Ioan Stefan Sacala

42 papers C 4Journal 10Unranked 26
YearRankTypeTitle / Venue / Authors
2025 conf
CSCS
Béatrix-May Balaban, Ioan Stefan Sacala, Claudia Alina Petrescu-Nita, Nicolae Constantin
2025 conf
CSCS
Miruna-Elena Iliuta, Eugen Pop, Alexandra Cernian, Stefan Mantale, Ioan Stefan Sacala, Mihnea Alexandru Moisescu
2025 J jnl
Future Internet
Ioana-Livia Stefan, Andrei Mateescu, Ionut Lentoiu, Silviu Raileanu, Florin Daniel Anton, Dragos Constantin Popescu, Ioan Stefan Sacala
2025 conf
AINA (8)
Béatrix-May Balaban, Ioan Stefan Sacala, Claudia Alina Petrescu-Nita
2025 J jnl
Future Internet
Carmen Ionela Rotuna, Ioan Stefan Sacala, Adriana Alexandru
2024 conf
ICE/ITMC
Dragos Constantin Popescu, Andrei Mateescu, Ioana-Livia Stefan, Ioana Miruna Vlasceanu, Ioan Stefan Sacala, Ioan Dumitrache
2024 conf
ICE/ITMC
Liviu Ilie, Eugen Pop, Ioan Stefan Sacala, Ana Magdalena Anghel, Luiza-Elena Burlacu
2024 C conf
INISTA
Ioana-Livia Stefan, Andrei Mateescu, Ioana Miruna Vlasceanu, Dragos Constantin Popescu, Ioan Stefan Sacala
2023 conf
CSCS
Béatrix-May Balaban, Ioan Stefan Sacala, Alina Petrescu-Nita, Razvan Nita
2023 conf
CSCS
Andrei Mateescu, Ioana-Livia Stefan, Dragos Constantin Popescu, Ioan Stefan Sacala, Silviu Raileanu
2022 conf
ITQM
Simona Iuliana Caramihai, Ioan Dumitrache, Mihnea Alexandru Moisescu, Ioan Stefan Sacala
2021 conf
CSCS
Radu-Constantin Simen, Ioan Stefan Sacala
2021 conf
CSCS
Eugen Pop, Daniela Gîfu, Aurelian Mihai Stanescu, Mihnea Alexandru Moisescu, Ioan Stefan Sacala
2021 conf
CSCS
Béatrix-May Balaban, Ioan Stefan Sacala, Alina Petrescu-Nita, Florin Pop
2021 conf
MED
Ioan Stefan Sacala, Eugen Pop, Mihnea Alexandru Moisescu, Ioan Dumitrache, Simona Iuliana Caramihai, Janetta Culita
2021 J jnl
Sensors
Alexandra Cernian, Nicoleta Vasile, Ioan Stefan Sacala
2021 J jnl
Int. J. Comput. Commun. Control
Ioan Dumitrache, Simona Iuliana Caramihai, Dragos Constantin Popescu, Mihnea Alexandru Moisescu, Ioan Stefan Sacala
2020 J jnl
Sensors
Janetta Culita, Simona Iuliana Caramihai, Ioan Dumitrache, Mihnea Alexandru Moisescu, Ioan Stefan Sacala
2019 conf
CSCS
Mihnea Alexandru Moisescu, Ioan Stefan Sacala, Ioan Dumitrache, Simona Iuliana Caramihai, Nicolae Constantin, Bogdan Barbulescu, Marius Danciuc
2019 J jnl
Sensors
Ioan Dumitrache, Simona Iuliana Caramihai, Mihnea Alexandru Moisescu, Ioan Stefan Sacala, Luige Vladareanu, Dragos Repta
2019 conf
ECBS
Mihnea Alexandru Moisescu, Ioan Dumitrache, Bogdan Barbulescu, Ioan Stefan Sacala, Simona Iuliana Caramihai, Marius Danciuc
2019 conf
CSCS
Eugen Pop, Daniela Gîfu, Ioan Stefan Sacala, Simona Iuliana Caramihai, Mihnea Alexandru Moisescu, Dragos Repta
2018 J jnl
Enterp. Inf. Syst.
Dragos Repta, Ioan Dumitrache, Ioan Stefan Sacala, Mihnea Alexandru Moisescu, Aurelian Mihai Stanescu, Simona Iuliana Caramihai
2018 conf
BIBM
Huiru Zheng, Jyotsna Talreja Wassan, Mihnea Alexandru Moisescu, Lacramioara Stoicu-Tivadar, João Miranda, Mihaela Crisan-Vida, Ioan Stefan Sacala, Almir Badnjevic, Ivan Chorbev, Boro Jakimovski
2018 conf
IEEE Conf. on Intelligent Systems
Dragos Repta, Ioan Stefan Sacala, Mihnea Alexandru Moisescu, Ioan Dumitrache
2017 conf
CSCS
Ioan Dumitrache, Simona Iuliana Caramihai, Ioan Stefan Sacala, Mihnea Alexandru Moisescu
2017 conf
CSCS
Eugen Pop, Mihnea Alexandru Moisescu, Ioan Stefan Sacala
2017 conf
ICE/ITMC
Ioan Stefan Sacala, Ioan Dumitrache, Mihnea Alexandru Moisescu, Aurelian Mihai Stanescu, Simona Iuliana Caramihai
2017 conf
SpringSim (Mod4Sim)
Mihnea Alexandru Moisescu, Ioan Stefan Sacala, Ioan Dumitrache, Dragos Repta
2017 J jnl
Int. J. Comput. Integr. Manuf.
Dragos Repta, Mihnea Alexandru Moisescu, Ioan Stefan Sacala, Ioan Dumitrache, Aurelian Mihai Stanescu
2016 conf
I-ESA
Dragos Repta, Ioan Stefan Sacala, Mihnea Alexandru Moisescu, Ioan Dumitrache, Aurelian Mihai Stanescu
2016 J jnl
J. Intell. Manuf.
Mihnea Alexandru Moisescu, Ioan Stefan Sacala
2015 conf
CSCS
Dragos Repta, Mihnea Alexandru Moisescu, Ioan Stefan Sacala, Aurelian Mihai Stanescu, Gabriel Neagu
2015 J jnl
Enterp. Inf. Syst.
Georgiana Stegaru, Cristian Danila, Ioan Stefan Sacala, Mihnea Alexandru Moisescu, Aurelian Mihai Stanescu
2015 C conf
MODELSWARD
Dragos Repta, Ioan Stefan Sacala, Mihnea Alexandru Moisescu, Calin Munteanu, Aurelian Mihai Stanescu
2014 C conf
PRO-VE
Aurelian Mihai Stanescu, Dragos Repta, Mihnea Alexandru Moisescu, Ioan Stefan Sacala, Monika Benea
2013 conf
MIM
Georgiana Stegaru, Mihnea Alexandru Moisescu, Ioan Stefan Sacala, Natalia Costetchi
2013 conf
CSCS
Ioan Stefan Sacala, Mihnea Alexandru Moisescu, Dragos Repta
2012 conf
I-ESA
Georgiana Stegaru, Aurelian Mihai Stanescu, Ioan Stefan Sacala, Mihnea Moisescu
2012 ch.
Service Orientation in Holonic and Multi-Agent Manufacturing Control
Aurelian Mihai Stanescu, Mihnea Alexandru Moisescu, Ioan Stefan Sacala, George Burlacu
2012 C conf
PRO-VE
Georgiana Stegaru, Cristian Danila, Ioan Stefan Sacala, Mihnea Moisescu, Aurelian Mihai Stanescu
2012 ch.
Service Orientation in Holonic and Multi-Agent Manufacturing Control
Calin Munteanu, Simona Caramihai, Mihnea Alexandru Moisescu, Ioan Stefan Sacala
redb/extractors/macho_extractor.py
← Index redb/extractors/macho_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect
import sys
import os

import machofile

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class MachOExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        macho=None,
    ):
        # Read binary and parse machofile BEFORE calling super().__init__
        # This avoids reading the file twice
        with open(filepath, "rb") as f:
            binary_data = f.read()

        # Parse machofile with binary data
        self.macho = macho if macho else self._generate_machofile_object(binary_data)

        # Extract hashes from machofile to pass to parent
        precomputed_hashes = None
        if self.macho:
            try:
                general_info = self.macho.get_general_info()
                if general_info:
                    # For FAT binaries, get_general_info() returns dict with 'fat' key
                    # For single-arch, it returns the info directly
                    if 'fat' in general_info:
                        fat_info = general_info['fat']
                        precomputed_hashes = {
                            'MD5': fat_info.get('MD5'),
                            'SHA1': fat_info.get('SHA1'),
                            'SHA256': fat_info.get('SHA256'),
                        }
                    else:
                        precomputed_hashes = {
                            'MD5': general_info.get('MD5'),
                            'SHA1': general_info.get('SHA1'),
                            'SHA256': general_info.get('SHA256'),
                        }
            except Exception as e:
                logger.debug(f"Could not get hashes from machofile: {e}")

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            precomputed_hashes=precomputed_hashes,
        )

        # Store binary data so base class doesn't re-read
        self._binary_data = binary_data

    @property
    def binary(self):
        """Override to use already-read binary data."""
        return self._binary_data

    def _generate_machofile_object(self, binary_data):
        """Generate and parse a machofile object from binary data."""
        macho = None
        try:
            macho = machofile.UniversalMachO(data=binary_data)
            if not macho:
                raise Exception("Empty file?")

            # Parse the MachO object once during initialization
            macho.parse()

        except Exception as e:
            logger.error(f"Format error parsing MachO: {e}")
        return macho

    # def _is_macho_file(self):
    #     """Check if the file is a valid Mach-O binary."""
    #     try:
    #         if not self.macho:
    #             return False
            
    #         # For Universal/FAT binaries, check if any architecture is valid
    #         if hasattr(self.macho, 'is_fat') and self.macho.is_fat:
    #             return len(self.macho.architectures) > 0
    #         else:
    #             # Single architecture binary
    #             return hasattr(self.macho, 'macho') and self.macho.macho is not None
    #     except Exception as e:
    #         self.log.error(f"Error checking Mach-O file: {e}")
    #         return False

    def _is_signed(self):
        """Check if the Mach-O binary is code signed using new API."""
        try:
            if not self.macho:
                return False

            # Get architectures using new API
            architectures = self.macho.get_architectures()

            # For each architecture, check if signed
            for arch in architectures:
                try:
                    signature_info = self.macho.get_code_signature_info(arch=arch)
                    if signature_info and signature_info.get('signed', False):
                        return True
                except Exception:
                    continue

            return False
        except Exception as e:
            self.log.error(f"Error checking Mach-O signature: {e}")
            return False

    def _get_architectures(self):
        """Get list of architectures in the Mach-O binary using new API."""
        try:
            if not self.macho:
                return []

            # Use new API method
            architectures = self.macho.get_architectures()
            return architectures if architectures else []
        except Exception as e:
            self.log.error(f"Error getting architectures: {e}")
            return []

    # def _get_macho_for_arch(self, arch_name=None):
    #     """Get MachO instance for specific architecture or default."""
    #     try:
    #         if not self.macho:
    #             return None
            
    #         if hasattr(self.macho, 'is_fat') and self.macho.is_fat:
    #             if arch_name:
    #                 return self.macho.architectures.get(arch_name)
    #             else:
    #                 # Return first available architecture
    #                 return next(iter(self.macho.architectures.values())) if self.macho.architectures else None
    #         else:
    #             # Single architecture binary
    #             return self.macho.macho if hasattr(self.macho, 'macho') else None
    #     except Exception as e:
    #         self.log.error(f"Error getting MachO for architecture: {e}")
    #         return None

    # def _get_formatted_header_values(self, header):
    #     """Get both raw and human-readable header values."""
    #     try:
    #         macho_instance = self._get_macho_for_arch()
    #         if not macho_instance:
    #             return None
            
    #         # Parse the MachO if not already parsed
    #         if not hasattr(macho_instance, 'header') or not macho_instance.header:
    #             macho_instance.parse()
            
    #         # Get human-readable values using machofile's formatting methods
    #         magic_str = macho_instance.format_magic_value(header.get('magic', 0))
            
    #         # Simple CPU type mapping since CPU_TYPE_MAP is not exposed
    #         cputype = header.get('cputype', 0)
    #         if cputype == 0x7:
    #             cputype_str = "x86"
    #         elif cputype == 0x1000007:
    #             cputype_str = "x86_64"
    #         elif cputype == 0xC:
    #             cputype_str = "ARM"
    #         elif cputype == 0x100000C:
    #             cputype_str = "ARM 64-bit"
    #         else:
    #             cputype_str = str(cputype)
            
    #         cpusubtype_str = macho_instance.decode_cpusubtype(header.get('cputype', 0), header.get('cpusubtype', 0))
    #         filetype_str = macho_instance.format_file_type(header.get('filetype', 0))
    #         flags_str = macho_instance.decode_flags(header.get('flags', 0))
            
    #         return {
    #             'raw': {
    #                 'magic': header.get('magic', 0),
    #                 'cputype': header.get('cputype', 0),
    #                 'cpusubtype': header.get('cpusubtype', 0),
    #                 'filetype': header.get('filetype', 0),
    #                 'flags': header.get('flags', 0),
    #             },
    #             'formatted': {
    #                 'magic_str': magic_str,
    #                 'cputype_str': cputype_str,
    #                 'cpusubtype_str': cpusubtype_str,
    #                 'filetype_str': filetype_str,
    #                 'flags_str': flags_str,
    #             }
    #         }
    #     except Exception as e:
    #         self.log.error(f"Error formatting header values: {e}")
    #         return None