H. M. W. Verbeek

60 papers A 6B 2C 1Misc 1Journal 26Unranked 24
YearRankTypeTitle / Venue / Authors
2022 J jnl
Int. J. Softw. Tools Technol. Transf.
H. M. W. Verbeek
2021 conf
ICPM Workshops
Moe Thandar Wynn, Julian Lebherz, Wil M. P. van der Aalst, Rafael Accorsi, Claudio Di Ciccio, Lakmali Jayarathna, H. M. W. Verbeek
2018 J jnl
Computing
Sebastiaan J. van Zelst, Boudewijn F. van Dongen, Wil M. P. van der Aalst, H. M. W. Verbeek
2018 B conf
EDOC
Prabhakar M. Dixit, H. M. W. Verbeek, Wil M. P. van der Aalst
2018 conf
BIS
Prabhakar M. Dixit, Joos C. A. M. Buijs, H. M. W. Verbeek, Wil M. P. van der Aalst
2018 conf
Business Process Management Workshops
Wai Lam Jonathan Lee, Jorge Munoz-Gama, H. M. W. Verbeek, Wil M. P. van der Aalst, Marcos Sepúlveda
2018 conf
FACS
Prabhakar M. Dixit, H. M. W. Verbeek, Wil M. P. van der Aalst
2018 A conf
ER
Prabhakar M. Dixit, H. M. W. Verbeek, Joos C. A. M. Buijs, Wil M. P. van der Aalst
2018 J jnl
CoRR
H. M. W. Verbeek, Renata Medeiros de Carvalho
2018 J jnl
Inf. Sci.
Wai Lam Jonathan Lee, H. M. W. Verbeek, Jorge Munoz-Gama, Wil M. P. van der Aalst, Marcos Sepúlveda
2018 J jnl
CoRR
Dennis M. M. Schunselaar, H. M. W. Verbeek
2017 J jnl
Trans. Petri Nets Other Model. Concurr.
H. M. W. Verbeek
2017 J jnl
CoRR
Sebastiaan J. van Zelst, Boudewijn F. van Dongen, Wil M. P. van der Aalst, H. M. W. Verbeek
2017 J jnl
Comput. J.
H. M. W. Verbeek, Wil M. P. van der Aalst, Jorge Munoz-Gama
2017 conf
BPM (Demos)
Wai Lam Jonathan Lee, H. M. W. Verbeek, Jorge Munoz-Gama, Wil M. P. van der Aalst, Marcos Sepúlveda
2016 conf
PNSE @ Petri Nets
H. M. W. Verbeek
2016 B conf
Petri Nets
H. M. W. Verbeek, Wil M. P. van der Aalst
2015 A conf
BPM
Dennis M. M. Schunselaar, H. M. W. Verbeek, Hajo A. Reijers, Wil M. P. van der Aalst
2014 conf
Business Process Management Workshops
Dennis M. M. Schunselaar, Henrik Leopold, H. M. W. Verbeek, Wil M. P. van der Aalst, Hajo A. Reijers
2014 conf
BPM (Demos)
Sebastiaan J. van Zelst, Andrea Burattin, Boudewijn F. van Dongen, H. M. W. Verbeek
2014 conf
Business Process Management Workshops
H. M. W. Verbeek, Wil M. P. van der Aalst
2014 conf
SIMPDA (Revised Selected Papers)
B. F. A. Hompes, H. M. W. Verbeek, Wil M. P. van der Aalst
2014 conf
Business Process Management Workshops
Jan Martijn E. M. van der Werf, H. M. W. Verbeek
2014 J jnl
Fundam. Informaticae
Wil M. P. van der Aalst, H. M. W. Verbeek
2014 conf
BPM (Demos)
Ronny Mans, Wil M. P. van der Aalst, H. M. W. Verbeek
2014 conf
Business Process Management Workshops
Dennis M. M. Schunselaar, H. M. W. Verbeek, Hajo A. Reijers, Wil M. P. van der Aalst
2013 conf
YAWL Symposium
Dennis M. M. Schunselaar, Tim van der Avoort, H. M. W. Verbeek, Wil M. P. van der Aalst
2012 A conf
BPM
Jan Martijn E. M. van der Werf, H. M. W. Verbeek, Wil M. P. van der Aalst
2011 conf
Business Process Management Workshops (2)
Jan Vogelaar, H. M. W. Verbeek, B. Luka, Wil M. P. van der Aalst
2011 J jnl
Formal Aspects Comput.
Wil M. P. van der Aalst, Kees M. van Hee, Arthur H. M. ter Hofstede, Natalia Sidorova, H. M. W. Verbeek, Marc Voorhoeve, Moe Thandar Wynn
2010 J jnl
Softw. Syst. Model.
Wil M. P. van der Aalst, Vladimir A. Rubin, H. M. W. Verbeek, Boudewijn F. van Dongen, Ekkart Kindler, Christian W. Günther
2010 J jnl
J. Comput. Syst. Sci.
H. M. W. Verbeek, Moe Thandar Wynn, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede
2010 conf
CAiSE Forum (Selected Papers)
H. M. W. Verbeek, Joos C. A. M. Buijs, Boudewijn F. van Dongen, Wil M. P. van der Aalst
2009 J jnl
Trans. Petri Nets Other Model. Concurr.
Kees M. van Hee, H. M. W. Verbeek, Christian Stahl, Natalia Sidorova
2009 J jnl
Bus. Process. Manag. J.
Moe Thandar Wynn, H. M. W. Verbeek, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, David Edmond
2009 J jnl
Inf. Softw. Technol.
Moe Thandar Wynn, H. M. W. Verbeek, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, David Edmond
2009 J jnl
Trans. Petri Nets Other Model. Concurr.
Wil M. P. van der Aalst, Kees M. van Hee, Arthur H. M. ter Hofstede, Natalia Sidorova, H. M. W. Verbeek, Marc Voorhoeve, Moe Thandar Wynn
2009 J jnl
Inf. Sci.
Moe Thandar Wynn, H. M. W. Verbeek, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede, David Edmond
2008 J jnl
Data Knowl. Eng.
Jan Mendling, H. M. W. Verbeek, Boudewijn F. van Dongen, Wil M. P. van der Aalst, Gustaf Neumann
2008 J jnl
IEEE Data Eng. Bull.
Wil M. P. van der Aalst, H. M. W. Verbeek
2008 J jnl
Int. J. Softw. Tools Technol. Transf.
Florian Gottschalk, Wil M. P. van der Aalst, Monique H. Jansen-Vullers, H. M. W. Verbeek
2007 J jnl
Inf. Syst.
Wil M. P. van der Aalst, Hajo A. Reijers, A. J. M. M. Weijters, Boudewijn F. van Dongen, Ana Karla Alves de Medeiros, Minseok Song, H. M. W. Verbeek
2007 conf
ICATPN
Wil M. P. van der Aalst, Boudewijn F. van Dongen, Christian W. Günther, R. S. Mans, Ana Karla Alves de Medeiros, Anne Rozinat, Vladimir A. Rubin, Minseok Song, H. M. W. Verbeek, A. J. M. M. Weijters
2007 J jnl
Comput. Ind.
Boudewijn F. van Dongen, Monique H. Jansen-Vullers, H. M. W. Verbeek, Wil M. P. van der Aalst
2007 J jnl
Comput. J.
H. M. W. Verbeek, Wil M. P. van der Aalst, Arthur H. M. ter Hofstede
2006 conf
The Role of Business Processes in Service Oriented Architectures
Wil M. P. van der Aalst, Marlon Dumas, Chun Ouyang, Anne Rozinat, H. M. W. Verbeek
2006 A conf
Business Process Management
Jan Mendling, Michael Moser, Gustaf Neumann, H. M. W. Verbeek, Boudewijn F. van Dongen, Wil M. P. van der Aalst
2006 conf
EMOI-INTEROP
H. M. W. Verbeek, Boudewijn F. van Dongen, Jan Mendling, Wil M. P. van der Aalst
2005 conf
EPEW/WS-FM
Wil M. P. van der Aalst, Marlon Dumas, Arthur H. M. ter Hofstede, Nick Russell, H. M. W. Verbeek, Petia Wohed
2005 conf
ICATPN
Boudewijn F. van Dongen, Ana Karla A. de Medeiros, H. M. W. Verbeek, A. J. M. M. Weijters, Wil M. P. van der Aalst
2005 A conf
CAiSE
Boudewijn F. van Dongen, Wil M. P. van der Aalst, H. M. W. Verbeek
2004 J jnl
Data Knowl. Eng.
Mathias Weske, Wil M. P. van der Aalst, H. M. W. Verbeek
2004 J jnl
Inf. Technol. Manag.
H. M. W. Verbeek, Wil M. P. van der Aalst, Akhil Kumar
2003 conf
ICATPN
H. M. W. Verbeek, Twan Basten
2003 Misc conf
SAC
Wil M. P. van der Aalst, Akhil Kumar, H. M. W. Verbeek
2002 A conf
CAiSE
Wil M. P. van der Aalst, Alexander Hirnschall, H. M. W. Verbeek
2002 conf
WES
H. M. W. Verbeek, Alexander Hirnschall, Wil M. P. van der Aalst
2001 J jnl
Comput. J.
H. M. W. Verbeek, Twan Basten, Wil M. P. van der Aalst
2001 C conf
CSCWD
Wil M. P. van der Aalst, H. M. W. Verbeek, Akhil Kumar
1999 conf
ICEIS
Wil M. P. van der Aalst, Twan Basten, H. M. W. Verbeek, Peter A. C. Verkoulen, Marc Voorhoeve
redb/extractors/elf_extractors/elf_imports.py
← Index redb/extractors/elf_extractors/elf_imports.py python
import inspect
from datetime import datetime, timezone
from typing import Any, List, Set

