M. Scott Marshall

51 papers A 3C 1Journal 14Unranked 17
YearRankTypeTitle / Venue / Authors
2026 ed.
SWAT4HCLS
José Emilio Labra Gayo, Alberto Labarga, Jerven T. Bolleman, Leyla Jael Castro, M. Scott Marshall, Andrea Splendiani, Andra Waagmeester
2024 ed.
SWAT4HCLS
Marco Roos, Annika Jacobsen, Andrea Splendiani, M. Scott Marshall, Andra Waagmeester, Leyla Jael García Castro, Katherine Wolstencroft, Kristina M. Hettne, Rutger A. Vos
2023 ed.
SWAT4HCLS
Atsuko Yamaguchi, Andrea Splendiani, M. Scott Marshall, Chris Baker, Jerven T. Bolleman, Albert Burger, Leyla Jael Castro, Ole Eigenbrod, Sabine Österle, Martin Romacker, Andra Waagmeester
2022 ed.
SWAT4HCLS
Katy Wolstencroft, Andrea Splendiani, M. Scott Marshall, Chris Baker, Andra Waagmeester, Marco Roos, Rutger A. Vos, Rianne Fijten, Leyla Jael Castro
2018 ed.
SWAT4LS
Adrian Paschke, Albert Burger, Andrea Splendiani, M. Scott Marshall, Paolo Romano, Valentina Presutti
2018 ed.
SWAT4LS
Andra Waagmeester, Christopher J. O. Baker, Andrea Splendiani, Oya Deniz Beyan, M. Scott Marshall
2017 ed.
SWAT4LS
Adrian Paschke, Albert Burger, Andrea Splendiani, M. Scott Marshall, Paolo Romano
2016 conf
HEALTHINF
Qing Hu, Zhisheng Huang, Annette ten Teije, Frank van Harmelen, M. Scott Marshall, Andre Dekker
2015 conf
MIE
M. Scott Marshall, Johan van Soest, R. Dresens, J. Paulissen, Philippe Lambin, Andre Dekker
2014 C conf
BIBE
Ahmed Ibrahim, Anca I. D. Bucur, Andre Dekker, M. Scott Marshall, David Pérez-Rey, Raúl Alonso-Calvo, Holger Stenzhorn, Sheng Yu, Cyril Krykwinski, Anouar Laarif, Keyur Mehta
2014 ed.
SWAT4LS
Adrian Paschke, Albert Burger, Paolo Romano, M. Scott Marshall, Andrea Splendiani
2014 ed.
SWAT4LS
Adrian Paschke, Albert Burger, Paolo Romano, M. Scott Marshall, Andrea Splendiani
2014 conf
MIE
Johan van Soest, Tim Lustberg, Detlef Grittner, M. Scott Marshall, Lucas Persoon, Bas Nijsten, Peter Feltens, Andre Dekker
2013 conf
MedInfo
Matthias Samwald, Robert R. Freimuth, Joanne S. Luciano, Simon M. Lin, Robert L. Powers, M. Scott Marshall, Klaus-Peter Adlassnig, Michel Dumontier, Richard D. Boyce
2013 ed.
SWAT4LS
Adrian Paschke, Albert Burger, Paolo Romano, M. Scott Marshall, Andrea Splendiani
2012 J jnl
J. Web Semant.
M. Scott Marshall, Richard D. Boyce, Helena F. Deus, Jun Zhao, Egon L. Willighagen, Matthias Samwald, Elgar Pichler, Janos G. Hajagos, Eric Prud'hommeaux, Susie Stephens
2012 J jnl
BMC Bioinform.
Albert Burger, Adrian Paschke, Paolo Romano, M. Scott Marshall, Andrea Splendiani
2012 J jnl
J. Biomed. Informatics
Helena F. Deus, Eric Prud'hommeaux, Michael Miller, Jun Zhao, James Malone, Tomasz Adamusiak, Jamie P. McCusker, Sudeshna Das, Philippe Rocca-Serra, Ronan Fox, M. