Kanika Sood

28 papers C 4Misc 1Journal 3Unranked 20
YearRankTypeTitle / Venue / Authors
2025 conf
ICECET
Jeremiah Herring, Noah Beidelman, Kanika Sood
2025 conf
SIGCSE (1)
Kevin A. Wortman, Aakash Gautam, Sarah Hug, Paul Salvador Inventado, Ayaan M. Kazerouni, Jane Lehr, Kanika Sood, Zoë J. Wood
2024 conf
SmartNets
Brennon Hahs, Kanika Sood, Desiree Gomez
2024 C conf
ISNCC
Yathartha Patankar, Kanika Sood
2024 conf
CCWC
Rakeshkumar V. Mahto, Kanika Sood
2024 Misc conf
ICMLC
Tina Torabinejad, Kanika Sood
2024 J jnl
CoRR
Azucena Lizbeth Jimenez Martinez, Kanika Sood, Rakeshkumar V. Mahto
2024 conf
CCWC
Rakeshkumar V. Mahto, Kanika Sood
2024 conf
UEMCON
Aakarsh Surendra, Kanika Sood, Craig Albuquerque, Shirin Akbar, Gourav Joshi, Pallavi Sakshi
2023 C conf
ISNCC
Bharti Moryani, Kanika Sood, Kirti Chaudhary
2023 conf
CCWC
Anna Chiu, Kanika Sood, Ariadne Rincon, Davina Doran
2023 conf
GHTC
Rakeshkumar V. Mahto, Kanika Sood
2023 C conf
ISNCC
Kunal Chhatrapati, Kanika Sood, Purva Surve
2023 conf
SmartNets
Victor Tran, Kanika Sood, Kayhan Bakian, Aneesh Reddy Sannapu
2023 C conf
ISNCC
Steven Rico, Kanika Sood, Kevin Hsu, Ethan Trinh
2023 conf
SmartNets
Nurhaliza Hassan, Kanika Sood, Gabriel Suzuki
2023 conf
AIIoT
Kanika Sood, Sijie Shang, Nima Nijad
2023 conf
UEMCON
Rakeshkumar V. Mahto, Kanika Sood, Nathaniel Ruppert
2023 conf
AIIoT
Kanika Sood, Aneesh Reddy Sannapu
2023 conf
CCWC
Nidhi Shah, Kanika Sood, Jayraj Arora
2023 conf
UEMCON
Kanika Sood, Azucena Lizbeth Jimenez Martinez
2022 conf
SmartNets
Merin Joseph, Kanika Sood, Tianhao Shen
2022 conf
ICHI
Kanika Sood, Prathyusha Gundlapally
2020 J jnl
Int. J. High Perform. Comput. Appl.
A. Grannan, Kanika Sood, Boyana Norris, Anshu Dubey
2017 conf
HPCC/SmartCity/DSS
Kanika Sood, Boyana Norris, Elizabeth R. Jessup
2016 J jnl
SIAM J. Sci. Comput.
Elizabeth R. Jessup, Pate Motter, Boyana Norris, Kanika Sood
2015 conf
SEPS@SPLASH
Kanika Sood, Boyana Norris, Elizabeth R. Jessup
2015 conf
SE-HPCCSE@SC
Pate Motter, Kanika Sood, Elizabeth R. Jessup, Boyana Norris
redb/extractors/pe_extractors/pe_sections.py
← Index redb/extractors/pe_extractors/pe_sections.py python
import base64
import hashlib
import inspect
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PESection
from datetime import datetime, timezone
from typing import Any


class PESectionExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_sections"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_SECTION.value

    def _extract_sections(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        sections = []
        for section in self.pe.sections:
            try:
                name = self.process_binary_string(section.Name)
            except Exception as e:
                name = "UnableToDecode"
                self.log.warning(
                    f'Unable to store section Name "{section.Name}" for {self.hash.sha256}'
                    f" exception {e}"
                )
            sec_sha256 = section.get_hash_sha256()
            sec_md5 = section.get_hash_md5()
            # sec_entropy = "%.2f" % section.get_entropy()
            sec_entropy = section.get_entropy()
            pe_section = PESection(
                _id=hashlib.sha256(
                    name.encode()
                ).hexdigest(),  # usecase 8e035beb02a411f8a9e92d4cf184ad34f52bbd0a81a50c222cdd4706e4e45104, all section have same sha256
                section_name=name,
                section_name_b64=base64.b64encode(
                    section.Name.rstrip(b'\x00')
                ).decode(),  # base64.b64decode(b64) to decode
                section_v_addr=section.VirtualAddress,
                section_v_addr_hex=hex(section.VirtualAddress),
                section_v_size=section.Misc_VirtualSize,
                section_size=section.SizeOfRawData,
                section_pointer_to_raw_data=hex(section.PointerToRawData),
                section_md5=sec_md5,
                section_sha256=sec_sha256,
                section_entropy=sec_entropy,
            )
            sections.append(pe_section)
        return sections

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            sections = self._extract_sections()
            # self.export_to_elastic(sections)  # Let the exporters handle this
            return sections
        except Exception as e:
            self.log.error(f"Error extracting PE sections: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            sections = self.extract()
            if sections is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for section in sections:
                data.append([
                    self.sha256,                          # sha256
                    self.md5,                             # md5
                    self.sha1,                            # sha1
                    section.section_name,                 # section_name
                    section.section_name_b64,             # section_name_b64
                    section.section_entropy,              # section_entropy
                    section.section_sha256,               # section_sha256
                    section.section_md5,                  # section_md5
                    section.section_size,                 # section_size
                    section.section_v_addr,               # section_v_addr
                    section.section_v_size,               # section_v_size
                    int(section.section_pointer_to_raw_data, 16),  # section_pointer_to_raw_data - convert from hex
                    current_time                          # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'section_name', 'section_name_b64',
                'section_entropy', 'section_sha256', 'section_md5', 'section_size',
                'section_v_addr', 'section_v_size', 'section_pointer_to_raw_data',
                'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(String)', 'LowCardinality(String)',
                'Float64', 'FixedString(64)', 'FixedString(32)', 'UInt64',
                'UInt64', 'UInt64', 'UInt64',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_sections"