Ilhami Colak

57 papers C 13Journal 33Unranked 11
YearRankTypeTitle / Venue / Authors
2025 J jnl
Int. J. Mach. Learn. Cybern.
Riadh Euldji, Mouloud Boumahdi, Mourad Bachene, Rafik Euldji, Ilhami Colak
2025 J jnl
Trans. Inst. Meas. Control
Habib Benbouhenni, Ilhami Colak, Nicu Bizon
2025 J jnl
IEEE Access
Mehrdad Ahmadi Kamarposhti, Hassan Shokouhandeh, Emad M. Ahmed, Zaki A. Zaki, Ilhami Colak, El Manaa Barhoumi, Kei Eguchi
2025 J jnl
IEEE Access
Benneth C. Oyinna, Kenneth Eloghene Okedu, Gauri Kalnoor, Leo Raju, V. B. Murali Krishna, Ilhami Colak
2025 J jnl
Int. J. Circuit Theory Appl.
Dhaval Joshi, Dipankar Deb, Ashutosh K. Giri, Ilhami Colak
2025 J jnl
EURASIP J. Wirel. Commun. Netw.
Jafar Ababneh, Hani Attar, Zakaria Che Muda, Ilhami Colak, Mohanad A. Deif, Samir Bendoukha, Ahmed A. A. Solyman
2025 J jnl
IEEE Access
Mehrdad Ahmadi Kamarposhti, Hassan Shokouhandeh, Yeonwoo Lee, Sun-Kyoung Kang, Ilhami Colak, El Manaa Barhoumi, Kei Eguchi
2025 J jnl
Sustain. Comput. Informatics Syst.
Abdesattar Mazouzi, Nadji Hadroug, Ahmed Hafaifa, Abdelhamid Iratni, Ilhami Colak
2025 J jnl
J. Ind. Inf. Integr.
Nadji Hadroug, Amel Sabrine Amari, Walaa Alayed, Abdelhamid Iratni, Ahmed Hafaifa, Ilhami Colak
2024 J jnl
Comput. Ind. Eng.
Larbi Brahimi, Nadji Hadroug, Abdelhamid Iratni, Ahmed Hafaifa, Ilhami Colak
2024 J jnl
Expert Syst. Appl.
Habib Benbouhenni, Nicu Bizon, Mohamed I. Mosaad, Ilhami Colak, Abdelkadir Belhadj Djilali, Hamza Gasmi
2024 J jnl
IEEE Access
Mourad Yessef, Habib Benbouhenni, Mohammed Taoussi, Ahmed Lagrioui, Ilhami Colak, Badre Bossoufi, Thamer A. H. Alghamdi
2024 J jnl
Soft Comput.
Oualid Aissa, Rabah Benkercha, Ziyad Bouchama, Badreddine Babes, Ilhami Colak
2024 J jnl
Neural Comput. Appl.
El-Sayed M. El-Kenawy, Nadjem Bailek, Kada Bouchouicha, Bilel Zerouali, Muhammed A. Hassan, Alban Kuriqi, Basharat Jamil, Ilhami Colak, Adel Khalil, Abdelhameed Ibrahim
2024 J jnl
Autom. Control. Comput. Sci.
Hakim Bagua, Belgacem Said Khaldi, Abdelhamid Iratni, Ahmed Hafaifa, Ilhami Colak
2024 J jnl
J. Circuits Syst. Comput.
Hamid Ghobadi Lamouki, Hassan Shokouhandeh, Mehrdad Ahmadi Kamarposhti, Fariba Asghari Matankolaei, Sanjeevikumar Padmanaban, Sun-Kyoung Kang, Ilhami Colak
2024 J jnl
IEEE Trans. Educ.
Korhan Kayisli, Ruhi Zafer Caglayan, Ilhami Colak
2024 J jnl
IEEE Access
Mourad Yessef, Habib Benbouhenni, Mohammed Taoussi, Ahmed Lagrioui, Ilhami Colak, Saleh Mobayen, Anton A. Zhilenkov, Badre Bossoufi
2023 J jnl
Eng. Appl. Artif. Intell.
Habib Benbouhenni, Ilhami Colak, Nicu Bizon
2023 conf
SSD
Nadji Hadroug, Tarek Idris Bisker, Abdellah Kouzou, Abdelhamid Iratni, Ahmed Hafaifa, Ilhami Colak
2023 J jnl
J. Electr. Comput. Eng.
M. V. Nageswara Rao, Mamidipaka Hema, Ramakrishna Raghutu, Ramakrishna S. S. Nuvvula, Polamarasetty P. Kumar, Ilhami Colak, Baseem Khan
2023 J jnl
IEEE Access
Habib Benbouhenni, Mohamed I. Mosaad, Ilhami Colak, Nicu Bizon, Hamza Gasmi, Mansour Aljohani, Emad Abdelkarim
2023 J jnl
Soft Comput.
Sidali Aissat, Abdelhamid Iratni, Ahmed Hafaifa, Mouloud Guemana, Obaid S. Alshammari, Ilhami Colak
2023 J jnl
Comput. Syst. Sci. Eng.
Hassan Shokouhandeh, Mehrdad Ahmadi Kamarposhti, William Holderbaum, Ilhami Colak, Phatiphat Thounthong
2022 J jnl
J. Circuits Syst. Comput.
Mehrdad Ahmadi Kamarposhti, Ilhami Colak, Celestine Iwendi, Shahab S. Band, Ebuka Ibeke
2022 J jnl
IEEE Access
Mehrdad Ahmadi Kamarposhti, Hassan Shokouhandeh, Meghdad Alipur, Ilhami Colak, Hassan Zare, Kei Eguchi
2021 conf
EVER
Ahmet Aksöz, Yassine Benomar, Thomas Geury, Mohamed El Baghdadi, Omar Hegazy, Salih Baris Ozturk, Ilhami Colak
2021 J jnl
IEEE Access
Mehrdad Ahmadi Kamarposhti, Hassan Shokouhandeh, Ilhami Colak, Shahab S. Band, Kei Eguchi
2020 conf
EVER
Giuseppe Schettino, Ilhami Colak, Antonino Oscar Di Tommaso, Rosario Miceli, Fabio Viola
2019 conf
ICSC
F. Mazouz, S. Belkacem, Saïd Drid, Larbi Chrifi-Alaoui, Ilhami Colak
2018 conf
ICSC
F. Mazouz, S. Belkacem, Ilhami Colak, Saïd Drid
2018 conf
ICIT
E. Emre Ozsoy, Sanjeevikumar Padmanaban, Fiaz Ahmad, Lucian Mihet-Popa, Ilhami Colak
2017 J jnl
Appl. Soft Comput.
Oualid Aissa, Samir Moulahoum, Ilhami Colak, Badreddine Babes, Nadir Kabache
2017 C conf
ICMLA
Rabah Benkercha, Samir Moulahoum, Ilhami Colak
2016 C conf
ICMLA
Hamdi Tolga Kahraman, Melike Ayaz, Ilhami Colak, Ramazan Bayindir
2016 C conf
ICMLA
Moustafa Sahnoune Chaouche, Hamza Houassine, Samir Moulahoum, Ilhami Colak
2016 C conf
IECON
Yudai Furukawa, Hidenori Maruta, Shingo Watanabe, Fujio Kurokawa, Nobumasa Matsui, Ilhami Colak
2016 J jnl
Int. J. Inf. Technol. Decis. Mak.
Hamdi Tolga Kahraman, Seref Sagiroglu, Ilhami Colak
2016 C conf
ICMLA
Mehmet Yesilbudak, Ilhami Colak, Ramazan Bayindir
2015 C conf
ICMLA
Ilhami Colak, Mehmet Yesilbudak, Naci Genç, Ramazan Bayindir
2014 J jnl
Comput. Appl. Eng. Educ.
Ilhami Colak, Erdal Irmak, Ersan Kabalci, Fatih Issi
2013 J jnl
Comput. Appl. Eng. Educ.
Hamdi Tolga Kahraman, Seref Sagiroglu, Ilhami Colak
2013 conf
ICMLA (2)
Ilhami Colak, Murat Sahin, Zafer Esen
2013 J jnl
Knowl. Based Syst.
Hamdi Tolga Kahraman, Seref Sagiroglu, Ilhami Colak
2012 conf
ICMLA (2)
Ramazan Bayindir, Ilhami Colak, Seref Sagiroglu, Hamdi Tolga Kahraman
2012 conf
ICMLA (2)
Ramazan Bayindir, Mehmet Yesilbudak, Ilhami Colak, Seref Sagiroglu
2012 conf
ICMLA (2)
Murat Sahin, H. Ibrahim Bulbul, Ilhami Colak
2011 J jnl
Comput. Appl. Eng. Educ.
Ilhami Colak, Sevki Demirbas, Seref Sagiroglu, Erdal Irmak
2011 J jnl
Comput. Appl. Eng. Educ.
Erdal Irmak, Ramazan Bayindir, Ilhami Colak, Mustafa Soysal
2011 conf
ICMLA (2)
Seref Sagiroglu, Hamdi Tolga Kahraman, Mehmet Yesilbudak, Ilhami Colak
2010 C conf
ICMLA
Ilhami Colak, Ramazan Bayindir, Orhan Kaplan, Ferhat Tas
2010 C conf
ICMLA
Ilhami Colak, Seref Sagiroglu, Mehmet Demirtas, Hamdi Tolga Kahraman
2009 C conf
ICMLA
Ilhami Colak, Mehmet Demirtas, Güngör Bal, Hamdi Tolga Kahraman
2009 C conf
ICMLA
Ilhami Colak, Ramazan Bayindir, Hamdi Tolga Kahraman, Mehmet Yesilbudak
2009 C conf
ICMLA
Ramazan Bayindir, Ilhami Colak, Ersan Kabalci, Erdal Irmak
2008 C conf
ICMLA
Ilhami Colak, Seref Sagiroglu, Hamdi Tolga Kahraman
2007 C conf
ICMLA
Hamdi Tolga Kahraman, Ilhami Colak, Seref Sagiroglu
redb/extractors/elf_extractor.py
← Index redb/extractors/elf_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class ELFExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious
        )
        # Store ELF object if provided, otherwise we'll create it per-operation for security
        self._provided_elf = elf
        self._elf_file_valid = None  # Cache validity check

