Kamal Taha

86 papers B 3C 7Misc 2Journal 59Unranked 15
YearRankTypeTitle / Venue / Authors
2026 J jnl
J. Intell. Manuf.
Kamal Taha
2026 J jnl
Pattern Recognit. Lett.
Mohammad Alshurbaji, Maregu Assefa, Ahmad Obeid, Mohamed L. Seghier, Taimur Hassan, Kamal Taha, Naoufel Werghi
2025 J jnl
IEEE Commun. Surv. Tutorials
Abeer Awadallah, Khouloud Eledlebi, Mohamed Jamal Zemerly, Deepak Puthal, Ernesto Damiani, Kamal Taha, Tae-Yeon Kim, Paul D. Yoo, Kim-Kwang Raymond Choo, Man-Sung Yim, Chan Yeob Yeun
2025 J jnl
J. Big Data
Kamal Taha
2025 J jnl
ACM Trans. Intell. Syst. Technol.
Kamal Taha
2025 J jnl
J. Big Data
Kamal Taha
2025 J jnl
Comput. Biol. Medicine
Kamal Taha
2025 J jnl
IEEE Access
Kamal Taha
2025 J jnl
Big Data Min. Anal.
Kamal Taha, Paul D. Yoo, Chan Yeob Yeun, Aya Taha
2025 conf
ICDM (Workshops)
Kamal Taha
2025 J jnl
BioData Min.
Kamal Taha
2024 J jnl
Comput. Sci. Rev.
Kamal Taha, Paul D. Yoo, Chan Yeob Yeun, Dirar Homouz, Aya Taha
2024 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Razan Alkhanbouli, Amira Al-Aamri, Maher Maalouf, Kamal Taha, Andreas Henschel, Dirar Homouz
2024 J jnl
CoRR
Kamal Taha
2024 J jnl
Big Data Min. Anal.
Kamal Taha, Paul D. Yoo, Chan Yeob Yeun, Aya Taha
2024 J jnl
CoRR
Kamal Taha, Paul D. Yoo, Aya Taha
2024 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Kamal Taha
2024 J jnl
Comput. Secur.
Kamal Taha, Paul D. Yoo, Yousof Al-Hammadi, Sami Muhaidat, Chan Yeob Yeun
2024 J jnl
CoRR
Kamal Taha, Abdulhadi Shoufan
2024 J jnl
CoRR
Kamal Taha, Paul D. Yoo, Chan Yeob Yeun, Aya Taha
2024 J jnl
IEEE Access
Kamal Taha
2023 J jnl
IEEE Trans. Comput. Soc. Syst.
Kamal Taha
2023 J jnl
IEEE Trans. Sustain. Comput.
Kamal Taha
2023 J jnl
CoRR
Kamal Taha
2023 Misc conf
CSR
Kamal Taha
2023 J jnl
Inf. Syst.
Kamal Taha
2022 J jnl
IEEE Access
Kamal Taha
2022 J jnl
Knowl. Based Syst.
Kamal Taha, Paul D. Yoo, Fatima Zohra Eddinari, Siniya Nedunkulathil
2021 J jnl
IEEE Trans. Knowl. Data Eng.
Kamal Taha
2020 conf
EMBC
Kamal Taha, Paul D. Yoo
2020 J jnl
IEEE Access
Seo Jin Lee, Paul D. Yoo, A. Taufiq Asyhari, Yoonchan Jhi, Lounis Chermak, Chan Yeob Yeun, Kamal Taha
2020 J jnl
IEEE Access
Kamal Taha
2020 J jnl
IEEE Trans. Cybern.
Ioannis Tsimperidis, Paul D. Yoo, Kamal Taha, Alexios Mylonas, Vasilis Katos
2020 J jnl
IEEE Access
Kamal Taha
2019 J jnl
BMC Bioinform.
Amira Al-Aamri, Kamal Taha, Yousof Al-Hammadi, Maher Maalouf, Dirar Homouz
2019 B conf
ARES
Luke R. Parker, Paul D. Yoo, A. Taufiq Asyhari, Lounis Chermak, Yoonchan Jhi, Kamal Taha
2019 C conf
CollaborateCom
Kamal Taha, Paul D. Yoo
2019 conf
BHI
Kamal Taha
2019 J jnl
BMC Bioinform.
Kamal Taha, Youssef Iraqi, Amira Al-Aamri
2019 C conf
CIBCB
Kamal Taha
2019 J jnl
IEEE Trans. Inf. Forensics Secur.
Kamal Taha, Paul D. Yoo
2018 conf
DASC/PiCom/DataCom/CyberSciTech
Kamal Taha, Paul D. Yoo
2018 J jnl
IEEE Trans. Comput. Soc. Syst.
Kamal Taha
2018 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Kamal Taha
2017 J jnl
IEEE Trans. Inf. Forensics Secur.
Kamal Taha, Paul D. Yoo
2016 conf
ICSC
Maryam R. Al-Shehhi, Benjamin Hirsch, Kamal Taha, Marcello Leida, Paul D. Yoo
2016 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Rami Al-Dalky, Kamal Taha, Dirar Mohammad Al Homouz, Murad Qasaimeh
2016 J jnl
IEEE Trans. Cybern.
Omar Y. Al-Jarrah, Omar Alhussein, Paul D. Yoo, Sami Muhaidat, Kamal Taha, Kwangjo Kim
2016 J jnl
BMC Bioinform.
Kamal Taha, Paul D. Yoo
2016 J jnl
BMC Bioinform.
Kamal Taha, Paul D. Yoo
2016 J jnl
IEEE Trans. Inf. Forensics Secur.
Kamal Taha, Paul D. Yoo
2015 B conf
ASONAM
Kamal Taha, Paul D. Yoo
2015 C conf
CIBCB
Kamal Taha, Paul D. Yoo
2015 J jnl
IEEE Trans. Inf. Forensics Secur.
Mohammed Alzaabi, Kamal Taha, Thomas Anthony Martin
2015 J jnl
Big Data Res.
Omar Y. Al-Jarrah, Paul D. Yoo, Sami Muhaidat, George K. Karagiannidis, Kamal Taha
2015 J jnl
CoRR
O. Y. Al-Jarrah, Paul D. Yoo, Sami Muhaidat, George K. Karagiannidis, Kamal Taha
2015 J jnl
IEEE J. Biomed. Health Informatics
Kamal Taha
2015 conf
EMBC
Kamal Taha, Paul D. Yoo
2015 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Omar Y. Al-Jarrah, Paul D. Yoo, Kamal Taha, Sami Muhaidat, Abdallah Shami, Nazar Zaki
2015 conf
BIBM
Kamal Taha
2015 J jnl
IEEE Trans. Ind. Informatics
Fatima Adly, Omar Alhussein, Paul D. Yoo, Yousof Al-Hammadi, Kamal Taha, Sami Muhaidat, Young-Seon Jeong, Uihyoung Lee, Mohammed Ismail
2015 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Kamal Taha, Paul D. Yoo, Mohammed Al Zaabi
2014 C conf
CIDM
Kamal Taha, Mohammed Al Zaabi
2014 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Kamal Taha
2014 C conf
CIBCB
Kamal Taha, Paul D. Yoo
2014 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Paul D. Yoo, Sami Muhaidat, Kamal Taha, Jamal Bentahar, Abdallah Shami
2013 J jnl
IEEE J. Biomed. Health Informatics
Kamal Taha
2013 conf
EMBC
Kamal Taha
2013 J jnl
BMC Bioinform.
Kamal Taha, Dirar Mohammad Al Homouz, Hassan Al-Muhairi, Zaid Al Mahmoud
2013 conf
ICECS
Maryam R. Al-Shehhi, Marcello Leida, Benjamin Hirsch, Paul D. Yoo, Kamal Taha
2012 C conf
CollaborateCom
Kamal Taha
2012 C conf
CIBCB
Kamal Taha, Ramez Elmasri
2012 Misc conf
AusDM
Kamal Taha
2012 B conf
ASONAM
Kamal Taha, Ramez Elmasri
2012 conf
CSE
Kamal Taha, Dirar Mohammad Al Homouz, Hassan Al-Muhairi
2011 J jnl
J. Integr. Bioinform.
Kamal Taha, Ramez Elmasri
2011 conf
IEEE SCC
Kamal Taha, Ramez Elmasri
2010 J jnl
J. Digit. Inf. Manag.
Kamal Taha, Ramez Elmasri
2010 J jnl
Knowl. Inf. Syst.
Kamal Taha, Ramez Elmasri
2010 J jnl
Inf. Syst.
Kamal Taha, Ramez Elmasri
2010 J jnl
IEEE Trans. Knowl. Data Eng.
Kamal Taha, Ramez Elmasri
2009 conf
XSym
Kamal Taha, Ramez Elmasri
2009 J jnl
J. Database Manag.
Kamal Taha, Ramez Elmasri
2009 conf
CSE (1)
Kamal Taha, Ramez Elmasri
2008 conf
DataX@EDBT
Kamal Taha, Ramez Elmasri
2007 conf
BNCOD
Kamal Taha, Ramez Elmasri
redb/extractors/malcontent.py
← Index redb/extractors/malcontent.py python
import inspect
import json
import subprocess
from typing import Any
from datetime import datetime, timezone

from redb.extractors.enum import Tag
from redb.models.dataclasses import Malcontent
from redb.extractors.extractor import Extractor
from dotenv import load_dotenv
import os

load_dotenv(override=True)


class MalcontentExtractor(Extractor):
    """
    Extractor for malcontent tool from chainguard-dev/malcontent.

    Malcontent discovers supply-chain compromises through context, differential
    analysis, and 14,000+ YARA rules. It analyzes binaries and code to detect
    malicious content and suspicious behavioral patterns.

    Binary can be extracted from Docker image:
        docker cp $(docker create cgr.dev/chainguard/malcontent:latest):/usr/bin/mal /usr/local/bin/mal

    Stores full JSON output for materialized view extraction.
    """

    # Cache version at class level to avoid repeated subprocess calls
    _cached_version = None

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious
        )
        self.malcontent = None

    @classmethod
    def _get_malcontent_version(cls, log) -> str:
        """Get malcontent version, cached at class level."""
        if cls._cached_version is not None:
            return cls._cached_version

        malcontent_path = os.getenv("MALCONTENT_PATH", "/usr/local/bin/mal")
        try:
            result = subprocess.run(
                [malcontent_path, "--version"],
                capture_output=True,
                text=True,
                timeout=10
            )
            version_output = result.stdout.strip()
            if result.returncode == 0 and version_output:
                # Parse "malcontent version v1.21.5" -> "1.21.5"
                if version_output.startswith("malcontent version v"):
                    version_output = version_output[len("malcontent version v"):]
                elif version_output.startswith("malcontent version "):
                    version_output = version_output[len("malcontent version "):]
                cls._cached_version = version_output
            else:
                cls._cached_version = "unknown"
        except Exception as e:
            log.warning(f"Could not get malcontent version: {e}")
            cls._cached_version = "unknown"

        return cls._cached_version

    def _extract_malcontent(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        TIMEOUT = int(os.getenv("MALCONTENT_TIMEOUT", "300"))
        malcontent_path = os.getenv("MALCONTENT_PATH", "/usr/local/bin/mal")

        malcontent_command = [malcontent_path, "analyze", "--format=json", self.filepath]

        import signal

        try:
            process = subprocess.Popen(
                malcontent_command,
                stdout=subprocess.PIPE,
                stderr=subprocess.PIPE,
                text=True,
                preexec_fn=os.setsid
            )

            try:
                stdout, stderr = process.communicate(timeout=TIMEOUT)
                if process.returncode != 0:
                    self.log.error(f"Error running malcontent, return code: {process.returncode}, stderr: {stderr}")
                    return {}
            except subprocess.TimeoutExpired:
                self.log.warning(f"The malcontent command timed out after {TIMEOUT} seconds, terminating process group")
                try:
                    os.killpg(process.pid, signal.SIGTERM)
                    try:
                        process.wait(timeout=3)
                    except subprocess.TimeoutExpired:
                        self.log.warning("Process didn't terminate with SIGTERM, sending SIGKILL")
                        os.killpg(process.pid, signal.SIGKILL)
                    process.wait()
                except (ProcessLookupError, OSError) as e:
                    self.log.warning(f"Error while killing process: {e}")
                return {}

            try:
                malcontent_output = json.loads(stdout)
            except json.JSONDecodeError as e:
                self.log.error(f"Error parsing malcontent output: {e}")
                return {}

            # Unwrap the Files/<path> structure to get the inner content
            # Structure is: {"Files": {"/path/to/file": {<actual content>}}}
            files_dict = malcontent_output.get("Files", {})
            if not files_dict:
                self.log.warning("Malcontent output has no 'Files' key")
                return {}

            # Get the first (and only) file's content
            file_content = next(iter(files_dict.values()), {})
            if not file_content:
                self.log.warning("Malcontent output has empty file content")
                return {}

            # Extract risk score and level from the unwrapped content
            risk_score = file_content.get("RiskScore", 0)
            risk_level = file_content.get("RiskLevel", "")

            version = self._get_malcontent_version(self.log)

            self.malcontent = Malcontent(
                malcontent_dump=json.dumps(file_content),
                version=version,
                risk_score=risk_score,
                risk_level=risk_level
            )
            self.log.debug(f"Malcontent analysis complete, version={version}, risk={risk_level}({risk_score})")

        except Exception as e:
            self.log.error(f"Unexpected error in malcontent extraction: {str(e)}")
            if 'process' in locals() and process.poll() is None:
                try:
                    os.killpg(process.pid, signal.SIGKILL)
                    process.wait()
                except:
                    pass
            return {}

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            data = [[
                self.sha256,
                current_time,
                self.malcontent.version,
                self.malcontent.risk_score,
                self.malcontent.risk_level,
                self.malcontent.malcontent_dump
            ]]

            column_names = [
                'sha256', 'analysis_date',
                'malcontent_version', 'malcontent_risk_score', 'malcontent_risk_level',
                'malcontent_json'
            ]

            column_type_names = [
                'FixedString(64)',
                'DateTime64(3, \'UTC\')',
                'LowCardinality(String)', 'UInt8', 'LowCardinality(String)',
                'JSON'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_malcontent"

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            self._extract_malcontent()
            return self.malcontent
        except Exception as e:
            self.log.error(f"Error extracting malcontent: {e}")
            return None

    def tag(self):
        return Tag.MALCONTENT.value