Kanok Boriboonsomsin

75 papers B 7C 1Journal 27Unranked 40
YearRankTypeTitle / Venue / Authors
2026 J jnl
CoRR
Ziyan Zhang, Chuheng Wei, Xuanpeng Zhao, Siyan Li, Will Snyder, Mike Stas, Peng Hao, Kanok Boriboonsomsin, Guoyuan Wu
2026 J jnl
CoRR
Ziyan Zhang, Changxin Wan, Peng Hao, Kanok Boriboonsomsin, Matthew J. Barth, Yongkang Liu, Seyhan Ucar, Guoyuan Wu
2025 conf
ITSC
Saswat Priyadarshi Nayak, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2025 J jnl
CoRR
Saswat Priyadarshi Nayak, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2025 conf
ITSC
Haishan Liu, Peng Hao, Zhensong Wei, Matthew J. Barth, Kanok Boriboonsomsin
2025 conf
ITSC
Emmanuel Hidalgo Gonzalez, Pengfei Fan, Matthew J. Barth, Kanok Boriboonsomsin
2024 conf
ITSC
Dongbo Peng, Matthew J. Barth, Kanok Boriboonsomsin
2024 J jnl
IEEE Trans. Veh. Technol.
Jacqueline Garrido, Emmanuel Hidalgo, Matthew J. Barth, Kanok Boriboonsomsin
2024 J jnl
IEEE Trans. Veh. Technol.
Fuad Un-Noor, Alexander Vu, Shams Tanvir, Zhiming Gao, Matthew J. Barth, Kanok Boriboonsomsin
2024 J jnl
IEEE Trans. Intell. Transp. Syst.
Haishan Liu, Peng Hao, Yejia Liao, Shams Tanvir, Kanok Boriboonsomsin, Matthew J. Barth
2023 conf
ITSC
Xuanpeng Zhao, Xishun Liao, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2023 J jnl
CoRR
Xuanpeng Zhao, Guoyuan Wu, Akula Venkatram, Ji Luo, Peng Hao, Kanok Boriboonsomsin, Shaohua Hu
2022 conf
ITSC
Yejia Liao, Ji Luo, Peng Hao, Matthew J. Barth, Kanok Boriboonsomsin
2021 J jnl
IEEE Intell. Transp. Syst. Mag.
Danyang Tian, Chao Wang, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth, Samer Rajab, Sue Bai
2021 conf
ITSC
Peng Hao, Zhensong Wei, Danial Esaid, Nigel Williams, Aravind Kailas, Pascal Amar, Kyle Palmeter, Lennard Levin, Stephen Orens, Matthew J. Barth, Kanok Boriboonsomsin
2021 conf
ITSC
David Oswald, Alexander Vu, Nigel Williams, Kanok Boriboonsomsin, Matthew J. Barth, Yoshinori Kunimura, Tomohiko Nagaya, Hiroki Yoshimatsu, Naoki Fukuoka
2020 J jnl
IEEE Trans. Intell. Veh.
Ziran Wang, Xishun Liao, Chao Wang, David Oswald, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth, Kyungtae Han, BaekGyu Kim, Prashant Tiwari
2020 J jnl
CoRR
Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2019 C conf
IV
Fei Ye, Peng Hao, Guoyuan Wu, Danial Esaid, Kanok Boriboonsomsin, Matthew J. Barth
2019 J jnl
IEEE Trans. Intell. Transp. Syst.
Danyang Tian, Guoyuan Wu, Peng Hao, Kanok Boriboonsomsin, Matthew J. Barth
2019 conf
ITSC
Ziran Wang, Pascal Amar, Eddie Garmon, Sandeep Tanugula, Yuan-Pu Hsu, Alexander Vu, Francisco Caballero, Peng Hao, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth, Aravind Kailas
2019 J jnl
CoRR
Ziran Wang, Yuan-Pu Hsu, Alexander Vu, Francisco Caballero, Peng Hao, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth, Aravind Kailas, Pascal Amar, Eddie Garmon, Sandeep Tanugula
2019 J jnl
IEEE Trans. Intell. Transp. Syst.
Peng Hao, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2019 J jnl
IEEE Trans. Intell. Transp. Syst.
Fei Ye, Peng Hao, Xuewei Qi, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2019 J jnl
IEEE Trans. Intell. Transp. Syst.
Xiaonian Shan, Peng Hao, Xiao-hong Chen, Kanok Boriboonsomsin, Guoyuan Wu, Matthew J. Barth
2018 J jnl
J. Intell. Transp. Syst.
Qichi Yang, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2018 conf
ITSC
Nigel Williams, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth, Samer Rajab, Sue Bai
2018 J jnl
IEEE Trans. Intell. Transp. Syst.
Xuewei Qi, Peng Wang, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2018 conf
ITSC
Fei Ye, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth, Samer Rajab, Sue Bai
2018 J jnl
IEEE Intell. Transp. Syst. Mag.
Danyang Tian, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2018 conf
ITSC
Ji Luo, Matthew J. Barth, Kanok Boriboonsomsin
2017 B conf
Intelligent Vehicles Symposium
Danyang Tian, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2017 B conf
Intelligent Vehicles Symposium
Xuewei Qi, Yadan Luo, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2017 B conf
Intelligent Vehicles Symposium
Ziran Wang, Guoyuan Wu, Peng Hao, Kanok Boriboonsomsin, Matthew J. Barth
2017 J jnl
IEEE Trans. Intell. Transp. Syst.
Xuewei Qi, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2017 conf
ITSC
Xuewei Qi, Peng Wang, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2017 J jnl
IEEE Trans. Intell. Veh.
Osman D. Altan, Guoyuan Wu, Matthew J. Barth, Kanok Boriboonsomsin, John A. Stark
2017 J jnl
IEEE Trans. Intell. Veh.
Xuewei Qi, Guoyuan Wu, Peng Hao, Kanok Boriboonsomsin, Matthew J. Barth
2017 conf
ITSC
Peng Hao, Ziran Wang, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2017 J jnl
IEEE Trans. Intell. Transp. Syst.
Peng Hao, Kanok Boriboonsomsin, Guoyuan Wu, Matthew J. Barth
2016 conf
ITSC
Fei Ye, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2016 conf
ITSC
Danyang Tian, Weixia Li, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth, Samer Rajab, Sue Bai
2016 conf
GECCO (Companion)
Xuewei Qi, Matthew J. Barth, Guoyuan Wu, Kanok Boriboonsomsin
2016 J jnl
IEEE Trans. Intell. Transp. Syst.
Qiu Jin, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2016 conf
ITSC
Xiaonian Shan, Peng Hao, Xiaohong Chen, Kanok Boriboonsomsin, Guoyuan Wu, Matthew J. Barth
2015 conf
ITSC
Xuewei Qi, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2015 B conf
Intelligent Vehicles Symposium
Peng Hao, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2015 conf
ICCVE
Guoyuan Wu, David Kari, Xuewei Qi, Kanok Boriboonsomsin, Matthew J. Barth
2015 B conf
Intelligent Vehicles Symposium
Xuewei Qi, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2015 conf
ICCVE
Peng Hao, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2014 conf
ITSC
Xuewei Qi, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2014 J jnl
IEEE Trans. Intell. Transp. Syst.
Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2014 B conf
Intelligent Vehicles Symposium
Qiu Jin, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2014 conf
ITSC
Peng Hao, Kanok Boriboonsomsin, Guoyuan Wu, Matthew J. Barth
2013 conf
ITSC
Qichi Yang, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2013 conf
ITSC
Haitao Xia, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2013 J jnl
J. Intell. Transp. Syst.
Haitao Xia, Kanok Boriboonsomsin, Matthew J. Barth
2013 conf
ITSC
Qiu Jin, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2013 conf
ICCVE
Matthew J. Barth, Kanok Boriboonsomsin, Guoyuan Wu
2012 B conf
Intelligent Vehicles Symposium
Qiu Jin, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2012 J jnl
IEEE Trans. Intell. Transp. Syst.
Kanok Boriboonsomsin, Matthew J. Barth, Weihua Zhu, Alexander Vu
2012 conf
ITSC
Haitao Xia, Kanok Boriboonsomsin, Friedrich Schweizer, Andreas Winckler, Kun Zhou, Wei-Bin Zhang, Matthew J. Barth
2012 conf
ICCVE
Qiu Jin, Guoyuan Wu, Kanok Boriboonsomsin, Matthew J. Barth
2012 conf
ITSC
Guoyuan Wu, Kanok Boriboonsomsin, Liping Zhang, Matthew J. Barth
2011 conf
ITSC
Qichi Yang, Kanok Boriboonsomsin, Matthew J. Barth
2011 conf
ITSC
Haitao Xia, Kanok Boriboonsomsin, Matthew J. Barth
2010 conf
ITSC
Scott Boskovich, Kanok Boriboonsomsin, Matthew J. Barth
2010 J jnl
J. Intell. Transp. Syst.
Weihua Zhu, Kanok Boriboonsomsin, Matthew J. Barth
2010 conf
ITSC
Anh Vu, Kanok Boriboonsomsin, Matthew J. Barth
2009 conf
ITSC
Sindhura Mandava, Kanok Boriboonsomsin, Matthew J. Barth
2008 conf
ITSC
Weihua Zhu, Kanok Boriboonsomsin, Matthew J. Barth
2008 conf
ITSC
Weihua Zhu, Kanok Boriboonsomsin, Matthew J. Barth
2007 conf
ITSC
Matthew J. Barth, Kanok Boriboonsomsin, Alexander Vu
2007 conf
ITSC
Weihua Zhu, Kanok Boriboonsomsin, Matthew J. Barth
2006 conf
ITSC
Oscar Servin, Kanok Boriboonsomsin, Matthew J. Barth
redb/extractors/elf_extractors/elf_relocations.py
← Index redb/extractors/elf_extractors/elf_relocations.py python
import inspect
from datetime import datetime, timezone
from typing import Any, List, Dict

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFRelocation


class ELFRelocationExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_relocations = []
        self.elastic_index = self.index_prefix + "-elf_relocations"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _get_relocation_type_string(self, reloc_type: int, machine_arch: str) -> str:
        """Convert relocation type number to human-readable string based on architecture."""
        # This is a simplified mapping - real implementation would need comprehensive
        # architecture-specific relocation type mappings

        common_types = {
            0: "R_NONE",
            1: "R_DIRECT",
            2: "R_PC_RELATIVE",
            3: "R_GOT",
            4: "R_PLT",
            5: "R_COPY",
            6: "R_GLOB_DAT",
            7: "R_JMP_SLOT",
            8: "R_RELATIVE"
        }

        # Architecture-specific mappings could be added here
        if machine_arch == "x86_64":
            x86_64_types = {
                1: "R_X86_64_64",
                2: "R_X86_64_PC32",
                3: "R_X86_64_GOT32",
                4: "R_X86_64_PLT32",
                5: "R_X86_64_COPY",
                6: "R_X86_64_GLOB_DAT",
                7: "R_X86_64_JUMP_SLOT",
                8: "R_X86_64_RELATIVE"
            }
            return x86_64_types.get(reloc_type, f"R_X86_64_{reloc_type}")
        elif machine_arch == "x86":
            i386_types = {
                1: "R_386_32",
                2: "R_386_PC32",
                3: "R_386_GOT32",
                4: "R_386_PLT32",
                5: "R_386_COPY",
                6: "R_386_GLOB_DAT",
                7: "R_386_JMP_SLOT",
                8: "R_386_RELATIVE"
            }
            return i386_types.get(reloc_type, f"R_386_{reloc_type}")

        return common_types.get(reloc_type, f"R_UNKNOWN_{reloc_type}")

    def _extract_relocation_data(self, relocation, section_name: str, machine_arch: str) -> Dict:
        """Extract data from a single relocation entry."""
        try:
            # Get relocation offset
            relocation_offset = relocation.entry.get('r_offset', 0)

            # Get relocation type
            relocation_type = relocation.entry.get('r_info_type', 0)

            # Get symbol index
            relocation_symbol_index = relocation.entry.get('r_info_sym', 0)

            # Get addend (only present in RELA sections)
            relocation_addend = None
            if hasattr(relocation.entry, 'r_addend'):
                relocation_addend = relocation.entry.get('r_addend', 0)

