Ja-Hwung Su

68 papers A* 1A 4B 12C 1Misc 5Journal 16Unranked 29
YearRankTypeTitle / Venue / Authors
2025 B conf
IEEE Big Data
Ja-Hwung Su, Liang-Yu Chen
2024 J jnl
IEEE Access
Tzung-Pei Hong, Jin-Hang Wu, Ja-Hwung Su, Tang-Kai Yin
2024 conf
ACIIDS (1)
Tzung-Pei Hong, Jerry Chun-Wei Lin, Ja-Hwung Su, Tang-Kai Yin
2023 conf
ACIIDS (1)
Ja-Hwung Su, Wei-Jiang Chen, Ming-Cheng Zhang, Yi-Wen Liao
2023 B conf
IEEE Big Data
Tzung-Pei Hong, Jin-Hang Wu, Ja-Hwung Su, Tang-Kai Yin
2022 conf
SCIS/ISIS
Ja-Hwung Su, Yi-Wen Liao, Ming-Hung Kao, Yung-Wen Tsai, Chih-Jui Chang, Hsiu-Wei Wu, Cheng-Wei Chen
2022 J jnl
IEEE Access
Tzung-Pei Hong, Chen-Chia Chiu, Ja-Hwung Su, Chun-Hao Chen
2022 J jnl
IEEE Access
Yi-Hsuan Chuang, Ja-Hwung Su, Ding-Hong Han, Yi-Wen Liao, Yeong-Chyi Lee, Yu-Fan Cheng, Tzung-Pei Hong, Katherine Shu-Min Li, Hsin-You Ou, Yi Lu, Chih-Chi Wang
2022 J jnl
Eng. Appl. Artif. Intell.
Ja-Hwung Su, Tzung-Pei Hong, Yu-Tang Chen, Chu-Yu Chin
2022 conf
ACIIDS (Companion)
Ja-Hwung Su, Yi-Wen Liao, Liang-Yu Chen
2022 conf
ACIIDS (Companion)
Ja-Hwung Su, Terry Ting-Yu Chiou, Yi-Wen Liao, Yu-Siou Liao, Chien-Hsin Wu, Wen-Yang Lin
2021 conf
IST
Tzung-Pei Hong, Wei-Chun Peng, Ja-Hwung Su, Shyue-Liang Wang
2020 J jnl
Vietnam. J. Comput. Sci.
Ja-Hwung Su, Chu-Yu Chin, Yi-Wen Liao, Hsiao-Chuan Yang, Vincent S. Tseng, Sun-Yuan Hsieh
2020 B conf
SMC
Ja-Hwung Su, Tzung-Pei Hong, Yao-Hong Hsieh, Shu-Min Li
2020 conf
ACIIDS (Companion)
Ja-Hwung Su, Tzung-Pei Hong, Hsuan-Hao Yeh
2020 B conf
SMC
Ja-Hwung Su, Yi-Wen Liao, Hong-Yi Wu, You-Wei Zhao
2019 B conf
SMC
Ja-Hwung Su, Wen-Yang Lin, Yi-Wen Liao, Guan-Hua Lai
2019 conf
ACIIDS (2)
Tzung-Pei Hong, Yu-Chiao Yang, Ja-Hwung Su, Chun-Hao Chen
2019 conf
ACIIDS (2)
Ja-Hwung Su, Chu-Yu Chin, Tzung-Pei Hong, Jung-Jui Su
2019 J jnl
Int. J. High Perform. Comput. Netw.
Ja-Hwung Su, Chu-Yu Chin, Jyun-Yu Li, Vincent S. Tseng
2018 J jnl
Vietnam. J. Comput. Sci.
Ja-Hwung Su, Tzung-Pei Hong, Chu-Yu Chin, Zhi-Feng Liao, Shyr-Yuan Cheng
2018 conf
ACIIDS (1)
Ja-Hwung Su, Chu-Yu Chin, Hsiao-Chuan Yang, Vincent S. Tseng, Sun-Yuan Hsieh
2018 conf
TAAI
Ja-Hwung Su, Tzung-Pei Hong, Jyun-Yu Li, Jung-Jui Su
2018 A conf
ICS
Tzung-Pei Hong, Yu-Chiao Yang, Ja-Hwung Su, Shyue-Liang Wang
2017 conf
ACIIDS (1)
Ja-Hwung Su, Tzung-Pei Hong, Chu-Yu Chin, Zhi-Feng Liao, Shyr-Yuan Cheng
2017 J jnl
Appl. Intell.
Jerry Chun-Wei Lin, Shifeng Ren, Philippe Fournier-Viger, Tzung-Pei Hong, Ja-Hwung Su, Bay Vo
2017 conf
IFSA-SCIS
Chun-Hao Chen, Wan-Yi Shen, Tzung-Pei Hong, Ja-Hwung Su
2017 J jnl
Intell. Data Anal.
Ja-Hwung Su, Wei-Yi Chang, Vincent S. Tseng
2017 conf
iCAST
Ja-Hwung Su, Chu-Yu Chin, Jyun-Yu Li, Vincent S. Tseng
2016 conf
ACIIDS (2)
Ja-Hwung Su, Ting-Wei Chiu
2016 A* conf
ICDM
Jerry Chun-Wei Lin, Ting Li, Philippe Fournier-Viger, Tzung-Pei Hong, Ja-Hwung Su
2016 B conf
SMC
Jerry Chun-Wei Lin, Jiexiong Zhang, Philippe Fournier-Viger, Tzung-Pei Hong, Chien-Ming Chen, Ja-Hwung Su
2016 B conf
FUZZ-IEEE
Jerry Chun-Wei Lin, Ting Li, Philippe Fournier-Viger, Tzung-Pei Hong, Ja-Hwung Su
2016 conf
ACIIDS (2)
Josh Jia-Ching Ying, Ja-Hwung Su
2016 conf
BigMM
Ja-Hwung Su, Tzung-Pei Hong, Yu-Tang Chang, Hsu-Yuan Tung
2016 B conf
CEC
Chun-Hao Chen, Cheng-Yu Lu, Tzung-Pei Hong, Ja-Hwung Su
2014 C conf
MoMM
Wen-Yang Lin, Ja-Hwung Su
2014 Misc conf
GrC
Ja-Hwung Su, Chun-Yen Wang, Ting-Wei Chiu, Josh Jia-Ching Ying, Vincent S. Tseng
2013 conf
ICME Workshops
Ja-Hwung Su, Yi-Cheng Tsai, Vincent S. Tseng
2013 Misc conf
GrC
Ja-Hwung Su, Chung-Chieh Hsu, Josh Jia-Ching Ying
2013 B conf
KES
Ja-Hwung Su, Wei-Yi Chang, Vincent S. Tseng
2012 conf
TAAI
Ja-Hwung Su, Shao-Yu Fu, Vincent S. Tseng
2012 Misc conf
GrC
Ja-Hwung Su, Chun-Yi Kuo, Vincent S. Tseng
2012 J jnl
Soft Comput.
Wen-Yang Lin, Ja-Hwung Su, Ming-Cheng Tseng
2011 conf
KES (2)
Ja-Hwung Su, Tzu-Shiang Hung, Chun-Jen Lee, Chung-Li Lu, Wei-Lun Chang, Vincent S. Tseng
2011 J jnl
IEEE Trans. Multim.
Ja-Hwung Su, Chien-Li Chou, Ching-Yung Lin, Vincent S. Tseng
2011 J jnl
IEEE Trans. Knowl. Data Eng.
Ja-Hwung Su, Wei-Jyun Huang, Philip S. Yu, Vincent S. Tseng
2011 A conf
ICME
Ja-Hwung Su, Ming-Hua Hsieh, Tao Mei, Vincent S. Tseng
2010 Misc conf
SAC
Ja-Hwung Su, Hsin-Ho Yeh, Vincent S. Tseng
2010 J jnl
Expert Syst. Appl.
Ja-Hwung Su, Yu-Ting Huang, Hsin-Ho Yeh, Vincent S. Tseng
2010 A conf
ICME
Ja-Hwung Su, Chien-Li Chou, Ching-Yung Lin, Vincent S. Tseng
2010 J jnl
IEEE Intell. Syst.
Ja-Hwung Su, Hsin-Ho Yeh, Philip S. Yu, Vincent S. Tseng
2010 J jnl
Inf. Sci.
Ja-Hwung Su, Bo-Wen Wang, Chin-Yuan Hsiao, Vincent S. Tseng
2010 B conf
FUZZ-IEEE
Wen-Yang Lin, Ming-Cheng Tseng, Ja-Hwung Su
2009 conf
Web Intelligence/IAT Workshops
Ja-Hwung Su, Bo-Wen Wang, Hsin-Ho Yeh, Vincent S. Tseng
2008 conf
Web Intelligence/IAT Workshops
Ja-Hwung Su, Bo-Wen Wang, Vincent S. Tseng
2008 J jnl
IEEE Trans. Multim.
Vincent S. Tseng, Ja-Hwung Su, Jhih-Hong Huang, Chih-Jen Chen
2008 A conf
ICME
Vincent S. Tseng, Ja-Hwung Su, Hao-Hua Ku, Bo-Wen Wang
2008 conf
SUTC
Vincent S. Tseng, Ja-Hwung Su, Bo-Wen Wang, Chin-Yuan Hsiao, Jay Huang, Hsin-Ho Yeh
2008 B conf
PAKDD
Vincent S. Tseng, Ja-Hwung Su, Jhih-Hong Huang, Chih-Jen Chen
2007 conf
IIH-MSP
Vincent S. Tseng, Ja-Hwung Su, Chih-Jen Chen
2007 conf
IFSA (2)
Vincent S. Tseng, Ja-Hwung Su, Wei-Jyun Huang
2007 Misc conf
SAC
Vincent S. Tseng, Ja-Hwung Su, Bo-Wen Wang, Yu-Ming Lin
2005 conf
ICDE Workshops
Vincent Shin-Mu Tseng, Ming-Hsiang Wang, Ja-Hwung Su
2005 conf
MDM/KDD
Vincent S. Tseng, Chon-Jei Lee, Ja-Hwung Su
2004 conf
SMC (4)
Wen-Yang Lin, Ming-Cheng Tseng, Ja-Hwung Su
2004 conf
HICSS
Ja-Hwung Su, Wen-Yang Lin
2002 B conf
PAKDD
Wen-Yang Lin, Ming-Cheng Tseng, Ja-Hwung Su
yara/README.md
← Index yara/README.md markdown
# YARA Rules Directory

This folder contains YARA rules for scanning binary samples.

## Setting Up YARA-Forge Rules

To use the YARA-Forge rules from [https://github.com/YARAHQ/yara-forge](https://github.com/YARAHQ/yara-forge):

```bash
# Download the latest release
cd /path/to/redb/yara
# wget https://github.com/YARAHQ/yara-forge/releases/latest/download/yara-forge-rules-core.zip
wget https://github.com/YARAHQ/yara-forge/releases/latest/download/yara-forge-rules-extended.zip

# Extract rules
# unzip yara-forge-rules-core.zip
unzip yara-forge-rules-extended.zip
```

Available packages:
- `yara-forge-rules-core.zip` - Core rules (~5,000 rules)
- `yara-forge-rules-extended.zip` - Extended rules (~10,000 rules)
- `yara-forge-rules-full.zip` - Full rules (~11,000+ rules)

## Pre-compiling Rules (Recommended for Production)

For large rulesets like YARA-Forge, pre-compiling rules significantly improves startup time:

```bash
# Pre-compile all rules into a single .yarac file
python -m redb.extractors.yara --compile

# Or specify custom paths
python -m redb.extractors.yara --compile --rules-path /path/to/rules --output /path/to/output.yarac
```

This creates `yara/compiled_rules.yarac` which is loaded automatically on subsequent runs.

### Performance Comparison

| Method | First Scan Startup | Subsequent Scans |
|--------|-------------------|------------------|
| Source files (.yar) | ~10-30 seconds (11k rules) | Instant (cached) |
| Pre-compiled (.yarac) | ~1-2 seconds | Instant (cached) |

## Directory Structure

```
yara/
├── README.md
├── .gitkeep
├── compiled_rules.yarac    # (optional) Pre-compiled rules
├── packages/               # YARA-Forge packages
│   └── core/
│       └── *.yar
└── custom/                 # Your custom rules
    └── my_rules.yar
```

Rules are loaded in this priority:
1. `compiled_rules.yarac` (if exists) - fastest
2. All `.yar` and `.yara` files recursively - compiles on first run

## Usage

### Scan with YARA only

```bash
# Scan local files
python start.py --path /path/to/samples -y --repo my_repo --index_prefix redb

# Scan S3 samples
python start.py --s3 --repo bazaar -y --index_prefix redb

# Dry-run (print results instead of storing in ClickHouse)
python start.py --path /path/to/samples -y --dry-run --repo test --index_prefix redb
```

### Scan already-analyzed samples

Run YARA on samples that were previously analyzed (already in `basic_properties`).
Deduplication is handled by the `yara_matches` table — samples already scanned are
automatically excluded before processing begins:

```bash
# Scan all analyzed macho samples with YARA
python start.py --analyzed --magika macho -y --index_prefix redb

# Scan all analyzed PE samples with YARA
python start.py --analyzed --magika pe -y --index_prefix redb

# Scan all analyzed samples (no filetype filter)
python start.py --analyzed -y --index_prefix redb
```

### Partition large YARA runs by date

Combine `--analyzed` with `--range` to partition millions of samples into
manageable batches. Only samples in `basic_properties` AND within the date
range (by `first_seen` in `catalog_samples`) are processed:

```bash
# Scan analyzed PE samples from Feb 2025
python start.py --range 2025-02-01 2025-02-28 --analyzed --magika pebin -y --index_prefix redb

# Scan analyzed PE samples from first week of March 2025
python start.py --range 2025-03-01 2025-03-08 --analyzed --magika pebin -y --index_prefix redb
```

YARA dedup still applies — re-running a range safely skips already-scanned samples.

### Combined Features + YARA

Run feature extraction and YARA scanning together on the same samples:

```bash
# Local files with features + YARA
python start.py --path /path/to/samples --with-yara --repo my_repo --index_prefix redb

# S3 samples with features + YARA
python start.py --s3 --repo bazaar --with-yara --index_prefix redb
```

### Pre-compile Rules

```bash
# Compile and save to default location (yara/compiled_rules.yarac)
python -m redb.extractors.yara --compile

# Compile with custom paths
python -m redb.extractors.yara --compile --rules-path ./my_rules --output ./compiled.yarac
```

### Sync Rules to Database

Before batch scanning, sync rules to ensure all rule metadata is stored:

```bash
# Sync rules to database
python -m redb.extractors.yara --sync-rules

# Sync with custom source collection name
python -m redb.extractors.yara --sync-rules --source-collection yara-forge-core

# Compile and sync in one command
python -m redb.extractors.yara --compile --sync-rules
```

## ClickHouse Table Schema

YARA data uses a **normalized schema** with two tables for efficient storage.

### Matches Table: `yara_matches`

Stores one row per sample-rule match (optimized with binary sha256 and rule_id):

| Column | Type | Description |
|--------|------|-------------|
| sha256 | FixedString(32) | Binary SHA256 (32 bytes, use `hex(sha256)` to display) |
| rule_id | UInt64 | Unique rule identifier (xxHash64 of canonical rule content) |
| rule_name | LowCardinality(String) | YARA rule name (denormalized for convenience) |
| scan_date | DateTime64(3, 'UTC') | Scan timestamp |
| match_strings | Array(String) | Matched string identifiers |

### Rules Table: `yara_rules`

Stores rule metadata once per unique rule (deduplicated by rule_id):

| Column | Type | Description |
|--------|------|-------------|
| rule_id | UInt64 | Unique rule identifier (xxHash64 of canonical rule content) |
| rule_name | String | YARA rule name |
| source_collection | LowCardinality(String) | Source collection (e.g., 'yara-forge-core', 'malpedia') |
| ingested_at | DateTime64(3, 'UTC') | When this rule was ingested |
| rule_text | String | Full rule source code |
| rule_meta | JSON | Rule metadata (author, description, reference, etc.) |
| rule_tags | Array(LowCardinality(String)) | Rule tags |

### Schema Benefits

- **Binary SHA256**: 32 bytes vs 64 bytes (50% storage savings on hash columns)
- **UInt64 rule_id**: Fast joins and lookups via integer key
- **Content-based rule_id**: xxHash64 of canonical rule content (excluding metadata) for deduplication
- **Denormalized rule_name**: Allows queries without joins for common use cases

### Example Queries

```sql
-- Get matches with hex sha256
SELECT
    hex(m.sha256) as sha256,
    m.rule_name,
    m.match_strings
FROM yara_matches m
WHERE m.sha256 = unhex('abc123...')

-- Join with rules for full metadata
SELECT
    hex(m.sha256) as sha256,
    m.rule_name,
    m.match_strings,
    r.rule_meta,
    r.source_collection
FROM yara_matches m
JOIN yara_rules r ON m.rule_id = r.rule_id
WHERE m.sha256 = unhex('abc123...')

-- Find all samples matching a specific rule
SELECT hex(sha256), scan_date
FROM yara_matches
WHERE rule_name = 'APT_Lazarus_Loader'
ORDER BY scan_date DESC
```

## Environment Variables

| Variable | Description | Default |
|----------|-------------|---------|
| `YARA_RULES_PATH` | Override the YARA rules directory | `yara/` |
| `YARA_COMPILED_RULES` | Compiled rules filename | `compiled_rules.yarac` |
| `YARA_SOURCE_COLLECTION` | Default source collection name | `default` |