Ida Bagus Krishna Yoga Utama

27 papers Journal 12Unranked 15
YearRankTypeTitle / Venue / Authors
2026 conf
ICAIIC
Muhammad Fairuz Mummtaz, Jaejun Yoo, Ida Bagus Krishna Yoga Utama, Irzal Zaini, Yeong Min Jang
2026 J jnl
IEEE Internet Things J.
Herfandi Herfandi, Ones Sanjerico Sitanggang, Khairi Hindriyandhito Nurcahyo, Ida Bagus Krishna Yoga Utama, Md. Minhazur Rahman, Huy Nguyen, Yeong Min Jang
2026 conf
ICAIIC
Ida Bagus Krishna Yoga Utama, Su Mon Ko, Irzal Zaini, Muhammad Fairuz Mummtaz, Yeong Min Jang
2026 conf
ICAIIC
Su Mon Ko, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2025 conf
ICAIIC
Irzal Zaini, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2025 J jnl
IEEE Access
Herfandi Herfandi, Ones Sanjerico Sitanggang, Muhammad Rangga Aziz Nasution, Ida Bagus Krishna Yoga Utama, Md. Minhazur Rahman, Huy Nguyen, Su Mon Ko, Yeong Min Jang
2025 J jnl
IEEE Access
Muhammad Rangga Aziz Nasution, Jaejun Yoo, Miftahul Khoir Shilahul Umam, Ida Bagus Krishna Yoga Utama, Muhammad Fairuz Mummtaz, Muhammad Alfi Aldolio, Su Mon Ko, Yeong Min Jang
2025 conf
ICAIIC
Md Shahriar Nazim, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2025 J jnl
IEEE Access
Muhammad Fairuz Mummtaz, Jaejun Yoo, Muhammad Rangga Aziz Nasution, Ida Bagus Krishna Yoga Utama, Miftahul Khoir Shilahul Umam, Muhammad Alfi Aldolio, Su Mon Ko, Yeong Min Jang
2025 J jnl
IEEE Access
Miftahul Khoir Shilahul Umam, Jaejun Yoo, Ida Bagus Krishna Yoga Utama, Muhammad Rangga Aziz Nasution, Muhammad Fairuz Mummtaz, Muhammad Alfi Aldolio, Su Mon Ko, Yeong Min Jang
2024 J jnl
ICT Express
Radityo Fajar Pamungkas, Ida Bagus Krishna Yoga Utama, Khairi Hindriyandhito, Yeong Min Jang
2024 J jnl
IEEE Commun. Mag.
Huy Nguyen, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2024 J jnl
IEEE Access
Ida Bagus Krishna Yoga Utama, Ones Sanjerico Sitanggang, Muhammad Rangga Aziz Nasution, Md. Ibne Joha, Jaejun Yoo, Yeong Min Jang
2024 conf
ICAIIC
Khairi Hindriyandhito, Radityo Fajar Pamungkas, Ida Bagus Krishna Yoga Utama, ByungDeok Chung, Yeong Min Jang
2024 conf
ICAIIC
Ida Bagus Krishna Yoga Utama, ByungDeok Chung, Yeong Min Jang
2023 conf
ICAIIC
Duc Hoang Tran, Van Linh Nguyen, Ida Bagus Krishna Yoga Utama, Huy Nguyen, ByungDeok Chung, Yeong Min Jang
2023 J jnl
Sensors
Radityo Fajar Pamungkas, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2023 J jnl
IEEE Trans. Cogn. Commun. Netw.
Md. Habibur Rahman, Mostafa Zaman Chowdhury, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2023 conf
ICUFN
Ida Bagus Krishna Yoga Utama, Duc Hoang Tran, Muhammad Miftah Faridh, ByungDeok Chung, Yeong Min Jang
2023 conf
ICAIIC
Radityo Fajar Pamungkas, Ida Bagus Krishna Yoga Utama, Muhammad Miftah Faridh, Md. Morshed Alam, ByungDeok Chung, Yeong Min Jang
2023 J jnl
Sensors
Ida Bagus Krishna Yoga Utama, Radityo Fajar Pamungkas, Muhammad Miftah Faridh, Yeong Min Jang
2023 conf
ICAIIC
Ida Bagus Krishna Yoga Utama, Duc Hoang Tran, Radityo Fajar Pamungkas, ByungDeok Chung, Yeong Min Jang
2023 J jnl
Sensors
Syed Samiul Alam, Arbil Chakma, Md. Habibur Rahman, Raihan Bin Mofidul, Md. Morshed Alam, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2022 conf
ICUFN
Duc Hoang Tran, Van Linh Nguyen, Ida Bagus Krishna Yoga Utama, Yeong Min Jang
2022 conf
ICAIIC
Ida Bagus Krishna Yoga Utama, Md. Habibur Rahman, ByungDeok Chung, Yeong Min Jang
2022 conf
ICUFN
Ida Bagus Krishna Yoga Utama, Duc Hoang Tran, Yeong Min Jang
2021 conf
ICUFN
Aji Teguh Prihatno, Ida Bagus Krishna Yoga Utama, Jun Yong Kim, Yeong Min Jang
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"