Chai Wutiwiwatchai

72 papers A* 1A 19B 5C 4Journal 19Unranked 24
YearRankTypeTitle / Venue / Authors
2020 J jnl
IEICE Trans. Inf. Syst.
Sila Chunwijitra, Phondanai Khanti, Supphachoke Suntiwichaya, Kamthorn Krairaksa, Pornchai Tummarattananont, Marut Buranarach, Chai Wutiwiwatchai
2019 conf
O-COCOSDA
Sittipong Saychum, Anocha Rugchatjaroen, Chai Wutiwiwatchai
2019 J jnl
Lang. Resour. Evaluation
Sawit Kasuriya, Thanaruk Theeramunkong, Chai Wutiwiwatchai, Piyawat Sukhummek
2019 J jnl
Speech Commun.
Anocha Rugchatjaroen, Sittipong Saychum, Sarawoot Kongyoung, Patcharika Chootrakool, Sawit Kasuriya, Chai Wutiwiwatchai
2018 conf
O-COCOSDA
Chai Wutiwiwatchai, Patcharika Chootrakool, Sawit Kasuriya, Kalyanee Makarabhirom, Nantiya Ooppanasak, Benjamas Prathanee
2017 J jnl
EURASIP J. Audio Speech Music. Process.
Vataya Chunwijitra, Chai Wutiwiwatchai
2017 conf
APSIPA
Surasak Boonkla, Masashi Unoki, Chai Wutiwiwatchai, Stanislav S. Makhanov
2017 conf
APSIPA
Phuttapong Sertsi, Surasak Boonkla, Vataya Chunwijitra, Nattapong Kurpukdee, Chai Wutiwiwatchai
2017 conf
APSIPA
Nattapong Kurpukdee, Tomoki Koriyama, Takao Kobayashi, Sawit Kasuriya, Chai Wutiwiwatchai, Poonlap Lamsrichan
2017 conf
APSIPA
Jessada Karnjana, Kasorn Galajit, Pakinee Aimmanee, Chai Wutiwiwatchai, Masashi Unoki
2016 J jnl
EURASIP J. Audio Speech Music. Process.
Vataya Chunwijitra, Ananlada Chotimongkol, Chai Wutiwiwatchai
2016 J jnl
IEICE Trans. Inf. Syst.
Sila Chunwijitra, Chanchai Junlouchai, Sitdhibong Laokok, Pornchai Tummarattananont, Kamthorn Krairaksa, Chai Wutiwiwatchai
2016 J jnl
J. Electr. Comput. Eng.
Jessada Karnjana, Masashi Unoki, Pakinee Aimmanee, Chai Wutiwiwatchai
2016 A conf
INTERSPEECH
Sittipong Saychum, Sarawoot Kongyoung, Anocha Rugchatjaroen, Patcharika Chootrakool, Sawit Kasuriya, Chai Wutiwiwatchai
2016 conf
APSIPA
Jessada Karnjana, Masashi Unoki, Pakinee Aimmanee, Chai Wutiwiwatchai
2016 J jnl
IEICE Trans. Inf. Syst.
Jessada Karnjana, Masashi Unoki, Pakinee Aimmanee, Chai Wutiwiwatchai
2016 J jnl
IEICE Trans. Fundam. Electron. Commun. Comput. Sci.
Surasak Boonkla, Masashi Unoki, Stanislav S. Makhanov, Chai Wutiwiwatchai
2016 conf
SLTU
Prachya Boonkwan, Thepchai Supnithi, Wandee Tosuwan, Chai Wutiwiwatchai
2015 conf
APSIPA
Jessada Karnjana, Pakinee Aimmanee, Masashi Unoki, Chai Wutiwiwatchai
2015 A conf
INTERSPEECH
Vataya Chunwijitra, Ananlada Chotimongkol, Chai Wutiwiwatchai
2015 conf
O-COCOSDA/CASLRE
Ananlada Chotimongkol, Vataya Chunwijitra, Sumonmas Thatphithakkul, Nattapong Kurpukdee, Chai Wutiwiwatchai
2015 conf
ICPhS
Charturong Tantibundhit, Chutamanee Onsuwan, Adirek Munthuli, Krit Kosawat, Chai Wutiwiwatchai
2015 conf
KICSS
Watchira Buranasing, Marut Buranarach, Chai Wutiwiwatchai
2014 C conf
IWDW
Jessada Karnjana, Masashi Unoki, Pakinee Aimmanee, Chai Wutiwiwatchai
2014 conf
O-COCOSDA
Chai Wutiwiwatchai
2014 conf
ISCSLP
Surasak Boonkla, Masashi Unoki, Stanislav S. Makhanov, Chai Wutiwiwatchai
2014 conf
O-COCOSDA
Ananlada Chotimongkol, Kwanchiva Thangthai, Chai Wutiwiwatchai
2013 J jnl
IEICE Trans. Inf. Syst.
