Carlos Alonso-Ramos

23 papers Journal 1Unranked 22
YearRankTypeTitle / Venue / Authors
2026 J jnl
Appl. Soft Comput.
Loukia Avramelou, Manos Kirtas, Odysseas Asimopoulos, Theodoros Moschos, Antonios Prapas, Georgios Tsamis, Apostolos Tsakyridis, Miltiadis Moralis-Pegios, Aitor V. Velasco, Irene Olivares, Carlos Alonso-Ramos, Sara Toxqui Rodríguez, Nikolaos Passalis, Nikolaos Pleros, Anastasios Tefas
2025 conf
OFC
Jens H. Schmid, Pavel Cheben, J. Zhang, R. Korcek, M. Saad Bin-Alam, Ross Cheriton, Siegfried Janz, Dan-Xia Xu, Shurui Wang, Martin Vachon, R. Ma, Robert Halir, J. Gonzalo Wangüemert-Pérez, Alejandro Ortega-Moñux, I. Molina Fernandez, Alejandro Sánchez-Postigo, Jose M. Luque-González, A. F. Hinestrosa, Daniele Melati, Z. Mokeddem, Carlos Alonso-Ramos, Laurent Vivien, Winnie N. Ye, Shahrzad Khajavi, W. Fraser, Daniel Benedikovic, Y. D. Sirmaci, I. Staude, T. Pertsch, C. Naraine, J. Bradley, Andrew P. Knights, Thalía Domínguez Bucio, Frederic Y. Gardes
2024 conf
ICTON
Paula Nuño Ruano, J. Zhang, David González-Andrade, H. B. Ferhart, T. T. D. Dinh, David E. Medina-Quiroz, S. Edmond, Pavel Cheben, Delphine Marris-Morini, Eric Cassan, Laurent Vivien, Norberto Daniel Lanzillotti-Kimura, Carlos Alonso-Ramos
2024 conf
ICTON
Pavel Cheben, Jens H. Schmid, J. Zhang, M. Saad Bin-Alam, A. F. Hinestrosa, W. Fraser, R. Korcek, Jose M. Luque-González, Carlos Pérez-Armenta, Alejandro Sánchez-Postigo, Alejandro Ortega-Moñux, J. Gonzalo Wangüemert-Pérez, Íñigo Molina-Fernández, Robert Halir, Pablo Ginel-Moreno, Daniel Benedikovic, Milan Dado, Shahrzad Khajavi, Winnie N. Ye, Z. Mokeddem, Daniele Melati, Carlos Alonso-Ramos, David González-Andrade, Laurent Vivien, D. Sirmaci, I. Staude, Dan-Xia Xu, Yuri Grinberg, Siegfried Janz, S. Wang, Martin Vachon, Ross Cheriton, R. Fernández de Cabo, Aitor V. Velasco, C. Naraine, J. Bradley, A. Knights
2023 conf
ICTON
David E. Medina-Quiroz, Quentin Wilmart, Ségolène Olivier, Sylvain Guerber, Sébastien Tanzilli, Laurent Vivien, Laurent Labonté, Eric Cassan, Carlos Alonso-Ramos
2023 conf
ICTON
Paula Nuño Ruano, Jianhao Zhang, Xavier Le Roux, Daniele Melati, David González-Andrade, Eric Cassan, Delphine Marris-Morini, Laurent Vivien, Norberto Daniel Lanzillotti-Kimura, Carlos Alonso-Ramos
2023 conf
ICTON
Pavel Cheben, Jens H. Schmid, Pablo Ginel-Moreno, Shahrzad Khajavi, R. Korcek, W. Fraser, D. Sirmaci, Alejandro Fernández Hinestrosa, Jose M. Luque-González, Daniel Pereira-Martín, Alejandro Sánchez-Postigo, Abdelfettah Hadij-ElHouati, Daniel Benedikovic, Alejandro Ortega-Moñux, J. Gonzalo Wangüemert-Pérez, I. Molina Fernandez, Robert Halir, Winnie N. Ye, Daniele Melati, Carlos Alonso-Ramos, David González-Andrade, Laurent Vivien, I. Staude, J. Zhang, Maziyar Milanizadeh, Dan-Xia Xu, Yuri Grinberg, Ross Cheriton, Siegfried Janz, S. Wang, Martin Vachon, Milan Dado, R. Fernández de Cabo, Aitor V. Velasco
