Hai Huang

31 papers A* 2A 6B 3C 2Misc 2Journal 4Unranked 11
YearRankTypeTitle / Venue / Authors
2023 Misc conf
COMSNETS
Dushyant Behl, Hai Huang, Palanivel A. Kodeswaran, Sayandeep Sen
2021 J jnl
IEEE Trans. Parallel Distributed Syst.
Rupesh Raj Karn, Prabhakar Kudva, Hai Huang, Sahil Suneja, Ibrahim M. Elfadel
2021 conf
SoCC
Mert Toslali, Srinivasan Parthasarathy, Fábio Oliveira, Hai Huang, Ayse K. Coskun
2021 J jnl
IEEE Trans. Cloud Comput.
Jidong Xiao, Lei Lu, Hai Huang, Haining Wang
2020 J jnl
IEEE Trans. Parallel Distributed Syst.
Ali Anwar, Yue Cheng, Hai Huang, Jingoo Han, Hyogi Sim, Dongyoon Lee, Fred Douglis, Ali Raza Butt
2019 J jnl
Future Gener. Comput. Syst.
Hong Zhang, Hai Huang, Liqiang Wang
2018 conf
DASC/PiCom/DataCom/CyberSciTech
Hong Zhang, Zixia Liu, Hai Huang, Liqiang Wang
2018 A conf
SC
Ali Anwar, Yue Cheng, Hai Huang, Jingoo Han, Hyogi Sim, Dongyoon Lee, Fred Douglis, Ali Raza Butt
2017 A conf
IPDPS
Hong Zhang, Hai Huang, Liqiang Wang
2016 conf
HotStorage
Ali Anwar, Yue Cheng, Hai Huang, Ali Raza Butt
2016 conf
USENIX ATC
Jidong Xiao, Lei Lu, Hai Huang, Haining Wang
2015 C conf
SecureComm
Jidong Xiao, Hai Huang, Haining Wang
2015 conf
LISA
Jidong Xiao, Lei Lu, Hai Huang, Haining Wang
2015 C conf
SecureComm
Jidong Xiao, Hai Huang, Haining Wang
2014 B conf
ICPP
Hong Zhang, Liqiang Wang, Hai Huang
2014 B conf
CNSM
Duy Le, Jidong Xiao, Hai Huang, Haining Wang
2014 B conf
ICNP
Nan Zheng, Kun Bai, Hai Huang, Haining Wang
2013 A conf
DSN
Jidong Xiao, Zhang Xu, Hai Huang, Haining Wang
2012 A* conf
CCS
Jidong Xiao, Zhang Xu, Hai Huang, Haining Wang
2012 A conf
FAST
Duy Le, Hai Huang, Haining Wang
2010 A conf
EuroSys
Xiaoning Ding, Hai Huang, Yaoping Ruan, Anees Shaikh, Brian Peterson, Xiaodong Zhang
2009 conf
Integrated Network Management
Hai Huang, Yaoping Ruan, Anees Shaikh, Ramani Routray, Chung-Hao Tan, Sandeep Gopisetty
2008 conf
LISA
Xiaoning Ding, Hai Huang, Yaoping Ruan, Anees Shaikh, Xiaodong Zhang
2007 conf
LISA
Hai Huang, Raymond B. Jennings III, Yaoping Ruan, Ramendra K. Sahoo, Sambit Sahu, Anees Shaikh
2007 Misc conf
MSST
Hai Huang, Kang G. Shin
2006
Hai Huang
2005 A* conf
SOSP
Hai Huang, Wanda Hung, Kang G. Shin
2005 A conf
ISLPED
Hai Huang, Kang G. Shin, Charles Lefurgy, Tom W. Keller
2004 conf
PACS
Hai Huang, Kang G. Shin, Charles Lefurgy, Karthick Rajamani, Tom W. Keller, Eric Van Hensbergen, Freeman L. Rawson III
2003 conf
USENIX ATC, General Track
Hai Huang, Padmanabhan Pillai, Kang G. Shin
2002 conf
USENIX ATC, General Track
Hai Huang, Padmanabhan Pillai, Kang G. Shin
redb/extractors/pe_extractors/pe_sections.py
← Index redb/extractors/pe_extractors/pe_sections.py python
import base64
import hashlib
import inspect
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PESection
from datetime import datetime, timezone
from typing import Any


class PESectionExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_sections"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_SECTION.value

    def _extract_sections(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        sections = []
        for section in self.pe.sections:
            try:
                name = self.process_binary_string(section.Name)
            except Exception as e:
                name = "UnableToDecode"
                self.log.warning(
                    f'Unable to store section Name "{section.Name}" for {self.hash.sha256}'
                    f" exception {e}"
                )
            sec_sha256 = section.get_hash_sha256()
            sec_md5 = section.get_hash_md5()
            # sec_entropy = "%.2f" % section.get_entropy()
            sec_entropy = section.get_entropy()
            pe_section = PESection(
                _id=hashlib.sha256(
                    name.encode()
                ).hexdigest(),  # usecase 8e035beb02a411f8a9e92d4cf184ad34f52bbd0a81a50c222cdd4706e4e45104, all section have same sha256
                section_name=name,
                section_name_b64=base64.b64encode(
                    section.Name.rstrip(b'\x00')
                ).decode(),  # base64.b64decode(b64) to decode
                section_v_addr=section.VirtualAddress,
                section_v_addr_hex=hex(section.VirtualAddress),
                section_v_size=section.Misc_VirtualSize,
                section_size=section.SizeOfRawData,
                section_pointer_to_raw_data=hex(section.PointerToRawData),
                section_md5=sec_md5,
                section_sha256=sec_sha256,
                section_entropy=sec_entropy,
            )
            sections.append(pe_section)
        return sections

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            sections = self._extract_sections()
            # self.export_to_elastic(sections)  # Let the exporters handle this
            return sections
        except Exception as e:
            self.log.error(f"Error extracting PE sections: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            sections = self.extract()
            if sections is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for section in sections:
                data.append([
                    self.sha256,                          # sha256
                    self.md5,                             # md5
                    self.sha1,                            # sha1
                    section.section_name,                 # section_name
                    section.section_name_b64,             # section_name_b64
                    section.section_entropy,              # section_entropy
                    section.section_sha256,               # section_sha256
                    section.section_md5,                  # section_md5
                    section.section_size,                 # section_size
                    section.section_v_addr,               # section_v_addr
                    section.section_v_size,               # section_v_size
                    int(section.section_pointer_to_raw_data, 16),  # section_pointer_to_raw_data - convert from hex
                    current_time                          # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'section_name', 'section_name_b64',
                'section_entropy', 'section_sha256', 'section_md5', 'section_size',
                'section_v_addr', 'section_v_size', 'section_pointer_to_raw_data',
                'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(String)', 'LowCardinality(String)',
                'Float64', 'FixedString(64)', 'FixedString(32)', 'UInt64',
                'UInt64', 'UInt64', 'UInt64',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_sections"