Santi Nuratch, Panuthat Boonpramuk, Chai Wutiwiwatchai
2013 A conf
INTERSPEECH
Kwanchiva Thangthai, Ananlada Chotimongkol, Chai Wutiwiwatchai
2013 J jnl
Comput. Speech Lang.
Sakriani Sakti, Michael Paul, Andrew M. Finch, Shinsuke Sakai, Thang Tat Vu, Noriyuki Kimura, Chiori Hori, Eiichiro Sumita, Satoshi Nakamura, Jun Park, Chai Wutiwiwatchai, Bo Xu, Hammam Riza, Karunesh Arora, Chi Mai Luong, Haizhou Li
2013 conf
O-COCOSDA/CASLRE
Sawit Kasuriya, Thanaruk Theeramunkong, Chai Wutiwiwatchai
2013 A conf
INTERSPEECH
Charturong Tantibundhit, Chutamanee Onsuwan, Nittayapa Klangpornkun, P. Phienphanich, Tanawan Saimai, Nantaporn Saimai, P. Pitathawatchai, Chai Wutiwiwatchai
2013 J jnl
Expert Syst. Appl.
Pat Taweewat, Chai Wutiwiwatchai
2013 J jnl
Int. Arab J. Inf. Technol.
Saritchai Predawan, Chom Kimpan, Chai Wutiwiwatchai
2012 conf
CCNC
Therdpong Daengsi, Chai Wutiwiwatchai, Apiruk Preechayasomboon, Saowanit Sukparungsee
2012 A conf
INTERSPEECH
Charturong Tantibundhit, Chutamanee Onsuwan, P. Phienphanich, Chai Wutiwiwatchai
2012 conf
IWSLT
Chai Wutiwiwatchai
2011 C conf
ASRU
Chai Wutiwiwatchai, Ausdang Thangthai, Ananlada Chotimongkol, Chatchawarn Hansakunbuntheung, Nattanun Thatphithakkul
2011 conf
VRCAI
Thavesak Chuensaichol, Pizzanu Kanongchaiyos, Chai Wutiwiwatchai
2011 conf
Culture and Computing
Thavesak Chuensaichol, Pizzanu Kanongchaiyos, Chai Wutiwiwatchai
2010 A conf
INTERSPEECH
Sirinoot Boonsuk, Donglai Zhu, Bin Ma, Atiwong Suchato, Proadpran Punyabukkana, Nattanun Thatphithakkul, Chai Wutiwiwatchai
2010 conf
IALP
Santi Nuratch, Panuthat Boonpramuk, Chai Wutiwiwatchai
2010 B conf
LREC
Kwanchiva Saykham, Ananlada Chotimongkol, Chai Wutiwiwatchai
2010 conf
NEWS@ACL
Chai Wutiwiwatchai, Ausdang Thangthai
2009 J jnl
IEEE Ann. Hist. Comput.
Hugh Thaweesak Koanantakool, T. Karoonboonyanan, Chai Wutiwiwatchai
2009 J jnl
Speech Commun.
Chai Wutiwiwatchai, Sadaoki Furui
2009 A conf
INTERSPEECH
Vataya Boonpiam, Anocha Rugchatjaroen, Chai Wutiwiwatchai
2009 J jnl
Speech Commun.
Markpong Jongtaveesataporn, Issara Thienlikit, Chai Wutiwiwatchai, Sadaoki Furui
2009 A conf
INTERSPEECH
Ausdang Thangthai, Anocha Rugchatjaroen, Nattanun Thatphithakkul, Ananlada Chotimongkol, Chai Wutiwiwatchai
2009 A conf
INTERSPEECH
Anocha Rugchatjaroen, Nattanun Thatphithakkul, Ananlada Chotimongkol, Ausdang Thangthai, Chai Wutiwiwatchai
2009 C conf
ASRU
Sakriani Sakti, Noriyuki Kimura, Michael Paul, Chiori Hori, Eiichiro Sumita, Satoshi Nakamura, Jun Park, Chai Wutiwiwatchai, Bo Xu, Hammam Riza, Karunesh Arora, Chi Mai Luong, Haizhou Li
2008 B conf
IJCNLP
Chai Wutiwiwatchai, Thepchai Supnithi, Krit Kosawat
2008 A conf
INTERSPEECH
Ausdang Thangthai, Nattanun Thatphithakkul, Chai Wutiwiwatchai, Anocha Rugchatjaroen, Sittipong Saychum
2008 B conf
LREC
Markpong Jongtaveesataporn, Chai Wutiwiwatchai, Koji Iwano, Sadaoki Furui
2008 A conf
INTERSPEECH
Kwanchiva Saykhum, Vataya Boonpiam, Nattanun Thatphithakkul, Chai Wutiwiwatchai, Cholwich Nattee
2007 A conf
INTERSPEECH
Ausdang Thangthai, Chai Wutiwiwatchai, Anocha Rugchatjaroen, Sittipong Saychum
2007 J jnl
Speech Commun.
Chai Wutiwiwatchai, Sadaoki Furui
2007 A conf
INTERSPEECH
Markpong Jongtaveesataporn, Issara Thienlikit, Chai Wutiwiwatchai, Sadaoki Furui
2006 J jnl
Speech Commun.
Chai Wutiwiwatchai, Sadaoki Furui
2006 A conf
INTERSPEECH
Nattanun Thatphithakkul, Boontee Kruatrachue, Chai Wutiwiwatchai, Sanparith Marukatat, Vataya Boonpiam
2006 A conf
INTERSPEECH
Ausdang Thangthai, Chatchawarn Hansakunbuntheung, Rungkarn Siricharoenchai, Chai Wutiwiwatchai
2005 A conf
INTERSPEECH
Chatchawarn Hansakunbuntheung, Ausdang Thangthai, Chai Wutiwiwatchai, Rungkarn Siricharoenchai
2004 A conf
INTERSPEECH
Chai Wutiwiwatchai, Sadaoki Furui
2003 A conf
INTERSPEECH
Chai Wutiwiwatchai, Sadaoki Furui
2002 B conf
LREC
Chai Wutiwiwatchai, Patcharika Cotsomrong, Sinaporn Suebvisai, Supphanat Kanokphara
2001 J jnl
Int. J. Uncertain. Fuzziness Knowl. Based Syst.
Sawit Kasuriya, Chai Wutiwiwatchai, Varin Achariyakulporn, Chularat Tanprasert
2001 A conf
INTERSPEECH
Chai Wutiwiwatchai, Varin Achariyakulporn, Sawit Kasuriya
2000 A* conf
ACL
Virach Sornlertlamvanich, Tanapong Potipiti, Chai Wutiwiwatchai, Pradit Mittrapiyanuruk
1999 B conf
IJCNN
Chularat Tanprasert, Chai Wutiwiwatchai, Sutat Sae-Tang
1998 conf
ICSLP
Chai Wutiwiwatchai, Somchai Jitapunkul, Visarut Ahkuputra, Ekkarit Maneenoi, Sudaporn Luksaneeyanawin
1998 conf
ICSLP
Chai Wutiwiwatchai, Somchai Jitapunkul, Visarut Ahkuputra, Ekkarit Maneenoi, Sudaporn Luksaneeyanawin
1998 C conf
MMSP
Chai Wutiwiwatchai, Somchai Jitapunkul, Sudaporn Luksaneeyanawin, Visarut Ahkuputra
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |