Chaitan Baru

29 papers A* 1B 1Misc 3Journal 12Unranked 12
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Vinay K. Chaudhri, Chaitan Baru, Brandon Bennett, Mehul Bhatt, Darion Cassel, Anthony G. Cohn, Rina Dechter, Esra Erdem, David A. Ferrucci, Kenneth D. Forbus, Gregory Gelfond, Michael R. Genesereth, Andrew S. Gordon, Benjamin N. Grosof, Gopal Gupta, Jim Hendler, Sharat Israni, Tyler R. Josephson, Patrick C. Kyllonen, Yuliya Lierler, Vladimir Lifschitz, Clifton James McFate, Hande K. McGinty, Leora Morgenstern, Alessandro Oltramari, Praveen K. Paritosh, Dan Roth, Blake Shepard, Cogan Shimizu, Denny Vrandecic, Mark Whiting, Michael Witbrock
2025 J jnl
AI Mag.
Vinay K. Chaudhri, Chaitan Baru, Brandon Bennett, Mehul Bhatt, Darion Cassel, Anthony G. Cohn, Rina Dechter, Esra Erdem, David A. Ferrucci, Kenneth D. Forbus, Gregory Gelfond, Michael R. Genesereth, Andrew S. Gordon, Benjamin N. Grosof, Gopal Gupta, Jim Hendler, Sharat Israni, Tyler R. Josephson, Patrick C. Kyllonen, Yuliya Lierler, Vladimir Lifschitz, Clifton James McFate, Hande K. McGinty, Leora Morgenstern, Alessandro Oltramari, Praveen K. Paritosh, Dan Roth, Blake Shepard, Cogan Shimizu, Denny Vrandecic, Mark Whiting, Michael Witbrock
2022 J jnl
Earth Sci. Informatics
Siri Jodha S. Khalsa, Adrian A. Borsa, Viswanath Nandigam, Minh Phan, Kai Lin, Christopher J. Crosby, Helen Amanda Fricker, Chaitan Baru, Luis Lopez
2017 conf
IPDPS Workshops
Chaitan Baru, Fen Zhao, Joanna Chan
2014 J jnl
Concurr. Comput. Pract. Exp.
Choonhan Youn, Jinchi Lu, Ahmed Elgamal, Chaitan Baru
2014 Misc conf
AMIA
Stephanie L. Martch, Karen M. Basen-Engquist, Wendy Demark-Wahnefried, Alexander V. Prokhorov, Kevin Patrick, Eileen H. Shinn, Emilia Farcas, Chaitan Baru, Ingolf Krueger, Kai Lin, Phillip Rios, Yan Yan, Viswanath Nandigam, Susan K. Peterson
2014 conf
XSEDE
Richard Lee Moore, Chaitan Baru, Diane Baxter, Geoffrey Charles Fox, Amitava Majumdar, Philip M. Papadopoulos, Wayne Pfeiffer, Robert S. Sinkovits, Shawn Strande, Mahidhar Tatineni, Richard P. Wagner, Nancy Wilkins-Diehr, Michael L. Norman
2014 conf
XSEDE
Choonhan Youn, Viswanath Nandigam, Minh Phan, David Tarboton, Nancy Wilkins-Diehr, Chaitan Baru, Christopher J. Crosby, Anand Padmanabhan, Shaowen Wang
2012 conf
HICSS
Chaitan Baru, Nathan Botts, Thomas A. Horan, Kevin Patrick, Sue S. Feldman
2011 J jnl
Ecol. Informatics
Eric H. Fegraus, Kai Lin, Jorge A. Ahumada, Chaitan Baru, Sandeep Chandra, Choonhan Youn
2011 Misc conf
ICCS
Choonhan Youn, Sandeep Chandra, Eric H. Fegraus, Kai Lin, Chaitan Baru
2010 B conf
SSDBM
Viswanath Nandigam, Chaitan Baru, Christopher J. Crosby
2009 J jnl
Int. J. Digit. Earth
Chaitan Baru, Kai Lin
2009 J jnl
Int. J. Digit. Earth
Chaitan Baru, Sandeep Chandra, Kai Lin, Ashraf Memon, Choonhan Youn
2009 J jnl
Gov. Inf. Q.
Hector Jasso, William S. Hodgkiss, Chaitan Baru, Tony Fountain, Don Reich, Kurt Warner
2008 conf
DG.O
Hector Jasso, Chaitan Baru, Tony Fountain, William S. Hodgkiss, Don Reich, Kurt Warner
2007 J jnl
Concurr. Comput. Pract. Exp.
Choonhan Youn, Chaitan Baru, Karan Bhatia, Sandeep Chandra, Kai Lin, Ashraf Memon, Ghulam Memon, Dogan Seber
2007 conf
DG.O
Hector Jasso, Tony Fountain, Chaitan Baru, William S. Hodgkiss, Don Reich, Kurt Warner
2006 Misc conf
International Conference on Computational Science (3)
Efrat Jaeger-Frank, Christopher J. Crosby, Ashraf Memon, Viswanath Nandigam, J. Ramon Arrowsmith, Jeffery Conner, Ilkay Altintas, Chaitan Baru
2006 J jnl
Sci. Program.
Efrat Jaeger-Frank, Christopher J. Crosby, Ashraf Memon, Viswanath Nandigam, Jeffery Conner, J. Ramon Arrowsmith, Ilkay Altintas, Chaitan Baru
2006 conf
DG.O
Hector Jasso, Tony Fountain, Chaitan Baru, William S. Hodgkiss, Don Reich, Kurt Warner
2006 conf
WIDM
Ullas Nambiar, Bertram Ludäscher, Kai Lin, Chaitan Baru
2005 conf
HealthGrid
Jeffrey S. Grethe, Chaitan Baru, Amarnath Gupta, Mark James, Bertram Ludäscher, Maryann E. Martone, Philip M. Papadopoulos, Steven Peltier, Arcot Rajasekar, Simone Santini, Ilya Zaslavsky, Mark H. Ellisman
2004 conf
DG.O
Chaitan Baru, Amarnath Gupta, Ilya Zaslavsky, Yannis Papakonstantinou, Peter Joftis
2003 A* conf
ICDE
Chaitan Baru
2003 conf
WISE Workshops
Vivek Manpuria, Ilya Zaslavsky, Chaitan Baru
2001 conf
WISE (2)
Chaitan Baru, Amit Behere, Charles Cowart
2000 J jnl
D Lib Mag.
Reagan W. Moore, Chaitan Baru, Arcot Rajasekar, Bertram Ludäscher, Richard Marciano, Michael Wan, Wayne Schroeder, Amarnath Gupta
2000 J jnl
D Lib Mag.
Reagan W. Moore, Chaitan Baru, Arcot Rajasekar, Bertram Ludäscher, Richard Marciano, Michael Wan, Wayne Schroeder, Amarnath Gupta
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"