Irina A. Kunina

15 papers C 11Journal 4
YearRankTypeTitle / Venue / Authors
2023 C conf
ICMV
Aleksey D. Bursikov, Sergey A. Usilin, Irina A. Kunina
2023 C conf
ICMV
L. S. Tolstenko, Irina A. Kunina
2022 J jnl
J. Imaging
Daria Senshina, Dmitry Polevoy, Egor I. Ershov, Irina A. Kunina
2020 C conf
ICMV
Ekaterina I. Panfilova, Oleg S. Shipitko, Irina A. Kunina
2019 J jnl
CoRR
Mikhail A. Aliev, Dmitry Bocharov, Irina A. Kunina, Dmitry P. Nikolaev
2019 J jnl
CoRR
Ekaterina I. Panfilova, Mikhail A. Aliev, Irina A. Kunina, Vasiliy V. Postnikov, Dmitry P. Nikolaev
2019 J jnl
CoRR
Irina A. Kunina, Mikhail A. Aliev, N. V. Arlazarov, Dmitry V. Polevoy
2019 C conf
ICMV
Mikhail A. Aliev, Dmirty A. Nikolaev, Irina A. Kunina, Dmitry Bocharov
2019 C conf
ICMV
Ekaterina I. Panfilova, Mikhail A. Aliev, Irina A. Kunina, Vasiliy V. Postnikov, Dmitry P. Nikolaev
2019 C conf
ICMV
Irina A. Kunina, Mikhail A. Aliev, N. V. Arlazarov, Dmitry V. Polevoy
2018 C conf
ICMV
Oleg S. Shipitko, Maxim P. Abramov, Artem S. Lukoyanov, Ekaterina I. Panfilova, Irina A. Kunina, Anton S. Grigoryev
2018 C conf
ICMV
Irina A. Kunina, Ekaterina I. Panfilova, A. Gladkov
2017 C conf
ICMV
Irina A. Kunina, Lev Teplyakov, Andrey Gladkov, Timur M. Khanipov, Dmitry P. Nikolaev
2016 C conf
ICMV
Irina A. Kunina, Arseniy P. Terekhin, Timur M. Khanipov, Elena G. Kuznetsova, Dmitry P. Nikolaev
2015 C conf
ICMV
Irina A. Kunina, Aleksey Volkov, Sergey Gladilin, Dmitry P. Nikolaev
redb/extractors/decompiler/bninja/analysis/strings.py
← Index redb/extractors/decompiler/bninja/analysis/strings.py python
from collections import Counter
import math

class StringAnalysis:
    def __init__(self, bv, functions):
        self.bv = bv
        self.functions = functions

    def entropy(self, s: str) -> float:
        """Compute Shannon entropy of a string."""
        if not s:
            return 0.0
        freq = Counter(s)
        length = len(s)
        return -sum((count / length) * math.log2(count / length) for count in freq.values())

    def analyze(self):
        """
        Extract unique strings from the binary.

        Deduplicates by (string, encoding) within the same binary, keeping the
        first occurrence (lowest offset). Cross-binary deduplication and
        aggregation is handled by ClickHouse materialized views.
        """
        strings = {}

        # Sort strings by their starting address
        sorted_entries = sorted(self.bv.strings, key=lambda e: e.start)

        for entry in sorted_entries:
            # Key is the string and its encoding
            key = (entry.value, entry.type.name)

            # Skip if this string (value + encoding) was already added.
            # Because entries are sorted by address, the first one is always kept.
            if key in strings:
                continue

            # Store only the first occurrence with schema-matching field names
            # entry.length is the raw byte length, len(entry.value) is decoded string length
            string_entry = {
                "string": entry.value,
                "string_raw": entry.raw,
                "string_encoding": entry.type.name,
                "string_offset": entry.start,
                "string_length": len(entry.value),
                "string_raw_length": entry.length,
                "string_entropy": self.entropy(entry.value),
            }

            strings[key] = string_entry

        # Return as list for export compatibility
        return list(strings.values())