James R. Zeidler

115 papers A* 1B 17Misc 17Journal 53Unranked 27
YearRankTypeTitle / Venue / Authors
2015 J jnl
IEEE Trans. Signal Process.
Ahsen U. Ahmed, James R. Zeidler
2013 J jnl
IEEE Trans. Wirel. Commun.
Sheu-Sheu Tan, James R. Zeidler, Bhaskar D. Rao
2013 J jnl
IEEE Trans. Wirel. Commun.
Sheu-Sheu Tan, James R. Zeidler, Bhaskar Rao
2013 Misc conf
ICASSP
Sheu-Sheu Tan, James R. Zeidler, Bhaskar Rao
2012 Misc conf
ICASSP
Sagnik Ghosh, Bhaskar D. Rao, James R. Zeidler
2012 conf
MILCOM
Ahsen U. Ahmed, Steve C. Thompson, David W. Chi, James R. Zeidler
2012 J jnl
IEEE Trans. Signal Process.
Sagnik Ghosh, Bhaskar D. Rao, James R. Zeidler
2011 J jnl
CoRR
Seong-Ho (Paul) Hur, Bhaskar D. Rao, Min-Joong Rim, James R. Zeidler
2010 J jnl
IEEE Trans. Wirel. Commun.
Kostas Stamatiou, John G. Proakis, James R. Zeidler
2010 A* conf
INFOCOM
Sheu-Sheu Tan, Dong Zheng, Junshan Zhang, James R. Zeidler
2010 J jnl
IEEE Trans. Signal Process.
Sagnik Ghosh, Bhaskar D. Rao, James R. Zeidler
2010 Misc conf
ICASSP
Sagnik Ghosh, Bhaskar D. Rao, James R. Zeidler
2009 conf
ICC
Ioannis Spyropoulos, James R. Zeidler
2009 B conf
WiOpt
Kostas Stamatiou, Francesco Rossetto, Martin Haenggi, Tara Javidi, James R. Zeidler, Michele Zorzi
2009 conf
ICC
Nathan Ricklin, James R. Zeidler
2009 J jnl
IEEE Trans. Commun.
Haichang Sui, James R. Zeidler
2009 Misc conf
ICASSP
Arun Batra, James R. Zeidler
2009 J jnl
IEEE Trans. Veh. Technol.
Ioannis Spyropoulos, James R. Zeidler
2008 J jnl
EURASIP J. Adv. Signal Process.
Arun Batra, James R. Zeidler, Aloysius A. Beex
2008 J jnl
IEEE Trans. Commun.
Steve C. Thompson, Ahsen U. Ahmed, John G. Proakis, James R. Zeidler, Michael J. Geile
2008 conf
ICC
Nathan Ricklin, James R. Zeidler
2008 conf
ACSCC
Adam L. Anderson, James R. Zeidler, Michael A. Jensen
2008 J jnl
IEEE Trans. Signal Process.
Takeshi Ikuma, Aloysius A. Beex, James R. Zeidler
2008 J jnl
IEEE Trans. Commun.
Jittra Jootar, James R. Zeidler, John G. Proakis
2008 J jnl
IEEE Trans. Commun.
Jittra Jootar, James R. Zeidler, John G. Proakis
2008 J jnl
IEEE J. Sel. Areas Commun.
Adam L. Anderson, James R. Zeidler, Michael A. Jensen
2008 conf
VTC Fall
Adam L. Anderson, James R. Zeidler, Michael A. Jensen
2008 conf
ACSCC
James R. Zeidler
2008 J jnl
EURASIP J. Adv. Signal Process.
Adam L. Anderson, James R. Zeidler, Michael A. Jensen
2007 J jnl
IEEE J. Sel. Areas Commun.
Haichang Sui, James R. Zeidler
2007 conf
VTC Spring
Ioannis Spyropoulos, James R. Zeidler
2007 B conf
GLOBECOM
Kostas Stamatiou, John G. Proakis, James R. Zeidler
2007 conf
ICC
Kostas Stamatiou, John G. Proakis, James R. Zeidler
2007 B conf
GLOBECOM
Arun Batra, James R. Zeidler, Aloysius A. Beex
2007 J jnl
IEEE Trans. Commun.
Tiejun Wang, John G. Proakis, James R. Zeidler
2007 conf
ICASSP (3)
Takeshi Ikuma, A. A. (Louis) Beex, James R. Zeidler
2006 B conf
PIMRC
Tiejun Wang, John G. Proakis, James R. Zeidler
2006 J jnl
IEEE Wirel. Commun.
Michele Zorzi, James R. Zeidler, Adam L. Anderson, Bhaskar Rao, John G. Proakis, A. Lee Swindlehurst, Michael A. Jensen, Srikanth V. Krishnamurthy
