James Anderson

113 papers A* 5A 1C 12Journal 70Unranked 25
YearRankTypeTitle / Venue / Authors
2026 J jnl
CoRR
Leonardo F. Toso, Davit Shadunts, Yunyang Lu, Nihal Sharma, Donglin Zhan, Nam H. Nguyen, James Anderson
2026 J jnl
Trans. Mach. Learn. Res.
Han Wang, Leonardo Felipe Toso, Aritra Mitra, James Anderson
2025 J jnl
CoRR
Ming Yi, Yiqian Wu, Saud Alghumayjan, James Anderson, Bolun Xu
2025 J jnl
CoRR
Kasra Fallah, Leonardo F. Toso, James Anderson
2025 J jnl
INFORMS J. Comput.
Haoting Zhang, Donglin Zhan, James Anderson, Rhonda Righter, Zeyu Zheng
2025 conf
CDC
Donglin Zhan, Haoting Zhang, Rhonda Righter, Zeyu Zheng, James Anderson
2025 J jnl
CoRR
Donglin Zhan, Haoting Zhang, Rhonda Righter, Zeyu Zheng, James Anderson
2025 conf
CDC
Donglin Zhan, Leonardo F. Toso, James Anderson
2025 J jnl
CoRR
Donglin Zhan, Leonardo F. Toso, James Anderson
2025 J jnl
Computer
Diman Zad Tootaghaj, Yiqian Wu, Ting He, Nilanjan Ray Chaudhuri, Dejan S. Milojicic, Luka V. Strezoski, James Anderson, Puneet Sharma
2025 J jnl
CoRR
Yiqian Wu, Bolun Xu, James Anderson
2025 conf
CDC
Leonardo F. Toso, Lintao Ye, James Anderson
2025 J jnl
CoRR
Leonardo F. Toso, Lintao Ye, James Anderson
2025 J jnl
IEEE Trans. Smart Grid
Yiqian Wu, Jip Kim, Siddharth Bhela, Gil Zussman, James Anderson
2025 J jnl
CoRR
Kasra Fallah, Leonardo F. Toso, James Anderson
2025 J jnl
CoRR
Yiqian Wu, Ming Yi, Bolun Xu, James Anderson
2025 J jnl
CoRR
Anna Scampicchio, Leonardo F. Toso, Rahel Rickenbach, James Anderson, Melanie N. Zeilinger
2025 J jnl
CoRR
Charis J. Stamouli, Leonardo F. Toso, Anastasios Tsiamis, George J. Pappas, James Anderson
2025 J jnl
IEEE Control. Syst. Lett.
Charis J. Stamouli, Leonardo F. Toso, Anastasios Tsiamis, George J. Pappas, James Anderson
2025 A* conf
AAAI
Bruce D. Lee, Leonardo F. Toso, Thomas T. Zhang, James Anderson, Nikolai Matni
2024 conf
CDC
Leonardo F. Toso, Han Wang, James Anderson
2024 conf
CVPR Workshops
Donglin Zhan, James Anderson
2024 J jnl
CoRR
Donglin Zhan, James Anderson
2024 J jnl
Trans. Mach. Learn. Res.
Han Wang, Aritra Mitra, Hamed Hassani, George J. Pappas, James Anderson
2024 A* conf
ICLR
Chenyu Zhang, Han Wang, Aritra Mitra, James Anderson
2024 J jnl
CoRR
Chenyu Zhang, Han Wang, Aritra Mitra, James Anderson
2024 conf
CDC
Yiqian Wu, Bolun Xu, James Anderson
2024 J jnl
CoRR
Yiqian Wu, Bolun Xu, James Anderson
2024 A conf
SDM
Donglin Zhan, Yusheng Dai, Yiwei Dong, Jinghai He, Zhenyi Wang, James Anderson
2024 J jnl
CoRR
Leonardo F. Toso, Donglin Zhan, James Anderson, Han Wang
2024 conf
L4DC
Leonardo Felipe Toso, Donglin Zhan, James Anderson, Han Wang
2024 A* conf
ICML
Han Wang, Sihong He, Zhili Zhang, Fei Miao, James Anderson
2024 J jnl
CoRR
Han Wang, Sihong He, Zhili Zhang, Fei Miao, James Anderson
2024 C conf
ACC
Leonardo F. Toso, Han Wang, James Anderson
2024 J jnl
IEEE Trans. Control. Netw. Syst.
Gal Morgenstern, Jip Kim, James Anderson, Gil Zussman, Tirza Routtenberg
2024 J jnl
CoRR
Bruce D. Lee, Leonardo F. Toso, Thomas T. C. K. Zhang, James Anderson, Nikolai Matni
2024 A* conf
ICLR
Thomas T. C. K. Zhang, Leonardo Felipe Toso, James Anderson, Nikolai Matni
2023 J jnl
IEEE Trans. Control. Netw. Syst.
Carmen Amo Alonso, Jing Shuang Li, Nikolai Matni, James Anderson
2023 J jnl
IEEE Trans. Control. Netw. Syst.
Carmen Amo Alonso, Jing Shuang Li, James Anderson, Nikolai Matni
2023 conf
L4DC
Han Wang, Leonardo Felipe Toso, James Anderson
2023 J jnl
CoRR
Han Wang, Aritra Mitra, Hamed Hassani, George J. Pappas, James Anderson
2023 A* conf
NeurIPS
Guangchen Lan, Han Wang, James Anderson, Christopher G. Brinton, Vaneet Aggarwal
2023 J jnl
CoRR
Guangchen Lan, Han Wang, James Anderson, Christopher G. Brinton, Vaneet Aggarwal
2023 C conf
SSS
Gal Morgenstern, Lital Dabush, Jip Kim, James Anderson, Gil Zussman, Tirza Routtenberg
2023 conf
CDC
Leonardo F. Toso, Han Wang, James Anderson
2023 J jnl
CoRR
Leonardo Felipe Toso, Han Wang, James Anderson
2023 J jnl
CoRR
Thomas T. C. K. Zhang, Leonardo Felipe Toso, James Anderson, Nikolai Matni
2023 J jnl
CoRR
Leonardo Felipe Toso, Han Wang, James Anderson
2023 J jnl
CoRR
Gal Morgenstern, Jip Kim, James Anderson, Gil Zussman, Tirza Routtenberg
2022 J jnl
CoRR
Carmen Amo Alonso, Jing Shuang Li, Nikolai Matni, James Anderson
2022 conf
CDC
Yuxiao Chen, Jip Kim, James Anderson
2022 J jnl
CoRR
Yuxiao Chen, Jip Kim, James Anderson
2022 J jnl
CoRR
Han Wang, Siddartha Marella, James Anderson
2022 conf
CDC
Han Wang, Siddartha Marella, James Anderson
2022 J jnl
CoRR
Han Wang, Leonardo Felipe Toso, James Anderson
2022 conf
SmartGridComm
Jip Kim, Siddharth Bhela, James Anderson, Gil Zussman
2022 J jnl
CoRR
Jip Kim, Siddharth Bhela, James Anderson, Gil Zussman
2022 C conf
ACC
Han Wang, James Anderson
2022 conf
L4DC
Han Wang, James Anderson
2022 J jnl
CoRR
Yiqian Wu, Jip Kim, James Anderson
2021 J jnl
CoRR
Han Wang, James Anderson
2021 J jnl
CoRR
Han Wang, James Anderson
2021 C conf
ACC
Jing Yu, Yuh-Shyang Wang, James Anderson
2021 J jnl
IEEE Trans. Control. Netw. Syst.
Yuxiao Chen, James Anderson, Karanjit Kalsi, Aaron D. Ames, Steven H. Low
2021 J jnl
IEEE Trans. Control. Netw. Syst.
Fengyu Zhou, James Anderson, Steven H. Low
2020 C conf
ACC
Shih-Hao Tseng, James Anderson
2020 conf
CDC
Carmen Amo Alonso, Nikolai Matni, James Anderson
2020 J jnl
CoRR
Carmen Amo Alonso, Nikolai Matni, James Anderson
2020 J jnl
CoRR
Jing Yu, Yuh-Shyang Wang, James Anderson
2020 J jnl
CoRR
Shih-Hao Tseng, James Anderson
2020 C conf
ACC
James Anderson, Fengyu Zhou, Steven H. Low
2020 J jnl
CoRR
James Anderson, Fengyu Zhou, Steven H. Low
2019 C conf
ACC
Yuxiao Chen, James Anderson, Karan Kalsi, Steven H. Low, Aaron D. Ames
2019 J jnl
CoRR
Shih-Hao Tseng, James Anderson
2019 C conf
ACC
Fengyu Zhou, James Anderson, Steven H. Low
2019 J jnl
CoRR
Fengyu Zhou, James Anderson, Steven H. Low
2019 J jnl
CoRR
Yuxiao Chen, James Anderson, Karan Kalsi, Aaron D. Ames, Steven H. Low
2019 J jnl
CoRR
James Anderson, Nikolai Matni, Yuxiao Chen
2019 conf
CDC
Yuxiao Chen, James Anderson
2019 J jnl
CoRR
Yuxiao Chen, James Anderson
2019 J jnl
CoRR
James Anderson, John C. Doyle, Steven H. Low, Nikolai Matni
2019 J jnl
Annu. Rev. Control.
James Anderson, John C. Doyle, Steven H. Low, Nikolai Matni
2019 J jnl
CoRR
Fengyu Zhou, James Anderson, Steven H. Low
2018 J jnl
CoRR
Yuxiao Chen, James Anderson, Karan Kalsi, Steven H. Low, Aaron D. Ames
2017 J jnl
CoRR
James Anderson
2017 conf
CDC
James Anderson
2017 J jnl
Autom.
Giorgio Valmorbida, James Anderson
2017 conf
CDC
Nikolai Matni, Yuh-Shyang Wang, James Anderson
2017 J jnl
IEEE Trans. Autom. Control.
Aivar Sootla, James Anderson
2017 conf
Allerton
James Anderson, Nikolai Matni
2017 conf
CDC
John C. Doyle, Nikolai Matni, Yuh Shyang Wang, James Anderson, Steven H. Low
2016 C conf
ACC
Dhruva V. Raman, James Anderson, Antonis Papachristodoulou
2016 J jnl
CoRR
Aivar Sootla, James Anderson
2016 C conf
ACC
Aivar Sootla, James Anderson
2016 J jnl
Autom.
Dhruva V. Raman, James Anderson, Antonis Papachristodoulou
2016 J jnl
CoRR
Giorgio Valmorbida, James Anderson
2015 J jnl
CoRR
Giorgio Valmorbida, Dhruva V. Raman, James Anderson
2015 J jnl
IEEE Trans. Biomed. Circuits Syst.
Andreas W. K. Harris, James Dolan, Ciaran L. Kelly, James Anderson, Antonis Papachristodoulou
2015 J jnl
CoRR
Aivar Sootla, James Anderson
2014 J jnl
CoRR
Aivar Sootla, James Anderson
2014 J jnl
CoRR
Aivar Sootla, James Anderson
2014 conf
CDC
Aivar Sootla, James Anderson
2014 conf
CDC
Aivar Sootla, James Anderson
2014 C conf
ACC
Giorgio Valmorbida, James Anderson
2013 J jnl
CoRR
Antonis Papachristodoulou, James Anderson, Giorgio Valmorbida, Stephen Prajna, Pete Seiler, Pablo A. Parrilo
2012 J jnl
IEEE Trans. Autom. Control.
James Anderson, Antonis Papachristodoulou
2012 conf
CDC
James Dolan, James Anderson, Antonis Papachristodoulou
2011 conf
CDC/ECC
James Anderson, André Teixeira, Henrik Sandberg, Antonis Papachristodoulou
2011 J jnl
Autom.
James Anderson, Yo-Cheng Chang, Antonis Papachristodoulou
2010 C conf
ACC
James Anderson, Antonis Papachristodoulou
2010 conf
CDC
James Anderson, Antonis Papachristodoulou
2010 conf
CDC
Antonis Papachristodoulou, Yo-Cheng Chang, Elias August, James Anderson
2009 J jnl
BMC Bioinform.
James Anderson, Antonis Papachristodoulou
redb/extractors/capa.py
← Index redb/extractors/capa.py python
from dataclasses import asdict
import inspect
import json
import subprocess
import magic
from magika import Magika
from typing import Any, Dict, List, Tuple
from datetime import datetime, timezone

from redb.extractors.enum import Tag
from redb.models.dataclasses import CAPA
from redb.extractors.extractor import Extractor
from dotenv import load_dotenv
import os

load_dotenv(override=True)

class CAPAExtractor(Extractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
    ):
        super().__init__(
            filepath, 
            log, 
            exporters,
            index_prefix, 
            elastic_index, 
            known_benign, 
            known_malicious
        )
        self.capa = None
        self.elastic_index = self.index_prefix + "-capa"

    def _replace_empty_keys(self, dictionary, replacement="default_empty_key"):
        """
        Replace empty keys in a dictionary with a specified replacement.

        Args:
        dictionary (dict): The input dictionary
        replacement (str): The replacement for empty keys (default: 'empty_key')

        Returns:
        dict: A new dictionary with empty keys replaced
        """
        # tmp_dict = {}
        # for k, v in dictionary.items():
        #     if k == '':
        #         tmp_dict[replacement] = dictionary[k]
        #     else:
        #         tmp_dict[k] = dictionary[k]
        # return tmp_dict
        return {(replacement if k == "" else k): v for k, v in dictionary.items()}

    def _extract_capa(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        TIMEOUT = int(os.getenv("CAPA_TIMEOUT")) # 5 minutes in seconds
        capa_command = [os.getenv("CAPA_PATH"), "-j", self.filepath] # COMMENT FOR TESTING ON MAC

        import signal

        # try:
        #     result = subprocess.run(
        #         capa_command, capture_output=True, text=True, check=True, timeout=TIMEOUT
        #     )
        # except subprocess.TimeoutExpired:
        #     self.log.error(f"The capa command timed out after {TIMEOUT} seconds")
        #     return {}
        # except subprocess.CalledProcessError as e:
        #     self.log.error(f"Error running capa: {e}")
        #     return {}

        # try:
        #     capa_output = json.loads(result.stdout)
        # except json.JSONDecodeError as e:
        #     self.log.error("Error parsing capa output: {e}")
        #     return {}

        # Create a process group for easier termination of all child processes
        try:
            # Start the process in a new process group
            process = subprocess.Popen(
                capa_command,
                stdout=subprocess.PIPE,
                stderr=subprocess.PIPE,
                text=True,
                preexec_fn=os.setsid  # Use os.setsid() to create a new process group
            )
            
            # Implement timeout handling manually
            try:
                stdout, stderr = process.communicate(timeout=TIMEOUT)
                # Process completed within timeout
                if process.returncode != 0:
                    self.log.error(f"Error running capa, return code: {process.returncode}, stderr: {stderr}")
                    return {}
            except subprocess.TimeoutExpired:
                # Kill the entire process group on timeout
                self.log.warning(f"The capa command timed out after {TIMEOUT} seconds, terminating process group")
                
                try:
                    # Send SIGTERM to the entire process group
                    os.killpg(process.pid, signal.SIGTERM)
                    
                    # Give it a moment to terminate gracefully
                    try:
                        process.wait(timeout=3)
                    except subprocess.TimeoutExpired:
                        # If it's still running after 3 seconds, send SIGKILL
                        self.log.warning("Process didn't terminate with SIGTERM, sending SIGKILL")
                        os.killpg(process.pid, signal.SIGKILL)
                        
                    process.wait()  # Make sure process resources are fully cleaned up
                except (ProcessLookupError, OSError) as e:
                    self.log.warning(f"Error while killing process: {e}")
                    
                return {}
                
            try:
                capa_output = json.loads(stdout)
            except json.JSONDecodeError as e:
                self.log.error(f"Error parsing capa output: {e}")
                return {}

            capa_dump = {}  # dictionalry of capabilities
            capabilities = set()  # list of capabilities
            namespaces = set()  # list of namespaces
            attack_dump = {}  # dictionary of tuples [tactic](technique, technique_id)
            tactics = set()  # list of tactics
            techniques = set()  # list of techniques
            techniques_id = set()  # list of techniques_id
            mbc_dump = {}  # dictionary of tuples [objective](behavior, behavior_id)
            mbc_objectives = set()  # list of objectives
            mbc_behaviors = set()  # list of behaviors
            mbc_behaviors_id = set()  # list of behaviors_id

            if isinstance(capa_output, dict) and "rules" in capa_output:
                rules = capa_output["rules"]
                if isinstance(rules, dict):
                    for rule_name, rule_data in rules.items():
                        if isinstance(rule_data, dict) and "meta" in rule_data:
                            meta = rule_data["meta"]
                            if isinstance(meta, dict):
                                # Process capabilities
                                namespace = meta.get("namespace", "").lower()
                                # if namespace != 'lib':
                                if namespace not in capa_dump:
                                    capa_dump[namespace] = []
                                    namespaces.add(namespace)
                                capa_dump[namespace].append(rule_name)
                                capabilities.add(rule_name)

                                # Process ATTACK information
                                if "attack" in meta:
                                    for attack_entry in meta["attack"]:
                                        tactic = attack_entry.get("tactic", "")
                                        technique = attack_entry.get("technique", "")
                                        id = attack_entry.get("id", "")
                                        if tactic and technique:
                                            if tactic in attack_dump:
                                                attack_dump[tactic].append((technique, id))
                                            else:
                                                attack_dump[tactic] = [(technique, id)]
                                            tactics.add(tactic)
                                            techniques.add(technique)
                                            techniques_id.add(id)

                                # Process MBC information
                                if "mbc" in meta:
                                    for mbc_entry in meta["mbc"]:
                                        objective = mbc_entry.get("objective", "")
                                        behavior = mbc_entry.get("behavior", "")
                                        id = mbc_entry.get("id", "")
                                        if objective and behavior:
                                            if objective in mbc_dump:
                                                mbc_dump[objective].append((behavior, id))
                                            else:
                                                mbc_dump[objective] = [(behavior, id)]
                                            mbc_objectives.add(objective)
                                            mbc_behaviors.add(behavior)
                                            mbc_behaviors_id.add(id)

            # return {
            #     'capabilities_all': json.dumps(capabilities_all, indent=2),
            #     'capabilities': list(capabilities),
            #     'namespaces': list(namespaces),
            #     'attack': json.dumps(attack, indent=2),
            #     'tactics': list(tactics),
            #     'techniques': list(techniques),
            #     'techniques_id': list(techniques_id),
            #     'mbc': json.dumps(mbc, indent=2),
            #     'mbc_objectives': list(mbc_objectives),
            #     'mbc_behaviors': list(mbc_behaviors),
            #     'mbc_behaviors_id': list(mbc_behaviors_id)
            # }

            capa_dump = self._replace_empty_keys(capa_dump)
            attack_dump = self._replace_empty_keys(attack_dump)
            mbc_dump = self._replace_empty_keys(mbc_dump)
            self.capa = CAPA(
                json.dumps(capa_dump, indent=2),
                list(capabilities),
                list(namespaces),
                json.dumps(attack_dump, indent=2),
                list(tactics),
                list(techniques),
                list(techniques_id),
                json.dumps(mbc_dump, indent=2),
                list(mbc_objectives),
                list(mbc_behaviors),
                list(mbc_behaviors_id),
            )
            self.log.debug(f"CAPA dump: {self.capa})")
            
        except Exception as e:
            self.log.error(f"Unexpected error in CAPA extraction: {str(e)}")
            # Try to clean up any process if possible
            if 'process' in locals() and process.poll() is None:
                try:
                    os.killpg(process.pid, signal.SIGKILL)
                    process.wait()
                except:
                    pass
            return {}

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.capa
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)
            
            # Prepare data for multiple tables
            tables_data = {
                'multi_table': True,  # Flag for multi-table export
                
                # Raw data table
                'raw': {
                    'table': 'redb_capa',
                    'data': [[
                        self.sha256,
                        self.md5,
                        self.sha1,
                        current_time,
                        self.capa.capa_dump,  # capa_dump
                        self.capa.attack_dump,            # attack_dump
                        self.capa.mbc_dump                # mbc_dump
                    ]],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'capa_dump', 'attack_dump', 'mbc_dump'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'JSON', 'JSON', 'JSON'
                    ]
                },
                
                # Capabilities table
                'capabilities': {
                    'table': 'redb_capa_capabilities',
                    'data': [
                        [self.sha256, self.md5, self.sha1, current_time, namespace, capability]
                        for namespace, capabilities in json.loads(self.capa.capa_dump).items()
                        for capability in capabilities
                    ],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'namespace', 'capability'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'LowCardinality(String)', 'LowCardinality(String)'
                    ]
                },
                
                # MITRE ATT&CK table
                'attack': {
                    'table': 'redb_capa_attack',
                    'data': [
                        [self.sha256, self.md5, self.sha1, current_time, 
                         tactic, technique[0], technique[1]]  # technique[0] is the name, technique[1] is the ID
                        for tactic, techniques in json.loads(self.capa.attack_dump).items()
                        for technique in techniques
                    ],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'tactic', 'technique', 'technique_id'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'LowCardinality(String)', 'LowCardinality(String)', 
                        'LowCardinality(String)'
                    ]
                },
                
                # MBC table
                'mbc': {
                    'table': 'redb_capa_mbc',
                    'data': [
                        [self.sha256, self.md5, self.sha1, current_time,
                         objective, behavior[0], behavior[1]]  # behavior[0] is the name, behavior[1] is the ID
                        for objective, behaviors in json.loads(self.capa.mbc_dump).items()
                        for behavior in behaviors
                    ],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'objective', 'behavior', 'behavior_id'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'LowCardinality(String)', 'LowCardinality(String)',
                        'LowCardinality(String)'
                    ]
                }
            }
            
            return tables_data

    def get_clickhouse_table(self) -> str:
        return "redb_capa"  # Return the main table name

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            self._extract_capa()
            return self.capa  # Return the extracted data instead of exporting directly
        except Exception as e:
            self.log.error(f"Error extracting CAPA: {e}")
            return None

    def tag(self):
        return Tag.CAPA.value