Isai Michel Lombera

17 papers B 1C 3Misc 2Journal 6Unranked 5
YearRankTypeTitle / Venue / Authors
2016 J jnl
Comput. Networks
Isai Michel Lombera, Louise E. Moser, P. M. Melliar-Smith, Yung-Ting Chuang
2016 J jnl
Peer-to-Peer Netw. Appl.
Yung-Ting Chuang, Peter Michael Melliar-Smith, Louise Elizabeth Moser, Isai Michel Lombera
2016 J jnl
Comput. J.
Yung-Ting Chuang, P. M. Melliar-Smith, Louise E. Moser, Isai Michel Lombera
2014 J jnl
Comput. Networks
Isai Michel Lombera, Louise E. Moser, P. Michael Melliar-Smith, Yung-Ting Chuang
2013 C conf
WEBIST
Boyang Peng, Louise E. Moser, P. Michael Melliar-Smith, Yung-Ting Chuang, Isai Michel Lombera
2013 J jnl
Mob. Networks Appl.
Isai Michel Lombera, Louise E. Moser, P. M. Melliar-Smith, Yung-Ting Chuang
2013 conf
WPMC
Isai Michel Lombera, Louise E. Moser, P. M. Melliar-Smith, Yung-Ting Chuang
2012 conf
IEEE MS
Isai Michel Lombera, Louise E. Moser, P. Michael Melliar-Smith, Yung-Ting Chuang
2012 B conf
WiMob
Isai Michel Lombera, Louise E. Moser, P. M. Melliar-Smith, Yung-Ting Chuang
2012 C conf
WEBIST
Christopher M. Badger, Louise E. Moser, P. Michael Melliar-Smith, Isai Michel Lombera, Yung-Ting Chuang
2012 conf
ICOIN
Yung-Ting Chuang, Isai Michel Lombera, P. M. Melliar-Smith, Louise E. Moser
2012 J jnl
J. Comput. Sci. Eng.
Yung-Ting Chuang, P. Michael Melliar-Smith, Louise E. Moser, Isai Michel Lombera
2012 Misc conf
ICDCN
P. Michael Melliar-Smith, Louise E. Moser, Isai Michel Lombera, Yung-Ting Chuang
2011 conf
MobiCASE
Isai Michel Lombera, Yung-Ting Chuang, Louise E. Moser, P. M. Melliar-Smith
2009 conf
SNA
Stuart Harvey Rubin, Isai Michel Lombera, Michael Armella, Jeremy Conn, Shu-Ching Chen, Gordon K. Lee
2009 Misc conf
IRI
Michael Armella, Isai Michel Lombera, Stuart Harvey Rubin, Shu-Ching Chen, Gordon K. Lee
2008 C conf
CAINE
Isai Michel Lombera, Jayeshkumar Patel, Stuart Harvey Rubin, Shu-Ching Chen, Gordon K. Lee
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"