    def _with_elf_file(self, operation):
        """Safely execute an operation with an ELF file using context manager.

        Args:
            operation: A callable that takes an ELFFile object and returns a result

        Returns:
            The result of the operation, or None if an error occurred
        """
        if self._provided_elf:
            try:
                return operation(self._provided_elf)
            except ELFError as e:
                if "String Table not found" in str(e):
                    self.log.warning(f"String table missing in ELF {self.hash.sha256}: {e}")
                    return None
                else:
                    self.log.error(f"ELF format error {self.hash.sha256} Full error: {e}")
                    return None
            except Exception as e:
                self.log.error(f"Error processing ELF file {self.hash.sha256} Full error: {e}")
                return None

        try:
            with open(self.filepath, 'rb') as f:
                elf = ELFFile(f)
                if not elf:
                    raise ELFError("Empty file?")
                return operation(elf)
        except ELFError as e:
            if "String Table not found" in str(e):
                self.log.warning(f"String table missing in ELF {self.hash.sha256}: {e}")
                return None
            else:
                self.log.error(f"ELF format error {self.hash.sha256} Full error: {e}")
                return None
        except Exception as e:
            self.log.error(f"Error reading ELF file {self.hash.sha256} Full error: {e}")
            return None

    def _is_elf_file(self):
        """Check if the file is a valid ELF binary."""
        if self._elf_file_valid is not None:
            return self._elf_file_valid

        def check_elf_validity(elf):
            # pyelftools ELFFile object existing means it's valid ELF
            # Just check that we can access the header
            header = elf.header
            return header is not None

        try:
            result = self._with_elf_file(check_elf_validity)
            self._elf_file_valid = bool(result)
            return self._elf_file_valid
        except Exception as e:
            self.log.error(f"Error checking ELF file: {e}")
            self._elf_file_valid = False
            return False

    def _is_64bit(self):
        """Check if the ELF binary is 64-bit."""
        def check_64bit(elf):
            return elf.header.get('e_ident', {}).get('EI_CLASS') == 'ELFCLASS64'

        try:
            result = self._with_elf_file(check_64bit)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking ELF bitness: {e}")
            return False

    def _is_stripped(self):
        """Check if the ELF binary is stripped (no symbol table)."""
        def check_stripped(elf):
            # Look for symbol table sections
            for section in elf.iter_sections():
                if section.name in ['.symtab', '.strtab']:
                    return False
            return True

        try:
            result = self._with_elf_file(check_stripped)
            return result if result is not None else True
        except Exception as e:
            self.log.error(f"Error checking if ELF is stripped: {e}")
            return True

    def _has_debug_info(self):
        """Check if the ELF binary contains debug information."""
        def check_debug_info(elf):
            # Look for debug sections
            debug_sections = ['.debug_info', '.debug_line', '.debug_str', '.debug_abbrev']
            for section in elf.iter_sections():
                if section.name in debug_sections:
                    return True
            return False

        try:
            result = self._with_elf_file(check_debug_info)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking debug info: {e}")
            return False

    def _get_architecture(self):
        """Get the architecture of the ELF binary."""
        def get_arch(elf):
            machine = elf.header.get('e_machine', 'EM_NONE')

            # Map common machine types to readable names
            arch_map = {
                'EM_386': 'x86',
                'EM_X86_64': 'x86_64',
                'EM_ARM': 'ARM',
                'EM_AARCH64': 'ARM64',
                'EM_MIPS': 'MIPS',
                'EM_PPC': 'PowerPC',
                'EM_PPC64': 'PowerPC64',
                'EM_SPARC': 'SPARC',
                'EM_RISCV': 'RISC-V'
            }

            return arch_map.get(machine, machine)

        try:
            result = self._with_elf_file(get_arch)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting architecture: {e}")
            return "unknown"

    def _get_endianness(self):
        """Get the endianness of the ELF binary."""
        def get_endian(elf):
            data_encoding = elf.header.get('e_ident', {}).get('EI_DATA')
            if data_encoding == 'ELFDATA2LSB':
                return "little"
            elif data_encoding == 'ELFDATA2MSB':
                return "big"
            return "unknown"

        try:
            result = self._with_elf_file(get_endian)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting endianness: {e}")
            return "unknown"

    def _get_file_type(self):
        """Get the file type of the ELF binary."""
        def get_file_type(elf):
            etype = elf.header.get('e_type', 'ET_NONE')

