Igor Yanovsky

35 papers A* 2C 13Journal 14Unranked 6
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Trans. Geosci. Remote. Sens.
Alex B. Akins, Alan B. Tanner, Andreas Colliander, Nicole-Jeanne Schlegel, Kenza Boudad, Igor Yanovsky, Shannon T. Brown, Sidharth Misra
2024 C conf
IGARSS
Alex Akins, Alan B. Tanner, Andreas Colliander, Nicole Schlegel, Igor Yanovsky, Kenza Boudad, Sidharth Misra, Shannon T. Brown
2023 C conf
IGARSS
Igor Yanovsky, Derek J. Posselt, Longtao Wu, Svetla M. Hristova-Veleva, Hai Nguyen, Bjorn Lambrigtsen, Xubin Zeng
2023 C conf
IGARSS
Alex Akins, Alan B. Tanner, Nicole-Jeanne Schlegel, Andreas Colliander, Igor Yanovsky, Sidharth Misra, Shannon T. Brown
2023 C conf
IGARSS
Joel Barnett, Andrea L. Bertozzi, Luminita A. Vese, Igor Yanovsky
2023 C conf
IGARSS
Igor Yanovsky, Alan B. Tanner, Alex Akins
2022 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Bjorn Lambrigtsen, Pekka Kangaslahti, Oliver Montes, Noppasin Niamsuwan, Derek J. Posselt, Jacola A. Roman, Mathias Schreier, Alan B. Tanner, Longtao Wu, Igor Yanovsky
2021 C conf
IGARSS
Igor Yanovsky, Thomas S. Pagano, Evan M. Manning, Steven E. Broberg, Hartmut H. Aumann, Luminita A. Vese
2021 C conf
IGARSS
Igor Yanovsky, Jing Qin
2020 C conf
IGARSS
Igor Yanovsky, Benjamin Holt, François Ayoub
2018 C conf
IGARSS
Charles Z. Marshak, Igor Yanovsky, Luminita A. Vese
2018 C conf
IGARSS
Jing Qin, Igor Yanovsky
2018 J jnl
Remote. Sens.
Igor Yanovsky, Konstantin Dragomiretskiy
2017 C conf
IGARSS
Konstantin Dragomiretskiy, Igor Yanovsky
2017 J jnl
Remote. Sens.
Igor Yanovsky, Ali Behrangi, Yixin Wen, Mathias Schreier, Van Dang, Bjorn Lambrigtsen
2017 C conf
IGARSS
Igor Yanovsky, Ali Behrangi, Mathias Schreier, Van Dang, Berry Wen, Bjorn Lambrigtsen
2015 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Igor Yanovsky, Bjorn Lambrigtsen, Alan B. Tanner, Luminita A. Vese
2015 J jnl
IEEE Trans. Geosci. Remote. Sens.
Igor Yanovsky, Anthony B. Davis
2014 C conf
IGARSS
Igor Yanovsky, Anthony B. Davis, Veljko M. Jovanovic
2013 J jnl
NeuroImage
Boris Gutman, Xue Hua, Priya Rajagopalan, Yi-Yu Chou, Yalin Wang, Igor Yanovsky, Arthur W. Toga, Clifford R. Jack Jr., Michael W. Weiner, Paul M. Thompson
2012 J jnl
Comput. Methods Programs Biomed.
Daren Lee, Ivo D. Dinov, Bin Dong, Boris Gutman, Igor Yanovsky, Arthur W. Toga
2012 conf
ISVC (1)
Jian Ye, Igor Yanovsky, Bin Dong, Rima Gandlin, Achi Brandt, Stanley J. Osher
2011 J jnl
NeuroImage
Xue Hua, Boris Gutman, Christina P. Boyle, Priya Rajagopalan, Alex D. Leow, Igor Yanovsky, Anand R. Kumar, Arthur W. Toga, Clifford R. Jack Jr., Norbert Schuff, Gene E. Alexander, Kewei Chen, Eric Reiman, Michael W. Weiner, Paul M. Thompson
2010 J jnl
NeuroImage
Xue Hua, Suh Lee, Derrek P. Hibar, Igor Yanovsky, Alex D. Leow, Arthur W. Toga, Clifford R. Jack Jr., Matt A. Bernstein, Eric Reiman, Danielle J. Harvey, John Kornak, Norbert Schuff, Gene E. Alexander, Michael W. Weiner, Paul M. Thompson
2009 J jnl
NeuroImage
Alex D. Leow, Igor Yanovsky, Neelroop Parikshak, Xue Hua, Suh Lee, Arthur W. Toga, Clifford R. Jack Jr., Matt A. Bernstein, Paula J. Britson, Jeffrey L. Gunter, Chadwick P. Ward, Bret J. Borowski, Leslie M. Shaw, John Q. Trojanowski, Adam Fleisher, Danielle J. Harvey, John Kornak, Norbert Schuff, Gene E. Alexander, Michael W. Weiner, Paul M. Thompson, Alzheimer's Disease Neuroimaging Initiative
2009 J jnl
Medical Image Anal.
Igor Yanovsky, Alex D. Leow, Suh Lee, Stanley J. Osher, Paul M. Thompson
2009 J jnl
NeuroImage
Xue Hua, Suh Lee, Igor Yanovsky, Alex D. Leow, Yi-Yu Chou, April J. Ho, Boris Gutman, Arthur W. Toga, Clifford R. Jack Jr., Matt A. Bernstein, Eric Reiman, Danielle J. Harvey, John Kornak, Norbert Schuff, Gene E. Alexander, Michael W. Weiner, Paul M. Thompson
2008 conf
CVPR Workshops
Igor Yanovsky, Paul M. Thompson, Stanley J. Osher, Alex D. Leow
2008 conf
Computational Imaging
Igor Yanovsky, Paul M. Thompson, Stanley J. Osher, Alex D. Leow
2008 conf
ISBI
Igor Yanovsky, Paul M. Thompson, Stanley J. Osher, Xue Hua, David W. Shattuck, Arthur W. Toga, Alex D. Leow
2007 conf
VISAPP (1)
Igor Yanovsky, Stanley J. Osher, Paul M. Thompson, Alex D. Leow
2007 A* conf
CVPR
Igor Yanovsky, Paul M. Thompson, Stanley J. Osher, Luminita A. Vese, Alex D. Leow
2007 conf
ISBI
Igor Yanovsky, Ming-Chang Chiang, Paul M. Thompson, Andrea D. Klunder, James T. Becker, Simon W. Davis, Arthur W. Toga, Alex D. Leow
2007 J jnl
IEEE Trans. Medical Imaging
Alex D. Leow, Igor Yanovsky, Ming-Chang Chiang, Agatha D. Lee, Andrea D. Klunder, Allen Lu, James T. Becker, Simon W. Davis, Arthur W. Toga, Paul M. Thompson
2007 A* conf
CVPR
Igor Yanovsky, Paul M. Thompson, Stanley J. Osher, Alex D. Leow
redb/extractors/js_extractors/js_deobfuscation.py
← Index redb/extractors/js_extractors/js_deobfuscation.py python
import hashlib
import inspect
import re
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor
from redb.extractors.js_extractors.js_patterns import PATTERNS

