Haitham El-Hussieny

42 papers A 1B 3C 1Journal 22Unranked 15
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Yomna Mokhtar, Tarek Shohdy, Abdallah A. Hassan, Mostafa Eshra, Omar Elmenawy, Osama Khalil, Haitham El-Hussieny
2025 J jnl
Neural Comput. Appl.
Radwa Hashem, Haitham El-Hussieny, Shinjiro Umezu, Ahmed M. R. Fath El-Bab
2025 J jnl
CoRR
Haitham El-Hussieny
2024 C conf
CoDIT
Eric Vincent Galeta, Ayman A. Nada, Sabah M. Ahmed, Victor Parque, Haitham El-Hussieny
2024 J jnl
CoRR
Eric Vincent Galeta, Ayman A. Nada, Sabah M. Ahmed, Victor Parque, Haitham El-Hussieny
2024 J jnl
IEEE Access
Haitham El-Hussieny, Ibrahim A. Hameed, Tamer F. Megahed, Ahmed Fares
2024 conf
MESA
Hend Abdelaziz, Abdullah Ahmed, Haitham El-Hussieny
2024 conf
MESA
Ibrahim Muhammed, Ayman A. Nada, Haitham El-Hussieny
2024 J jnl
IEEE Access
Haitham El-Hussieny, Ibrahim A. Hameed
2024 J jnl
CoRR
Haitham El-Hussieny, Ibrahim A. Hameed
2024 J jnl
CoRR
Riham M. Hilal, Haitham El-Hussieny, Ayman A. Nada
2023 conf
SICE
K. M. Asy, Ahmed Bayoumy Zaki, Haitham El-Hussieny, Hiroyuki Ishii, Mahmoud El-Samanty
2023 conf
SICE
Eric Vincent Galeta, Sabah M. Ahmed, Victor Parque, Haitham El-Hussieny
2023 conf
SICE
Sudhir Solomon Zhuwawu, Ahmed Bayoumy Zaky, Mahmoud El-Samanty, Victor Parque, Haitham El-Hussieny
2023 conf
SICE
Haitham El-Hussieny
2023 J jnl
IEEE Robotics Autom. Lett.
Ibrahim A. Seleem, Haitham El-Hussieny, Hiroyuki Ishii
2023 J jnl
J. Intell. Robotic Syst.
Ibrahim A. Seleem, Haitham El-Hussieny, Hiroyuki Ishii
2023 conf
AIM
Sudhir Solomon Zhuwawu, Ahmed Bayoumy Zaki, Mahmoud El-Samanty, Victor Parque, Haitham El-Hussieny
2023 J jnl
CoRR
Hend Abdelaziz, Ayman A. Nada, Hiroyuki Ishii, Haitham El-Hussieny
2022 conf
MESA
Abdullah Ahmed, Yasser F. O. Mohammad, Victor Parque, Haitham El-Hussieny, Sabah M. Ahmed
2022 conf
ARSO
Amos Alwala, Haitham El-Hussieny, Abdelfatah M. Mohamed, Kiyotaka Iwasaki, Samy F. M. Assal
2021 J jnl
J. Intell. Robotic Syst.
Hamed Majidi Fard Vatan, Samia Nefti-Meziani, Steve Davis, Zahra Saffari, Haitham El-Hussieny
2021 J jnl
IEEE Access
Mohamed Essam Shalabi, Ahmed M. R. Fath El-Bab, Haitham El-Hussieny, A. A. Abouelsoud
2020 J jnl
IEEE Access
Mohamed G. B. Atia, Haitham El-Hussieny, Omar Salah
2020 J jnl
IEEE Access
Ibrahim A. Seleem, Haitham El-Hussieny, Samy F. M. Assal, Hiroyuki Ishii
2020 J jnl
IEEE Access
Haitham El-Hussieny, Ibrahim A. Hameed, Jee-Hwan Ryu
2020 J jnl
IEEE Robotics Autom. Mag.
Margaret M. Coad, Laura H. Blumenschein, Sadie Cutler, Javier A. Reyna Zepeda, Nicholas D. Naclerio, Haitham El-Hussieny, Usman Mehmood, Jee-Hwan Ryu, Elliot W. Hawkes, Allison M. Okamura
2019 conf
ROBIO
Mohamed Essam Shalabi, Haitham El-Hussieny, A. A. Abouelsoud, Ahmed M. R. Fath El-Bab
2019 J jnl
IEEE Access
Ibrahim A. Seleem, Samy F. M. Assal, Hiroyuki Ishii, Haitham El-Hussieny
2019 conf
ICINCO (1)
Mohamed Essam Shalabi, Haitham El-Hussieny, A. A. Abouelsoud, Ahmed M. R. Fath El-Bab
2019 J jnl
Appl. Intell.
Haitham El-Hussieny, Jee-Hwan Ryu
2019 B conf
SMC
Ajani S. Oladayo, Samy F. M. Assal, Haitham El-Hussieny
2019 J jnl
CoRR
Margaret M. Coad, Laura H. Blumenschein, Sadie Cutler, Javier A. Reyna Zepeda, Nicholas D. Naclerio, Haitham El-Hussieny, Usman Mehmood, Jee-Hwan Ryu, Elliot W. Hawkes, Allison M. Okamura
2018 A conf
IROS
Haitham El-Hussieny, Usman Mehmood, Syed Zain Mehdi, Sang-Goo Jeong, Muhammad Usman, Elliot Wright Hawkes, Allison M. Okarnura, Jee-Hwan Ryu
2018 B conf
SMC
Ibrahim A. Seleem, Haitham El-Hussieny, Samy F. M. Assal
2018 B conf
RO-MAN
Ibrahim A. Seleem, Haitham El-Hussieny, Samy F. M. Assal
2018 conf
ROBIO
Mohamed G. B. Atia, Omar Salah, Haitham El-Hussieny
2018 J jnl
Intell. Serv. Robotics
Haitham El-Hussieny, Samy F. M. Assal, Jee-Hwan Ryu
2016 J jnl
Eng. Appl. Artif. Intell.
Haitham El-Hussieny, A. A. Abouelsoud, Samy F. M. Assal, Said M. Megahed
2015 conf
ICM
Haitham El-Hussieny, Samy F. M. Assal, A. A. Abouelsoud, Said M. Megahed
2015 conf
SoCPaR
Haitham El-Hussieny, Samy F. M. Assal, A. A. Abouelsoud, Said M. Megahed, Tsukasa Ogasawara
2013 conf
CICSyN
Haitham El-Hussieny, Samy F. M. Assal, Mohamed Abdellatif
docs/macho_extractors_README.md
← Index docs/macho_extractors_README.md markdown
# MachO Extractors for RedB

This document describes the MachO extractors implementation for the RedB binary analysis framework.

## Overview

The MachO extractors provide comprehensive analysis capabilities for Mach-O binaries (macOS, iOS, watchOS, tvOS executables) following the same pattern as the existing PE extractors. The implementation uses the `machofile` library located in the `docs/` folder.

## Architecture

### Main Components

1. **MachOExtractor** (`redb/extractors/macho_extractor.py`)
   - Abstract base class for all MachO extractors
   - Handles MachO file parsing and common functionality
   - Supports both single-architecture and Universal/FAT binaries

2. **Individual Extractors** (`redb/extractors/macho_extractors/`)
   - `macho_features.py` - Basic MachO header and metadata
   - `macho_segments.py` - Segment information and analysis
   - `macho_imports.py` - Imported functions and libraries
   - `macho_exports.py` - Exported symbols
   - `macho_dylibs.py` - Dynamic library dependencies
   - `macho_signature.py` - Code signing information

3. **Data Models** (`redb/models/dataclasses.py`)
   - MachO-specific dataclasses for structured data storage
   - Compatible with Elasticsearch and ClickHouse exporters

## Features

### Supported Binary Types
- Single-architecture Mach-O binaries (32-bit and 64-bit)
- Universal/FAT binaries with multiple architectures
- All major CPU architectures (x86, x86_64, ARM, ARM64)

### Extracted Information

#### MachO Features
- Header information (magic, CPU type, file type, flags)
- Architecture detection
- Entry point information
- UUID
- Version information
- Signing status
- Encryption status
- Counts (segments, dylibs, imports, exports)

#### Segments
- Segment names and properties
- Virtual addresses and sizes
- File offsets and sizes
- Protection flags
- Entropy calculation
- Segment hashes (MD5, SHA256)

#### Imports
- Imported function names
- Library dependencies
- Import counts and statistics

#### Exports
- Exported symbol names
- Export counts and statistics

#### Dynamic Libraries
- Dylib names and paths
- Version information
- Timestamps
- Load command types

#### Code Signing
- Signing status
- Certificate information
- Entitlements
- Code directory details

## Usage

### Basic Usage

```python
from redb.extractors.macho_extractors import MachOFeaturesExtractor

# Create extractor
extractor = MachOFeaturesExtractor(
    filepath="/path/to/macho/binary",
    log=logger
)

# Extract data
features = extractor.extract()

# Export to databases
extractor.export_data()
```

### Testing

Use the provided test script to verify functionality:

```bash
python test_macho_extractors.py /path/to/macho/binary
```

## Implementation Details

### Universal Binary Support

The extractors handle Universal/FAT binaries by:
1. Detecting FAT binary format
2. Extracting individual architectures
3. Providing unified interface for both single and multi-arch binaries
4. Supporting architecture-specific extraction

### Error Handling

- Graceful handling of malformed binaries
- Comprehensive logging for debugging
- Fallback mechanisms for missing data
- Exception handling for corrupted files

### Performance Considerations

- Lazy parsing of MachO structures
- Efficient memory usage for large binaries
- Cached property access for repeated queries
- Optimized data extraction patterns

## Integration

### Database Exporters

The extractors support both Elasticsearch and ClickHouse exporters:

- **Elasticsearch**: JSON document storage with full-text search
- **ClickHouse**: Columnar storage for analytical queries

### Schema Compatibility

All extractors follow the established schema patterns:
- Consistent field naming
- Proper data types
- Timestamp handling
- Hash field inclusion

## Future Enhancements

Potential areas for improvement:

1. **Additional Extractors**
   - MachO resources extraction
   - Symbol table analysis
   - Relocation information
   - Thread state analysis

2. **Enhanced Analysis**
   - Malware detection patterns
   - Behavioral analysis
   - Similarity hashing
   - YARA rule integration

3. **Performance Optimizations**
   - Parallel processing for multi-arch binaries
   - Streaming data processing
   - Memory-mapped file access

## Dependencies

- `machofile` library (included in `docs/`)
- Standard Python libraries (hashlib, datetime, etc.)
- RedB framework components

## Contributing

When adding new MachO extractors:

1. Follow the established pattern in existing extractors
2. Add appropriate dataclasses to `dataclasses.py`
3. Update the enum tags in `enum.py`
4. Include comprehensive error handling
5. Add tests for new functionality
6. Update this documentation

## Troubleshooting

### Common Issues

1. **Import Errors**: Ensure `machofile` library is accessible
2. **Memory Issues**: Large Universal binaries may require significant memory
3. **Corrupted Files**: Malformed MachO files may cause parsing errors
4. **Architecture Mismatch**: Some features may not be available for all architectures

### Debugging

Enable debug logging to see detailed extraction process:

```python
import logging
logging.basicConfig(level=logging.DEBUG)
```

## License

This implementation follows the same license as the main RedB project.