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFImport


class ELFImportExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_imports = None
        self.elastic_index = self.index_prefix + "-elf_imports"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _get_import_libraries(self, elf) -> List[str]:
        """Extract imported libraries from dynamic section."""
        libraries = []

        try:
            # Get the dynamic section
            dynamic_section = elf.get_section_by_name('.dynamic')
            if not dynamic_section:
                return libraries

            # Extract DT_NEEDED entries (required libraries)
            for tag in dynamic_section.iter_tags():
                if tag.entry.d_tag == 'DT_NEEDED':
                    libraries.append(tag.needed)

        except Exception as e:
            self.log.error(f"Error extracting import libraries: {e}")

        return libraries

    def _get_imported_functions_from_symbols(self, elf) -> Set[str]:
        """Extract imported functions from dynamic symbol table."""
        imported_functions = set()

        try:
            # Get the dynamic symbol table
            dynsym_section = elf.get_section_by_name('.dynsym')
            if not dynsym_section or not hasattr(dynsym_section, 'iter_symbols'):
                return imported_functions

            # Look for undefined symbols (imports)
            for symbol in dynsym_section.iter_symbols():
                # Check if symbol is undefined (imported)
                if (symbol.entry.get('st_shndx', 0) == 'SHN_UNDEF' and
                    symbol.name and
                    symbol.entry.get('st_info', {}).get('bind') in ['STB_GLOBAL', 'STB_WEAK']):
                    imported_functions.add(symbol.name)

        except Exception as e:
            self.log.error(f"Error extracting imported functions from symbols: {e}")

        return imported_functions

    def _get_imported_functions_from_relocations(self, elf) -> Set[str]:
        """Extract imported functions from relocation sections."""
        imported_functions = set()

        try:
            # Look through relocation sections
            for section in elf.iter_sections():
                if hasattr(section, 'iter_relocations'):
                    try:
                        for relocation in section.iter_relocations():
                            # Get symbol associated with relocation
                            if hasattr(relocation, 'symbol') and relocation.symbol:
                                symbol_name = relocation.symbol.name
                                if symbol_name:
                                    imported_functions.add(symbol_name)
                    except Exception as e:
                        self.log.debug(f"Could not process relocations in section {section.name}: {e}")

        except Exception as e:
            self.log.error(f"Error extracting imported functions from relocations: {e}")

        return imported_functions

    def _get_plt_functions(self, elf) -> Set[str]:
        """Extract functions from PLT (Procedure Linkage Table) sections."""
        plt_functions = set()

        try:
            # Look for PLT-related sections
            plt_sections = ['.plt', '.plt.got', '.plt.sec']

            for section_name in plt_sections:
                section = elf.get_section_by_name(section_name)
                if section:
                    # PLT functions are typically associated with relocations
                    # We'll get them from the relocation analysis
                    pass

        except Exception as e:
            self.log.error(f"Error extracting PLT functions: {e}")

        return plt_functions

    def tag(self):
        return Tag.ELF_IMPORTS.value if hasattr(Tag, 'ELF_IMPORTS') else "elf_imports"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_data(elf):
                # Extract import libraries
                import_libraries = self._get_import_libraries(elf)

                # Extract imported functions from multiple sources
                imported_functions = set()

                # From dynamic symbols
                symbol_imports = self._get_imported_functions_from_symbols(elf)
                imported_functions.update(symbol_imports)

                # From relocations
                relocation_imports = self._get_imported_functions_from_relocations(elf)
                imported_functions.update(relocation_imports)

                # From PLT
                plt_imports = self._get_plt_functions(elf)
                imported_functions.update(plt_imports)

                # Convert to sorted lists for consistent output
                import_libraries_list = sorted(list(set(import_libraries)))
                import_functions_list = sorted(list(imported_functions))

                # Return ELFImport dataclass
                return ELFImport(
                    elf_imports_total=len(import_functions_list),
                    elf_import_libraries=import_libraries_list,
                    elf_import_functions=import_functions_list,
                )

            if not self._is_elf_file():
                return None

            result = self._with_elf_file(extract_data)
            if result is None:
                return None

            self.elf_imports = result
            return self.elf_imports

        except Exception as e:
            self.log.error(f"Error extracting ELF imports {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_imports
        elif exporter_type == "ClickHouseExporter":
            try:
                if not self.elf_imports:
                    return None

                # Prepare data array
                data = [[
                    self.sha256,
                    self.md5,
                    self.sha1,
                    self.elf_imports.elf_imports_total,
                    self.elf_imports.elf_import_libraries,
                    self.elf_imports.elf_import_functions,
                    datetime.now(timezone.utc)
                ]]

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'elf_imports_total',
                    'elf_import_libraries',
                    'elf_import_functions',
                    'analysis_date'
                ]

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    'UInt32',
                    'Array(LowCardinality(String))',
                    'Array(LowCardinality(String))',
                    'DateTime64(3, \'UTC\')'
                ]

                if not data:
                    return None

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_imports"