James W. Modestino

102 papers A* 3A 1B 8C 2Misc 6Journal 64Unranked 18
YearRankTypeTitle / Venue / Authors
2015 conf
MSAN
Qi Qu, Yong Pei, James W. Modestino, Xusheng Tian, Bin Wang, Xunqi Yu
2009 J jnl
Wirel. Pers. Commun.
Yong Pei, James W. Modestino
2008 J jnl
IEEE/ACM Trans. Netw.
Xunqi Yu, James W. Modestino, Ragip Kurceren, Yee Sin Chan
2008 B conf
ICIP
Dian Fan, Yee Sin Chan, Xunqi Yu, James W. Modestino
2008 J jnl
IEEE Trans. Inf. Theory
Xunqi Yu, James W. Modestino, Xusheng Tian
2007 J jnl
IEEE Trans. Multim.
Yee Sin Chan, James W. Modestino, Qi Qu, Xingzhe Fan
2007 J jnl
EURASIP J. Adv. Signal Process.
Yong Pei, James W. Modestino
2007 J jnl
Wirel. Pers. Commun.
Yong Pei, Viraj S. Ambetkar, James W. Modestino, Xiaochun Wang
2007 J jnl
Int. J. Wirel. Mob. Comput.
Qi Qu, Yong Pei, Xusheng Tian, James W. Modestino
2006 J jnl
IEEE Trans. Commun.
Yee Sin Chan, James W. Modestino
2006 B conf
ICIP
Xunqi Yu, James W. Modestino, Yee Sin Chan
2006 J jnl
IEEE Trans. Multim.
Qi Qu, Yong Pei, James W. Modestino
2006 Misc conf
CISS
Xiaodong Cai, James W. Modestino
2006 B conf
GLOBECOM
Harendra Narayan, Dilip Sarkar, James W. Modestino
2006 conf
MobiMedia
Viraj S. Ambetkar, Paul Bender, Jianing Ma, Yong Pei, James W. Modestino
2006 conf
MobiMedia
Xunqi Yu, James W. Modestino, Dian Fan
2006 J jnl
Wirel. Pers. Commun.
Yong Pei, James W. Modestino
2006 J jnl
EURASIP J. Adv. Signal Process.
Qi Qu, Yong Pei, James W. Modestino, Xusheng Tian
2005 J jnl
Int. J. Wirel. Mob. Comput.
Yee Sin Chan, James W. Modestino
2005 conf
DMS
Qi Qu, Yong Pei, James W. Modestino
2005 J jnl
EURASIP J. Wirel. Commun. Netw.
Qi Qu, Yong Pei, James W. Modestino, Xusheng Tian, Bin Wang
2005 conf
ICIP (3)
Qi Qu, Yong Pei, James W. Modestino, Xusheng Tian, Bin Wang
2005 J jnl
Telecommun. Syst.
Yong Pei, Viraj S. Ambetkar, James W. Modestino, Qi Qu, Xiaochun Wang
2005 conf
DMS
Xunqi Yu, James W. Modestino, Ivan V. Bajic
2005 conf
ICC
Qi Qu, Yong Pei, Xusheng Tian, James W. Modestino, Yee Sin Chan
2005 conf
ICIP (2)
Xunqi Yu, James W. Modestino, Ivan V. Bajic
2005 A* conf
INFOCOM
Xunqi Yu, James W. Modestino, Xusheng Tian
2004 B conf
ICIP
Qi Qu, Yong Pei, James W. Modestino, Xusheng Tian
2004 J jnl
EURASIP J. Adv. Signal Process.
Yong Pei, James W. Modestino
2004 B conf
GLOBECOM
Qi Qu, Ivan V. Bajic, Xusheng Tian, James W. Modestino
2003 J jnl
IEEE J. Sel. Areas Commun.
Yee Sin Chan, James W. Modestino
2003 C conf
VCIP
Yong Pei, James W. Modestino, Qi Qu, Xiaochun Wang
2003 C conf
VCIP
Yee Sin Chan, James W. Modestino
2003 conf
ICASSP (4)
Yong Pei, James W. Modestino
2003 A conf
ICME
Yong Pei, James W. Modestino
2003 conf
ISCAS (2)
Yong Pei, James W. Modestino
2003 B conf
GLOBECOM
Yee Sin Chan, James W. Modestino
2002 conf
ICIP (1)
Yong Pei, James W. Modestino
2001 J jnl
IEEE Trans. Commun.
Maja Bystrom, James W. Modestino
2001 J jnl
Eur. Trans. Telecommun.
Ragip Kurceren, James W. Modestino
2001 conf
ICIP (2)
Yong Pei, James W. Modestino
2001 conf
ICIP (2)
Yee Sin Chan, James W. Modestino
2000 A* conf
INFOCOM
Ragip Kurceren, James W. Modestino
2000 B conf
ICIP
Ragip Kurceren, James W. Modestino
2000 J jnl
IEEE J. Sel. Areas Commun.
Maja Bystrom, James W. Modestino
2000 J jnl
IEEE Trans. Circuits Syst. Video Technol.
Maja Bystrom, Vasu Parthasarathy, James W. Modestino
1999 J jnl
IEEE Trans. Circuits Syst. Video Technol.
Maja Bystrom, Vasu Parthasarathy, James W. Modestino
1999 J jnl
IEEE Trans. Image Process.
Michael J. Ruf, James W. Modestino
1999 J jnl
IEEE Trans. Image Process.
Vasu Parthasarathy, James W. Modestino, Kenneth S. Vastola
1998 J jnl
IEEE Trans. Signal Process.
Karl J. Molnar, James W. Modestino
1998 J jnl
IEEE Trans. Image Process.
David A. Langan, James W. Modestino, Jun Zhang
1998 conf
ICIP (2)
Maja Bystrom, James W. Modestino
1997 J jnl
IEEE Trans. Circuits Syst. Video Technol.
Vasu Parthasarathy, James W. Modestino, Kenneth S. Vastola
1995 B conf
ICIP
Michael J. Ruf, James W. Modestino
1994 conf
ICIP (2)
David A. Langan, James W. Modestino, Jun Zhang
1994 J jnl
IEEE Trans. Image Process.
Jun Zhang, James W. Modestino, David A. Langan
1994 conf
ICIP (3)
Ramin Baseri, James W. Modestino
1993 J jnl
IEEE Trans. Commun.
Yong Han Kim, James W. Modestino
1993 J jnl
IEEE Trans. Commun.
Yong Han Kim, James W. Modestino
1992 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
James W. Modestino, Jun Zhang
1992 J jnl
IEEE Trans. Image Process.
Yong Han Kim, James W. Modestino
1992 J jnl
IEEE Trans. Signal Process.
James W. Modestino, Yong Han Kim
1992 Misc conf
ICASSP
David A. Langan, Karl J. Molnar, James W. Modestino, Jun Zhang
1990 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
Jun Zhang, James W. Modestino
1990 J jnl
IEEE Trans. Inf. Theory
Daniel D. Harrison, James W. Modestino
1990 J jnl
IEEE Trans. Commun.
David H. Sargrad, James W. Modestino
1990 J jnl
IEEE Trans. Commun.
James W. Modestino, Daniel D. Harrison, Nariman Farvardin
1989 A* conf
CVPR
James W. Modestino, Jun Zhang
1989 Misc conf
ICASSP
James W. Modestino, Daniel D. Harrison
1988 Misc conf
ICASSP
Jun Zhang, James W. Modestino
1988 J jnl
IEEE J. Sel. Areas Commun.
Kirt R. Matis, James W. Modestino
1988 J jnl
IEEE Trans. Commun.
James W. Modestino, David H. Sargrad, Robert E. Bollen
1987 J jnl
IEEE Trans. Commun.
James W. Modestino, M. Vedat Eyuboglu
1986 J jnl
IEEE Trans. Inf. Theory
Nariman Farvardin, James W. Modestino
1986 conf
ICC
T. Schaub, James W. Modestino
1986 J jnl
IEEE Trans. Inf. Theory
James W. Modestino, M. Vedat Eyuboglu
1986 J jnl
IEEE J. Sel. Areas Commun.
James W. Modestino, Christopher S. Massey, Robert E. Bollen, Ram P. Prabhu
1986 J jnl
IEEE Trans. Inf. Theory
Nariman Farvardin, James W. Modestino
1985 J jnl
IEEE Trans. Commun.
James W. Modestino, Nariman Farvardin, Michael A. Ogrinc
1985 J jnl
IEEE Trans. Inf. Theory
Nariman Farvardin, James W. Modestino
1984 conf
ICC (1)
F. Azadegan, James W. Modestino, Nariman Farvardin
1984 J jnl
IEEE Trans. Commun.
James W. Modestino, Vasudev Bhaskaran
1984 J jnl
IEEE J. Sel. Areas Commun.
James W. Modestino, Kirt R. Matis
1984 Misc conf
ICASSP
James W. Modestino, Nariman Farvardin
1984 J jnl
IEEE Trans. Inf. Theory
Nariman Farvardin, James W. Modestino
1983 J jnl
IEEE Trans. Commun.
David G. Daut, James W. Modestino
1982 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
Acie L. Vickers, James W. Modestino
1982 J jnl
IEEE Trans. Inf. Theory
David G. Daut, James W. Modestino, Lee D. Wismer
1982 J jnl
IEEE Trans. Inf. Theory
Kirt R. Matis, James W. Modestino
1981 J jnl
IEEE Trans. Commun.
James W. Modestino, David G. Daut, Acie L. Vickers
1981 J jnl
IEEE Trans. Commun.
James W. Modestino, Vasudev Bhaskaran
1981 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
James W. Modestino, Robert W. Fries, Acie L. Vickers
1981 J jnl
IEEE Trans. Inf. Theory
James W. Modestino, Vasudev Bhaskaran, John B. Anderson
1981 J jnl
IEEE Trans. Commun.
David G. Daut, Robert W. Fries, James W. Modestino
1980 J jnl
IEEE Trans. Inf. Theory
James W. Modestino, Robert W. Fries
1979 J jnl
IEEE Trans. Commun.
James W. Modestino, David G. Daut
1979 J jnl
IEEE Trans. Inf. Theory
James W. Modestino, Aaron Y. Ningo
1979 Misc conf
ICASSP
Robert W. Fries, James W. Modestino
1977 J jnl
IEEE Trans. Commun.
James W. Modestino
1977 J jnl
IEEE Trans. Commun.
Shou Y. Mui, James W. Modestino
1976 J jnl
IEEE Trans. Commun.
James W. Modestino, Shou Y. Mui
1970 J jnl
IEEE Trans. Inf. Theory
Lee D. Davisson, Edward A. Feustel, James W. Modestino
redb/extractors/elf_extractors/elf_segments.py
← Index redb/extractors/elf_extractors/elf_segments.py python
import inspect
import hashlib
import math
from collections import Counter
from datetime import datetime, timezone
from typing import Any, List, Dict

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFSegment


class ELFSegmentExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_segments = []
        self.elastic_index = self.index_prefix + "-elf_segments"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _is_empty_result(self, extracted_data) -> bool:
        """
        Override: Empty segments is an ERROR, not a valid empty case.
        A valid ELF file must have segments (program headers).
        """
        # Always return False - empty segments should be treated as an error
        return False

    def _calculate_entropy(self, data: bytes) -> float:
        """Calculate Shannon entropy of data."""
        if not data:
            return 0.0

        try:
            # Count frequency of each byte
            byte_counts = Counter(data)
            data_len = len(data)

            # Calculate entropy
            entropy = 0.0
            for count in byte_counts.values():
                if count > 0:
                    frequency = count / data_len
                    entropy -= frequency * math.log2(frequency)

            return entropy
        except Exception as e:
            self.log.error(f"Error calculating entropy: {e}")
            return 0.0

    def _map_segment_type(self, p_type_str: str) -> int:
        """Map segment type string to enum value."""
        type_map = {
            'PT_NULL': 0,
            'PT_LOAD': 1,
            'PT_DYNAMIC': 2,
            'PT_INTERP': 3,
            'PT_NOTE': 4,
            'PT_SHLIB': 5,
            'PT_PHDR': 6,
            'PT_TLS': 7
        }
        return type_map.get(p_type_str, 0)

    def _decode_segment_flags(self, flags: int) -> List[str]:
        """Decode segment flags to human-readable strings."""
        flag_strings = []

        if flags & 0x1:  # PF_X
            flag_strings.append('EXECUTE')
        if flags & 0x2:  # PF_W
            flag_strings.append('WRITE')
        if flags & 0x4:  # PF_R
            flag_strings.append('READ')

        return flag_strings if flag_strings else ['NONE']

    def _extract_segment_data(self, segment) -> ELFSegment:
        """Extract data from a single segment with granular error handling."""
        # Initialize with safe defaults
        segment_type = 0
        segment_type_str = 'unknown'
        segment_flags = 0
        segment_flags_str = ['NONE']
        segment_offset = 0
        segment_vaddr = 0
        segment_paddr = 0
        segment_filesz = 0
        segment_memsz = 0
        segment_align = 0
        segment_entropy = 0.0
        segment_sha256 = ""
        segment_md5 = ""

        # Try to get segment header
        header = None
        try:
            header = segment.header
        except Exception as e:
            self.log.warning(f"Could not access segment header: {e}")
            return ELFSegment(
                segment_type=segment_type, segment_type_str=segment_type_str,
                segment_flags=segment_flags, segment_flags_str=segment_flags_str,
                segment_offset=segment_offset, segment_vaddr=segment_vaddr,
                segment_paddr=segment_paddr, segment_filesz=segment_filesz,
                segment_memsz=segment_memsz, segment_align=segment_align,
                segment_entropy=segment_entropy, segment_sha256=segment_sha256,
                segment_md5=segment_md5
            )

        # Extract segment type
        try:
            p_type_str = header.get('p_type', 'PT_NULL')
            segment_type = self._map_segment_type(p_type_str)
            segment_type_str = p_type_str.replace('PT_', '') if p_type_str.startswith('PT_') else p_type_str
        except Exception as e:
            self.log.warning(f"Could not extract segment type: {e}")

        # Extract segment flags
        try:
            segment_flags = header.get('p_flags', 0)
            segment_flags_str = self._decode_segment_flags(segment_flags)
        except Exception as e:
            self.log.warning(f"Could not extract segment flags: {e}")

        # Extract segment addresses and sizes
        try:
            segment_offset = header.get('p_offset', 0)
        except Exception as e:
            self.log.warning(f"Could not extract segment offset: {e}")

        try:
            segment_vaddr = header.get('p_vaddr', 0)
        except Exception as e:
            self.log.warning(f"Could not extract segment vaddr: {e}")

        try:
            segment_paddr = header.get('p_paddr', 0)
        except Exception as e:
            self.log.warning(f"Could not extract segment paddr: {e}")

        try:
            segment_filesz = header.get('p_filesz', 0)
        except Exception as e:
            self.log.warning(f"Could not extract segment filesz: {e}")

        try:
            segment_memsz = header.get('p_memsz', 0)
        except Exception as e:
            self.log.warning(f"Could not extract segment memsz: {e}")

        try:
            segment_align = header.get('p_align', 0)
        except Exception as e:
            self.log.warning(f"Could not extract segment align: {e}")

