Karthee Sivalingam

11 papers Misc 1Journal 5Unranked 5
YearRankTypeTitle / Venue / Authors
2024 conf
SC Workshops
Lorenzo Pichetti, Daniele De Sensi, Karthee Sivalingam, Stepan Nassyr, Daniele Cesarini, Matteo Turisini, Dirk Pleiter, Aldo Artigiani, Flavio Vella
2023 conf
CF
Julian Martin Kunkel, Christian Boehme, Jonathan Decker, Fabrizio Magugliani, Dirk Pleiter, Bastian Koller, Karthee Sivalingam, Sabri Pllana, Alexander Nikolov, Müjdat Soytürk, Christian Racca, Andrea Bartolini, Adrian Tate, Berkay Yaman
2023 J jnl
CoRR
Julian M. Kunkel, Christian Boehme, Jonathan Decker, Fabrizio Magugliani, Dirk Pleiter, Bastian Koller, Karthee Sivalingam, Sabri Pllana, Alexander Nikolov, Müjdat Soytürk, Christian Racca, Andrea Bartolini, Adrian Tate, Berkay Yaman
2020 Misc conf
SYNASC
Elisabetta Di Nitto, Jesús Gorroñogoitia, Indika Kumara, Georgios Meditskos, Dragan Radolovic, Karthee Sivalingam, Román Sosa González
2020 conf
ISC Workshops
Karthee Sivalingam, Harvey Richardson
2020 conf
HPEC
Nina Mujkanovic, Karthee Sivalingam, Alfio Lazzaro
2020 J jnl
CoRR
Nina Mujkanovic, Karthee Sivalingam, Alfio Lazzaro
2019 J jnl
CoRR
Andrew Turner, Dominic Sloan-Murphy, Karthee Sivalingam, Harvey Richardson, Julian M. Kunkel
2019 conf
SpringSim
Karthee Sivalingam, Harvey Richardson, Adrian Tate, Martin Lafferty
2019 J jnl
CoRR
Karthee Sivalingam, Harvey Richardson, Adrian Tate, Martin Lafferty
2015 J jnl
CoRR
Karthee Sivalingam, Grenville Lister, Bryan Lawrence
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"