides
1995 C conf
ISCC
Kurt Maly, Hussein M. Abdel-Wahab, C. Michael Overstreet, Ajay Gupta, Muthu Kumar, R. Srivatsava
1995 conf
HPN
Kurt Maly, C. Michael Overstreet, Hussein M. Abdel-Wahab, Ajay K. Gupta, Muthu Kumar, Rahul Srivastava
1995 J jnl
J. Parallel Distributed Comput.
Stephan Olariu, C. Michael Overstreet, Zhaofang Wen
1994 conf
IFIP Congress (2)
Kurt Maly, C. Michael Overstreet
1994 C conf
APSEC
Toyohiko Hirota, M. Tohki, C. Michael Overstreet, Masaaki Hashimoto, Robert Cherinka
1994 conf
CSEE
Kurt Maly, Dennis E. Ray, J. Christian Wild, Irwin B. Levinstein, Stephan Olariu, C. Michael Overstreet, Nageswara S. V. Rao, Tijen Ireland, George Kantsios
1994 conf
ICSM
Robert Cherinka, C. Michael Overstreet, A. Cadwell, J. Ricci
1994 Misc conf
WSC
C. Michael Overstreet, Ernest H. Page, Richard E. Nance
1994 conf
HPN
Edwin C. Foudriat, Kurt Maly, Ravi Mukkamala, C. Michael Overstreet, L. Mathews, S. Balay
1993 conf
ICSM
Robert Cherinka, C. Michael Overstreet, R. Sparks
1992 C conf
ICCI
Kurt Maly, Frank Paterra, C. Michael Overstreet, Ravi Mukkamala, Sanjeev Khanna
1992 J jnl
Comput. Networks ISDN Syst.
Kurt Maly, Edwin C. Foudriat, Ravi Mukkamala, C. Michael Overstreet, David Game
1992 conf
IFIP Congress (1)
Kurt Maly, Sanjeev Khanna, C. Michael Overstreet, Ravi Mukkamala, Mohammad Zubair, Y. S. Sekhar
1992 conf
HPN
Kurt Maly, Sanjeev Khanna, Ravi Mukkamala, C. Michael Overstreet, Ramesh Yerraballi, Edwin C. Foudriat, B. Madan
1992 conf
IFIP Congress (3)
Edwin C. Foudriat, Kurt Maly, C. Michael Overstreet, Liping Zhang, Weisheng Sun
1991 J jnl
Comput. J.
Stephan Olariu, C. Michael Overstreet, Zhaofang Wen
1991 J jnl
Comput. Commun. Rev.
Edwin C. Foudriat, Kurt Maly, C. Michael Overstreet, Sanjeev Khanna, Frank Paterra
1991 C conf
ICCI
Stephan Olariu, C. Michael Overstreet, Zhaofang Wen
1991 B conf
LCN
Edwin C. Foudriat, Kurt Maly, C. Michael Overstreet, Sanjay Khanna, Liping Zhang, Weisheng Sun
1990 Misc conf
WSC
Frank Paterra, C. Michael Overstreet, Kurt Maly
1989 A* conf
SIGCOMM
Kurt Maly, Edwin C. Foudriat, David Game, Ravi Mukkamala, C. Michael Overstreet
1988 A* conf
SIGCOMM
Kurt Maly, C. Michael Overstreet, Xia-ping Qiu, Deqing Tang
1988 conf
ICSM
C. Michael Overstreet, Ji Chen, Frank Byrum
1987 Misc conf
WSC
Richard E. Nance, C. Michael Overstreet
1987 Misc conf
WSC
C. Michael Overstreet
1985 J jnl
Commun. ACM
C. Michael Overstreet, Richard E. Nance
1983 Misc conf
WSC
C. Michael Overstreet
1982
C. Michael Overstreet
1981 Misc conf
WSC
Richard E. Nance, Ahmed L. Mezaache, C. Michael Overstreet
redb/extractors/apk_extractors/apk_inconsistency_tests.py
← Index redb/extractors/apk_extractors/apk_inconsistency_tests.py python
import inspect
import re
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKInconsistencyTests

# Emulator detection indicator strings
EMULATOR_INDICATORS = {
    "generic", "sdk", "google_sdk", "Emulator",
    "goldfish", "ranchu", "Andy", "Genymotion",
    "BlueStacks", "nox", "ttVM_Hdragon",
}

# Root detection indicator strings
ROOT_INDICATORS = {
    "/system/app/Superuser.apk",
    "/system/xbin/su",
    "/system/bin/su",
    "com.noshufou.android.su",
    "com.thirdparty.superuser",
    "eu.chainfire.supersu",
    "com.koushikdutta.superuser",
    "com.topjohnwu.magisk",
}

# Standard DEX filename pattern
STANDARD_DEX_PATTERN = re.compile(r"^classes\d*\.dex$")


class APKInconsistencyTestsExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.test_results = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_INCONSISTENCY_TESTS.value

    def _test_zip_bomb(self):
        """Check if any ZIP entry has compression ratio > 100:1."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            with zf:
                for info in zf.infolist():
                    if info.compress_size > 0:
                        ratio = info.file_size / info.compress_size
                        if ratio > 100:
                            return True
            return False
        except Exception as e:
            self.log.warning(f"Error in zip bomb test: {e}")
            return None

    def _test_zip_duplicate_entries(self):
        """Check for duplicate filenames in ZIP directory."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            with zf:
                names = [info.filename for info in zf.infolist()]
                return len(names) != len(set(names))
        except Exception as e:
            self.log.warning(f"Error in duplicate entries test: {e}")
            return None

    def _test_zip_path_traversal(self):
        """Check for path traversal (../) in ZIP entry names."""
        try:
            for f in self._list_files():
                if ".." in f or f.startswith("/"):
                    return True
            return False
        except Exception as e:
            self.log.warning(f"Error in path traversal test: {e}")
            return None

    def _test_zip_suspicious_timestamps(self):
        """Check for timestamps at epoch (1980) or in the future."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            now = datetime.now()
            with zf:
                for info in zf.infolist():
                    try:
                        dt = datetime(*info.date_time)
                        if dt.year <= 1980 or dt > now:
                            return True
                    except (ValueError, TypeError):
                        continue
            return False
        except Exception as e:
            self.log.warning(f"Error in suspicious timestamps test: {e}")
            return None

    def _test_hidden_dex_files(self):
        """Check for DEX files not matching classes*.dex pattern."""
        try:
            for f in self._list_files():
                if f.endswith(".dex"):
                    basename = f.split("/")[-1]
                    if not STANDARD_DEX_PATTERN.match(basename):
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in hidden DEX files test: {e}")
            return None

    def _test_manifest_component_mismatch(self):
        """Check for declared components that don't exist in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            # Get all class names from DEX
            dex_classes = set()
            try:
                from androguard.core.dex import DEX
                for dex_data in (self.apk.get_all_dex() or []):
                    try:
                        d = DEX(dex_data)
                        for cls in d.get_classes():
                            name = cls.get_name()
                            if name:
                                # Convert "Lcom/example/Foo;" to "com.example.Foo"
                                dex_classes.add(
                                    name[1:-1].replace("/", ".") if name.startswith("L") else name
                                )
                    except Exception:
                        continue
            except Exception:
                return None

            if not dex_classes:
                return None

            # Check manifest components against DEX classes
            components = []
            try:
                components.extend(self.apk.get_activities() or [])
                components.extend(self.apk.get_services() or [])
                components.extend(self.apk.get_receivers() or [])
                components.extend(self.apk.get_providers() or [])
            except Exception:
                return None

            for comp in components:
                if comp and comp not in dex_classes:
                    # Component might use a shorthand; check with package prefix
                    package = self.apk.get_package() or ""
                    full_name = package + comp if comp.startswith(".") else comp
                    if full_name not in dex_classes:
                        return True

            return False
        except Exception as e:
            self.log.warning(f"Error in manifest component mismatch test: {e}")
            return None

    def _test_debuggable_release(self):
        """Check android:debuggable=true combined with a release signature."""
        try:
            if not self._is_valid_apk():
                return None

            is_debuggable = self.apk.get_attribute_value(
                "application", "debuggable"
            ) == "true"

            if not is_debuggable:
                return False

            # Check if it has a signing certificate (release builds have certs)
            try:
                certs = self.apk.get_certificates()
                if certs and len(certs) > 0:
                    return True
            except Exception:
                pass

            return False
        except Exception as e:
            self.log.warning(f"Error in debuggable release test: {e}")
            return None

    def _get_dex_strings(self):
        """Get all string constants from DEX files."""
        all_strings = set()
        try:
            from androguard.core.dex import DEX
            for dex_data in (self.apk.get_all_dex() or []):
                try:
                    d = DEX(dex_data)
                    for s in d.get_strings():
                        if s:
                            all_strings.add(s)
                except Exception:
                    continue
        except Exception:
            pass
        return all_strings

    def _test_emulator_detection_strings(self):
        """Check for emulator detection patterns in DEX strings."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            for indicator in EMULATOR_INDICATORS:
                for s in dex_strings:
                    if indicator in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in emulator detection test: {e}")
            return None

    def _test_debugger_detection(self):
        """Check for debugger detection API calls in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            debugger_patterns = {
                "isDebuggerConnected",
                "waitingForDebugger",
                "Debug.isDebuggerConnected",
            }
            for pattern in debugger_patterns:
                for s in dex_strings:
                    if pattern in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in debugger detection test: {e}")
            return None

    def _test_root_detection(self):
        """Check for root detection patterns in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            for indicator in ROOT_INDICATORS:
                for s in dex_strings:
                    if indicator in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in root detection test: {e}")
            return None

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        self.test_results = APKInconsistencyTests(
            test_zip_bomb=self._test_zip_bomb(),
            test_zip_duplicate_entries=self._test_zip_duplicate_entries(),
            test_zip_path_traversal=self._test_zip_path_traversal(),
            test_zip_suspicious_timestamps=self._test_zip_suspicious_timestamps(),
            test_hidden_dex_files=self._test_hidden_dex_files(),
            test_manifest_component_mismatch=self._test_manifest_component_mismatch(),
            test_debuggable_release=self._test_debuggable_release(),
            test_emulator_detection_strings=self._test_emulator_detection_strings(),
            test_debugger_detection=self._test_debugger_detection(),
            test_root_detection=self._test_root_detection(),
        )
        return self.test_results

    def _bool_to_nullable(self, val):
        """Convert bool/None to ClickHouse Nullable(UInt8)."""
        if val is None:
            return None
        return int(val)

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.test_results:
                return None

            current_time = datetime.now(timezone.utc)
            t = self.test_results

            data = [[
                self.sha256,
                self._bool_to_nullable(t.test_zip_bomb),
                self._bool_to_nullable(t.test_zip_duplicate_entries),
                self._bool_to_nullable(t.test_zip_path_traversal),
                self._bool_to_nullable(t.test_zip_suspicious_timestamps),
                self._bool_to_nullable(t.test_hidden_dex_files),
                self._bool_to_nullable(t.test_manifest_component_mismatch),
                self._bool_to_nullable(t.test_debuggable_release),
                self._bool_to_nullable(t.test_emulator_detection_strings),
                self._bool_to_nullable(t.test_debugger_detection),
                self._bool_to_nullable(t.test_root_detection),
                current_time,
            ]]

            column_names = [
                'sha256',
                'test_zip_bomb', 'test_zip_duplicate_entries',
                'test_zip_path_traversal', 'test_zip_suspicious_timestamps',
                'test_hidden_dex_files', 'test_manifest_component_mismatch',
                'test_debuggable_release', 'test_emulator_detection_strings',
                'test_debugger_detection', 'test_root_detection',
                'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_inconsistency_tests"