2006 conf
VTC Fall
Haichang Sui, James R. Zeidler
2006 conf
ICC
Haichang Sui, James R. Zeidler
2006 conf
EUSIPCO
Arun Batra, James R. Zeidler, A. A. (Louis) Beex
2006 conf
ICC
Jittra Jootar, James R. Zeidler, John G. Proakis
2006 J jnl
IEEE Trans. Wirel. Commun.
Tiejun Wang, John G. Proakis, Elias Masry, James R. Zeidler
2006 J jnl
IEEE Trans. Commun.
Jittra Jootar, James R. Zeidler, John G. Proakis
2006 J jnl
IEEE Trans. Commun.
Jittra Jootar, James R. Zeidler, John G. Proakis
2006 J jnl
IEEE Trans. Veh. Technol.
Jittra Jootar, Jean-Francois Diouris, James R. Zeidler
2006 J jnl
IEEE Signal Process. Mag.
Yingbo Hua, Urbashi Mitra, Brian M. Sadler, Dirk T. M. Slock, James R. Zeidler
2005 J jnl
IEEE Trans. Wirel. Commun.
Joe P. Burke, James R. Zeidler, Bhaskar D. Rao
2005 B conf
GLOBECOM
Haichang Sui, James R. Zeidler
2005 J jnl
IEEE Trans. Wirel. Commun.
Brian C. Banister, James R. Zeidler
2005 B conf
GLOBECOM
Tiejun Wang, John G. Proakis, James R. Zeidler
2005 B conf
PIMRC
Steve C. Thompson, John G. Proakis, James R. Zeidler
2005 B conf
WCNC
Jittra Jootar, James R. Zeidler, John G. Proakis
2005 B conf
WCNC
Tiejun Wang, John G. Proakis, James R. Zeidler
2005 B conf
GLOBECOM
Steve C. Thompson, John G. Proakis, James R. Zeidler
2004 conf
ICASSP (2)
A. A. (Louis) Beex, James R. Zeidler
2004 J jnl
IEEE Trans. Veh. Technol.
William Cooper, James R. Zeidler, Robert R. Bitmead
2004 J jnl
Proc. IEEE
Chad Schell, Stephen Paul Linder, James R. Zeidler
2003 J jnl
IEEE Trans. Signal Process.
Brian C. Banister, James R. Zeidler
2003 J jnl
IEEE J. Sel. Areas Commun.
Brian C. Banister, James R. Zeidler
2003 conf
SIP
Aloysius A. Beex, Rachel E. Goshorn, James R. Zeidler
2003 conf
ICASSP (6)
A. A. (Louis) Beex, James R. Zeidler
2003 conf
ISSPA (2)
A. A. (Louis) Beex, James R. Zeidler
2003 B conf
PIMRC
Tiejun Wang, John G. Proakis, James R. Zeidler
2003 B conf
GLOBECOM
Jittra Jootar, James R. Zeidler
2002 conf
ICC
Jianxia Luo, James R. Zeidler, John G. Proakis
2002 J jnl
IEEE Trans. Signal Process.
Paul C. Wei, Jun Han, James R. Zeidler, Walter H. Ku
2002 conf
DSP
A. A. (Louis) Beex, James R. Zeidler
2002 J jnl
IEEE Trans. Veh. Technol.
Jianxia Luo, James R. Zeidler, John G. Proakis
2002 J jnl
IEEE Trans. Commun.
Thomas L. Staley, Jianxia Luo, Walter H. Ku, James R. Zeidler
2002 conf
VTC Spring
Joseph P. Burke, James R. Zeidler
2002 J jnl
EURASIP J. Adv. Signal Process.
Jun Han, James R. Zeidler, Walter H. Ku
2002 J jnl
IEEE Trans. Veh. Technol.
William Cooper, James R. Zeidler, Stephen McLaughlin
2002 J jnl
IEEE Trans. Signal Process.
Brian C. Banister, James R. Zeidler
2001 B conf
GLOBECOM
Joseph P. Burke, James R. Zeidler
2001 B conf
GLOBECOM
Joseph P. Burke, James R. Zeidler
2001 B conf
GLOBECOM
Jianxia Luo, James R. Zeidler
2001 conf
VTC Fall
Jianxia Luo, James R. Zeidler
2001 J jnl
IEEE Trans. Commun.
Michael Reuter, Jeffery C. Allen, James R. Zeidler, Richard C. North
2001 J jnl
IEEE Trans. Veh. Technol.
Jianxia Luo, James R. Zeidler, Stephen McLaughlin
2001 J jnl
IEEE Trans. Veh. Technol.
Thomas L. Staley, Richard C. North, Jianxia Luo, Walter H. Ku, James R. Zeidler
2001 Misc conf
ICASSP
Brian C. Banister, James R. Zeidler
2001 B conf
GLOBECOM
Brian C. Banister, James R. Zeidler
2000 J jnl
IEEE Trans. Inf. Theory
Kevin J. Quirk, Laurence B. Milstein, James R. Zeidler
1999 J jnl
IEEE Trans. Signal Process.
Michael Reuter, James R. Zeidler
1999 conf
ICC
Jean-François Diouris, Steve McLaughlin, James R. Zeidler
1999 J jnl
Ann. des Télécommunications
Jean-François Diouris, Kouroch Mahdjoubi, James R. Zeidler, Joseph Sallxard
1998 Misc conf
ICASSP
Kevin J. Quirk, James R. Zeidler, Laurence B. Milstein
1998 J jnl
Ann. des Télécommunications
Jean-François Diouris, James R. Zeidler, Soodesh Buljore
1998 J jnl
IEEE Trans. Signal Process.
Roy A. Axford Jr., Laurence B. Milstein, James R. Zeidler
1997 J jnl
IEEE Trans. Signal Process.
Paul C. Wei, James R. Zeidler, Walter H. Ku
1997 J jnl
IEEE Trans. Signal Process.
Simon Haykin, Ali H. Sayed, James R. Zeidler, Paul Yee, Paul C. Wei
1997 J jnl
IEEE Trans. Image Process.
Pearse A. Ffrench, James R. Zeidler, Walter H. Ku
1997 Misc conf
ICASSP
Michael Reuter, James R. Zeidler
1997 conf
ICC (1)
Thomas L. Staley, Richard C. North, Walter H. Ku, James R. Zeidler
1997 B conf
PIMRC
Hisato Iwai, Soodesh Buljore, James R. Zeidler, Laurence B. Milstein
1995 J jnl
IEEE Trans. Signal Process.
Tarun Soni, James R. Zeidler, Walter H. Ku
1995 Misc conf
ICASSP
Michael Reuter, Richard C. North, James R. Zeidler
1994 J jnl
IEEE J. Sel. Areas Commun.
Paul C. Wei, James R. Zeidler, Walter H. Ku
1994 conf
ICIP (1)
Pearse A. Ffrench, James R. Zeidler, Walter H. Ku
1994 J jnl
IEEE Trans. Signal Process.
Kay-Cheung Chew, Tarun Soni, James R. Zeidler, Walter H. Ku
1994 conf
VBC
L. Jarrett Malone, James R. Zeidler, Walter H. Ku, David W. Yeung
1993 J jnl
IEEE Trans. Signal Process.
Richard C. North, James R. Zeidler, Walter H. Ku, Terence R. Albert
1993 J jnl
IEEE Trans. Image Process.
Tarun Soni, James R. Zeidler, Walter H. Ku
1993 conf
ICASSP (3)
Tarun Soni, James R. Zeidler, Walter H. Ku
1992 Misc conf
ICASSP
Richard C. North, James R. Zeidler, Terence R. Albert, Walter H. Ku
1992 Misc conf
ICASSP
Tarun Soni, James R. Zeidler, Walter H. Ku
1991 Misc conf
ICASSP
Richard C. North, James R. Zeidler, Walter H. Ku, Terence R. Albert
1991 Misc conf
ICASSP
Tarun Soni, Bhaskar D. Rao, James R. Zeidler, Walter H. Ku
1991 Misc conf
ICASSP
Kay-Cheung Chew, James R. Zeidler, Walter H. Ku
1990 J jnl
Proc. IEEE
James R. Zeidler
1981 Misc conf
ICASSP
Mauro J. Dentino, H. M. Huey, James R. Zeidler
1979 Misc conf
ICASSP
Terry Rickard, Mauro J. Dentino, James R. Zeidler
1979 Misc conf
ICASSP
Edgar H. Satorius, James R. Zeidler, S. Thomas Alexander
1978 Misc conf
ICASSP
S. Thomas Alexander, Edgar H. Satorius, James R. Zeidler
redb/extractors/apk_extractors/apk_inconsistency_tests.py
← Index redb/extractors/apk_extractors/apk_inconsistency_tests.py python
import inspect
import re
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKInconsistencyTests

# Emulator detection indicator strings
EMULATOR_INDICATORS = {
    "generic", "sdk", "google_sdk", "Emulator",
    "goldfish", "ranchu", "Andy", "Genymotion",
    "BlueStacks", "nox", "ttVM_Hdragon",
}

# Root detection indicator strings
ROOT_INDICATORS = {
    "/system/app/Superuser.apk",
    "/system/xbin/su",
    "/system/bin/su",
    "com.noshufou.android.su",
    "com.thirdparty.superuser",
    "eu.chainfire.supersu",
    "com.koushikdutta.superuser",
    "com.topjohnwu.magisk",
}

# Standard DEX filename pattern
STANDARD_DEX_PATTERN = re.compile(r"^classes\d*\.dex$")


class APKInconsistencyTestsExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.test_results = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_INCONSISTENCY_TESTS.value

    def _test_zip_bomb(self):
        """Check if any ZIP entry has compression ratio > 100:1."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            with zf:
                for info in zf.infolist():
                    if info.compress_size > 0:
                        ratio = info.file_size / info.compress_size
                        if ratio > 100:
                            return True
            return False
        except Exception as e:
            self.log.warning(f"Error in zip bomb test: {e}")
            return None

    def _test_zip_duplicate_entries(self):
        """Check for duplicate filenames in ZIP directory."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            with zf:
                names = [info.filename for info in zf.infolist()]
                return len(names) != len(set(names))
        except Exception as e:
            self.log.warning(f"Error in duplicate entries test: {e}")
            return None

    def _test_zip_path_traversal(self):
        """Check for path traversal (../) in ZIP entry names."""
        try:
            for f in self._list_files():
                if ".." in f or f.startswith("/"):
                    return True
            return False
        except Exception as e:
            self.log.warning(f"Error in path traversal test: {e}")
            return None

    def _test_zip_suspicious_timestamps(self):
        """Check for timestamps at epoch (1980) or in the future."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            now = datetime.now()
            with zf:
                for info in zf.infolist():
                    try:
                        dt = datetime(*info.date_time)
                        if dt.year <= 1980 or dt > now:
                            return True
                    except (ValueError, TypeError):
                        continue
            return False
        except Exception as e:
            self.log.warning(f"Error in suspicious timestamps test: {e}")
            return None

    def _test_hidden_dex_files(self):
        """Check for DEX files not matching classes*.dex pattern."""
        try:
            for f in self._list_files():
                if f.endswith(".dex"):
                    basename = f.split("/")[-1]
                    if not STANDARD_DEX_PATTERN.match(basename):
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in hidden DEX files test: {e}")
            return None

    def _test_manifest_component_mismatch(self):
        """Check for declared components that don't exist in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            # Get all class names from DEX
            dex_classes = set()
            try:
                from androguard.core.dex import DEX
                for dex_data in (self.apk.get_all_dex() or []):
                    try:
                        d = DEX(dex_data)
                        for cls in d.get_classes():
                            name = cls.get_name()
                            if name:
                                # Convert "Lcom/example/Foo;" to "com.example.Foo"
                                dex_classes.add(
                                    name[1:-1].replace("/", ".") if name.startswith("L") else name
                                )
                    except Exception:
                        continue
            except Exception:
                return None

            if not dex_classes:
                return None

            # Check manifest components against DEX classes
            components = []
            try:
                components.extend(self.apk.get_activities() or [])
                components.extend(self.apk.get_services() or [])
                components.extend(self.apk.get_receivers() or [])
                components.extend(self.apk.get_providers() or [])
            except Exception:
                return None

