Karsten Ehrig

39 papers A* 2A 1B 7Journal 13Unranked 15
YearRankTypeTitle / Venue / Authors
2018 J jnl
Comput. Geosci.
Jürgen Titschack, Daniel Baum, K. Matsuyama, K. Boos, C. Färber, Wolf-Achim Kahl, Karsten Ehrig, Dietmar Meinel, C. Soriano, Stuart R. Stock
2011 conf
Three-Dimensional Imaging, Interaction, and Measurement
Ulrich Neuschaefer-Rube, Markus Bartscher, Marko Neukamm, Michael Neugebauer, Frank Härtig, Jürgen Goebbels, Karsten Ehrig, Andreas Staude
2010 J jnl
Formal Aspects Comput.
Hartmut Ehrig, Karsten Ehrig, Claudia Ermel, Ulrike Prange
2010 J jnl
Electron. Commun. Eur. Assoc. Softw. Sci. Technol.
Claudia Ermel, Karsten Ehrig
2009 J jnl
Softw. Syst. Model.
Karsten Ehrig, Jochen Malte Küster, Gabriele Taentzer
2009 A* conf
ASE
Enrico Biermann, Karsten Ehrig, Claudia Ermel, Jonas Hurrelmann
2009 J jnl
Electron. Commun. Eur. Assoc. Softw. Sci. Technol.
Hartmut Ehrig, Karsten Ehrig, Claudia Ermel
2008 B conf
FASE
Hartmut Ehrig, Karsten Ehrig, Claudia Ermel, Ulrike Prange
2008 B conf
VL/HCC
Enrico Biermann, Claudia Ermel, Jonas Hurrelmann, Karsten Ehrig
2008 J jnl
Electron. Commun. Eur. Assoc. Softw. Sci. Technol.
Hartmut Ehrig, Karsten Ehrig, Frank Hermann
2007 J jnl
Theor. Comput. Sci.
Juan de Lara, Roswitha Bardohl, Hartmut Ehrig, Karsten Ehrig, Ulrike Prange, Gabriele Taentzer
2007 conf
AGTIVE
Enrico Biermann, Karsten Ehrig, Claudia Ermel, Gabriele Taentzer
2007 B conf
FASE
Hartmut Ehrig, Karsten Ehrig, Claudia Ermel, Frank Hermann, Gabriele Taentzer
2007 J jnl
Bull. EATCS
Hartmut Ehrig, Karsten Ehrig, Claudia Ermel, Ulrike Prange
2007 conf
AGTIVE
Enrico Biermann, Karsten Ehrig, Claudia Ermel, Christian Köhler, Gabriele Taentzer
2007 conf
AGTIVE
Claudia Ermel, Karsten Ehrig
2006 J jnl
Electron. Commun. Eur. Assoc. Softw. Sci. Technol.
Enrico Biermann, Karsten Ehrig, Christian Köhler, Günter Kuhns, Gabriele Taentzer, Eduard Weiss
2006 J jnl
Fundam. Informaticae
Hartmut Ehrig, Karsten Ehrig, Ulrike Prange, Gabriele Taentzer
2006 book
Hartmut Ehrig, Karsten Ehrig, Ulrike Prange, Gabriele Taentzer
2006 conf
FMOODS
Karsten Ehrig, Jochen Malte Küster, Gabriele Taentzer, Jessica Winkelmann
2006 A conf
MoDELS
Enrico Biermann, Karsten Ehrig, Christian Köhler, Günter Kuhns, Gabriele Taentzer, Eduard Weiss
2006 B conf
ICGT
Karsten Ehrig, Reiko Heckel, Georgios Lajios
2006 J jnl
Electron. Commun. Eur. Assoc. Softw. Sci. Technol.
Claudia Ermel, Karsten Ehrig, Gabriele Taentzer, Eduard Weiss
2006 J jnl
Electron. Commun. Eur. Assoc. Softw. Sci. Technol.
Claudia Ermel, Hartmut Ehrig, Karsten Ehrig
2006 J jnl
Fundam. Informaticae
Hartmut Ehrig, Karsten Ehrig, Annegret Habel, Karl-Heinz Pennemann
2006 conf
GT-VMT@ETAPS
Jessica Winkelmann, Gabriele Taentzer, Karsten Ehrig, Jochen Malte Küster
2006 conf
TGC
Luciano Baresi, Karsten Ehrig, Reiko Heckel
2005 B conf
VL/HCC
Hartmut Ehrig, Karsten Ehrig, Ulrike Prange, Gabriele Taentzer
2005 A* conf
ASE
Karsten Ehrig, Claudia Ermel, Stefan Hänsgen, Gabriele Taentzer
2005 conf
Bildverarbeitung für die Medizin
Karsten Ehrig, Jürgen Braun, Thomas Tolxdorff
2005 conf
GRaMoT@GPCE
Karsten Ehrig, Jessica Winkelmann
2005 conf
GRaMoT@GPCE
Hartmut Ehrig, Karsten Ehrig
2005 conf
Transformation Techniques in Software Engineering
Hartmut Ehrig, Karsten Ehrig, Gabriele Taentzer, Juan de Lara, Dániel Varró, Szilvia Varró-Gyapay
2005 B conf
FASE
Hartmut Ehrig, Karsten Ehrig, Juan de Lara, Gabriele Taentzer, Dániel Varró, Szilvia Varró-Gyapay
2005 conf
GRaMoT@GPCE
Karsten Ehrig, Claudia Ermel, Stefan Hänsgen
2004 B conf
ICGT
Hartmut Ehrig, Karsten Ehrig, Annegret Habel, Karl-Heinz Pennemann
2004 conf
GT-VMT@ETAPS
Juan de Lara Jaramillo, Claudia Ermel, Gabriele Taentzer, Karsten Ehrig
2004 conf
VLFM
Karsten Ehrig, Claudia Ermel, Stefan Hänsgen, Gabriele Taentzer
2004 conf
PNGT@ICGT
Claudia Ermel, Karsten Ehrig
redb/extractors/pe_extractors/pe_imports.py
← Index redb/extractors/pe_extractors/pe_imports.py python
import inspect
from typing import Any, List, Tuple
from datetime import datetime, timezone

from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PEImport


class PEImportExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_imports"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_IMPORT.value

    def _extract_imports(self):
        self.log.debug(inspect.currentframe().f_code.co_name)

        imports_symbols = []
        imports_lib = []
        imports_total = 0
        # pe_import = None
        try:
            directory_entry_import = getattr(self.pe, "DIRECTORY_ENTRY_IMPORT", [])
            imports_total = len(directory_entry_import)
            for entry in directory_entry_import:
                symbols = []
                tmp_import = {}
                libname = entry.dll.decode() if entry.dll else ""
                imports_lib.append(libname)
                # replace . with _ to avoid issues with elastic
                # entryname = entryname.replace(".", "_")
                for symbol in entry.imports:
                    if symbol.name:
                        symbols.append(symbol.name.decode())
                # imports_symbols[entryname] = symbols
                tmp_import[libname] = symbols
                imports_symbols.append(tmp_import)
            return PEImport(
                pe_imports_total=imports_total,
                pe_import_libraryName=imports_lib if imports_lib else None,
                pe_import_functions=imports_symbols if imports_symbols else None,
            )
        except Exception as e:
            self.log.error(f"Extract imports error {self.hash.sha256} Exception: {e}")
        return pe_import

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)
            return self._extract_imports()
        except Exception as e:
            self.log.error(f"Extract imports error {self.hash.sha256} Exception: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            imports = self.extract()
            if (
                imports is None
                or imports.pe_imports_total == 0
                or (
                    imports.pe_import_libraryName is None
                    and imports.pe_import_functions is None
                )
            ):
                return None

            # Flatten the data - one row per function import
            data = []
            current_time = datetime.now(timezone.utc)

            for lib_funcs in imports.pe_import_functions:
                for lib, funcs in lib_funcs.items():
                    for func in funcs:
                        data.append(
                            [
                                self.sha256,  # sha256
                                self.md5,  # md5
                                self.sha1,  # sha1
                                lib,  # library_name
                                func,  # function_name
                                current_time,  # analysis_date
                            ]
                        )

            column_names = [
                "sha256",
                "md5",
                "sha1",
                "library_name",
                "function_name",
                "analysis_date",
            ]

            column_type_names = [
                "FixedString(64)",
                "FixedString(32)",
                "FixedString(40)",
                "LowCardinality(Nullable(String))",
                "LowCardinality(Nullable(String))",
                "DateTime64(3, 'UTC')",
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_imports"