Jaime A. Pavlich-Mariscal

27 papers A 1B 2C 3Journal 13Unranked 8
YearRankTypeTitle / Venue / Authors
2025 J jnl
SoftwareX
Geraldine Gómez-Millán, Claudia Huguett-Aragón, Jennifer A. Méndez-Romero, Jaime A. Pavlich-Mariscal, Andrés Moreno, Zulma M. Cucunubá
2021 J jnl
Technol. Knowl. Learn.
Alexandra Ramos Marroquin, Karen Sommer Henao, Javier Sandoval Albarracín, Carlos Parra, Angela Carrillo Ramos, Juan Jesús Arenas, Mónica Brijaldo, Mariela J. Curiel H., Jaime A. Pavlich-Mariscal, Juan E. Gómez-Morantes, Martha Sabogal
2019 J jnl
Int. J. Web Inf. Syst.
Juan Camilo González-Vargas, Angela Carrillo Ramos, Ramón Fabregat, Lizzeth Camargo, Maria Caridad García Cepero, Jaime A. Pavlich-Mariscal
2018 J jnl
Int. J. Web Inf. Syst.
Luis Fernando Morales-Alzate, Clara Mabel Solano-Vanegas, Angela Carrillo Ramos, Jairo R. Montoya-Torres, Ramón Fabregat, Jaime A. Pavlich-Mariscal
2018 conf
CIbSE
José Bocanegra, Luis Hernán García Paucar, Jaime A. Pavlich-Mariscal, Nelly Bencomo
2016 J jnl
Int. J. Web Inf. Syst.
María Consuelo Franky, Jaime A. Pavlich-Mariscal, Maria Catalina Acero, Angee Zambrano, John C. Olarte, Jorge Camargo, Nicolás Pinzón
2016 J jnl
Int. J. Web Inf. Syst.
Luisa Fernanda Barrera-León, Nadia Alejandra Mejia-Molina, Angela Carrillo Ramos, Leonardo Floréz-Valencia, Jaime A. Pavlich-Mariscal
2015 conf
CSEDU (1)
Jaime A. Pavlich-Mariscal, Yolima Uribe, Luisa Fernanda Barrera-León, Nadia Alejandra Mejia-Molina, Angela Carrillo Ramos, Alexandra Pomares-Quimbaya, Mónica Brijaldo, Martha Sabogal, Rosa Maria Vicari, Hervé Martin
2015 J jnl
ACM SIGSOFT Softw. Eng. Notes
María Consuelo Franky, Jaime A. Pavlich-Mariscal, Leonardo Giral, Andrea Barraza-Urbina, Luisa Fernanda Barrera, Angee Zambrano
2015 C conf
WEBIST
Jaime A. Pavlich-Mariscal, Yolima Uribe, Luisa Fernanda Barrera-León, Nadia Alejandra Mejia-Molina, Angela Carrillo Ramos, Alexandra Pomares-Quimbaya, Rosa Maria Vicari, Ramón Fabregat, Silvia Baldiris
2015 conf
CSEDU (Selected Papers)
Jaime A. Pavlich-Mariscal, Mery Yolima Uribe Rios, Luisa Fernanda Barrera-León, Nadia Alejandra Mejia-Molina, Angela Carrillo Ramos, Alexandra Pomares-Quimbaya, Juan Camilo González-Vargas, Mónica Brijaldo, Martha Sabogal, Rosa Vicari, Ramón Fabregat, Hervé Martin
2015 J jnl
Int. J. Web Inf. Syst.
Diana Janeth Lancheros Cuesta, Angela Carrillo Ramos, Jaime A. Pavlich-Mariscal
2015 C conf
WEBIST
José Bocanegra, Jaime A. Pavlich-Mariscal, Angela Carrillo Ramos
2014 J jnl
Int. J. Web Inf. Syst.
Diana Janeth Lancheros Cuesta, Angela Carrillo Ramos, Jaime A. Pavlich-Mariscal
2014 conf
WEBIST (2)
Luisa Fernanda Barrera, Angela Carrillo Ramos, Leonardo Floréz-Valencia, Jaime A. Pavlich-Mariscal, Nadia Alejandra Mejia-Molina
2013 J jnl
Rev. Avances en Sistemas Informática
María Paula Arias-Báez, Jaime A. Pavlich-Mariscal, Angela Carrillo Ramos
2012 conf
BIBM Workshops
Alberto De la Rosa Algarin, Steven A. Demurjian, Solomon Berhe, Jaime A. Pavlich-Mariscal
2012 J jnl
Rev. Avances en Sistemas Informática
Diana Janeth Lancheros Cuesta, Angela Carrillo Ramos, Jaime A. Pavlich-Mariscal
2012 C conf
CLEI
María Consuelo Franky, Jaime A. Pavlich-Mariscal
2012 conf
CLEI Selected Papers
Jaime A. Pavlich-Mariscal, María Consuelo Franky, Ariel Lopez
2011 B conf
DBSec
Solomon Berhe, Steven A. Demurjian, Swapna S. Gokhale, Jaime A. Pavlich-Mariscal, Rishi Saripalle
2010 J jnl
Comput. Secur.
Jaime A. Pavlich-Mariscal, Steven A. Demurjian, Laurent D. Michel
2010 J jnl
Comput. Secur.
Jaime A. Pavlich-Mariscal, Steven A. Demurjian, Laurent D. Michel
2008 conf
SCCC
Jaime A. Pavlich-Mariscal, Steven A. Demurjian, Laurent D. Michel
2005 A conf
MoDELS
Jaime A. Pavlich-Mariscal, Laurent Michel, Steven A. Demurjian
2005 conf
MoDELS (Satellite Events)
Jaime A. Pavlich-Mariscal, Steven A. Demurjian, Laurent D. Michel
2005 B conf
DBSec
Jaime A. Pavlich-Mariscal, Thuong Doan, Laurent Michel, Steven A. Demurjian, T. C. Ting
redb/extractors/decompiler/_archive/GhidraDecompilerScript-latest.java
← Index redb/extractors/decompiler/_archive/GhidraDecompilerScript-latest.java java
import ghidra.app.script.GhidraScript;
import ghidra.program.model.listing.*;
import ghidra.app.decompiler.*;
import ghidra.program.model.block.*;
import ghidra.program.model.symbol.*;
import ghidra.program.model.pcode.*;
import ghidra.program.model.address.*;
import org.json.JSONObject;
import org.json.JSONArray;
import java.security.MessageDigest;
import java.nio.charset.StandardCharsets;

public class GhidraDecompilerScript extends GhidraScript {
    private DecompInterface decompInterface;
    private BasicBlockModel basicBlockModel;
    
    @Override
    public void run() throws Exception {
        // Get binary hash and filepath from arguments
        String[] args = getScriptArgs();
        if (args.length < 2) {
            System.err.println("{\"error\": \"Both SHA256 and filepath arguments are required\"}");
            return;
        }
        String sha256 = args[0];
        String filepath = args[1];

        // Initialize analysis components
        setupDecompiler();
        basicBlockModel = new BasicBlockModel(currentProgram);

        // Create the main JSON object for output
        JSONObject output = new JSONObject();
        output.put("sha256", sha256);
        output.put("decompiled", new JSONArray());
        output.put("disassembled", new JSONArray());
        output.put("cfg", new JSONArray());

        // Process all functions
        FunctionIterator functions = currentProgram.getFunctionManager().getFunctions(true);
        for (Function function : functions) {
            processFunction(function, output);
        }

        // Output the final JSON to stdout
        System.out.println(output.toString());
    }

    private void setupDecompiler() {
        decompInterface = new DecompInterface();
        DecompileOptions options = new DecompileOptions();
        decompInterface.setOptions(options);
        decompInterface.openProgram(currentProgram);
    }

    private void processFunction(Function function, JSONObject output) {
        Address entry = function.getEntryPoint();
        String functionName = function.getName();
        String functionAddress = entry.toString();

        // Process decompiled code
        processDecompiledCode(function, output.getJSONArray("decompiled"), 
                            functionName, functionAddress);

        // Process disassembled code
        processDisassembledCode(function, output.getJSONArray("disassembled"), 
                              functionName, functionAddress);

