In-Ho Lee

51 papers A* 2A 2B 1C 3Journal 26Unranked 17
YearRankTypeTitle / Venue / Authors
2023 J jnl
Comput. Phys. Commun.
In-Ho Lee, Seoleun Shin
2019 J jnl
IEEE Trans. Robotics
Hyobin Jeong, In-Ho Lee, Jaesung Oh, Kang Kyu Lee, Jun-Ho Oh
2019 J jnl
Robotics Auton. Syst.
Hyobin Jeong, In-Ho Lee, Okkee Sim, Kang Kyu Lee, Jun-Ho Oh
2019 J jnl
Adv. Robotics
Jaesung Oh, In-Ho Lee, Hyobin Jeong, Jun-Ho Oh
2017 J jnl
J. Inf. Process. Syst.
In-Ho Lee, Howon Lee
2017 J jnl
J. Inform. and Commun. Convergence Engineering
In-Ho Lee
2017 J jnl
J. Inf. Process. Syst.
In-Ho Lee, Hyun-Ho Choi, Howon Lee
2017 J jnl
J. Field Robotics
Jeongsoo Lim, In-Ho Lee, Inwook Shim, Hyobin Jung, Hyun-Min Joe, Hyoin Bae, Okkee Sim, Jaesung Oh, Taejin Jung, Seunghak Shin, Kyungdon Joo, Mingeuk Kim, Kang Kyu Lee, Yunsu Bok, Dong-Geol Choi, Cho Buyoun, Sungwoo Kim, Jungwoo Heo, Inhyeok Kim, Jungho Lee, In So Kweon, Jun-Ho Oh
2016 conf
CCNC
Sungjin Park, Howon Lee, In-Ho Lee, Dong-Ho Cho
2016 J jnl
Int. J. Distributed Sens. Networks
Hyun-Ho Choi, Howon Lee, Sanghoon Kim, Jung-Ryun Lee, In-Ho Lee
2016 J jnl
J. Intell. Robotic Syst.
In-Ho Lee, Jun-Ho Oh
2016 J jnl
J. Commun. Networks
Hyun-Ho Choi, Howon Lee, Sanghoon Kim, In-Ho Lee
2016 A conf
IROS
Hyoin Bae, In-Ho Lee, Taejin Jung, Jun-Ho Oh
2015 conf
Humanoids
In-Ho Lee, Kang Kyu Lee, Okkee Sim, Kim Sung Woo, Cho Buyoun, Jun-Ho Oh
2015 J jnl
J. Commun. Networks
Hyun-Ho Choi, In-Ho Lee, Howon Lee
2015 J jnl
J. Inform. and Commun. Convergence Engineering
Seok-Chul Kwon, In-Ho Lee
2015 J jnl
IEEE Commun. Lett.
In-Ho Lee, Seok-Chul Kwon
2014 J jnl
IET Commun.
In-Ho Lee, Sangjun Lee
2014 J jnl
J. Inf. Process. Syst.
Myungjin Cho, In-Ho Lee
2013 J jnl
IEEE Commun. Lett.
Hyun-Ho Choi, Jung-Min Moon, In-Ho Lee, Howon Lee
2013 J jnl
IEEE Commun. Lett.
In-Ho Lee, Howon Lee, Hyun-Ho Choi
2013 J jnl
J. Intell. Robotic Syst.
Jae-Wook Chung, In-Ho Lee, Baek-Kyu Cho, Jun-Ho Oh
2012 J jnl
IEEE Commun. Lett.
In-Ho Lee
2012 J jnl
IEEE Trans. Wirel. Commun.
Hyungseok Yu, In-Ho Lee, Gordon L. Stüber
2010 C conf
ICOST
Won-Kyung Song, Jongbae Kim, Kwang-Ok An, In-Ho Lee, Won-Jin Song, Bum-Suk Lee, Sung-Il Hwang, Mi-Ok Son, Eun-Chang Lee
2008 J jnl
J. Econ. Theory
In-Ho Lee, Robin Mason
2007 J jnl
Games Econ. Behav.
Larry Karp, In-Ho Lee, Robin Mason
2007 conf
MIRAGE
Sung-Soo Kim, Seung-Woo Nam, In-Ho Lee
2007 J jnl
J. WSCG
Sung-Soo Kim, Seung-Woo Nam, Do-Hyung Kim, In-Ho Lee
2006 C conf
Image Processing: Algorithms and Systems
Hongseok Kim, Chang-Joon Park, Sung-Eun Kim, In-Ho Lee
2006 B conf
ACIVS
Soon-Yong Park, Jaekyoung Moon, Chang-Joon Park, In-Ho Lee
2006 A conf
BMVC
Jae-Hean Kim, Myung Jin Chung, Chang-Joon Park, In-Ho Lee
2005 conf
ICAT
Sung June Chang, In-Ho Lee
2005 conf
SIGGRAPH Posters
Hongseok Kim, Chang-Joon Park, In-Ho Lee
2004 conf
Eurographics (Short Presentations)
Il-Kwon Jeong, In-Ho Lee
2004 A* conf
ICRA
Choon-Young Lee, Il-Kwon Jeong, In-Ho Lee, Kap-Ho Seo, Ju-Jang Lee
2004 A* conf
ICRA
Choon-Young Lee, Il-Kwon Jeong, In-Ho Lee, Ju-Jang Lee
2004 conf
ICCSA (2)
In-Ho Lee, Joo-Heon Cha, Jay-Jung Kim, M.-W. Park
2003 conf
Eurographics (Posters)
Il-Kwon Jeong, In-Ho Lee
2003 conf
Computer Graphics and Imaging
Il-Kwon Jeong, In-Ho Lee
2003 conf
CISST
Ji-Hyung Lee, Sang-Won Ghyme, Seung-Woo Nam, In-Ho Lee
2003 conf
SIP
Sung-Eun Kim, Chang-Joon Park, Ran-Hee Lee, In-Ho Lee
2003 conf
ICAT
Seongmin Baek, Il-Kwon Jeong, In-Ho Lee
2003 conf
Robotics and Applications
Chang-Joon Park, In-Ho Lee
2003 J jnl
J. Econ. Theory
Larry Karp, In-Ho Lee
2002 C conf
ICCE
Sung-Eun Kim, Ran-Hee Lee, Chang-Joon Park, In-Ho Lee
2001 conf
VIIP
Ran-Hee Lee, Ji-Hyung Lee, Chil-Woo Lee, In-Ho Lee
2001 conf
VIIP
Sung-Eun Kim, In-Ho Lee, Kang-Hyun Jo
2001 J jnl
J. Econ. Theory
Larry Karp, In-Ho Lee
1999 conf
SIP
Weon-Geun Oh, Chang-Joon Park, Hyeon-Jin Kim, In-Ho Lee
1998 conf
KES (3)
Hyeon-Jin Kim, In-Ho Lee, Weon-Geun Oh, Young-Kyu Yang
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"