Ibrahim Omara

17 papers B 1C 1Journal 11Unranked 4
YearRankTypeTitle / Venue / Authors
2026 J jnl
Expert Syst. Appl.
Ibrahim Omara, Randa F. Soliman
2024 J jnl
Clust. Comput.
Oussama Aiadi, Belal Khaldi, Aicha Korichi, Mourad Chaa, Mohamed Ben Bezziane, Ibrahim Omara
2022 J jnl
Remote. Sens.
Souleyman Chaib, Dou El Kefel Mansouri, Ibrahim Omara, Ahmed Hagag, Sahraoui Dhelim, Djamel Amar Bensaber
2021 J jnl
IEEE Access
Ibrahim Omara, Ahmed Hagag, Souleyman Chaib, Guangzhi Ma, Fathi E. Abd El-Samie, Enmin Song
2021 J jnl
Mach. Vis. Appl.
Ibrahim Omara, Ahmed Hagag, Guangzhi Ma, Fathi E. Abd El-Samie, Enmin Song
2021 J jnl
J. Vis. Commun. Image Represent.
Ahmed Hagag, Ibrahim Omara, Souleyman Chaib, Guangzhi Ma, Fathi E. Abd El-Samie
2020 B conf
IJCB
Ibrahim Omara, Guangzhi Ma, Enmin Song
2019 J jnl
Autom. Control. Comput. Sci.
Adil Khan, Feng Jiang, Shaohui Liu, Ibrahim Omara
2018 conf
ICBBB
Ibrahim Omara, Xiaoming Li, Gang Xiao, Adil Khan, Wangmeng Zuo
2018 conf
ICBEA
Ibrahim Omara, Ahmed Hagag, Wangmeng Zuo
2018 J jnl
IET Biom.
Ibrahim Omara, Xiaohe Wu, Hongzhi Zhang, Yong Du, Wangmeng Zuo
2018 J jnl
CoRR
Ibrahim Omara, Hongzhi Zhang, Faqiang Wang, Wangmeng Zuo
2018 J jnl
Inf.
Ibrahim Omara, Hongzhi Zhang, Faqiang Wang, Ahmed Hagag, Xiaoming Li, Wangmeng Zuo
2018 conf
ICBEA
Doaa Khalaf, Ibrahim Omara, Ahmed Hagag, Shaohui Liu
2017 conf
ICBEA
Ibrahim Omara, Mahmoud Emam, Mohamed Hammad, Wangmeng Zuo
2017 C conf
ICIS
Ibrahim Omara, Xiaohe Wu, Hongzhi Zhang, Yong Du, Wangmeng Zuo
2016 J jnl
Expert Syst. Appl.
Ibrahim Omara, Feng Li, Hongzhi Zhang, Wangmeng Zuo
redb/extractors/apk_extractors/apk_native_libs.py
← Index redb/extractors/apk_extractors/apk_native_libs.py python
import fnmatch
import hashlib
import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKNativeLib

# Known packer/protector native library names
KNOWN_PACKER_LIBS = {
    # Jiagu (360/Qihoo)
    "libjiagu.so", "libjiagu_a64.so", "libjiagu_x86.so", "libjiagu_x64.so",
    # Bangcle/SecNeo
    "libsecexe.so", "libsecmain.so", "libSecShell.so",
    # Baidu
    "libbaiduprotect.so",
    # Tencent (Legu)
    "libtxAppProtect.so", "libBugly.so",
    # iJiami
    "libexec.so", "libexecmain.so",
    # Alibaba
    "libmobisec.so", "libaliprotect.so",
    # APKProtect
    "libAPKProtect.so",
    # Pangxie (Pangolin)
    "libdexjni.so",
    # DexProtector
    "libdexprotector.so",
    # AppSolid
    "libAppSolid.so",
    # Kiwisec
    "libkwscmm.so",
    # DingXiang
    "libx3g.so",
    # NQ Shield
    "libnqshield.so",
    # Generic / other
    "libprotectClass.so",
    "libDexHelper.so",
    "libdexloader.so",
    "libfdog.so",
}

# Glob-style patterns for packer libs (e.g. libshella-*.so)
KNOWN_PACKER_PATTERNS = [
    "libshella-*.so",
    "libshell-super.*.so",
]


def is_known_packer_lib(filename):
    """Check if a native library filename matches known packer signatures."""
    if filename in KNOWN_PACKER_LIBS:
        return True
    for pattern in KNOWN_PACKER_PATTERNS:
        if fnmatch.fnmatch(filename, pattern):
            return True
    return False


class APKNativeLibExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.native_libs = []
        self.abis = set()
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_NATIVE_LIBS.value

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        self.native_libs = []
        self.abis = set()

        zf = self._get_zip_file()
        if not zf:
            return None

        with zf:
            for info in zf.infolist():
                if not (info.filename.startswith("lib/") and info.filename.endswith(".so")):
                    continue
                parts = info.filename.split("/")
                if len(parts) < 3:
                    continue

                abi = parts[1]
                filename = parts[-1]
                self.abis.add(abi)

                try:
                    data = zf.read(info.filename)
                    lib_sha256 = hashlib.sha256(data).hexdigest()
                except Exception as e:
                    self.log.warning(f"Error reading native lib {info.filename}: {e}")
                    continue

                self.native_libs.append(APKNativeLib(
                    abi=abi,
                    filename=filename,
                    size=info.file_size,
                    sha256=lib_sha256,
                    is_known_packer=is_known_packer_lib(filename),
                ))

        if not self.native_libs:
            return None

        return {
            "native_lib_count": len(self.native_libs),
            "abis": sorted(self.abis),
            "native_libs": self.native_libs,
            "known_packer_libs": [
                lib for lib in self.native_libs if lib.is_known_packer
            ],
        }

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.native_libs:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for lib in self.native_libs:
                data.append([
                    self.sha256,
                    lib.abi,
                    lib.filename,
                    lib.size,
                    lib.sha256,
                    int(lib.is_known_packer),
                    current_time,
                ])

            column_names = [
                'sha256', 'lib_abi', 'lib_filename', 'lib_size',
                'lib_sha256', 'lib_is_known_packer', 'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)', 'LowCardinality(String)', 'String', 'UInt64',
                'FixedString(64)', 'UInt8', "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_native_libs"