            # Map file types to readable names
            type_map = {
                'ET_NONE': 'none',
                'ET_REL': 'relocatable',
                'ET_EXEC': 'executable',
                'ET_DYN': 'shared_object',
                'ET_CORE': 'core_dump'
            }

            return type_map.get(etype, etype)

        try:
            result = self._with_elf_file(get_file_type)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting file type: {e}")
            return "unknown"

    def _is_pie(self):
        """Check if the ELF binary is position-independent executable."""
        def check_pie(elf):
            # PIE binaries are typically ET_DYN type
            etype = elf.header.get('e_type', 'ET_NONE')
            if etype == 'ET_DYN':
                # Check if it has an entry point (executable) vs library
                entry_point = elf.header.get('e_entry', 0)
                return entry_point > 0
            return False

        try:
            result = self._with_elf_file(check_pie)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking PIE: {e}")
            return False

    def _has_stack_protection(self):
        """Check if the binary has stack protection (canaries)."""
        def check_stack_protection(elf):
            # Look for stack protection symbols
            stack_symbols = ['__stack_chk_fail', '__stack_chk_guard']

            for section in elf.iter_sections():
                if hasattr(section, 'iter_symbols'):
                    for symbol in section.iter_symbols():
                        if symbol.name in stack_symbols:
                            return True
            return False

        try:
            result = self._with_elf_file(check_stack_protection)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking stack protection: {e}")
            return False

    def _has_nx_bit(self):
        """Check if the binary has NX bit (non-executable stack)."""
        def check_nx_bit(elf):
            # Look for GNU_STACK segment
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_GNU_STACK':
                    flags = segment.header.get('p_flags', 0)
                    # Check if execute flag is NOT set (NX enabled)
                    return not (flags & 0x1)  # PF_X = 0x1
            return False

        try:
            result = self._with_elf_file(check_nx_bit)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking NX bit: {e}")
            return False

    def _has_relro(self):
        """Check if the binary has RELRO (Relocation Read-Only)."""
        def check_relro(elf):
            # Look for GNU_RELRO segment
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_GNU_RELRO':
                    return True
            return False

        try:
            result = self._with_elf_file(check_relro)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking RELRO: {e}")
            return False

    def _get_build_id(self):
        """Extract build ID from notes section."""
        def get_build_id(elf):
            # Look for build ID in notes sections
            for section in elf.iter_sections():
                if section.name == '.note.gnu.build-id':
                    for note in section.iter_notes():
                        if note['n_type'] == 'NT_GNU_BUILD_ID':
                            # Convert bytes to hex string
                            build_id = note['n_desc']
                            if isinstance(build_id, bytes):
                                return build_id.hex()
                            return str(build_id)
            return None

        try:
            result = self._with_elf_file(get_build_id)
            return result
        except Exception as e:
            self.log.error(f"Error getting build ID: {e}")
            return None

    def _count_sections(self):
        """Count the number of sections in the ELF file."""
        def count_sections(elf):
            return elf.header.get('e_shnum', 0)

        try:
            result = self._with_elf_file(count_sections)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting sections: {e}")
            return 0

    def _count_segments(self):
        """Count the number of segments (program headers) in the ELF file."""
        def count_segments(elf):
            return elf.header.get('e_phnum', 0)

        try:
            result = self._with_elf_file(count_segments)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting segments: {e}")
            return 0

    def _count_symbols(self):
        """Count the total number of symbols in symbol tables."""
        def count_symbols(elf):
            symbol_count = 0
            for section in elf.iter_sections():
                if hasattr(section, 'iter_symbols'):
                    symbol_count += section.num_symbols()
            return symbol_count

        try:
            result = self._with_elf_file(count_symbols)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting symbols: {e}")
            return 0

    def _get_dependencies(self):
        """Get list of dynamic dependencies."""
        def get_dependencies(elf):
            dependencies = []
            dynamic_section = elf.get_section_by_name('.dynamic')
            if dynamic_section:
                for tag in dynamic_section.iter_tags():
                    if tag.entry.d_tag == 'DT_NEEDED':
                        dependencies.append(tag.needed)
            return dependencies

        try:
            result = self._with_elf_file(get_dependencies)
            return result if result is not None else []
        except Exception as e:
            self.log.error(f"Error getting dependencies: {e}")
            return []