            # Get symbol name if available
            relocation_symbol_name = ""
            if hasattr(relocation, 'symbol') and relocation.symbol:
                relocation_symbol_name = relocation.symbol.name or f"<symbol_{relocation_symbol_index}>"
            else:
                relocation_symbol_name = f"<symbol_{relocation_symbol_index}>"

            # Get type string mapping
            relocation_type_str = self._get_relocation_type_string(relocation_type, machine_arch)

            return ELFRelocation(
                relocation_offset=relocation_offset,
                relocation_type=relocation_type,
                relocation_type_str=relocation_type_str,
                relocation_symbol_index=relocation_symbol_index,
                relocation_symbol_name=relocation_symbol_name,
                relocation_section=section_name,
                relocation_addend=relocation_addend
            )

        except Exception as e:
            self.log.error(f"Error extracting relocation data: {e}")
            return None

    def _extract_relocations_from_section(self, section, machine_arch: str) -> List[Dict]:
        """Extract all relocations from a relocation section."""
        relocations = []

        try:
            if not hasattr(section, 'iter_relocations'):
                return relocations

            section_name = section.name or f"<unnamed_section>"

            for relocation in section.iter_relocations():
                reloc_data = self._extract_relocation_data(relocation, section_name, machine_arch)
                if reloc_data:
                    relocations.append(reloc_data)

        except Exception as e:
            self.log.error(f"Error extracting relocations from section {section.name}: {e}")

        return relocations

    def tag(self):
        return Tag.ELF_RELOCATIONS.value if hasattr(Tag, 'ELF_RELOCATIONS') else "elf_relocations"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_data(elf):
                # Get architecture for relocation type mapping
                machine_arch = self._get_architecture()
                all_relocations = []

                # Iterate through all sections looking for relocation sections with per-section error handling
                for section_index, section in enumerate(elf.iter_sections()):
                    try:
                        # Check if this is a relocation section (.rel or .rela)
                        if (section.name and
                            (section.name.startswith('.rel') or section.name.startswith('.rela')) and
                            hasattr(section, 'iter_relocations')):

                            section_relocations = self._extract_relocations_from_section(section, machine_arch)
                            all_relocations.extend(section_relocations)
                            self.log.debug(f"Extracted {len(section_relocations)} relocations from section {section.name}")
                    except Exception as e:
                        section_name = getattr(section, 'name', f'section_{section_index}')
                        self.log.warning(f"Error processing relocation section {section_name}: {e}")
                        # Continue processing other sections

                return all_relocations

            if not self._is_elf_file():
                return None

            result = self._with_elf_file(extract_data)
            if result is None:
                return None

            self.elf_relocations = result
            return self.elf_relocations

        except Exception as e:
            self.log.error(f"Error extracting ELF relocations {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_relocations
        elif exporter_type == "ClickHouseExporter":
            try:
                # Return valid empty structure if no relocations (e.g., statically linked binary)
                # None is reserved for actual errors

                # Prepare data arrays for all relocations
                data = []
                current_time = datetime.now(timezone.utc)
                for reloc in self.elf_relocations:
                    row = [
                        self.sha256,
                        self.md5,
                        self.sha1,
                        reloc.relocation_offset,
                        reloc.relocation_type,
                        reloc.relocation_type_str,
                        reloc.relocation_symbol_index,
                        reloc.relocation_symbol_name,
                        reloc.relocation_addend,
                        reloc.relocation_section,
                        current_time
                    ]
                    data.append(row)

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'relocation_offset', 'relocation_type', 'relocation_type_str',
                    'relocation_symbol_index', 'relocation_symbol_name',
                    'relocation_addend', 'relocation_section',
                    'analysis_date'
                ]

                if not data:
                    return None

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    'UInt64', 'UInt32', 'LowCardinality(String)',
                    'UInt32', 'LowCardinality(String)',
                    'Nullable(Int64)', 'LowCardinality(String)',
                    'DateTime64(3, \'UTC\')'
                ]

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_relocations"