Jaehwui Bae

25 papers B 1C 1Journal 1Unranked 22
YearRankTypeTitle / Venue / Authors
2024 conf
ICTC
Jaehwui Bae, Haechan Kwon, Sung Ik Park, Jae-Hyun Seo
2024 conf
ICTC
Haechan Kwon, Jaehwui Bae, Sung-Ik Park, Jae-Hyun Seo
2023 conf
BMSB
Haechan Kwon, Jaehwui Bae, Youngsu Kim, Jae-Hyun Seo, Sung-Ik Park
2023 conf
ICTC
Jaehwui Bae, Haechan Kwon, Youngsu Kim, Jae-Hyun Seo, Sung-Ik Park
2022 conf
ICTC
Jaehwui Bae, Jae-Hyun Seo, Namho Hur, Dong-Joon Choi
2021 conf
ICTC
Jaehwui Bae, Jae-Hyun Seo, Namho Hur, Dong-Joon Choi
2021 conf
BMSB
Jaehwui Bae, Namho Hur, Dong-Joon Choi
2020 conf
BMSB
Jaehwui Bae, Youngsu Kim, Namho Hur, Dong-Joon Choi, Ho Jae Kim, Hyoung-Nam Kim
2020 conf
ICTC
Jaehwui Bae, Youngsu Kim, Namho Hur, Dong-Joon Choi
2019 C conf
APCC
Ho Jae Kim, Hyoung-Nam Kim, Jaehwui Bae, Namho Hur
2019 conf
ICCE-Berlin
Jaehwui Bae, Sunhyong Kwon, Youngsu Kim, Namho Hur, Dong-Joon Choi, Ho Jae Kim, Hyoung-Nam Kim
2019 conf
ICTC
Jaehwui Bae, Jae-Hyun Seo, Youngsu Kim, Jae-Young Lee, Namho Hur, Dong-Joon Choi, Ho Jae Kim, Hyoung-Nam Kim
2017 conf
ICTC
Jaehwui Bae, Jae-Hyun Seo, Youngsu Kim, Jae-Young Lee, Namho Hur, Heung Mook Kim
2017 conf
BMSB
Jaehwui Bae, JinHyuk Song, Jewon Lee, Dong-Joon Choi, Joonyoung Jung, Namho Hur
2016 conf
BMSB
Jaehwui Bae, JinHyuk Song, Sang-Jung Ra, Dong-Joon Choi, Namho Hur
2016 conf
ICTC
Sang-Jung Ra, JinHyuk Song, Jaehwui Bae, Joonyoung Jung, Namho Hur, Cheol-Sung Kim
2016 conf
BMSB
Sang-Jung Ra, JinHyuk Song, Jaehwui Bae, Joonyoung Jung, Dong-Joon Choi, Namho Hur, Cheol-Sung Kim
2016 conf
ICTC
Jaehwui Bae, JinHyuk Song, Sang-Jung Ra, Dong-Joon Choi, Joon-Young Jung, Namho Hur
2015 conf
ICCE-Berlin
Jaehwui Bae, Sang-Jung Ra, Jae-Ho Lee, Dong-Joon Choi, Namho Hur
2015 conf
ICTC
Jaehwui Bae, JinHyuk Song, Sang-Jung Ra, Dong-Joon Choi, Namho Hur
2012 conf
ICTC
Jaehwui Bae, Woongshik You, O-Hyung Kwon
2010 conf
VTC Fall
Junho Kim, Hojun Kim, Taejin Jung, Jaehwui Bae, Gwangsoon Lee
2009 B conf
PIMRC
Youngsu Kim, Jaehwui Bae, Jong Soo Lim, Yun Jeong Song, Soo In Lee
2008 conf
VTC Fall
Jaehwui Bae, Youngsu Kim, Ju Yeun Kim, Jong Soo Lim, Soo In Lee, Dong-Seog Han
2007 J jnl
IEEE Trans. Consumer Electron.
Jaehwui Bae, Youngsu Kim, Jong Soo Lim, Soo In Lee, Dong-Seog Han
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"