        // Process CFG
        processCFG(function, output.getJSONArray("cfg"), functionAddress);
    }

    private void processDecompiledCode(Function function, JSONArray decompArray, 
                                     String functionName, String functionAddress) {
        DecompileResults results = decompInterface.decompileFunction(function, 30, monitor);
        if (results.decompileCompleted()) {
            String decompiledCode = results.getDecompiledFunction().getC();
            String contentHash = calculateHash(decompiledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("decompiled_content_hash", contentHash);
            functionObj.put("decompiled_function_name", functionName);
            functionObj.put("decompiled_function_address", functionAddress);
            functionObj.put("decompiled_function", decompiledCode);
            
            decompArray.put(functionObj);
        }
    }

    private void processDisassembledCode(Function function, JSONArray disasmArray, 
                                       String functionName, String functionAddress) {
        try {
            StringBuilder disassembly = new StringBuilder();
            StringBuilder normalized = new StringBuilder();
            int instructionCount = 0;

            Listing listing = currentProgram.getListing();
            AddressSetView functionBody = function.getBody();
            InstructionIterator instructions = listing.getInstructions(functionBody, true);

            while (instructions.hasNext()) {
                try {
                    Instruction instr = instructions.next();
                    String disasmLine = instr.toString();
                    disassembly.append(disasmLine).append("\n");
                    normalized.append(normalizeInstruction(disasmLine)).append("\n");
                    instructionCount++;
                } catch (Exception e) {
                    System.err.println("Error processing instruction in " + functionName + ": " + e.getMessage());
                }
            }

            String disassembledCode = disassembly.toString();
            String contentHash = calculateHash(disassembledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("disassembled_content_hash", contentHash);
            functionObj.put("disassembled_function_name", functionName);
            functionObj.put("disassembled_function_address", functionAddress);
            functionObj.put("disassembled_function", disassembledCode);
            functionObj.put("normalized_disassembly", normalized.toString());
            functionObj.put("instruction_count", instructionCount);

            // Set similarity-related fields to null for now
            functionObj.put("minhash_signature", JSONObject.NULL);
            functionObj.put("opcode_frequency_vector", JSONObject.NULL);
            functionObj.put("api_calls_vector", JSONObject.NULL);
            functionObj.put("instruction_embedding", JSONObject.NULL);

            disasmArray.put(functionObj);
        } catch (Exception e) {
            System.err.println("Error processing disassembly for " + functionName + ": " + e.getMessage());
        }
    }

    private void processCFG(Function function, JSONArray cfgArray, String functionAddress) {
        try {
            CodeBlockIterator blocks = basicBlockModel.getCodeBlocksContaining(
                function.getBody(), monitor);

            while (blocks.hasNext()) {
                CodeBlock block = blocks.next();
                String blockInstructions = getBlockInstructions(block);
                String blockId = calculateHash(blockInstructions);

                JSONObject blockObj = new JSONObject();
                blockObj.put("block_id", blockId);
                blockObj.put("function_address", functionAddress);
                blockObj.put("block_instructions", blockInstructions);

                // Get successor blocks
                CodeBlockReferenceIterator successors = block.getDestinations(monitor);
                JSONArray successorAddresses = new JSONArray();
                while (successors.hasNext()) {
                    CodeBlockReference ref = successors.next();
                    successorAddresses.put(ref.getDestinationAddress().toString());
                }
                blockObj.put("successor_blocks", successorAddresses);

                cfgArray.put(blockObj);
            }
        } catch (Exception e) {
            System.err.println("{\"error\": \"Error processing CFG: " + 
                             e.getMessage().replace("\"", "'") + "\"}");
        }
    }

    private String normalizeInstruction(String instruction) {
        return instruction.replaceAll("0x[0-9a-fA-F]+", "IMM")
                        .replaceAll("\\b\\d+\\b", "NUM");
    }

    private String getBlockInstructions(CodeBlock block) {
        StringBuilder instructions = new StringBuilder();
        AddressIterator addresses = block.getAddresses(true);
        while (addresses.hasNext()) {
            Address addr = addresses.next();
            Instruction instr = currentProgram.getListing().getInstructionAt(addr);
            if (instr != null) {
                instructions.append(instr.toString()).append("\n");
            }
        }
        return instructions.toString();
    }

    private String calculateHash(String content) {
        try {
            MessageDigest digest = MessageDigest.getInstance("SHA-256");
            byte[] hash = digest.digest(content.getBytes(StandardCharsets.UTF_8));
            StringBuilder hexString = new StringBuilder();
            for (byte b : hash) {
                hexString.append(String.format("%02x", b));
            }
            return hexString.toString();
        } catch (Exception e) {
            System.err.println("{\"error\": \"Error calculating hash\"}");
            return "";
        }
    }
}