Imad Mougharbel

32 papers A 3B 1C 11Journal 8Unranked 9
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Access
Amani Fawaz, Imad Mougharbel, Kamal Al-Haddad, Hadi Youssef Kanaan
2024 C conf
IECON
Amani Fawaz, Imad Mougharbel, Kamal Al-Haddad, Hadi Youssef Kanaan
2023 conf
ISGT EUROPE
Fouad Boutros, Moustapha Doumiati, Jean-Christophe Olivier, Imad Mougharbel, Hadi Youssef Kanaan
2022 A conf
MSWiM
Nabil Makarem, Wafaa Bou Diab, Imad Mougharbel, Naceur Malouch
2022 J jnl
Vis. Comput.
Abbass Ballit, Imad Mougharbel, Hassan Ghaziri, Tien-Tuan Dao
2022 J jnl
Comput. Networks
Nabil Makarem, Wafaa Bou Diab, Imad Mougharbel, Naceur Malouch
2022 C conf
IECON
Fouad Boutros, Moustapha Doumiati, Jean-Christophe Olivier, Imad Mougharbel, Hadi Youssef Kanaan
2021 conf
ISIE
Amani Fawaz, Imad Mougharbel, Hadi Youssef Kanaan
2021 C conf
IECON
Charles Ibrahim, Imad Mougharbel, Hadi Youssef Kanaan
2020 C conf
IECON
Charles Ibrahim, Imad Mougharbel, Hadi Youssef Kanaan, Nivine Abou Daher, Semaan Georges, Maarouf Saad
2020 J jnl
IEEE Access
Charles Ibrahim, Imad Mougharbel, Hadi Youssef Kanaan, Semaan Georges, Nivine Abou Daher, Maarouf Saad
2019 B conf
Networking
Nabil Makarem, Wafaa Bou Diab, Imad Mougharbel, Naceur Malouch
2018 C conf
IECON
Charles Ibrahim, Imad Mougharbel, Nivine Abou Daher, Hadi Youssef Kanaan, Maarouf Saad, Semaan Georges
2018 conf
ICIT
Catherine Nasr El-Khoury, Hadi Youssef Kanaan, Imad Mougharbel, Kamal Al-Haddad
2018 J jnl
IEEE Access
Claude Ziad El-Bayeh, Imad Mougharbel, Dalal Asber, Maarouf Saad, Ambrish Chandra, Serge Lefebvre
2017 conf
ICIT
Charles Ibrahim, Imad Mougharbel, Nivine Abou Daher, Hadi Youssef Kanaan, Maarouf Saad, Semaan Georges
2015 conf
ICIT
Catherine Nasr El-Khoury, Hadi Youssef Kanaan, Imad Mougharbel, Kamal Al-Haddad
2014 conf
ISIE
Catherine Nasr El-Khoury, Hadi Youssef Kanaan, Imad Mougharbel
2014 J jnl
Sensors
Hiba Haj Chhadé, Fahed Abdallah, Imad Mougharbel, Amadou Gning, Simon Julier, Lyudmila Mihaylova
2014 C conf
FUSION
Hiba Haj Chhadé, Fahed Abdallah, Imad Mougharbel, Amadou Gning, Lyudmila Mihaylova, Simon Julier
2014 J jnl
Math. Comput. Sci.
Hiba Haj Chhadé, Amadou Gning, Fahed Abdallah, Imad Mougharbel, Simon Julier
2013 C conf
IECON
Catherine Nasr El-Khoury, Hadi Youssef Kanaan, Imad Mougharbel, Kamal Al-Haddad
2012 conf
Med-Hoc-Net
Abdel Mehsen Ahmad, Mahmoud Doughan, Imad Mougharbel, Michel Marot
2012 conf
NDT (1)
Chadi Fouad Riman, Éric Monacelli, Imad Mougharbel, Ali El-Hajj
2012 C conf
IECON
Imad Mougharbel, Zeina Shehab, Semaan Georges
2011 J jnl
Int. J. Online Eng.
Chadi Fouad Riman, Ali El-Hajj, Imad Mougharbel
2011 conf
BMEI
Hode Sbeity, Rafic Younes, Suat Topçu, Imad Mougharbel
2011 C conf
ICOST
Marwa Hassan, Imad Mougharbel, Nada Meskawi, Jean-Yves Tigli, Michel Riveill
2010 C conf
MoMM
Abdel Mehsen Ahmad, Mahmoud Doughan, Vincent Gauthier, Imad Mougharbel, Michel Marot
2009 C conf
ICOST
Imad Mougharbel, Nada Miskawi, Adelle Abdallah
2006 A conf
IROS
Éric Monacelli, Chadi Fouad Riman, Roland Thieffry, Imad Mougharbel, Stephane Delaplace
2006 A conf
IROS
H. Peralta, Chadi Fouad Riman, Roland Thieffry, Éric Monacelli, Fathi Ben Ouezdou, Yasser Alayli, G. De Matteo, J. Bouteille, Isabelle Laffont, Imad Mougharbel, Ali El-Hajj
redb/extractors/decompiler/_archive/GhidraDecompilerScript-v2.java
← Index redb/extractors/decompiler/_archive/GhidraDecompilerScript-v2.java java
import ghidra.app.script.GhidraScript;
import ghidra.program.model.listing.*;
import ghidra.app.decompiler.*;
import ghidra.program.model.block.*;
import ghidra.program.model.symbol.*;
import ghidra.program.model.pcode.*;
import ghidra.program.model.address.*;
import org.json.JSONObject;
import org.json.JSONArray;
import java.security.MessageDigest;
import java.nio.charset.StandardCharsets;

