Haifeng Hu

40 papers C 2Journal 31Unranked 7
YearRankTypeTitle / Venue / Authors
2026 J jnl
IEEE Trans. Commun.
Bin Liu, Haifeng Hu, Lin Chen, Rongfang Song
2026 J jnl
CoRR
Tianyou Li, Haifeng Hu, Dapeng Li
2025 J jnl
CoRR
Suofei Zhang, Xinxin Wang, Xiaofu Wu, Quan Zhou, Haifeng Hu
2024 J jnl
IEEE Trans. Commun.
Bin Liu, Haifeng Hu, Hongkui Shi, Hong Wang, Rongfang Song
2024 J jnl
IEEE Commun. Lett.
Bin Liu, Haifeng Hu, Laurent Decreusefond, Haitao Zhao
2024 J jnl
Sensors
Haifeng Hu, Yuyang Feng, Dapeng Li, Suofei Zhang, Haitao Zhao
2024 J jnl
Bioinform.
Yueming Yin, Haifeng Hu, Jitao Yang, Chun Ye, Wilson Wen Bin Goh, Adams Wai-Kin Kong, Jiansheng Wu
2024 J jnl
IEEE Trans. Veh. Technol.
Haifeng Hu, Zhefei Xie, Hongkui Shi, Bin Liu, Haitao Zhao, Guan Gui
2023 J jnl
CoRR
Yueming Yin, Haifeng Hu, Zhen Yang, Jitao Yang, Chun Ye, Jiansheng Wu, Wilson Wen Bin Goh
2023 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Xingxing Zhou, Ming Ling, Qingde Lin, Shidi Tang, Jiansheng Wu, Haifeng Hu
2023 J jnl
J. Chem. Inf. Model.
Ji Ding, Shidi Tang, Zheming Mei, Lingyue Wang, Qinqin Huang, Haifeng Hu, Ming Ling, Jiansheng Wu
2022 J jnl
Briefings Bioinform.
Yueming Yin, Haifeng Hu, Zhen Yang, Feihu Jiang, Yihe Huang, Jiansheng Wu
2022 J jnl
Frontiers Comput. Sci.
Jiansheng Wu, Chuangchuang Lan, Xuelin Ye, Jiale Deng, Wanqing Huang, Xueni Yang, Yanxiang Zhu, Haifeng Hu
2022 J jnl
Frontiers Comput. Sci.
Haifeng Hu, Yan Yang, Yueming Yin, Jiansheng Wu
2022 J jnl
Comput. Biol. Chem.
Jiansheng Wu, Chuangchuang Lan, Zheming Mei, Xiaohuyan Chen, Yanxiang Zhu, Haifeng Hu, Yemin Diao
2022 J jnl
Pattern Recognit.
Yueming Yin, Zhen Yang, Haifeng Hu, Xiaofu Wu
2021 J jnl
Neurocomputing
Yueming Yin, Zhen Yang, Haifeng Hu, Xiaofu Wu
2021 J jnl
Knowl. Based Syst.
Yueming Yin, Zhen Yang, Xiaofu Wu, Haifeng Hu
2021 J jnl
J. Chem. Inf. Model.
Yueming Yin, Haifeng Hu, Zhen Yang, Huajian Xu, Jiansheng Wu
2020 J jnl
J. Chem. Inf. Model.
Jiansheng Wu, Yi Sun, Wallace K. B. Chan, Yanxiang Zhu, Wenyong Zhu, Wanqing Huang, Haifeng Hu, Shancheng Yan, Tao Pang, Xiaoyan Ke, Fei Li
2020 J jnl
CoRR
Yueming Yin, Zhen Yang, Haifeng Hu, Xiaofu Wu
2020 J jnl
CoRR
Yueming Yin, Zhen Yang, Haifeng Hu, Xiaofu Wu
2020 J jnl
CoRR
Yueming Yin, Zhen Yang, Xiaofu Wu, Haifeng Hu
2019 J jnl
IEEE Access
Haifeng Hu, Zhikai Cui, Jiansheng Wu, Kun Wang
2019 J jnl
Bioinform.
Jiansheng Wu, Ben Liu, Wallace K. B. Chan, Weijian Wu, Tao Pang, Haifeng Hu, Shancheng Yan, Xiaoyan Ke, Yang Zhang
2019 J jnl
IEEE Trans. Image Process.
Haifeng Hu, Kun Wang, Chenggang Lv, Jiansheng Wu, Zhen Yang
2018 conf
ICACI
Haifeng Hu, Xiangfeng Xu, Jiansheng Wu
2018 J jnl
Bioinform.
Jiansheng Wu, Qiuming Zhang, Weijian Wu, Tao Pang, Haifeng Hu, Wallace K. B. Chan, Xiaoyan Ke, Yang Zhang
2017 J jnl
Int. J. Distributed Sens. Networks
Haifeng Hu, Jiefang He, Jiansheng Wu, Kun Wang, Wei Zhuang
2016 conf
WCSP
Haifeng Hu, Li Zhu, Jiansheng Wu
2015 conf
PAAP
Haifeng Hu, Jiefang He, Jiansheng Wu
2015 C conf
KSEM
Haifeng Hu, Yong Sun, Jiansheng Wu
2015 conf
ICACI
Haifeng Hu, Liang Zhang, Jiansheng Wu
2014 J jnl
Int. J. Distributed Sens. Networks
Wei Li, Zhen Yang, Haifeng Hu
2014 conf
ICSAI
Tao Zhang, Jiansheng Wu, Haifeng Hu
2013 C conf
APCC
Wei Li, Zhen Yang, Haifeng Hu
2013 J jnl
IEEE Trans. Veh. Technol.
Wei Li, Zhen Yang, Haifeng Hu
2012 J jnl
KSII Trans. Internet Inf. Syst.
Aiqing Zhang, Xinrong Ye, Haifeng Hu
2011 conf
WCSP
Haifeng Hu, Zhen Yang
2007 conf
SNPD (1)
Haifeng Hu, Zhen Yang
redb/extractors/detectiteasy.py
← Index redb/extractors/detectiteasy.py python
import inspect
from pprint import pprint
import subprocess
import json
from typing import Any
from datetime import datetime, timezone
import os
from dotenv import load_dotenv

