Karina Gibert

97 papers A* 1C 4Journal 39Unranked 48
YearRankTypeTitle / Venue / Authors
2025 J jnl
Cogn. Syst. Res.
Xavier Angerri, Joan Vázquez, Karina Gibert
2024 conf
CCIA
Ashutosh Karna, Karina Gibert
2024 conf
CCIA
Xavier Angerri, Oscar Delgado, Karina Gibert
2024 A* conf
KDD
Karina Gibert, Wee Hyong Tok, Miquel Sànchez-Marrè
2024 conf
CCIA
Sergi Ramirez-Mitjans, Huilin Ni, Jofre Moseguí, Javier Puerta, Marcel Vera, Karina Gibert
2023 conf
CCIA
Xavier Angerri, Karina Gibert
2023 conf
CCIA
Ashutosh Karna, Karina Gibert
2023 J jnl
Int. J. Artif. Intell. Tools
Xavier Angerri, Karina Gibert
2022 J jnl
Neural Comput. Appl.
Alfredo Vellido, Cecilio Angulo, Karina Gibert
2022 J jnl
Neural Comput. Appl.
Ashutosh Karna, Karina Gibert
2022 conf
CCIA
Ashutosh Karna, Karina Gibert
2021 conf
CCIA
Karina Gibert, Yaroslav Hernandez-Potiomkin
2021 J jnl
Symmetry
Raffaele Mattera, Massimiliano Giacalone, Karina Gibert
2021 J jnl
Log. J. IGPL
Zoe Falomir, Vicent Costa, Enric Plaza, Karina Gibert
2021 conf
CCIA
Shikha Suman, Ashutosh Karna, Karina Gibert
2021 conf
SOCO
Angel X. Astudillo Aguilar, Stefano Rosso, Karina Gibert, Alfredo Vellido
2020 ed.
WSOM+
Alfredo Vellido, Karina Gibert, Cecilio Angulo, José David Martín-Guerrero
2020 J jnl
Pattern Recognit. Lett.
Zoe Falomir, Karina Gibert, Enric Plaza
2019 J jnl
Comput. Environ. Urban Syst.
Álvaro Gómez-Losada, Francisca M. Santos, Karina Gibert, José Carlos M. Pires
2019 conf
IWINAC (2)
Miquel Sànchez-Marrè, Karina Gibert, Beatriz Sevilla Villanueva
2019 C conf
ETFA
Karina Gibert, Conxi Pérez Andreu, Núria Castell
2019 conf
CCIA
Karina Gibert, Beatriz Sevilla Villanueva, Miquel Sànchez-Marrè, Lluis Marquès, Eric Casanova, Montserrat Fito
2019 conf
WSOM+
Ashutosh Karna, Karina Gibert
2018 ed.
CCIA
Zoe Falomir, Karina Gibert, Enric Plaza
2018 J jnl
Environ. Model. Softw.
Karina Gibert, Jeffery S. Horsburgh, Ioannis N. Athanasiadis, Geoff Holmes
2018 conf
CCIA
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2018 conf
CAEPIA
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2018 J jnl
Environ. Model. Softw.
Karina Gibert, Jeffery S. Horsburgh, Ioannis N. Athanasiadis, Geoff Holmes
2018 J jnl
Environ. Model. Softw.
Karina Gibert
2018 J jnl
Inf. Manag.
Aïda Valls, Karina Gibert, Alicia Orellana, Salvador Anton Clavé
2018 conf
CCIA
Arturo Palomino, Karina Gibert
2018 J jnl
Environ. Model. Softw.
Karina Gibert, Joaquín Izquierdo, Miquel Sànchez-Marrè, Serena H. Hamilton, Ignasi Rodríguez-Roda, Geoff Holmes
2017 J jnl
Pattern Recognit. Lett.
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2017 J jnl
IEEE J. Biomed. Health Informatics
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè, Montserrat Fito, Maria-Isabel Covas
2017 conf
CCIA
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2016 conf
CCIA
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2016 J jnl
AI Commun.
Karina Gibert, Miquel Sànchez-Marrè, Joaquín Izquierdo
2016 J jnl
Int. J. Comput. Math.
Karina Gibert, Dante Conti
2016 J jnl
AI Commun.
Karina Gibert
2016 J jnl
J. Comput. Appl. Math.
Karina Gibert, Beatriz Sevilla Villanueva, Miquel Sànchez-Marrè
2016 J jnl
Eng. Appl. Artif. Intell.
Alejandro García-Rudolph, Karina Gibert
2016 conf
CAEPIA
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2015 conf
SITIS
Romain David, Jean-Pierre Feral, Sophie Gachet, Alrick Dias, Cyrille Blanpain, Julien Lecubin, Cristinel Diaconu, Christian Surace, Karina Gibert
2015 conf
CCIA
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2015 J jnl
AI Commun.
Karina Gibert, Carles Sierra
2015 J jnl
AI Commun.
Karina Gibert, Dante Conti
2014 J jnl
Expert Syst. Appl.
Alejandro García-Rudolph, Karina Gibert
2014 J jnl
Knowl. Inf. Syst.
Karina Gibert, Aïda Valls, Montserrat Batet
2014 J jnl
Int. J. Comput. Math.
Karina Gibert
2014 conf
CCIA
Arturo Palomino, Karina Gibert
2013 conf
CCIA
Dante Conti, Karina Gibert
2013 ed.
CCIA
Karina Gibert, Vicent J. Botti, Ramón Reig Bolaño
2013 conf
CCIA
Alejandro García-Rudolph, Karina Gibert
2013 conf
CCIA
Beatriz Sevilla Villanueva, Karina Gibert, Miquel Sànchez-Marrè
2013 J jnl
Math. Comput. Model.
Karina Gibert, Gustavo Rodríguez Silva, Roberta Annicchiarico
2013 J jnl
Appl. Intell.
Montserrat Batet, David Sánchez, Aïda Valls, Karina Gibert
2012 conf
IPMU (2)
Karina Gibert, Dante Conti, Miquel Sànchez-Marrè
2012 J jnl
J. Intell. Inf. Syst.
Montserrat Batet, David Isern, Lucas Marin, Sergio Martínez, Antonio Moreno, David Sánchez, Aïda Valls, Karina Gibert
2012 conf
CCIA
Dante Conti, Karina Gibert
2011 J jnl
Environ. Model. Softw.
Karina Gibert, Miquel Sànchez-Marrè
2011 conf
ICAART (1)
Montserrat Batet, Aïda Valls, Karina Gibert
2010 conf
IEA/AIE (1)
Montserrat Batet, David Sánchez, Aïda Valls, Karina Gibert
2010 J jnl
Artif. Intell.
Javier Farreres, Karina Gibert, Horacio Rodríguez, Charnyote Pluempitiwiriyawej
2010 J jnl
Environ. Model. Softw.
Karina Gibert, Gustavo Rodríguez Silva, Ignasi Rodríguez-Roda
2010 J jnl
J. Intell. Inf. Syst.
David Sánchez, Montserrat Batet, Aïda Valls, Karina Gibert
2010 conf
ICAISC (1)
Montserrat Batet, Aïda Valls, Karina Gibert
2010 conf
CCIA
Montserrat Batet, Aïda Valls, Karina Gibert, David Sánchez
2010 J jnl
Int. J. Medical Informatics
Aïda Valls, Karina Gibert, David Sánchez, Montserrat Batet
2009 conf
CCIA
Montserrat Batet, Sergio Martínez, Aïda Valls, Karina Gibert
2009 conf
MIE
Karina Gibert, Alejandro García-Rudolph, Lluïsa Curcoll, Dolors Soler, Laura Pla, José María Tormos
2009 conf
CCIA
Gustavo Rodríguez Silva, Karina Gibert
2008 conf
K4HelP
Montserrat Batet, Aïda Valls, Karina Gibert, Sergio Martínez, Ester Morales
2008 C conf
CIARP
Karina Gibert, Gustavo Rodríguez Silva
2008 conf
CCIA
Angela Chieppa, Karina Gibert, Ignasi Gómez-Sebastià, Miquel Sànchez-Marrè
2008 conf
CCIA
Karina Gibert, Alejandro García-Rudolph, Alberto García-Molina, Teresa Roig-Rovira, Montserrat Bernabeu, José María Tormos
2008 conf
MIE
Karina Gibert, Aïda Valls, David Riaño
2007 conf
CCIA
Xavier Lluis Martorell, Raimon Massanet Vila, Karina Gibert, Miquel Sànchez-Marrè, Juan Carlos Martín, Almudena Martorell
2007 conf
K4CARE
Karina Gibert, Aïda Valls, Joan Casals
2007 conf
CCIA
Karina Gibert, Gustavo Rodríguez Silva
2007 conf
K4CARE
Montserrat Batet, Karina Gibert, Aïda Valls
2007 C conf
CIARP
Alejandra Pérez-Bonilla, Karina Gibert
2006 conf
CCIA
Karina Gibert, Alejandra Pérez-Bonilla, Gustavo Rodríguez Silva
2006 J jnl
Environ. Model. Softw.
Karina Gibert, Miquel Sànchez-Marrè, Ignasi Rodríguez-Roda
2006 ch.
Data Science and Classification
Karina Gibert, Alejandra Pérez-Bonilla
2005 J jnl
AI Commun.
Karina Gibert, Miquel Sànchez-Marrè, Xavier Flores
2005 conf
EUSFLAT Conf.
Karina Gibert, Alejandra Pérez-Bonilla
2005 J jnl
BMC Bioinform.
Marco Masseroli, Osvaldo Galati, Mauro Manzotti, Karina Gibert, Francesco Pinciroli
2005 conf
MIE
Karina Gibert, Roberta Annicchiarico, Ulises Cortés, Carlo Caltagirone
2004 J jnl
Res. Comput. Sci.
Ignasi Rodríguez-Roda, Karina Gibert, Miguel Sánchez-Marrè
2003 C conf
CIARP
Karina Gibert, R. Nonell
2002 conf
CCIA
Laura Alonso Alemany, Irene Castellón, Karina Gibert, Lluís Padró
2002 J jnl
Proces. del Leng. Natural
Laura Alonso Alemany, Irene Castellón Masalles, Karina Gibert, Lluís Padró
2002 conf
CCIA
Jorge Rodas Osollo, Karina Gibert, J. Emilio Rojo
2001 conf
ISMDA
Jorge Rodas Osollo, Karina Gibert, J. Emilio Rojo
2001 J jnl
AI Commun.
Joaquim Comas, Saso Dzeroski, Karina Gibert, Ignasi R.-Roda, Miquel Sànchez-Marrè
1998 conf
PKDD
Karina Gibert, Tomàs Aluja-Banet, Ulises Cortés
1995
Karina Gibert
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |