Jan Korenek

84 papers A* 1A 2B 16C 31Misc 3Journal 7Unranked 23
YearRankTypeTitle / Venue / Authors
2024 Misc conf
FCCM
Tomás Martínek, Jan Korenek, Tomás Cejka
2023 conf
INFOCOM Workshops
Jakub Cabal, Vladislav Válek, Martin Spinler, Daniel Kondys, Jan Korenek
2023 C conf
ISCC
Vlastimil Kosar, Lukas Sismis, Jirí Matousek, Jan Korenek
2023 B conf
PAM
Lukas Sismis, Jan Korenek
2023 C conf
DDECS
Michal Kekely, Jan Korenek
2022 J jnl
IEEE/ACM Trans. Netw.
Jirí Matousek, Adam Lucanský, David Janecek, Jozef Sabo, Jan Korenek, Gianni Antichi
2022 B conf
FPL
Jakub Cabal, Jiri Sikora, Stepán Friedl, Martin Spinler, Jan Korenek
2021 C conf
DDECS
Roman Vrána, Jan Korenek
2021 conf
FPT
Tomás Fukac, Jirí Matousek, Jan Korenek, Lukás Kekely
2021 C conf
ISCC
Tomás Fukac, Jan Korenek, Jirí Matousek
2020 conf
SOSR
Jan Kucera, Diana Andreea Popescu, Han Wang, Andrew W. Moore, Jan Korenek, Gianni Antichi
2020 J jnl
Microprocess. Microsystems
Michal Kekely, Lukás Kekely, Jan Korenek
2020 B conf
LCN
Tomás Fukac, Vlastimil Kosar, Jan Korenek, Jirí Matousek
2020 C conf
DSD
Lukás Kekely, Jakub Cabal, Viktor Pus, Jan Korenek
2019 C conf
DDECS
Roman Vrana, Jan Korenek, David Novak
2019 Misc conf
FCCM
Milan Ceska, Vojtech Havlena, Lukás Holík, Jan Korenek, Ondrej Lengál, Denis Matousek, Jirí Matousek, Jakub Semric, Tomás Vojnar
2019 J jnl
CoRR
Milan Ceska, Vojtech Havlena, Lukás Holík, Jan Korenek, Ondrej Lengál, Denis Matousek, Jirí Matousek, Jakub Semric, Tomás Vojnar
2019 conf
ARCS
Lukás Kekely, Jakub Cabal, Jan Korenek
2019 C conf
DDECS
Tomas Fukac, Jan Korenek
2018 B conf
FPL
Lukas Kekely, Martin Spinler, Stepan Friedl, Jiri Sikora, Jan Korenek
2018 A conf
FPGA
Jakub Cabal, Pavel Benácek, Lukas Kekely, Michal Kekely, Viktor Pus, Jan Korenek
2018 conf
FPT
Lukás Kekely, Martin Spinler, Stepán Friedl, Jiri Sikora, Jan Korenek, Viktor Pus
2018 C conf
ICCD
Jan Kucera, Lukas Kekely, Adam Piecek, Jan Korenek
2018 conf
FPT
Jakub Cabal, Lukás Kekely, Jan Korenek
2018 Misc conf
FCCM
Denis Matousek, Jirí Matousek, Jan Korenek
2018 B conf
NOMS
Lukas Kekely, Martin Spinler, Stepan Friedl, Jiri Sikora, Jan Korenek
2018 C conf
DSD
Michal Kekely, Lukas Kekely, Jan Korenek
2018 conf
ANCS
Denis Matousek, Juraj Kubis, Jirí Matousek, Jan Korenek
2018 J jnl
CoRR
Jan Kucera, Diana Andreea Popescu, Gianni Antichi, Jan Korenek, Andrew W. Moore
2017 conf
ANCS
Jirí Matousek, Gianni Antichi, Adam Lucanský, Andrew W. Moore, Jan Korenek
2017 J jnl
Appl. Soft Comput.
Roland Dobai, Jan Korenek, Lukás Sekanina
2017 B conf
FPL
Pavel Benácek, Viktor Pus, Jan Korenek, Michal Kekely
2017 B conf
FPL
Michal Kekely, Jan Korenek
2017 C conf
DSD
Michal Kekely, Jan Korenek
2016 conf
SSCI
Roland Dobai, Jan Korenek, Lukás Sekanina
2016 C conf
DSD
Vlastimil Kosar, Jan Korenek
2016 conf
AIMS
Václav Bartos, Jan Korenek
2016 J jnl
Appl. Soft Comput.
David Grochol, Lukás Sekanina, Martin Zádník, Jan Korenek, Vlastimil Kosar
2016 conf
FPT
Denis Matousek, Jan Korenek, Viktor Pus
2016 B conf
FPL
Jan Viktorin, Jan Korenek
2016 J jnl
IEEE Trans. Computers
Lukas Kekely, Jan Kucera, Viktor Pus, Jan Korenek, Athanasios V. Vasilakos
2015 B conf
EvoApplications
David Grochol, Lukás Sekanina, Martin Zádník, Jan Korenek
2015 conf
SSCI
Roland Dobai, Jan Korenek
2015 B conf
IM
Viktor Pus, Petr Velan, Lukas Kekely, Jan Korenek, Pavel Minarík
2015 C conf
DSD
Vlastimil Kosar, Jan Korenek
2014 C conf
DDECS
Viktor Pus, Lukas Kekely, Jan Korenek
2014 C conf
DDECS
Lukas Kekely, Martin Zádník, Jirí Matousek, Jan Korenek
2014 C conf
DDECS
Milan Dvorak, Jan Korenek
2014 ed.
MEMICS
Petr Hlinený, Zdenek Dvorák, Jirí Jaros, Jan Kofron, Jan Korenek, Petr Matula, Karel Pala
2014 conf
ANCS
Jan Viktorin, Pavol Korcek, Tomas Fukac, Jan Korenek
2014 C conf
DDECS
Vlastimil Kosar, Jan Korenek
2014 A* conf
INFOCOM
Lukas Kekely, Viktor Pus, Jan Korenek
2014 B conf
FPL
Lukas Kekely, Viktor Pus, Pavel Benácek, Jan Korenek
2013 conf
DASIP
Jan Viktorin, Pavol Korcek, Vlastimil Kosar, Jan Korenek
2013 C conf
DDECS
Jan Korenek
2013 C conf
DDECS
Jan Kastil, Vlastimil Kosar, Jan Korenek
2013 B conf
FPL
Jirí Matousek, Martin Skacan, Jan Korenek
2013 conf
FPT
Vlastimil Kosar, Martin Zádník, Jan Korenek
2013 C conf
DDECS
Jirí Matousek, Martin Skacan, Jan Korenek
2012 conf
ANCS
Jan Korenek, Pavol Korcek, Vlastimil Kosar, Martin Zádník, Jan Viktorin
2012 conf
ANCS
Viktor Pus, Lukas Kekely, Jan Korenek
2012 B conf
IWCMC
Viktor Pus, Jan Korenek
2011 C conf
DDECS
Jiri Tobola, Jan Korenek
2011 C conf
DDECS
Viktor Pus, Michal Kajan, Jan Korenek
2011 conf
ANCS
Viktor Pus, Jiri Tobola, Vlastimil Kosar, Jan Kastil, Jan Korenek
2011 C conf
DDECS
Vlastimil Kosar, Jan Korenek
2010 C conf
DDECS
Jan Korenek, Vlastimil Kosar
2010 conf
ANCS
Michal Kajan, Jan Korenek
2010 C conf
DDECS
Jan Kastil, Jan Korenek
2010 conf
ANCS
Jan Kastil, Jan Korenek
2010 C conf
DDECS
Viktor Pus, Juraj Blaho, Jan Korenek
2010 conf
ANCS
Jan Korenek, Vlastimil Kosar
2009 A conf
FPGA
Viktor Pus, Jan Korenek
2009 conf
ANCS
Juraj Blaho, Jan Korenek, Viktor Pus
2009 C conf
DSD
Jan Kastil, Jan Korenek, Ondrej Lengál
2009 C conf
DDECS
Petr Kobierský, Jan Korenek, Libor Polcak
2008 B conf
FPL
Tamas Malek, Tomás Martínek, Jan Korenek
2008 C conf
DDECS
Martin Zádník, Jan Korenek, Petr Kobierský, Ondrej Lengál
2007 B conf
FPL
Martin Kosek, Jan Korenek
2007 C conf
DDECS
Jan Korenek, Petr Kobierský
2007 C conf
DSD
Jiri Tobola, Zdenek Kotásek, Jan Korenek, Tomás Martínek, Martin Straka
2006 C conf
DDECS
Tomás Martínek, Jan Korenek, Otto Fucík, Matej Lexa
2005 conf
ICES
Jan Korenek, Lukás Sekanina
2005 B conf
FPL
Martin Zádník, Tomas Pecenka, Jan Korenek
redb/extractors/decompiler/apk/smali_normalization.py
← Index redb/extractors/decompiler/apk/smali_normalization.py python
"""Semantic normalization of Dalvik/smali instructions.

Analogous to Binary Ninja's LLIL normalization: strips register allocation
noise and instruction encoding variants while preserving semantic operations.

Three normalization levels (most aggressive to most detailed):
  - 'category':    semantic category only (MOV, ALU, CALL, ...)
  - 'opcode':      base opcode, width-invariant (add, sub, invoke, ...)
  - 'opcode_api':  opcode category + API method/field references for
                   invoke/field/alloc instructions (default for MinHash)

References:
  - Smali+ 12-category reduction (Canfora et al.)
  - MOSDroid opcode family grouping
  - DroidSIFT/DroidSim API-sensitive similarity
"""

import re
from typing import List

# ---------------------------------------------------------------------------
# Dalvik opcode -> semantic category mapping
# ---------------------------------------------------------------------------
# Prefix-matched against instruction opcodes. Order matters for overlapping
# prefixes (longer/more-specific prefixes should come first in iteration,
# but since we use startswith and break on first match, we order by
# specificity within the list).

OPCODE_CATEGORIES = {
    # Arithmetic/logic
    "add": "ALU", "sub": "ALU", "mul": "ALU", "div": "ALU",
    "rem": "ALU", "and": "ALU", "or": "ALU", "xor": "ALU",
    "shl": "ALU", "shr": "ALU", "ushr": "ALU", "neg": "ALU",
    "not": "ALU",
    # Data movement
    "move": "MOV", "const": "CONST",
    # Memory access (field/array)
    "iget": "LOAD", "sget": "LOAD", "aget": "LOAD",
    "iput": "STORE", "sput": "STORE", "aput": "STORE",
    # Invocations
    "invoke": "CALL",
    # Control flow
    "if": "BRANCH", "goto": "JMP",
    "switch": "SWITCH",
    "return": "RET",
    # Object/type
    "new": "ALLOC", "check": "TYPE", "instance": "TYPE",
    # Array
    "fill": "ARR", "array": "ARR",
    # Comparison
    "cmpl": "CMP", "cmpg": "CMP", "cmp": "CMP",
    # Exception / synchronization
    "throw": "EXC", "monitor": "SYNC",
    # Conversion (int-to-long, float-to-int, etc.)
    "int-to": "CONV", "long-to": "CONV", "float-to": "CONV",
    "double-to": "CONV",
}

# Pre-compiled regexes for operand extraction
_METHOD_REF_RE = re.compile(r"(L[\w/$]+;->[\w<>]+\(.*?\)[\w/$;\[]*)")
_FIELD_REF_RE = re.compile(r"(L[\w/$]+;->[\w]+:[\w/$;\[]+)")
_CLASS_REF_RE = re.compile(r"(L[\w/$]+;)")
_CONST_STRING_RE = re.compile(r'^const-string(?:/jumbo)?\s')


def categorize_opcode(opcode: str) -> str:
    """Map a Dalvik opcode to its semantic category.

    Prefix-matched: 'add-int/2addr' matches 'add' -> 'ALU'.
    Returns 'OTHER' for unrecognized opcodes.
    """
    for prefix, cat in OPCODE_CATEGORIES.items():
        if opcode.startswith(prefix):
            return cat
    return "OTHER"


# Mapping from semantic categories to the ACFG feature vector indices
# used by Binary Ninja's build_block_features (cfg_features.py).
# This enables cross-platform ACFG feature comparison.
CATEGORY_TO_ACFG_INDEX = {
    "ALU": 0,       # CAT_ARITHMETIC
    "CONV": 0,      # arithmetic-adjacent
    "CMP": 4,       # CAT_COMPARISON
    "MOV": 2,       # CAT_TRANSFER
    "CONST": 2,     # transfer-adjacent (loading constants)
    "LOAD": 5,      # CAT_MEMORY
    "STORE": 5,     # CAT_MEMORY
    "CALL": 3,      # CAT_CALL
    "BRANCH": 1,    # CAT_LOGIC (conditional logic)
    "JMP": 1,       # CAT_LOGIC
    "SWITCH": 1,    # CAT_LOGIC
    "RET": 2,       # CAT_TRANSFER
    "ALLOC": 5,     # CAT_MEMORY (heap allocation)
    "TYPE": 6,      # CAT_OTHER
    "ARR": 5,       # CAT_MEMORY
    "EXC": 6,       # CAT_OTHER
    "SYNC": 6,      # CAT_OTHER
    "OTHER": 6,     # CAT_OTHER
}


def normalize_instruction(line: str, level: str = "opcode_api") -> str:
    """Normalize a single smali instruction line.

    Args:
        line: A single smali instruction (whitespace-stripped).
        level: Normalization level:
            'category'   - most aggressive: just semantic category
            'opcode'     - base opcode only, width/addressing-mode invariant
            'opcode_api' - category + API references for invoke/field/alloc
                          (default, best for MinHash similarity)

    Returns:
        Normalized instruction string, or empty string for non-instructions.
    """
    stripped = line.strip()
    if not stripped:
        return ""

    parts = stripped.split(None, 1)
    opcode = parts[0]
    operands = parts[1] if len(parts) > 1 else ""

    if level == "category":
        return categorize_opcode(opcode)

    if level == "opcode":
        # Strip type/width suffixes for invariance:
        # add-int, add-long, add-float -> 'add'
        # add-int/2addr -> 'add'
        base = re.split(r"[-/]", opcode)[0]
        return base

    if level == "opcode_api":
        # const-string: preserve string content (encrypted strings are a
        # key malware indicator)
        if _CONST_STRING_RE.match(stripped):
            # Extract the string literal
            str_match = re.search(r'"(.*)"', operands)
            if str_match:
                return f"CONST_STR \"{str_match.group(1)}\""
            return "CONST_STR"

        # invoke-*: preserve method reference
        if opcode.startswith("invoke"):
            ref = _METHOD_REF_RE.search(operands)
            if ref:
                return f"CALL {ref.group(1)}"
            return "CALL"

        # Field access: preserve field reference
        if opcode.startswith(("iget", "iput", "sget", "sput")):
            ref = _FIELD_REF_RE.search(operands)
            if ref:
                cat = "LOAD" if "get" in opcode else "STORE"
                return f"{cat} {ref.group(1)}"
            # Fallback: try space-separated format from androguard
            # e.g. "iget v0, p0, Lcom/Foo;->field Ljava/lang/String;"
            space_ref = re.search(
                r"(L[\w/$]+;->[\w]+)\s+([\w/$;\[]+)", operands
            )
            if space_ref:
                cat = "LOAD" if "get" in opcode else "STORE"
                return f"{cat} {space_ref.group(1)}:{space_ref.group(2)}"
            cat = "LOAD" if "get" in opcode else "STORE"
            return cat

        # new-instance: preserve allocated type
        if opcode.startswith("new-instance") or opcode == "new-array":
            ref = _CLASS_REF_RE.search(operands)
            if ref:
                return f"ALLOC {ref.group(1)}"
            return "ALLOC"

        # Everything else: just the category
        return categorize_opcode(opcode)

    # Unknown level: return raw opcode
    return opcode


def normalize_method_body(
    body: str, level: str = "opcode_api"
) -> List[str]:
    """Normalize all instructions in a smali method body.

    Filters out directives (.), labels (:), comments (#), and blank lines.
    Returns a list of normalized instruction strings.

    Args:
        body: Raw smali method body text.
        level: Normalization level (see normalize_instruction).

    Returns:
        List of normalized instruction strings (no empty strings).
    """
    normalized = []
    for line in body.split("\n"):
        stripped = line.strip()
        # Skip non-instructions
        if not stripped:
            continue
        if stripped.startswith((".",":", "#")):
            continue
        result = normalize_instruction(stripped, level)
        if result:
            normalized.append(result)
    return normalized