Iftikhar Ahmad

43 papers A* 1B 1C 3Journal 29Unranked 9
YearRankTypeTitle / Venue / Authors
2026 J jnl
Neurocomputing
Iftikhar Ahmad, Caicai Zheng, Cheng Hu, Juan Yu
2025 J jnl
J. Syst. Softw.
Muhammad Waseem, Aakash Ahmad, Peng Liang, Muhammad Azeem Akbar, Arif Ali Khan, Iftikhar Ahmad, Manu Setälä, Tommi Mikkonen
2025 J jnl
CoRR
Iftikhar Ahmad, Teemu Autto, Teerath Das, Joonas Hämäläinen, Pasi Jalonen, Viljami Järvinen, Harri Kallio, Tomi Kankainen, Taija Kolehmainen, Pertti Kontio, Pyry Kotilainen, Matti Kurittu, Tommi Mikkonen, Rahul Mohanani, Niko Mäkitalo, Jari Partanen, Roope Pajasmaa, Jarkko Pellikka, Manu Setälä, Jari Siukonen, Anssi Sorvisto, Maha Sroor, Teppo Suominen, Salla Timonen, Muhammad Waseem, Yuriy Yevstihnyeyev, Verneri Äberg, Leif Åstrand
2025 J jnl
Bull. Comput. Data Sci.
Iftikhar Ahmad, Wang Zu
2025 J jnl
Bull. Comput. Data Sci.
Iftikhar Ahmad
2025 J jnl
Neurocomputing
Iftikhar Ahmad, Wei Lu, Si-Bao Chen, Jin Tang, Bin Luo
2025 C conf
HSI
Iftikhar Ahmad, Shahzad Ali, Soon Ki Jung
2025 J jnl
npj Digit. Medicine
Prateek Munjal, Ahmed Al-Mahrooqi, Ronnie Rajan, Andrew Jeremijenko, Iftikhar Ahmad, Muhammad Imran Akhtar, Marco A. F. Pimentel, Shadab Khan
2024 J jnl
CoRR
Muhammad Waseem, Aakash Ahmad, Peng Liang, Muhammad Azeem Akbar, Arif Ali Khan, Iftikhar Ahmad, Manu Setälä, Tommi Mikkonen
2024 J jnl
Bull. Comput. Data Sci.
Iftikhar Ahmad
2024 conf
RACS
Iftikhar Ahmad, Shahzad Ali, Yu Rim Lee, Soo Young Park, Won Young Tak, Soon Ki Jung
2024 J jnl
Biomed. Signal Process. Control.
Ali Hamza, Muhammad Uneeb, Iftikhar Ahmad, Komal Saleem, Zunaib Ali
2023 J jnl
Comput. Networks
Attai Ibrahim Abubakar, Michael S. Mollel, Oluwakayode Onireti, Metin Öztürk, Iftikhar Ahmad, Syed Muhammad Asad, Yusuf A. Sambo, Ahmed Zoha, Sajjad Hussain, Muhammad Ali Imran
2023 J jnl
Frontiers Commun. Networks
Ahsan Raza Khan, Iftikhar Ahmad, Lina S. Mohjazi, Sajjad Hussain, Rao Naveed Bin Rais, Muhammad Ali Imran, Ahmed Zoha
2023 B conf
PIMRC
Iftikhar Ahmad, Ahsan Raza Khan, Rao Naveed Bin Rais, Ahmed Zoha, Muhammad Ali Imran, Sajjad Hussain
2022 J jnl
CoRR
Attai Ibrahim Abubakar, Iftikhar Ahmad, Kenechi G. Omeke, Metin Öztürk, Cihat Öztürk, Ali Makine Abdel-Salam, Michael S. Mollel, Qammer H. Abbasi, Sajjad Hussain, Muhammad Ali Imran
2022 J jnl
BMC Bioinform.
Yi Yue, Chen Ye, Pei-Yun Peng, Hui-Xin Zhai, Iftikhar Ahmad, Chuan Xia, Yun-Zhi Wu, You-Hua Zhang
2022 J jnl
IEEE Trans. Intell. Veh.