from redb.extractors.enum import Tag
from redb.models.dataclasses import DIEinfo
from redb.extractors.extractor import Extractor

load_dotenv(override=True)

class DIEExtractor(Extractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        precomputed_hashes=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix, elastic_index, known_benign, known_malicious,
            precomputed_hashes=precomputed_hashes
        )
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.die_info = None
        self.die_info_dict = {}
        self.elastic_index = self.index_prefix + "-die"

    def _recursive_entry(self, die_dict, master_key):
        self.log.debug(inspect.currentframe().f_code.co_name)
        if master_key:
            self.die_info_dict[master_key] = {}
        else:
            self.die_info_dict = {}
        for value in die_dict:
            if "type" in value:
                type_key = value["type"].lower().replace(" ", "_")
                name = value.get("name", "")
                version = f"({value.get('version')})" if value.get("version") else ""
                info = f"[{value.get('info')}]" if value.get("info") else ""

                if master_key:
                    self.die_info_dict[master_key][type_key] = f"{name}"
                    self.die_info_dict[master_key][f'{type_key}(full)'] = f"{name}{version}{info}"
                else:
                    self.die_info_dict[type_key] = f"{name}"
                    self.die_info_dict[f'{type_key}(full)'] = f"{name}{version}{info}"

            elif "parentfilepart" in value:
                child_key = (
                    value["parentfilepart"].lower().replace(" ", "_")
                    + "."
                    + value["filetype"].lower().replace(" ", "_")
                )
                if master_key:
                    self._recursive_entry(value["values"], f"{master_key}.{child_key}")
                else:
                    self._recursive_entry(value["values"], f"{child_key}")

    def _extract_dieinfo(self):
        """
        Execute a command-line binary with arguments and parse its JSON output.

        :param command: The command or path to the binary to execute
        :param args: Additional arguments to pass to the command
        :return: Parsed JSON output as a Python object
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # Construct the full command
        # command = "nfdc" # UNCOMMENT FOR PROD
        # command = "/Users/p4c0/_tools/NFD.app/Contents/MacOS/nfdc" # COMMENT FOR TESTING ON MAC
        command = os.getenv("DIE_PATH")
        args = ["-durj", self.filepath]
        full_command = [command] + list(args)
        TIMEOUT = int(os.getenv("DIE_TIMEOUT", "180"))

        try:
            # Execute the command and capture its output
            result = subprocess.run(
                full_command,
                capture_output=True,
                text=True,
                check=True,
                timeout=TIMEOUT,
            )

            # Parse the JSON output
            nfdc_output = json.loads(result.stdout)

            # Extract the DIE information from the json output
            for die_entry in nfdc_output["detects"]:
                if die_entry["parentfilepart"] == "Header":
                    master_key = (
                        die_entry["parentfilepart"].lower().replace(" ", "_")
                        + "."
                        + die_entry["filetype"].lower().replace(" ", "_")
                    )
                    self._recursive_entry(die_entry["values"], None)

            # pprint(json.dumps(self.die_info_dict, indent=2)) #debug
            self.die_info = DIEinfo(result.stdout, self.die_info_dict)
            self.log.debug(f"NFDC-DIE JSON dump: todo")
        except subprocess.TimeoutExpired:
            self.log.error(f"The DIE command timed out after {TIMEOUT} seconds")
            return None
        except subprocess.CalledProcessError as e:
            self.log.error(f"Error executing DIE command: {e}")
            self.log.error(f"Command output (stderr): {e.stderr}")
            return None
        except json.JSONDecodeError as e:
            self.log.error(f"Error parsing DIE JSON output: {e}")
            self.log.error(f"Raw output: {result.stdout}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.die_info
        elif exporter_type == "ClickHouseExporter":
            # Convert DIE info to JSON string
            die_info_json = json.dumps(self.die_info_dict)
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                die_info_json,
                datetime.now(timezone.utc)
            ]]
            
            column_names = [
                'sha256', 'md5', 'sha1', 'die_info', 'analysis_date'
            ]
            
            column_type_names = [
                'String', 'String', 'String', 'JSON', 'DateTime64(3, \'UTC\')'
            ]
            
            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_die"

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            self._extract_dieinfo()
            
            # Check if there's a packer in the DIE results
            is_packed = False
            if self.die_info_dict:
                # Check if 'packer' exists in the DIE results
                is_packed = bool(self.die_info_dict.get('packer'))
            
            return self.die_info  # Return the extracted data instead of exporting directly
        except Exception as e:
            self.log.error(f"Error extracting DIE information: {e}")
            return None

    def tag(self):
        return Tag.DIEC.value