2021 conf
ECOC
Daniele Melati, Mohsen Kamandar Dezfouli, Yuri Grinberg, Muhammad Al-Digeil, Dan-Xia Xu, Jens H. Schmid, Pavel Cheben, Abi Waqas, Paolo Manfredi, Jianhao Zhang, Laurent Vivien, Carlos Alonso-Ramos
2019 conf
ICTON
D. Oser, Xavier Le Roux, F. Mazeas, Diego Pérez-Galacho, Daniel Benedikovic, Elena Durán-Valdeiglesias, V. Vakarin, Olivier Alibart, Pavel Cheben, Sebastien Tanzilli, Laurent Labonté, Delphine Marris-Morini, Eric Cassan, Laurent Vivien, Carlos Alonso-Ramos
2018 conf
ICTON
Joan Manel Ramirez, Qiankun Liu, V. Vakarin, Jacopo Frigerio, A. Ballabio, Daniel Chrastina, Xavier Le Roux, Carlos Alonso-Ramos, Giovanni Isella, Laurent Vivien, Delphine Marris-Morini
2018 conf
ECOC
Pavel Cheben, Robert Halir, Jens H. Schmid, Jirí Ctyroký, Daniel Benedikovic, Carlos Alonso-Ramos, Alejandro Ortega-Moñux, Alejandro Sánchez-Postigo, David González-Andrade, J. Gonzalo Wangüemert-Pérez, Íñigo Molina-Fernández, Aitor V. Velasco, Alaine Herrero-Bermello, Jose M. Luque-González, Daniel Pereira-Martín, Jean Lapointe, Siegfried Janz, Dan-Xia Xu, Daniele Melati, Yuri Grinberg, Shurui Wang, Martin Vachon, V. Vakarin, Laurent Vivien, Jan Litvik, Jarmila Müllerová, Milan Dado
2017 conf
ICTON
Weiwei Zhang, Elena Durán-Valdeiglesias, Thi Hong Cam Hoang, Matteo Balestrieri, Samuel Serna, Carlos Alonso-Ramos, Xavier Le Roux, Arianna Filoramo, Laurent Vivien, M. Gurioli, Eric Cassan
2017 conf
OFC
Léopold Virot, Daniel Benedikovic, Bertrand Szelag, Carlos Alonso-Ramos, Jean-Michel Hartmann, Paul Crozat, Eric Cassan, Delphine Marris-Morini, Charles Baudot, Frédéric Boeuf, Jean-Marc Fedeli, Christophe Kopp, Laurent Vivien
2017 conf
ICTON
Carlos Alonso-Ramos, Diego Pérez-Galacho, D. Oser, Xavier Le Roux, Daniel Benedikovic, F. Mazeas, W. Zhang, Samuel Serna, V. Vakarin, Elena Durán-Valdeiglesias, Laurent Labonté, Sebastien Tanzilli, Pavel Cheben, Eric Cassan, Delphine Marris-Morini, Laurent Vivien
2017 conf
OFC
Pavel Cheben, Jens H. Schmid, Robert Halir, Alejandro Sánchez-Postigo, Dan-Xia Xu, Siegfried Janz, Jean Lapointe, Shurui Wang, Martin Vachon, Alejandro Ortega-Moñux, J. Gonzalo Wangüemert-Pérez, Íñigo Molina-Fernández, Jose M. Luque-González, Jose Darío Sarmiento-Merenguel, James Pond, Daniel Benedikovic, Carlos Alonso-Ramos, Milan Dado, Jarmila Müllerová, Martin Papes, Vladimir Vasinek