Iftikhar Ahmad, Xiaohua Ge, Qing-Long Han
2022 J jnl
Bull. Comput. Data Sci.
Waqas Nazeer, Iftikhar Ahmad
2022 J jnl
IEEE Access
Saeed Akbar, Iftikhar Ahmad, Rizwan Khan, Ivandro Ortet Lopes, Rahmat Ullah
2021 J jnl
Complex.
Zhen Ying, Iftikhar Ahmad, Saima Mateen, Asad Zia, Ambreen, Shah Nazir, Neelam Mukhtar
2021 J jnl
IEEE CAA J. Autom. Sinica
Iftikhar Ahmad, Xiaohua Ge, Qing-Long Han
2021 J jnl
Wirel. Commun. Mob. Comput.
Qing QingChang, Iftikhar Ahmad, Xiaoqun Liao, Shah Nazir
2021 conf
EUROCON
Hasan Qayyum Chohan, Iftikhar Ahmad
2020 C conf
IECON
Iftikhar Ahmad, Xiaohua Ge, Qing-Long Han, Zhenwei Cao
2020 conf
ICCCS
Iftikhar Ahmad, Houjun Sun, Yi Zhang, Abdul Samad
2020 conf
UCET
Abdul Samad, Weidong Hu, Muhammad Sajid, Waseem Shahzad, Iftikhar Ahmad, Muhammad Nouman
2020 conf
ICIC (2)
Yujia Gao, Yiqiong Chen, Zhiyu Ma, Tao Zeng, Iftikhar Ahmad, Youhua Zhang, Zhenyu Yue
2020 conf
ICCCS
Iftikhar Ahmad, Houjun Sun, Yi Zhang, Qasim Ali
2017 C conf
ICMLA
Iftikhar Ahmad, Bushra Mukhtar, Kadir Kutlu, Farooq Ahmad
2017 J jnl
J. Sensors
Fei Yu, Chin-Chen Chang, Jian Shu, Iftikhar Ahmad, Jun Zhang, José María de Fuentes
2016 J jnl
Sensors
Aamir Shahzad, Malrey Lee, Neal Naixue Xiong, Gisung Jeong, Young Keun Lee, Jae-Young Choi, Abdul Waheed Mahesar, Iftikhar Ahmad
2015 J jnl
J. Sensors
Fei Yu, Chin-Chen Chang, Jian Shu, Iftikhar Ahmad, Jun Zhang, José María de Fuentes
2014 conf
ANT/SEIT
Mohsin Iftikhar, Iftikhar Ahmad
2014 J jnl
CoRR
Iftikhar Ahmad, Uzma Ashraf, Sadia Anum, Hira Tahir
2014 J jnl
J. Appl. Math.
Iftikhar Ahmad, Nasir Ali, Aamar Abbasi, Wajid Aziz, Muzamil Hussain, Manzoor Ahmad, Moeen Taj, Qamar Zaman
2014 J jnl
J. Appl. Math.
Iftikhar Ahmad, Muhmmad Sajid, Wasim Awan, Muhammad Rafique, Wajid Aziz, Manzoor Ahmed, Aamar Abbasi, Moeen Taj
2013 J jnl
CoRR
Iftikhar Ahmad, Humaira Jabeen, Faisal Riaz
2013 A* conf
ICRA
Iftikhar Ahmad, Abdelaziz Benallegue, AbdelHafid El Hadri
2012 conf
ROBIO
Iftikhar Ahmad, AbdelHafid El Hadri, Abdelaziz Benallegue
2011 conf
ICUMT
Irshad Ahmed Sumra, Iftikhar Ahmad, Halabi Hasbullah, Jamalul-lail Ab Manan
2009 J jnl
Appl. Math. Comput.
Iftikhar Ahmad, M. Sajid, Tasawar Hayat
2008 J jnl
Comput. Math. Appl.
Iftikhar Ahmad, M. Sajid, Tasawar Hayat, Muhammad Ayub
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |