Jafar Mohammadi

44 papers B 3Misc 1Journal 21Unranked 18
YearRankTypeTitle / Venue / Authors
2026 J jnl
CoRR
Pawani Porambage, Diego Lopez, Antonio Pastor, Bin Han, José María Jorquera Valero, Manuel Gil Pérez, Noelia Pérez Palma, Antonio F. Skarmeta, Prajnamaya Dass, Stefan Köpsell, Sonika Ujjwal, Javier Jose Diaz Rivera, Pol Alemany, Raul Muñoz, Jafar Mohammadi, Chaitanya Aggarwal, Betül Güvenç Paltun, Ferhat Karakoç
2025 conf
SaTML
Antti Koskela, Jafar Mohammadi
2025 J jnl
J. Sens. Actuator Networks
Chaitanya Aggarwal, Divya G. Nair, Jafar Mohammadi, Jyothisha J. Nair, Jörg Ott
2025 J jnl
IEEE Trans. Commun.
Dileepa Marasinghe, Le-Hang Nguyen, Jafar Mohammadi, Yejian Chen, Thorsten Wild, Nandana Rajatheva
2024 J jnl
CoRR
Antti Koskela, Jafar Mohammadi
2024 conf
ICC
Dileepa Marasinghe, Le-Hang Nguyen, Jafar Mohammadi, Yejian Chen, Thorsten Wild, Nandana Rajatheva
2024 J jnl
IEEE Trans. Veh. Technol.
Nuwanthika Rajapaksha, Jafar Mohammadi, Stefan Wesemann, Thorsten Wild, Nandana Rajatheva
2023 J jnl
Entropy
Naima Tasnim, Jafar Mohammadi, Anand D. Sarwate, Hafiz Imtiaz
2023 J jnl
CoRR
Dileepa Marasinghe, Le-Hang Nguyen, Jafar Mohammadi, Yejian Chen, Thorsten Wild, Nandana Rajatheva
2023 J jnl
IEEE Access
Mattia Merluzzi, Tamás Borsos, Nandana Rajatheva, András A. Benczúr, Hamed Farhadi, Taha Yassine, Markus Dominik Mueck, Sokratis Barmpounakis, Emilio Calvanese Strinati, Dilin Dampahalage, Panagiotis Demestichas, Pietro Ducange, Miltiadis C. Filippou, Leonardo Gomes Baltar, Johan Haraldson, Leyli Karaçay, Dani Korpi, Vasiliki Lamprousi, Francesco Marcelloni, Jafar Mohammadi, Nuwanthika Rajapaksha, Alessandro Renda, Mikko A. Uusitalo
2022 J jnl
IEEE Trans. Wirel. Commun.
Alessandro Brighente, Jafar Mohammadi, Paolo Baracca, Silvio Mandelli, Stefano Tomasin
2022 conf
AI6G@WCCI
Miltiadis C. Filippou, Vasiliki Lamprousi, Jafar Mohammadi, Mattia Merluzzi, Elif Ustundag Soykan, Tamás Borsos, Nandana Rajatheva, Nuwanthika Rajapaksha, Luc Le Magoarou, Pietro Piscione, András Benczúr, Quentin Lampin, Guillaume Larue, Dani Korpi, Pietro Ducange, Alessandro Renda, Hamed Farhadi, Johan Haraldson, Leonardo Gomes Baltar, Emilio Calvanese Strinati, Panagiotis Demestichas, Emrah Tomur
2022 B conf
PIMRC
Yejian Chen, Jafar Mohammadi, Stefan Wesemann, Thorsten Wild
2021 J jnl
IEEE Trans. Signal Process.
Hafiz Imtiaz, Jafar Mohammadi, Rogers F. Silva, Bradley T. Baker, Sergey M. Plis, Anand D. Sarwate, Vince D. Calhoun
2021 conf
WSA
Jafar Mohammadi, Gerhard Schreiber, Thorsten Wild, Yejian Chen
2021 J jnl
CoRR
Jafar Mohammadi, Gerhard Schreiber, Thorsten Wild, Yejian Chen
2021 conf
WSA
Mahmoud Ramezani-Mayiamiy, Jafar Mohammadi, Silvio Mandelli, Andreas Weber
2021 J jnl
CoRR
Alessandro Brighente, Jafar Mohammadi, Paolo Baracca, Silvio Mandelli, Stefano Tomasin
2021 conf
WSA
Silvio Mandelli, Andreas Weber, Paolo Baracca, Jafar Mohammadi
2021 conf
WSA
Yejian Chen, Jafar Mohammadi, Thorsten Wild
2021 conf
VTC Spring
Yejian Chen, Jafar Mohammadi, Stefan Wesemann, Thorsten Wild
2021 conf
VTC Spring
Yejian Chen, Jafar Mohammadi, Stefan Wesemann, Thorsten Wild
2020 J jnl
IEEE Access
Jafar Mohammadi, Firouz Badrkhani Ajaei
2020 conf
VTC Spring
Alessandro Brighente, Jafar Mohammadi, Paolo Baracca
2020 J jnl
CoRR
Alessandro Brighente, Jafar Mohammadi, Paolo Baracca
2019 J jnl
IEEE Access
Jafar Mohammadi, Firouz Badrkhani Ajaei
2019 J jnl
CoRR
Hafiz Imtiaz, Jafar Mohammadi, Anand D. Sarwate
2019 conf
VTC Fall
Yejian Chen, Silvio Mandelli, Marouan Mizmizi, Jafar Mohammadi
2019 J jnl
CoRR
Hafiz Imtiaz, Jafar Mohammadi, Rogers F. Silva, Bradley T. Baker, Sergey M. Plis, Anand D. Sarwate, Vince D. Calhoun
2019 J jnl
IEEE Access
Jafar Mohammadi, Firouz Badrkhani Ajaei
2017
Jafar Mohammadi
2016 conf
GLOBECOM Workshops
Ali A. Zaidi, Jian Luo, Robin Gerzaguet, Hua Wang, Xiaoming Chen, Yinan Qi, Nicolas Cassiau, Andreas Wolfgang, Jaakko Vihriälä, Anastasios Kakkavas, Tommy Svensson, Jafar Mohammadi, Richard J. Weiler, Michael Dieudonne, Hardy Halbauer, Vicent Moles-Cases, Honglei Miao
2016 B conf
ISIT
Igor Bjelakovic, Jafar Mohammadi, Slawomir Stanczak
2015 J jnl
CoRR
Steffen Limmer, Jafar Mohammadi, Slawomir Stanczak
2015 conf
Allerton
Steffen Limmer, Jafar Mohammadi, Slawomir Stanczak
2015 conf
ICC Workshops
Jafar Mohammadi, Slawomir Stanczak, Meng Zheng
2015 J jnl
CoRR
Igor Bjelakovic, Jafar Mohammadi, Slawomir Stanczak
2013 conf
ICC
Michal Kaliszan, Jafar Mohammadi, Slawomir Stanczak
2013 Misc conf
ACSSC
Jafar Mohammadi, Federico Penna, Slawomir Stanczak, Martin Kasparick
2013 J jnl
EURASIP J. Wirel. Commun. Netw.
Jafar Mohammadi, Feifei Gao, Yue Rong, Wen Chen
2012 conf
SPAWC
Meng Zheng, Jafar Mohammadi, Slawomir Stanczak, Haibin Yu
2012 conf
ACSCC
Jafar Mohammadi, Michal Kaliszan, Slawomir Stanczak, Jan Schreck
2011 conf
ISWCS
Jafar Mohammadi, Slawomir Stanczak, Renato L. G. Cavalcante, Jalal Etesami
2010 B conf
GLOBECOM
Jafar Mohammadi, Feifei Gao, Yue Rong
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |