Kallol Kumar Bagchi

69 papers B 4C 1Misc 1Journal 33Unranked 28
YearRankTypeTitle / Venue / Authors
2024 J jnl
Behav. Inf. Technol.
Godwin J. Udo, Kallol Kumar Bagchi, Laura Trevino, Saini Das
2022 J jnl
Inf. Resour. Manag. J.
Faruk Arslan, Kallol Kumar Bagchi, Somnath Mukhopadhyay, José Humberto Ablanedo-Rosas
2022 J jnl
Int. J. Inf. Technol. Syst. Approach
Niharika Dayyala, Kent A. Walstrom, Kallol Kumar Bagchi, Godwin J. Udo
2022 J jnl
Int. J. Inf. Secur. Priv.
Faruk Arslan, Kallol Kumar Bagchi, Godwin J. Udo
2021 J jnl
Int. J. Inf. Technol. Syst. Approach
Niharika Dayyala, Kent A. Walstrom, Kallol Kumar Bagchi
2020 J jnl
Inf. Resour. Manag. J.
Niharika Dayyala, Faruk Arslan, Kent A. Walstrom, Kallol Kumar Bagchi
2019 J jnl
Inf. Syst. Frontiers
Arunabha Mukhopadhyay, Samir Chatterjee, Kallol Kumar Bagchi, Peeter J. Kirs, Girja K. Shukla
2019 J jnl
Inf. Technol. People
Moutusy Maity, Kallol Kumar Bagchi, Arunima Shah, Ankita Misra
2019 J jnl
Int. J. Bus. Inf. Syst.
Michael L. Gonzales, Somnath Mukhopadhyay, Kallol Kumar Bagchi, Leopoldo A. Gemoets
2019 J jnl
Int. J. Inf. Manag.
Khendum Choden, Kallol Kumar Bagchi, Godwin J. Udo, Peeter J. Kirs
2017 J jnl
Behav. Inf. Technol.
Khadija Ali Vakeel, Saini Das, Godwin J. Udo, Kallol Kumar Bagchi
2016 J jnl
Ind. Manag. Data Syst.
Purnendu Mandal, Kallol Kumar Bagchi
2015 conf
AMCIS
Faruk Arslan, Kallol Kumar Bagchi, SeungEui Ryu
2015 J jnl
Comput. Hum. Behav.
Kallol Kumar Bagchi, Godwin J. Udo, Peeter J. Kirs, Khendum Choden
2014 conf
AMCIS
Faruk Arslan, Kallol Kumar Bagchi, Jie Zhang
2012 conf
AMCIS
Fernando Parra, Belal M. Abdelfattah, Kallol Kumar Bagchi
2012 J jnl
Comput. Hum. Behav.
Godwin J. Udo, Kallol Kumar Bagchi, Peeter Kirs
2012 conf
AMCIS
Jesus Cardenas, Jesus Francisco Matus, Kallol Kumar Bagchi
2012 conf
ISNN (1)
Zaiyong Tang, Kallol Kumar Bagchi, Youqin Pan, Gary J. Koehler
2012 J jnl
Inf. Syst. Manag.
Peeter Kirs, Kallol Kumar Bagchi, Zaiyong Tang
2012 conf
AMCIS
Kallol Kumar Bagchi, Arunabha Mukhopadhyay, Saini Das, Manoj Anand
2012 J jnl
Int. J. Inf. Syst. Chang. Manag.
Purnendu Mandal, Somnath Mukhopadhyay, Kallol Kumar Bagchi, Angappa Gunasekaran
2012 J jnl
Int. J. Inf. Manag.
Peeter Kirs, Kallol Kumar Bagchi
2011 J jnl
Int. J. Inf. Syst. Chang. Manag.
Kallol Kumar Bagchi, Purnendu Mandal, Arunabha Mukhopadhyay
2011 conf
HICSS
Michael L. Gonzales, Kallol Kumar Bagchi, Godwin J. Udo, Peeter Kirs
2011 J jnl
Comput. Hum. Behav.
Godwin J. Udo, Kallol Kumar Bagchi, Peeter Kirs
2010 J jnl
Int. J. Inf. Manag.
Godwin J. Udo, Kallol Kumar Bagchi, Peeter Kirs
2010 J jnl
Int. J. Inf. Technol. Manag.
Kallol Kumar Bagchi, Godwin J. Udo
2010 conf
AMCIS
Khendum Choden, Kallol Kumar Bagchi, Godwin J. Udo, Peeter Kirs
2010 J jnl
Comput. Inf. Sci.
Zaiyong Tang, Kallol Kumar Bagchi
2010 conf
AMCIS
Belal M. Abdelfattah, Kallol Kumar Bagchi, Godwin J. Udo, Peeter Kirs
2009 ch.
Encyclopedia of Artificial Intelligence
Zaiyong Tang, Xiaoyu Huang, Kallol Kumar Bagchi
2009 conf
AMCIS
Zaiyong Tang, Kallol Kumar Bagchi, Anurag Jain
2009 J jnl
Int. J. Electron. Bus.
Somnath Mukhopadhyay, Kallol Kumar Bagchi, Godwin J. Udo
2009 C conf
ICIS
Kallol Kumar Bagchi, Peeter Kirs
2008 conf
AMCIS
Kallol Kumar Bagchi, Peeter Kirs
2008 J jnl
Inf. Manag.
Kallol Kumar Bagchi, Peeter Kirs, Francisco López
2007 conf
AMCIS
Kallol Kumar Bagchi, Peeter Kirs, Godwin J. Udo
2007 J jnl
Commun. Assoc. Inf. Syst.
Kallol Kumar Bagchi, Godwin J. Udo, Peeter Kirs
2007 ch.
Encyclopedia of Portal Technologies and Applications
Zaiyong Tang, Kallol Kumar Bagchi
2006 conf
Social Inclusion
Kallol Kumar Bagchi, Peeter Kirs, Godwin J. Udo
2006 conf
AMCIS
Kallol Kumar Bagchi, Mo Adam Mahmood
2006 conf
DG.O
Kallol Kumar Bagchi, Stuart Diaz Galup, Robert Cerveny
2006 conf
AMCIS
Godwin J. Udo, Kallol Kumar Bagchi, Peeter Kirs
2006 J jnl
Commun. ACM
Kallol Kumar Bagchi, Peeter Kirs, Robert Cerveny
2006 conf
ISNN (2)
Zaiyong Tang, Caroline W. Leung, Kallol Kumar Bagchi
2006 J jnl
Int. J. Inf. Technol. Decis. Mak.
Kallol Kumar Bagchi, Somnath Mukhopadhyay
2005 conf
AMCIS
Kallol Kumar Bagchi, Godwin J. Udo, Mark Kesh
2005 J jnl
Int. J. Internet Enterp. Manag.
Kallol Kumar Bagchi, Adriano O. Solis, Godwin J. Udo
2004 conf
AMCIS
Kallol Kumar Bagchi, Mo Adam Mahmood
2004 Misc conf
IRI
Kallol Kumar Bagchi, Somnath Mukhopadhyay
2004 conf
AMCIS
Kallol Kumar Bagchi, Karl B. Putnam, Zaiyong Tang
2004 J jnl
Electron. J. Inf. Syst. Dev. Ctries.
Kallol Kumar Bagchi, Karl B. Putnam, Zaiyong Tang
2004 J jnl
Int. J. Electron. Commer.
Mo Adam Mahmood, Kallol Kumar Bagchi, Timothy C. Ford
2003 J jnl
Commun. Assoc. Inf. Syst.
Kallol Kumar Bagchi, Godwin J. Udo
2003 conf
AMCIS
Kallol Kumar Bagchi, Godwin J. Udo
2003 J jnl
Electron. J. Inf. Syst. Dev. Ctries.
Kallol Kumar Bagchi, Adriano O. Solis, Leopoldo A. Gemoets
2003 conf
AMCIS
Kallol Kumar Bagchi, Adriano O. Solis, Leopoldo A. Gemoets
2003 conf
AMCIS
Kallol Kumar Bagchi, Robert Cerveny, Paul Hart, Mark Peterson
2000 B conf
MASCOTS
Kallol Kumar Bagchi, Robert Cerveny
1997 B conf
MASCOTS
Kallol Kumar Bagchi
1994 B conf
MASCOTS
Yen-Wen Lu, Kallol Kumar Bagchi, James B. Burr, Allen M. Peterson
1994 conf
CAST
Gerard K. Yeh, James B. Burr, Kallol Kumar Bagchi, Allen M. Peterson
1994 conf
EURO-DAC
James B. Burr, Allen M. Peterson, Gerard K. Yeh, Kallol Kumar Bagchi
1994 conf
Annual Simulation Symposium
Gerard K. Yeh, Kallol Kumar Bagchi, James B. Burr, Allen M. Peterson
1993 B ed.
MASCOTS
Herbert D. Schwetman, Jean C. Walrand, Kallol Kumar Bagchi, Doug DeGroot
1991 conf
VLSI
Anders Færgemand Nielsen, Poul Martin Rands Jensen, Kallol Kumar Bagchi, Ole Olsen
1991 J jnl
Int. J. Comput. Simul.
Kallol Kumar Bagchi
1989 conf
Annual Simulation Symposium
Kallol Kumar Bagchi, Ole Olsen, A. Christensen, L. Sorensen
redb/extractors/pe_extractors/pe_resources.py
← Index redb/extractors/pe_extractors/pe_resources.py python
from hashlib import sha256
import inspect
from datetime import datetime, timezone
from typing import Any

import magic
from magika import Magika
import pefile
from pefile import UnicodeStringWrapperPostProcessor

from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PEResource


class PEResourceExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_resources"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_RESOURCE.value

    def _extract_resources(self):
        """
        Returns:
        resources: a list of dictionaries, one per each resources type found.
                    each dictionary the key represents the name of the content,
                    which is the value itself.
                    Empty list if no resources present.
        """
        self.log.debug(inspect.currentframe().f_code.co_name)
        resources_list = []
        try:
            if hasattr(self.pe, "DIRECTORY_ENTRY_RESOURCE"):
                for resource_type in self.pe.DIRECTORY_ENTRY_RESOURCE.entries:
                    # if resource_type.name is not None:
                    #     name = resource_type.name
                    # else:
                    #     name = pefile.RESOURCE_TYPE.get(resource_type.struct.Id)
                    # if not name:
                    #     name = resource_type.struct.Id
                    name = (
                        resource_type.name
                        if resource_type.name is not None
                        else pefile.RESOURCE_TYPE.get(resource_type.struct.Id)
                    )
                    if isinstance(name, UnicodeStringWrapperPostProcessor):
                        name = name.decode()
                    try:
                        if hasattr(resource_type, "directory"):
                            for resource_id in resource_type.directory.entries:
                                if hasattr(resource_id, "directory"):
                                    for resource_lang in resource_id.directory.entries:
                                        rsrc_data = self.pe.get_data(
                                            resource_lang.data.struct.OffsetToData,
                                            resource_lang.data.struct.Size,
                                        )
                                        file_type = magic.from_buffer(rsrc_data)
                                        magik = Magika().identify_bytes(rsrc_data).output.label

                                        rsrc_entropy = (
                                            "%.2f"
                                            % pefile.SectionStructure.entropy_H(
                                                self.pe, rsrc_data
                                            )
                                        )
                                        rsrc_sha256 = sha256(rsrc_data).hexdigest()
                                        lang = pefile.LANG.get(
                                            resource_lang.data.lang, "*unknown*"
                                        )
                                        sublang = pefile.get_sublang_name_for_lang(
                                            resource_lang.data.lang,
                                            resource_lang.data.sublang,
                                        )
                                        pe_resource = PEResource(
                                            _id=rsrc_sha256,
                                            resource_type=name,
                                            resource_entropy=rsrc_entropy,
                                            resource_sha256=rsrc_sha256,
                                            resource_filetype=file_type,
                                            resource_magika=magik,
                                            resource_language=lang,
                                            resource_rva=resource_lang.data.struct.OffsetToData,
                                            resource_size=resource_lang.data.struct.Size,
                                            resource_sub_lang=sublang,
                                        )
                                        resources_list.append(pe_resource)
                    except Exception as e:
                        self.log.warning(
                            f"Continue after Error in {self.hash.sha256}: {resource_type.name} "
                            f"Exception: {e}",
                            stack_info=True,
                        )
                        # resources_list.append({f"{e} - {resource_type.name}"})
                        continue
        except Exception as e:
            self.log.exception(
                f"Extract exports error {self.hash.sha256} Exception: {e}"
            )
        self.log.debug(f"Resource list {resources_list}")
        return resources_list

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)
            resources = self._extract_resources()
            # self.export_to_elastic(resources)  # Let the exporters handle this
            return resources
        except Exception as e:
            self.log.error(f"Extract resources error {self.hash.sha256} Exception: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            resources = self.extract()
            if resources is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for resource in resources:
                data.append([
                    self.sha256,                    # sha256
                    self.md5,                       # md5
                    self.sha1,                      # sha1
                    resource.resource_type,         # resource_type
                    resource.resource_entropy,      # resource_entropy
                    resource.resource_sha256,       # resource_sha256
                    resource.resource_filetype,     # resource_filetype
                    resource.resource_magika,       # resource_magika
                    resource.resource_language,     # resource_language
                    resource.resource_sub_lang,     # resource_sub_lang
                    resource.resource_size,         # resource_size
                    resource.resource_rva,          # resource_rva
                    current_time                    # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'resource_type', 'resource_entropy',
                'resource_sha256', 'resource_filetype', 'resource_magika',
                'resource_language', 'resource_sub_lang', 'resource_size',
                'resource_rva', 'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(Nullable(String))', 'Float64',
                'FixedString(64)', 'LowCardinality(Nullable(String))', 'LowCardinality(Nullable(String))',
                'LowCardinality(Nullable(String))', 'LowCardinality(Nullable(String))', 'UInt64',
                'UInt64', 'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_resources"