public class GhidraDecompilerScript extends GhidraScript {
    private DecompInterface decompInterface;
    private BasicBlockModel basicBlockModel;

    @Override
    public void run() throws Exception {
        System.err.println("{\"debug\": \"Script starting\"}");

        // Get binary hash and filepath from arguments
        String[] args = getScriptArgs();
        if (args.length < 2) {
            System.err.println("{\"error\": \"Both SHA256 and filepath arguments are required\"}");
            return;
        }
        String sha256 = args[0];
        String filepath = args[1];

        // Add debug output after setup
        System.err.println("{\"debug\": \"Processing file: " + args[1] + "\"}");

        // Initialize analysis components
        setupDecompiler();
        basicBlockModel = new BasicBlockModel(currentProgram);

        // Create the main JSON object for output
        JSONObject output = new JSONObject();
        output.put("sha256", sha256);
        output.put("decompiled", new JSONArray());
        output.put("disassembled", new JSONArray());
        output.put("cfg", new JSONArray());

        // Process all functions
        FunctionIterator functions = currentProgram.getFunctionManager().getFunctions(true);
        for (Function function : functions) {
            processFunction(function, output);
        }

        System.err.println("{\"debug\": \"Preparing final output\"}");
        // Output the final JSON to stdout
        System.out.println(output.toString());
    }

    private void setupDecompiler() {
        decompInterface = new DecompInterface();
        DecompileOptions options = new DecompileOptions();
        decompInterface.setOptions(options);
        decompInterface.openProgram(currentProgram);
    }

    private void processFunction(Function function, JSONObject output) {
        try {
            Address entry = function.getEntryPoint();
            String functionName = function.getName();
            String functionAddress = entry.toString();

            // Process each analysis type independently
            boolean hasAnyResults = false;

            try {
                if (processDecompiledCode(function, output.getJSONArray("decompiled"),
                                        functionName, functionAddress)) {
                    hasAnyResults = true;
                }
            } catch (Exception e) {
                System.err.println(String.format(
                    "{\"error\": \"Decompilation failed for function %s: %s\"}",
                    functionName, e.getMessage().replace("\"", "'")));
            }

            try {
                if (processDisassembledCode(function, output.getJSONArray("disassembled"),
                                        functionName, functionAddress)) {
                    hasAnyResults = true;
                }
            } catch (Exception e) {
                System.err.println(String.format(
                    "{\"error\": \"Disassembly failed for function %s: %s\"}",
                    functionName, e.getMessage().replace("\"", "'")));
            }

            try {
                if (processCFG(function, output.getJSONArray("cfg"), functionAddress)) {
                    hasAnyResults = true;
                }
            } catch (Exception e) {
                System.err.println(String.format(
                    "{\"error\": \"CFG extraction failed for function %s: %s\"}",
                    functionName, e.getMessage().replace("\"", "'")));
            }

            if (!hasAnyResults) {
                System.err.println(String.format(
                    "{\"warning\": \"No results obtained for function %s\"}",
                    functionName));
            }

        } catch (Exception e) {
            System.err.println(String.format(
                "{\"error\": \"Failed to process function: %s\"}",
                e.getMessage().replace("\"", "'")));
        }
    }

    private boolean processDecompiledCode(Function function, JSONArray decompArray,
                                        String functionName, String functionAddress) {
        try {
            DecompileResults results = decompInterface.decompileFunction(function, 30, monitor);
            if (results == null || !results.decompileCompleted()) {
                System.err.println(String.format(
                    "{\"warning\": \"Decompilation incomplete for function %s\"}",
                    functionName));
                return false;
            }

            String decompiledCode = results.getDecompiledFunction().getC();
            if (decompiledCode == null || decompiledCode.trim().isEmpty()) {
                System.err.println(String.format(
                    "{\"warning\": \"Empty decompilation result for function %s\"}",
                    functionName));
                return false;
            }

            String contentHash = calculateHash(decompiledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("decompiled_content_hash", contentHash);
            functionObj.put("decompiled_function_name", functionName);
            functionObj.put("decompiled_function_address", functionAddress);
            functionObj.put("decompiled_function", decompiledCode);

            decompArray.put(functionObj);
            return true;

        } catch (Exception e) {
            throw new RuntimeException("Decompilation error: " + e.getMessage(), e);
        }
    }

    private boolean processDisassembledCode(Function function, JSONArray disasmArray,
                                        String functionName, String functionAddress) {
        try {
            StringBuilder disassembly = new StringBuilder();
            StringBuilder normalized = new StringBuilder();
            int instructionCount = 0;
            boolean hasValidInstructions = false;

            Listing listing = currentProgram.getListing();
            AddressSetView functionBody = function.getBody();
            InstructionIterator instructions = listing.getInstructions(functionBody, true);

            while (instructions.hasNext()) {
                try {
                    Instruction instr = instructions.next();
                    if (instr != null) {
                        String disasmLine = instr.toString();
                        if (disasmLine != null && !disasmLine.trim().isEmpty()) {
                            disassembly.append(disasmLine).append("\n");
                            normalized.append(normalizeInstruction(disasmLine)).append("\n");
                            instructionCount++;
                            hasValidInstructions = true;
                        }
                    }
                } catch (Exception e) {
                    System.err.println(String.format(
                        "{\"warning\": \"Skipped invalid instruction in %s: %s\"}",
                        functionName, e.getMessage().replace("\"", "'")));
                }
            }

            if (!hasValidInstructions) {
                System.err.println(String.format(
                    "{\"warning\": \"No valid instructions found in function %s\"}",
                    functionName));
                return false;
            }

            String disassembledCode = disassembly.toString();
            String contentHash = calculateHash(disassembledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("disassembled_content_hash", contentHash);
            functionObj.put("disassembled_function_name", functionName);
            functionObj.put("disassembled_function_address", functionAddress);
            functionObj.put("disassembled_function", disassembledCode);
            functionObj.put("normalized_disassembly", normalized.toString());
            functionObj.put("instruction_count", instructionCount);

            // Initialize similarity fields as null
            functionObj.put("minhash_signature", JSONObject.NULL);
            functionObj.put("opcode_frequency_vector", JSONObject.NULL);
            functionObj.put("api_calls_vector", JSONObject.NULL);
            functionObj.put("instruction_embedding", JSONObject.NULL);

            disasmArray.put(functionObj);
            return true;

        } catch (Exception e) {
            throw new RuntimeException("Disassembly error: " + e.getMessage(), e);
        }
    }

    private boolean processCFG(Function function, JSONArray cfgArray, String functionAddress) {
        try {
            CodeBlockIterator blocks = basicBlockModel.getCodeBlocksContaining(
                function.getBody(), monitor);

            boolean hasValidBlocks = false;

            while (blocks.hasNext()) {
                try {
                    CodeBlock block = blocks.next();
                    String blockInstructions = getBlockInstructions(block);

                    if (blockInstructions == null || blockInstructions.trim().isEmpty()) {
                        continue;
                    }

                    String blockId = calculateHash(blockInstructions);

                    JSONObject blockObj = new JSONObject();
                    blockObj.put("block_id", blockId);
                    blockObj.put("function_address", functionAddress);
                    blockObj.put("block_instructions", blockInstructions);

                    // Process successors with error handling
                    JSONArray successorAddresses = new JSONArray();
                    try {
                        CodeBlockReferenceIterator successors = block.getDestinations(monitor);
                        while (successors.hasNext()) {
                            try {
                                CodeBlockReference ref = successors.next();
                                if (ref != null && ref.getDestinationAddress() != null) {
                                    successorAddresses.put(ref.getDestinationAddress().toString());
                                }
                            } catch (Exception e) {
                                System.err.println(String.format(
                                    "{\"warning\": \"Skipped invalid successor in block %s: %s\"}",
                                    blockId, e.getMessage().replace("\"", "'")));
                            }
                        }
                    } catch (Exception e) {
                        System.err.println(String.format(
                            "{\"warning\": \"Error processing successors for block %s: %s\"}",
                            blockId, e.getMessage().replace("\"", "'")));
                    }

                    blockObj.put("successor_blocks", successorAddresses);
                    cfgArray.put(blockObj);
                    hasValidBlocks = true;

                } catch (Exception e) {
                    System.err.println(String.format(
                        "{\"warning\": \"Skipped invalid block in function %s: %s\"}",
                        functionAddress, e.getMessage().replace("\"", "'")));
                }
            }

            return hasValidBlocks;

        } catch (Exception e) {
            throw new RuntimeException("CFG extraction error: " + e.getMessage(), e);
        }
    }

    private String getBlockInstructions(CodeBlock block) {
        StringBuilder instructions = new StringBuilder();
        try {
            AddressIterator addresses = block.getAddresses(true);
            while (addresses.hasNext()) {
                try {
                    Address addr = addresses.next();
                    if (addr != null) {
                        Instruction instr = currentProgram.getListing().getInstructionAt(addr);
                        if (instr != null) {
                            instructions.append(instr.toString()).append("\n");
                        }
                    }
                } catch (Exception e) {
                    System.err.println(String.format(
                        "{\"warning\": \"Skipped invalid instruction at address %s: %s\"}",
                        addresses.next(), e.getMessage().replace("\"", "'")));
                }
            }
        } catch (Exception e) {
            System.err.println(String.format(
                "{\"warning\": \"Error getting block instructions: %s\"}",
                e.getMessage().replace("\"", "'")));
        }
        return instructions.toString();
    }

    private String normalizeInstruction(String instruction) {
        try {
            if (instruction == null || instruction.trim().isEmpty()) {
                return "";
            }
            return instruction.replaceAll("0x[0-9a-fA-F]+", "IMM")
                            .replaceAll("\\b\\d+\\b", "NUM")
                            .replaceAll("[\\[\\]\\+\\-\\*/%&|^]+", "_OP_");
        } catch (Exception e) {
            System.err.println(String.format(
                "{\"warning\": \"Error normalizing instruction: %s\"}",
                e.getMessage().replace("\"", "'")));
            return instruction;
        }
    }

    private String calculateHash(String content) {
        try {
            if (content == null || content.trim().isEmpty()) {
                return "";
            }
            MessageDigest digest = MessageDigest.getInstance("SHA-256");
            byte[] hash = digest.digest(content.getBytes(StandardCharsets.UTF_8));
            StringBuilder hexString = new StringBuilder();
            for (byte b : hash) {
                hexString.append(String.format("%02x", b));
            }
            return hexString.toString();
        } catch (Exception e) {
            System.err.println(String.format(
                "{\"error\": \"Error calculating hash: %s\"}",
                e.getMessage().replace("\"", "'")));
            return "";
        }
    }
}