Ilka Philippow

48 papers A* 1A 3B 2C 3Misc 5Journal 9Unranked 24
YearRankTypeTitle / Venue / Authors
2013 B conf
REFSQ
Elke Bouillon, Patrick Mäder, Ilka Philippow
2013 B conf
REFSQ
Patrick Rempel, Patrick Mäder, Tobias Kuschke, Ilka Philippow
2013 conf
HCI (1)
Stefan Wendler, Ilka Philippow
2013 C conf
Software Engineering
Elke Bouillon, Matthias Riebisch, Ilka Philippow
2012 J jnl
Softwaretechnik-Trends
Elke Bouillon, Ilka Philippow
2011 conf
WCIT
Ghulam Rasool, Patrick Maeder, Ilka Philippow
2010 conf
Software Engineering Research and Practice
Ghulam Rasool, Patrick Maeder, Ilka Philippow
2010 J jnl
Adv. Eng. Softw.
Ghulam Rasool, Ilka Philippow, Patrick Mäder
2009 conf
ECMDA-FA
Patrick Mäder, Orlena Gotel, Ilka Philippow
2009 conf
TEFSE@ICSE
Patrick Mäder, Orlena Gotel, Ilka Philippow
2009 A conf
RE
Patrick Mäder, Orlena Gotel, Ilka Philippow
2009 conf
ICSE Companion
Patrick Mäder, Orlena Gotel, Ilka Philippow
2009 conf
SCSS
Ghulam Rasool, Ilka Philippow
2008 A* conf
ASE
Patrick Mäder, Orlena Gotel, Ilka Philippow
2008 conf
SCSS (1)
Ghulam Rasool, Ilka Philippow
2008 A conf
RE
Patrick Mäder, Orlena Gotel, Ilka Philippow
2008 A conf
RE
Patrick Mäder, Orlena Gotel, Tobias Kuschke, Ilka Philippow
2007 conf
SNPD (3)
Patrick Maeder, Ilka Philippow, Matthias Riebisch
2007 Misc conf
EuroPLoP
Klaus Meffert, Ilka Philippow
2007 conf
QoSA
Patrick Mäder, Ilka Philippow, Matthias Riebisch
2007 conf
ICSOFT (SE)
Klaus Meffert, Ilka Philippow
2006 J jnl
Softwaretechnik-Trends
Patrick Mäder, Matthias Riebisch, Ilka Philippow
2006 C conf
SoMeT
Klaus Meffert, Ilka Philippow
2006 conf
ECBS
Periklis Sochos, Matthias Riebisch, Ilka Philippow
2006 conf
SEDE
Patrick Maeder, Matthias Riebisch, Ilka Philippow
2005 J jnl
Softw. Syst. Model.
Ilka Philippow, Detlef Streitferdt, Matthias Riebisch, Sebastian Naumann
2005 conf
Perspectives Workshop
Manfred Broy, Matthias Jarke, Manfred Nagl, Hans Dieter Rombach, Armin B. Cremers, Jürgen Ebert, Sabine Glesner, Martin Glinz, Michael Goedicke, Gerhard Goos, Volker Gruhn, Wilhelm Hasselbring, Stefan Jähnichen, Stefan Kowalewski, Bernd J. Krämer, Stefan Leue, Claus Lewerentz, Peter Liggesmeyer, Christoph Lüth, Barbara Paech, Helmuth Arthur Partsch, Ilka Philippow, Lutz Prechelt, Andreas Rausch, Willem-Paul de Roever, Bernhard Rumpe, Gudula Rünger, Wilhelm Schäfer, Kurt Schneider, Andy Schürr, Walter F. Tichy, Bernhard Westfechtel, Wolf Zimmermann, Albert Zündorf
2005 C conf
Software Engineering
Periklis Sochos, Matthias Riebisch, Ilka Philippow
2005 conf
COMPSAC (2)
Detlef Streitferdt, Christian Heller, Ilka Philippow
2004 conf
IASTED Conf. on Software Engineering
Ilka Philippow, Ilian Pashov
2004 conf
Net.ObjectDays
Periklis Sochos, Ilka Philippow, Matthias Riebisch
2004 conf
CSMR
Ilian Pashov, Matthias Riebisch, Ilka Philippow
2003 J jnl
Softwaretechnik-Trends
Ilka Philippow, Ilian Pashov, Matthias Riebisch
2003 conf
ECBS
Detlef Streitferdt, Matthias Riebisch, Ilka Philippow
2002 Misc conf
FLAIRS
Rainer Knauf, Ilka Philippow, Avelino J. Gonzalez, Klaus P. Jantke, Dirk Salecker
2002 conf
NetObjectDays
Matthias Riebisch, Ilka Philippow, Marco Götze
2001 conf
ECBS
Ilka Philippow, Matthias Riebisch
2001 Misc conf
FLAIRS
Rainer Knauf, Ilka Philippow, Avelino J. Gonzalez, Klaus P. Jantke
2000 Misc conf
FLAIRS
Rainer Knauf, Ilka Philippow, Avelino J. Gonzalez, Klaus P. Jantke
2000 J jnl
J. Exp. Theor. Artif. Intell.
Rainer Knauf, Ilka Philippow, Avelino J. Gonzalez
2000 conf
TOOLS (34)
Martin Wolf, Evgeni Ivanov, Rainer Burkhardt, Ilka Philippow
1999 J jnl
Trans. SDPS
Evgeni Ivanov, Ilka Philippow, R. Preissel
1998 Misc conf
FLAIRS
Rainer Knauf, Klaus P. Jantke, Avelino J. Gonzalez, Ilka Philippow
1997 conf
UML Workshop
Martin Wolf, Rainer Burkhardt, Ilka Philippow
1996 J jnl
Künstliche Intell.
Ilka Philippow, Fred Roß, Ulf Döring
1996 J jnl
EMISA Forum
Ilka Philippow, Rainer Burkhardt, Martin Wolf
1995 conf
EMISA
Ilka Philippow, Rainer Burkhardt, Martin Wolf
1989
Ilka Philippow
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));