# String literals of 4+ characters; only used by the deobfuscation diff to count
# strings revealed after deobfuscation. Compiled once at module load.
_STRING_LITERAL_4PLUS_RE = re.compile(r"[\"\']([^\"\']{4,})[\"\']")


class JSDeobfuscationExtractor(JSExtractor):
    """Compute pre/post-deobfuscation metrics for a JS sample.

    The actual deobfuscation pass (external tool with jsbeautifier fallback)
    lives on `JSContext.deobfuscated` and is cached per sample, so any other
    extractor that needs the deobfuscated text reads the same value without
    re-running the subprocess. Configure the external tool via env vars:
        JS_DEOBFUSCATOR_PATH    Path or name (default: webcrack)
        JS_DEOBFUSCATE_TIMEOUT  Seconds (default: 60)
    """

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.deobfuscation_result = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_DEOBFUSCATION.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, deobfuscator_used = self._context.deobfuscated
        if deobfuscated is None:
            return None

        original_size = len(src)
        original_entropy = self._context.text_entropy
        deobfuscated_size = len(deobfuscated)
        deobfuscated_entropy = self._calculate_text_entropy(deobfuscated)
        size_change_ratio = round(deobfuscated_size / original_size, 4) if original_size else 0.0

        # Strings revealed by deobfuscation: matched literals are extracted from
        # both versions and the set difference is the count of "new" strings.
        original_strings = set(_STRING_LITERAL_4PLUS_RE.findall(src))
        deobfuscated_strings = set(_STRING_LITERAL_4PLUS_RE.findall(deobfuscated))
        new_strings = deobfuscated_strings - original_strings

        # Suspicious APIs revealed by deobfuscation. Both sides of the diff
        # come from JSContext caches: the raw scan is computed once for the
        # whole pipeline; the deobfuscated scan is computed once and reused
        # by JSSuspiciousAPIsExtractor's revealed_by_deobf rows.
        original_apis = {n for n in self._context.scan if n in PATTERNS}
        deobfuscated_apis = set(self._context.scan_deobfuscated)
        new_apis = deobfuscated_apis - original_apis

        deobfuscated_sha256 = hashlib.sha256(deobfuscated.encode('utf-8')).hexdigest()

        self.deobfuscation_result = {
            'deobfuscator_used': deobfuscator_used,
            'deobfuscation_successful': True,
            'original_size': original_size,
            'deobfuscated_size': deobfuscated_size,
            'size_change_ratio': size_change_ratio,
            'original_entropy': original_entropy,
            'deobfuscated_entropy': deobfuscated_entropy,
            'new_strings_found': len(new_strings),
            'new_apis_found': len(new_apis),
            'deobfuscated_sha256': deobfuscated_sha256,
        }
        return self.deobfuscation_result

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.deobfuscation_result:
                return None

            r = self.deobfuscation_result
            current_time = datetime.now(timezone.utc)
            data = [[
                self.sha256,
                r['deobfuscator_used'],
                int(r['deobfuscation_successful']),
                r['original_size'],
                r['deobfuscated_size'],
                r['size_change_ratio'],
                r['original_entropy'],
                r['deobfuscated_entropy'],
                r['new_strings_found'],
                r['new_apis_found'],
                r['deobfuscated_sha256'],
                current_time,
            ]]

            column_names = [
                "sha256", "deobfuscator_used", "deobfuscation_successful",
                "original_size", "deobfuscated_size", "size_change_ratio",
                "original_entropy", "deobfuscated_entropy",
                "new_strings_found", "new_apis_found",
                "deobfuscated_sha256", "analysis_date",
            ]

            column_type_names = [
                "FixedString(64)", "LowCardinality(String)", "UInt8",
                "UInt64", "UInt64", "Float64",
                "Float64", "Float64",
                "UInt32", "UInt32",
                "FixedString(64)", "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_js_deobfuscation"