            for comp in components:
                if comp and comp not in dex_classes:
                    # Component might use a shorthand; check with package prefix
                    package = self.apk.get_package() or ""
                    full_name = package + comp if comp.startswith(".") else comp
                    if full_name not in dex_classes:
                        return True

            return False
        except Exception as e:
            self.log.warning(f"Error in manifest component mismatch test: {e}")
            return None

    def _test_debuggable_release(self):
        """Check android:debuggable=true combined with a release signature."""
        try:
            if not self._is_valid_apk():
                return None

            is_debuggable = self.apk.get_attribute_value(
                "application", "debuggable"
            ) == "true"

            if not is_debuggable:
                return False

            # Check if it has a signing certificate (release builds have certs)
            try:
                certs = self.apk.get_certificates()
                if certs and len(certs) > 0:
                    return True
            except Exception:
                pass

            return False
        except Exception as e:
            self.log.warning(f"Error in debuggable release test: {e}")
            return None

    def _get_dex_strings(self):
        """Get all string constants from DEX files."""
        all_strings = set()
        try:
            from androguard.core.dex import DEX
            for dex_data in (self.apk.get_all_dex() or []):
                try:
                    d = DEX(dex_data)
                    for s in d.get_strings():
                        if s:
                            all_strings.add(s)
                except Exception:
                    continue
        except Exception:
            pass
        return all_strings

    def _test_emulator_detection_strings(self):
        """Check for emulator detection patterns in DEX strings."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            for indicator in EMULATOR_INDICATORS:
                for s in dex_strings:
                    if indicator in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in emulator detection test: {e}")
            return None

    def _test_debugger_detection(self):
        """Check for debugger detection API calls in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            debugger_patterns = {
                "isDebuggerConnected",
                "waitingForDebugger",
                "Debug.isDebuggerConnected",
            }
            for pattern in debugger_patterns:
                for s in dex_strings:
                    if pattern in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in debugger detection test: {e}")
            return None

    def _test_root_detection(self):
        """Check for root detection patterns in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            for indicator in ROOT_INDICATORS:
                for s in dex_strings:
                    if indicator in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in root detection test: {e}")
            return None

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        self.test_results = APKInconsistencyTests(
            test_zip_bomb=self._test_zip_bomb(),
            test_zip_duplicate_entries=self._test_zip_duplicate_entries(),
            test_zip_path_traversal=self._test_zip_path_traversal(),
            test_zip_suspicious_timestamps=self._test_zip_suspicious_timestamps(),
            test_hidden_dex_files=self._test_hidden_dex_files(),
            test_manifest_component_mismatch=self._test_manifest_component_mismatch(),
            test_debuggable_release=self._test_debuggable_release(),
            test_emulator_detection_strings=self._test_emulator_detection_strings(),
            test_debugger_detection=self._test_debugger_detection(),
            test_root_detection=self._test_root_detection(),
        )
        return self.test_results

    def _bool_to_nullable(self, val):
        """Convert bool/None to ClickHouse Nullable(UInt8)."""
        if val is None:
            return None
        return int(val)

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.test_results:
                return None

            current_time = datetime.now(timezone.utc)
            t = self.test_results

            data = [[
                self.sha256,
                self._bool_to_nullable(t.test_zip_bomb),
                self._bool_to_nullable(t.test_zip_duplicate_entries),
                self._bool_to_nullable(t.test_zip_path_traversal),
                self._bool_to_nullable(t.test_zip_suspicious_timestamps),
                self._bool_to_nullable(t.test_hidden_dex_files),
                self._bool_to_nullable(t.test_manifest_component_mismatch),
                self._bool_to_nullable(t.test_debuggable_release),
                self._bool_to_nullable(t.test_emulator_detection_strings),
                self._bool_to_nullable(t.test_debugger_detection),
                self._bool_to_nullable(t.test_root_detection),
                current_time,
            ]]

            column_names = [
                'sha256',
                'test_zip_bomb', 'test_zip_duplicate_entries',
                'test_zip_path_traversal', 'test_zip_suspicious_timestamps',
                'test_hidden_dex_files', 'test_manifest_component_mismatch',
                'test_debuggable_release', 'test_emulator_detection_strings',
                'test_debugger_detection', 'test_root_detection',
                'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_inconsistency_tests"