Hans Georg Schaathun

62 papers B 4C 12Journal 26Unranked 20
YearRankTypeTitle / Venue / Authors
2024 J jnl
CoRR
Miriam Kopperstad Wolff, Sam Royston, Anders Lyngvi Fougner, Hans Georg Schaathun, Martin Steinert, Rune Volden
2024 J jnl
Comput. Methods Programs Biomed.
Bismi Rasheed, Øystein Bjelland, Andreas Fagerhaug Dalen, Ute Schaarschmidt, Hans Georg Schaathun, Morten Dinhoff Pedersen, Martin Steinert, Robin T. Bye
2024 J jnl
IEEE Access
Miriam Kopperstad Wolff, Hans Georg Schaathun, Anders Lyngvi Fougner, Martin Steinert, Rune Volden
2024 C conf
ICDS
Rituka Jaiswal, Hans Georg Schaathun
2023 C conf
ECMS
Hans Georg Schaathun, Ben David Normann, Einar Leite Austnes, Simon Ingebrigtsen, Sondre Westbo Remoy, Simon Nedreberg Runde
2022 J jnl
IEEE Access
Øystein Bjelland, Bismi Rasheed, Hans Georg Schaathun, Morten Dinhoff Pedersen, Martin Steinert, Alf Inge Hellevik, Robin T. Bye
2019 conf
NIK
Hans Georg Schaathun
2018 conf
NIK
Hans Georg Schaathun, Adrian Rutle
2018 conf
NIK
Hans Georg Schaathun, Sebastian Gundersen
2017 conf
NIK
Hans Georg Schaathun, Que Tran, Mikael Tollefsen, Etienne Gernez
2017 J jnl
Int. J. Inf. Coding Theory
Hans Georg Schaathun, Minoru Kuribayashi
2016 C conf
ECMS
Robin T. Bye, Ottar L. Osen, Birger Skogeng Pedersen, Ibrahim A. Hameed, Hans Georg Schaathun
2016 C conf
ECMS
Ibrahim A. Hameed, Robin T. Bye, Ottar L. Osen, Birger Skogeng Pedersen, Hans Georg Schaathun
2015 conf
ICORES (Selected Papers)
Robin T. Bye, Hans Georg Schaathun
2015 conf
NIK
Welie Annett Schaathun, Hans Georg Schaathun
2015 C conf
ICORES
Robin T. Bye, Hans Georg Schaathun
2015 J jnl
J. Funct. Program.
Hans Georg Schaathun
2015 conf
NIK
Hans Georg Schaathun
2015 B conf
ICIP
Minoru Kuribayashi, Hans Georg Schaathun
2015 conf
NIK
Hans Georg Schaathun
2015 conf
EUSPN/ICTH
Adrian Rutle, Kent Inge Fagerland Simonsen, Hans Georg Schaathun, Ralf Kirchhoff
2014 C conf
ECMS
Robin T. Bye, Hans Georg Schaathun
2014 J jnl
IEEE Trans. Inf. Forensics Secur.
Hans Georg Schaathun
2014 conf
PAHI
Hans Georg Schaathun, Sven Inge Molnes, Helen Berg, Rigmor Einang Alnes
2014 conf
NIK
Hans Georg Schaathun
2013 conf
ROBIO
Filippo Sanfilippo, Lars I. Hatledal, Hans Georg Schaathun, Kristin Ytterstad Pettersen, Houxiang Zhang
2013 C conf
ECMS
Hans Georg Schaathun, Magne Aarset, Runar Ostnes, Robert Rylander
2011 J jnl
IEEE Trans. Inf. Forensics Secur.
Boris Skoric, Stefan Katzenbeisser, Hans Georg Schaathun, Mehmet Utku Celik
2010 conf
ICC
Johann A. Briffa, Hans Georg Schaathun, Stephan Wesemeyer
2009 conf
ICDP
Johann A. Briffa, Hans Georg Schaathun, Ainuddin Wahid Abdul Wahab
2009 C conf
IMACC
Hans Georg Schaathun
2009 J jnl
IACR Cryptol. ePrint Arch.
Boris Skoric, Stefan Katzenbeisser, Hans Georg Schaathun, Mehmet Utku Celik
2009 conf
WIFS
Boris Skoric, Stefan Katzenbeisser, Hans Georg Schaathun, Mehmet Utku Celik
2008 conf
MM&Sec
Hans Georg Schaathun
2008 J jnl
EURASIP J. Inf. Secur.
Hans Georg Schaathun
2008 J jnl
Multim. Syst.
Hans Georg Schaathun
2008 J jnl
IEEE Trans. Inf. Forensics Secur.
Hans Georg Schaathun
2008 C conf
IWDW
Ainuddin Wahid Abdul Wahab, Johann A. Briffa, Hans Georg Schaathun
2007 C conf
IWDW
Hans Georg Schaathun
2006 conf
AAECC
Hans Georg Schaathun, Gérard D. Cohen
2006 conf
ICICIC (3)
Hans Georg Schaathun
2006 J jnl
IEICE Trans. Fundam. Electron. Commun. Comput. Sci.
Hans Georg Schaathun, Marcel Fernandez
2006 J jnl
IEEE Trans. Inf. Forensics Secur.
Hans Georg Schaathun
2005 C conf
IMACC
Hans Georg Schaathun, Gérard D. Cohen
2005 B conf
ITW
Hans Georg Schaathun, Marcel Fernandez-Muñoz
2005 J jnl
IEEE Trans. Inf. Theory
Hans Georg Schaathun, Tor Helleseth
2004 J jnl
Des. Codes Cryptogr.
Hans Georg Schaathun
2004 J jnl
IEEE Trans. Inf. Theory
Hans Georg Schaathun
2004 B conf
ISIT
Hans Georg Schaathun
2004 J jnl
IEEE Trans. Inf. Theory
Tor Helleseth, Hans Georg Schaathun
2004 B conf
LATIN
Gérard D. Cohen, Hans Georg Schaathun
2004 J jnl
IEEE Trans. Inf. Theory
Gérard D. Cohen, Hans Georg Schaathun
2003 J jnl
Discret. Appl. Math.
Hans Georg Schaathun, Wolfgang Willems
2003 J jnl
Discret. Appl. Math.
Gérard D. Cohen, Sylvia B. Encheva, Simon Litsyn, Hans Georg Schaathun
2003 conf
AAECC
Hans Georg Schaathun
2003 J jnl
Discret. Appl. Math.
Gérard D. Cohen, Sylvia B. Encheva, Simon Litsyn, Hans Georg Schaathun
2003 C conf
IMACC
Hans Georg Schaathun, Tor Helleseth
2002 J jnl
IEEE Trans. Inf. Theory
Gérard D. Cohen, Sylvia B. Encheva, Hans Georg Schaathun
2001 conf
AAECC
Hans Georg Schaathun
2001 J jnl
Electron. Notes Discret. Math.
Conchita Martínez-Pérez, Hans Georg Schaathun, Wolfgang Willems
2001 J jnl
Discret. Math.
Hans Georg Schaathun
2000 J jnl
IEEE Trans. Inf. Theory
Hans Georg Schaathun
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));