2016 conf
OFC
Íñigo Molina-Fernández, Pedro J. Reyes-Iglesias, Robert Halir, J. Gonzalo Wangüemert-Pérez, José de-Oliva-Rubio, R. Godoy-Rubio, Pavel Cheben, Carlos Alonso-Ramos, Alejandro Ortega-Moñux
2016 conf
ICTON
Léopold Virot, Delphine Marris-Morini, Daniel Benedikovic, Carlos Alonso-Ramos, Jean-Michel Hartmann, Eric Cassan, Paul Crozat, Xavier Le Roux, Charles Baudot, Frédéric Boeuf, Jean-Marc Fedeli, Laurent Vivien
2016 conf
ICTON
Pedro Damas, Xavier Le Roux, Mathias Berciano, G. Marcaud, Carlos Alonso-Ramos, Daniel Benedikovic, Delphine Marris-Morini, Eric Cassan, Laurent Vivien
2016 conf
ICTON
Pavel Cheben, Jens H. Schmid, Dan-Xia Xu, Siegfried Janz, Jean Lapointe, M. Rahim, Shurui Wang, Martin Vachon, Robert Halir, Alejandro Ortega-Moñux, Jose Darío Sarmiento-Merenguel, J. Gonzalo Wangüemert-Pérez, Íñigo Molina-Fernández, James Pond, Daniel Benedikovic, Carlos Alonso-Ramos, Xavier Le Roux, Laurent Vivien, Delphine Marris-Morini, Jordi Soler Penadés, Milos Nedeljkovic, Goran Z. Mashanovich, Aitor V. Velasco, Maria Luisa Calvo, Milan Dado, Jarmila Müllerová, Weimin Ye, Martin Papes, Vladimir Vasinek
2015 conf
ICTON
Robert Halir, Pedro J. Reyes-Iglesias, Carlos Alonso-Ramos, Dario Sarmiento-Merenguel, J. Gonzalo Wangüemert-Pérez, Pavel Cheben, Íñigo Molina-Fernández, Alejandro Ortega-Moñux
2015 conf
ICTON
Pavel Cheben, Daniel Benedikovic, Carlos Alonso-Ramos, Jens H. Schmid, Martin Papes, Dan-Xia Xu, Siegfried Janz, Shurui Wang, Martin Vachon, J. Gonzalo Wangüemert-Pérez, Robert Halir, Alejandro Ortega-Moñux, I. Molina Fernandez, Jean-Marc Fedeli, Jirí Ctyroký, Jordi Soler Penadés, Milos Nedeljkovic, Goran Z. Mashanovich, W. Ye, Maria Luisa Calvo, Milan Dado, Jarmila Müllerová, Vladimir Vasinek
2014 conf
ICTON
Pavel Cheben, Siegfried Janz, N. Sabourin, Dan-Xia Xu, H. Ding, Shurui Wang, Jens H. Schmid, André Delâge, Jean Lapointe, W. Sinclair, Rubin Ma, S. Logan, R. MacKenzie, Q. Y. Liu, M. Gilmour, Robert Halir, Carlos Alonso-Ramos, J. Gonzalo Wangüemert-Pérez, Alejandro Ortega-Moñux, Íñigo Molina-Fernández, X. Le Roux, L. Laurent, A. Villafranca Velasco, Maria Luisa Calvo
2014 conf
ICTON
Jens H. Schmid, Pavel Cheben, Jean Lapointe, Dan-Xia Xu, Siegfried Janz, Martin Vachon, Shurui Wang, P. Bock, Daniel Benedikovic, Robert Halir, Alejandro Ortega-Moñux, Carlos Alonso-Ramos, J. Gonzalo Wangüemert-Pérez, Íñigo Molina-Fernández
redb/extractors/elf_extractors/elf_imports.py
← Index redb/extractors/elf_extractors/elf_imports.py python
import inspect
from datetime import datetime, timezone
from typing import Any, List, Set

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFImport


class ELFImportExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_imports = None
        self.elastic_index = self.index_prefix + "-elf_imports"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _get_import_libraries(self, elf) -> List[str]:
        """Extract imported libraries from dynamic section."""
        libraries = []

        try:
            # Get the dynamic section
            dynamic_section = elf.get_section_by_name('.dynamic')
            if not dynamic_section:
                return libraries

            # Extract DT_NEEDED entries (required libraries)
            for tag in dynamic_section.iter_tags():
                if tag.entry.d_tag == 'DT_NEEDED':
                    libraries.append(tag.needed)

        except Exception as e:
            self.log.error(f"Error extracting import libraries: {e}")

        return libraries

    def _get_imported_functions_from_symbols(self, elf) -> Set[str]:
        """Extract imported functions from dynamic symbol table."""
        imported_functions = set()

        try:
            # Get the dynamic symbol table
            dynsym_section = elf.get_section_by_name('.dynsym')
            if not dynsym_section or not hasattr(dynsym_section, 'iter_symbols'):
                return imported_functions

            # Look for undefined symbols (imports)
            for symbol in dynsym_section.iter_symbols():
                # Check if symbol is undefined (imported)
                if (symbol.entry.get('st_shndx', 0) == 'SHN_UNDEF' and
                    symbol.name and
                    symbol.entry.get('st_info', {}).get('bind') in ['STB_GLOBAL', 'STB_WEAK']):
                    imported_functions.add(symbol.name)

        except Exception as e:
            self.log.error(f"Error extracting imported functions from symbols: {e}")

        return imported_functions

    def _get_imported_functions_from_relocations(self, elf) -> Set[str]:
        """Extract imported functions from relocation sections."""
        imported_functions = set()

        try:
            # Look through relocation sections
            for section in elf.iter_sections():
                if hasattr(section, 'iter_relocations'):
                    try:
                        for relocation in section.iter_relocations():
                            # Get symbol associated with relocation
                            if hasattr(relocation, 'symbol') and relocation.symbol:
                                symbol_name = relocation.symbol.name
                                if symbol_name:
                                    imported_functions.add(symbol_name)
                    except Exception as e:
                        self.log.debug(f"Could not process relocations in section {section.name}: {e}")

        except Exception as e:
            self.log.error(f"Error extracting imported functions from relocations: {e}")

        return imported_functions

    def _get_plt_functions(self, elf) -> Set[str]:
        """Extract functions from PLT (Procedure Linkage Table) sections."""
        plt_functions = set()

        try:
            # Look for PLT-related sections
            plt_sections = ['.plt', '.plt.got', '.plt.sec']

            for section_name in plt_sections:
                section = elf.get_section_by_name(section_name)
                if section:
                    # PLT functions are typically associated with relocations
                    # We'll get them from the relocation analysis
                    pass

        except Exception as e:
            self.log.error(f"Error extracting PLT functions: {e}")

        return plt_functions

    def tag(self):
        return Tag.ELF_IMPORTS.value if hasattr(Tag, 'ELF_IMPORTS') else "elf_imports"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_data(elf):
                # Extract import libraries
                import_libraries = self._get_import_libraries(elf)

                # Extract imported functions from multiple sources
                imported_functions = set()

                # From dynamic symbols
                symbol_imports = self._get_imported_functions_from_symbols(elf)
                imported_functions.update(symbol_imports)

                # From relocations
                relocation_imports = self._get_imported_functions_from_relocations(elf)
                imported_functions.update(relocation_imports)

                # From PLT
                plt_imports = self._get_plt_functions(elf)
                imported_functions.update(plt_imports)

                # Convert to sorted lists for consistent output
                import_libraries_list = sorted(list(set(import_libraries)))
                import_functions_list = sorted(list(imported_functions))

                # Return ELFImport dataclass
                return ELFImport(
                    elf_imports_total=len(import_functions_list),
                    elf_import_libraries=import_libraries_list,
                    elf_import_functions=import_functions_list,
                )

            if not self._is_elf_file():
                return None

            result = self._with_elf_file(extract_data)
            if result is None:
                return None

            self.elf_imports = result
            return self.elf_imports

        except Exception as e:
            self.log.error(f"Error extracting ELF imports {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_imports
        elif exporter_type == "ClickHouseExporter":
            try:
                if not self.elf_imports:
                    return None

                # Prepare data array
                data = [[
                    self.sha256,
                    self.md5,
                    self.sha1,
                    self.elf_imports.elf_imports_total,
                    self.elf_imports.elf_import_libraries,
                    self.elf_imports.elf_import_functions,
                    datetime.now(timezone.utc)
                ]]

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'elf_imports_total',
                    'elf_import_libraries',
                    'elf_import_functions',
                    'analysis_date'
                ]

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    'UInt32',
                    'Array(LowCardinality(String))',
                    'Array(LowCardinality(String))',
                    'DateTime64(3, \'UTC\')'
                ]

                if not data:
                    return None

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_imports"