Carl B. Dietrich

50 papers B 5C 1Journal 28Unranked 16
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Open J. Commun. Soc.
Joseph Tolley, Carl B. Dietrich
2025 J jnl
J. Netw. Comput. Appl.
Joseph Tolley, Cameron Makin, Kenneth King, Carl B. Dietrich
2024 conf
DySPAN
Ta-Seen Reaz Niloy, Saurav Kumar, Aniruddha Hore, Zoheb Hassan, Carl B. Dietrich, Eric W. Burger, Jeffrey H. Reed, Vijay K. Shah
2024 J jnl
CoRR
Ta-Seen Reaz Niloy, Saurav Kumar, Aniruddha Hore, Md. Zoheb Hassan, Carl B. Dietrich, Eric W. Burger, Jeffrey H. Reed, Vijay K. Shah
2024 conf
SmartNets
Joseph Tolley, Carl B. Dietrich
2023 conf
FTC (1)
Benedict Isaac, Nishith D. Tripathi, Chris Anderson, Carl B. Dietrich, Jeffrey H. Reed
2023 J jnl
IEEE Commun. Mag.
Md. Zoheb Hassan, Erika Heeren-Moon, Javad Sabzehali, Vijay K. Shah, Carl B. Dietrich, Jeffrey H. Reed, Eric William Burger
2023 J jnl
IEEE Access
Joseph Tolley, Cameron Makin, Carl B. Dietrich
2022 J jnl
IEEE Trans. Intell. Transp. Syst.
Jun Sung Choi, Vuk Marojevic, Carl B. Dietrich, Seungyoung Ahn
2022 J jnl
IEEE Trans. Wirel. Commun.
Don-Roberts Emenonye, Carl B. Dietrich, R. Michael Buehrer
2021 B conf
Networking
Avik Dayal, Vijay K. Shah, Biplav Choudhury, Vuk Marojevic, Carl B. Dietrich, Jeffrey H. Reed
2021 J jnl
CoRR
Avik Dayal, Vijay K. Shah, Biplav Choudhury, Vuk Marojevic, Carl B. Dietrich, Jeffrey H. Reed
2021 J jnl
CoRR
Jun Sung Choi, Vuk Marojevic, Carl B. Dietrich, Seungyoung Ahn
2020 J jnl
IEEE Access
Jun Sung Choi, Vuk Marojevic, Carl B. Dietrich, Jeffrey H. Reed, Seungyoung Ahn
2020 J jnl
CoRR
Jun Sung Choi, Vuk Marojevic, Carl B. Dietrich, Jeffrey H. Reed, Seungyoung Ahn
2019 conf
VTC Spring
Jun Sung Choi, Vuk Marojevic, Randall Nealy, Jeffrey H. Reed, Carl B. Dietrich
2019 conf
CAVS
Jun Sung Choi, Vuk Marojevic, Christopher Robert Anderson, Carl B. Dietrich
2018 conf
5G World Forum
Vuk Marojevic, Shem Kikamaze, Randall Nealy, Carl B. Dietrich
2018 J jnl
CoRR
Vuk Marojevic, Shem Kikamaze, Randall Nealy, Carl B. Dietrich
2018 B conf
GLOBECOM
Seungmo Kim, Carl B. Dietrich
2018 J jnl
IEEE Wirel. Commun. Lett.
Jun Sung Choi, Vuk Marojevic, Aakanksha Sharma, Biniyam Zewede, Randall Nealy, Christopher Robert Anderson, Jared Withers, Carl B. Dietrich
2018 conf
VTC Fall
Jun Sung Choi, Vuk Marojevic, Carl B. Dietrich
2018 conf
VTC Fall
Amr Nabil, Komalbir Kaur, Carl B. Dietrich, Vuk Marojevic
2018 J jnl
CoRR
Amr Nabil, Vuk Marojevic, Komalbir Kaur, Carl B. Dietrich
2018 J jnl
CoRR
Jun Sung Choi, Vuk Marojevic, Mina Labib, Siddharth Kabra, Jayanthi Rao, Sushanta Das, Jeffrey H. Reed, Carl B. Dietrich
2018 C conf
FIE
Carl B. Dietrich, Richard M. Goff, Dimitri A. Dessources, Xavier Gomez, Joshua Garcia-Sheridan, Nicholas F. Polys, R. Michael Buehrer, Seungmo Kim, Vuk Marojevic, Christian Hearn
2017 J jnl
CoRR
Seungmo Kim, Carl B. Dietrich
2017 J jnl
IEEE J. Sel. Areas Commun.
Seungmo Kim, Eugene Visotsky, Prakash Moorut, Kamil Bechta, Amitava Ghosh, Carl B. Dietrich
2017 J jnl
CoRR
Seungmo Kim, Carl B. Dietrich
2017 J jnl
IEEE Wirel. Commun. Lett.
Seungmo Kim, Carl B. Dietrich
2017 conf
WiNTECH
Shem Kikamaze, Vuk Marojevic, Carl B. Dietrich
2017 conf
Web3D
Ayat Mohammed, Nicholas F. Polys, Vuk Marojevic, Richard M. Goff, Carl B. Dietrich
2017 B conf
WCNC
Thomas W. Tedesso, Christopher Rowe, Christopher Robert Anderson, Carl B. Dietrich
2017 conf
CCNC
Xiaofu Ma, Sayantan Guha, Jun Sung Choi, Christopher Robert Anderson, Randall Nealy, Jared Withers, Jeffrey H. Reed, Carl B. Dietrich
2016 conf
WCNC Workshops
Seungmo Kim, Jun Sung Choi, Carl B. Dietrich
2016 B conf
WCNC
Seungmo Kim, Jun Sung Choi, Carl B. Dietrich
2016 J jnl
IEEE Wirel. Commun. Lett.
Jeffrey H. Reed, Andrew W. Clegg, Aditya V. Padaki, Taeyoung Yang, Randall Nealy, Carl B. Dietrich, Christopher Robert Anderson, D. Michael Mearns
2016 J jnl
CoRR
Jeffrey H. Reed, Andrew W. Clegg, Aditya V. Padaki, Taeyoung Yang, Randall Nealy, Carl B. Dietrich, Christopher Robert Anderson, D. Michael Mearns
2016 J jnl
Mob. Inf. Syst.
Seungmo Kim, Jun Sung Choi, Carl B. Dietrich
2015 conf
VTC Fall
Eric Sollenberger, Ferdinando Romano, Carl B. Dietrich
2014 J jnl
Int. J. Softw. Tools Technol. Transf.
Jason Snyder, Deepan Seeralan, Shereef Sayed, Jeffery Wilson, Carl B. Dietrich, Stephen H. Edwards, Jeffrey H. Reed
2014 J jnl
IEEE Commun. Mag.
Sven G. Bilén, Alexander M. Wyglinski, Christopher Robert Anderson, Todor Cooklev, Carl B. Dietrich, Behrouz Farhang-Boroujeny, Julio V. Urbina, Stephen H. Edwards, Jeffrey H. Reed
2014 conf
Web3D
Nikita Sharakhov, Vuk Marojevic, Ferdinando Romano, Nicholas F. Polys, Carl B. Dietrich
2012 conf
CrownCom
Carl B. Dietrich, Edward W. Wolfe, Garrett M. Vanhoy
2012 J jnl
IEEE Commun. Mag.
Dinesh Datla, Xuetao Chen, Thomas Tsou, Sahana Raghunandan, S. M. Shajedul Hasan, Jeffrey H. Reed, Carl B. Dietrich, Tamal Bose, Bruce Fette, Jeong-Ho Kim
2011 conf
WTS
Duyun Chen, Garrett M. Vanhoy, MaryPat Beaufait, Carl B. Dietrich
2010 J jnl
Phys. Commun.
Andrew R. Cormier, Carl B. Dietrich, Jeremy C. Price, Jeffrey H. Reed
2009 J jnl
IEEE Commun. Mag.
Carlos Aguayo Gonzalez, Carl B. Dietrich, Shereef Sayed, Haris Volos, Joseph D. Gaeddert, Max Robert, Jeffrey H. Reed, Frank Kragh
2009 J jnl
IEEE Commun. Mag.
Carlos Aguayo Gonzalez, Carl B. Dietrich, Jeffrey H. Reed
1994 B conf
VTC
Peter Chow, Ali Karim, Victor Fung, Carl B. Dietrich
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"