        # Calculate entropy and hashes for segment data (most likely to fail)
        try:
            if segment_filesz > 0:
                segment_data = segment.data()
                if segment_data:
                    # Calculate entropy
                    segment_entropy = self._calculate_entropy(segment_data)

                    # Calculate hashes
                    segment_sha256 = hashlib.sha256(segment_data).hexdigest()
                    segment_md5 = hashlib.md5(segment_data).hexdigest()
        except Exception as e:
            self.log.warning(f"Could not read segment data for hashing: {e}")
            # Keep defaults (0.0, "", "")

        return ELFSegment(
            segment_type=segment_type,
            segment_type_str=segment_type_str,
            segment_flags=segment_flags,
            segment_flags_str=segment_flags_str,
            segment_offset=segment_offset,
            segment_vaddr=segment_vaddr,
            segment_paddr=segment_paddr,
            segment_filesz=segment_filesz,
            segment_memsz=segment_memsz,
            segment_align=segment_align,
            segment_entropy=segment_entropy,
            segment_sha256=segment_sha256,
            segment_md5=segment_md5
        )

    def tag(self):
        return Tag.ELF_SEGMENTS.value if hasattr(Tag, 'ELF_SEGMENTS') else "elf_segments"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_segments(elf):
                segments_data = []

                # Iterate through all segments with per-segment error handling
                for segment_index, segment in enumerate(elf.iter_segments()):
                    try:
                        segment_data = self._extract_segment_data(segment)
                        if segment_data:
                            segments_data.append(segment_data)
                        else:
                            self.log.warning(f"Failed to extract data for segment {segment_index}")
                    except Exception as e:
                        self.log.warning(f"Error processing segment {segment_index}: {e}")
                        # Continue processing other segments

                return segments_data

            # Check if file is valid ELF
            if not self._is_elf_file():
                self.log.error(f"No valid ELF file for {self.hash.sha256}")
                return None

            segments_data = self._with_elf_file(extract_segments)
            if segments_data is None:
                return None

            self.elf_segments = segments_data
            return self.elf_segments

        except Exception as e:
            self.log.error(f"Error extracting ELF segments {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_segments
        elif exporter_type == "ClickHouseExporter":
            try:
                if not self.elf_segments:
                    return None

                # Prepare data arrays for all segments
                data = []
                current_time = datetime.now(timezone.utc)
                for segment in self.elf_segments:
                    row = [
                        self.sha256,
                        self.md5,
                        self.sha1,
                        segment.segment_type,
                        segment.segment_type_str,
                        segment.segment_flags,
                        segment.segment_flags_str,
                        segment.segment_offset,
                        segment.segment_vaddr,
                        segment.segment_paddr,
                        segment.segment_filesz,
                        segment.segment_memsz,
                        segment.segment_align,
                        segment.segment_entropy,
                        segment.segment_sha256,
                        segment.segment_md5,
                        current_time
                    ]
                    data.append(row)

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'segment_type', 'segment_type_str', 'segment_flags', 'segment_flags_str',
                    'segment_offset', 'segment_vaddr', 'segment_paddr',
                    'segment_filesz', 'segment_memsz', 'segment_align',
                    'segment_entropy', 'segment_sha256', 'segment_md5',
                    'analysis_date'
                ]

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    "Enum8('NULL'=0, 'LOAD'=1, 'DYNAMIC'=2, 'INTERP'=3, 'NOTE'=4, 'SHLIB'=5, 'PHDR'=6, 'TLS'=7)",
                    'LowCardinality(String)',
                    'UInt32',
                    'Array(LowCardinality(String))',
                    'UInt64', 'UInt64', 'UInt64', 'UInt64', 'UInt64', 'UInt64',
                    'Float64',
                    'FixedString(64)', 'FixedString(32)',
                    'DateTime64(3, \'UTC\')'
                ]

                if not data:
                    return None

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_segments"