Carron Shankland

33 papers A* 1A 1B 3C 3Journal 12Unranked 12
YearRankTypeTitle / Venue / Authors
2022 conf
UKICER
Ella Taylor-Smith, Camilla Barnett, Sally Smith, Matthew Barr, Carron Shankland
2019 conf
CIBB
Ryan Mitchell, David E. Cairns, Dalila Hamami, Kevin G Pollock, Carron Shankland
2019 J jnl
J. Intell. Inf. Syst.
Dalila Hamami, Baghdad Atmani, Ross Cameron, Kevin G Pollock, Carron Shankland
2017 J jnl
Int. J. Inf. Syst. Serv. Sect.
Dalila Hamami, Baghdad Atmani, Carron Shankland
2016 conf
CIBB
Erin Scott, James Nicol, Jonathan Coulter, Andrew Hoyle, Carron Shankland
2014 conf
CMSB
Rachel Lintott, Stephen McMahon, Kevin M. Prise, Celine Addie-Lagorio, Carron Shankland
2012 A conf
GECCO
David Marco, Carron Shankland, David E. Cairns
2012 conf
CMSB
David Marco, Erin Scott, David E. Cairns, Andrea L. Graham, Judi Allen, Simmi Mahajan, Carron Shankland
2012 B conf
FM
Soufiene Benkirane, Rachel Norman, Erin Scott, Carron Shankland
2012 conf
PASM/PDMC
Erin Scott, Andrew Hoyle, Carron Shankland
2011 J jnl
Theory Biosci.
Chris McCaig, Mike Begon, Rachel Norman, Carron Shankland
2011 J jnl
Theor. Comput. Sci.
Chris McCaig, Rachel Norman, Carron Shankland
2011 B conf
IEEE Congress on Evolutionary Computation
David Marco, David E. Cairns, Carron Shankland
2009 J jnl
Math. Comput. Sci.
Chris McCaig, Rachel Norman, Carron Shankland
2008 conf
FBTC@ICALP
Soufiene Benkirane, Jane Hillston, Chris McCaig, Rachel Norman, Carron Shankland
2008 conf
AB
Chris McCaig, Rachel Norman, Carron Shankland
2006 J jnl
Theor. Comput. Sci.
Savi Maharaj, Carron Shankland, Charles Rattray
2005 A* conf
AAAI
Tran Hoai Nam, Chitta Baral, Carron Shankland
2004 ed.
AMAST
Charles Rattray, Savi Maharaj, Carron Shankland
2004 conf
AMAST
Carron Shankland, Jeremy W. Bryans, Lionel Morel
2004 B ed.
MPC
Dexter Kozen, Carron Shankland
2003 J jnl
Formal Aspects Comput.
Colin J. Fidge, Carron Shankland
2003 C conf
FORTE
Peter J. Robinson, Carron Shankland
2003 conf
EUROCAST
Rachel Norman, Carron Shankland
2003 J jnl
Formal Aspects Comput.
John Cooke, Savi Maharaj, Judi Romijn, Carron Shankland
2002 J jnl
Comput. J.
Muffy Calder, Savi Maharaj, Carron Shankland
2001 C conf
FORTE
Muffy Calder, Carron Shankland
2001 J jnl
Comput. Networks
Carron Shankland, Alberto Verdejo
2001 conf
FME
Muffy Calder, Savi Maharaj, Carron Shankland
2001 C conf
FORTE
Jeremy W. Bryans, Carron Shankland
2000 J jnl
J. Univers. Comput. Sci.
Savi Maharaj, Carron Shankland
1998 J jnl
Formal Aspects Comput.
Carron Shankland, Mark van der Zwaag
1997 conf
AMAST
Carron Shankland, Muffy Thomas
redb/extractors/pe_extractors/pe_sections.py
← Index redb/extractors/pe_extractors/pe_sections.py python
import base64
import hashlib
import inspect
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PESection
from datetime import datetime, timezone
from typing import Any


class PESectionExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_sections"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_SECTION.value

    def _extract_sections(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        sections = []
        for section in self.pe.sections:
            try:
                name = self.process_binary_string(section.Name)
            except Exception as e:
                name = "UnableToDecode"
                self.log.warning(
                    f'Unable to store section Name "{section.Name}" for {self.hash.sha256}'
                    f" exception {e}"
                )
            sec_sha256 = section.get_hash_sha256()
            sec_md5 = section.get_hash_md5()
            # sec_entropy = "%.2f" % section.get_entropy()
            sec_entropy = section.get_entropy()
            pe_section = PESection(
                _id=hashlib.sha256(
                    name.encode()
                ).hexdigest(),  # usecase 8e035beb02a411f8a9e92d4cf184ad34f52bbd0a81a50c222cdd4706e4e45104, all section have same sha256
                section_name=name,
                section_name_b64=base64.b64encode(
                    section.Name.rstrip(b'\x00')
                ).decode(),  # base64.b64decode(b64) to decode
                section_v_addr=section.VirtualAddress,
                section_v_addr_hex=hex(section.VirtualAddress),
                section_v_size=section.Misc_VirtualSize,
                section_size=section.SizeOfRawData,
                section_pointer_to_raw_data=hex(section.PointerToRawData),
                section_md5=sec_md5,
                section_sha256=sec_sha256,
                section_entropy=sec_entropy,
            )
            sections.append(pe_section)
        return sections

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            sections = self._extract_sections()
            # self.export_to_elastic(sections)  # Let the exporters handle this
            return sections
        except Exception as e:
            self.log.error(f"Error extracting PE sections: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            sections = self.extract()
            if sections is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for section in sections:
                data.append([
                    self.sha256,                          # sha256
                    self.md5,                             # md5
                    self.sha1,                            # sha1
                    section.section_name,                 # section_name
                    section.section_name_b64,             # section_name_b64
                    section.section_entropy,              # section_entropy
                    section.section_sha256,               # section_sha256
                    section.section_md5,                  # section_md5
                    section.section_size,                 # section_size
                    section.section_v_addr,               # section_v_addr
                    section.section_v_size,               # section_v_size
                    int(section.section_pointer_to_raw_data, 16),  # section_pointer_to_raw_data - convert from hex
                    current_time                          # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'section_name', 'section_name_b64',
                'section_entropy', 'section_sha256', 'section_md5', 'section_size',
                'section_v_addr', 'section_v_size', 'section_pointer_to_raw_data',
                'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(String)', 'LowCardinality(String)',
                'Float64', 'FixedString(64)', 'FixedString(32)', 'UInt64',
                'UInt64', 'UInt64', 'UInt64',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_sections"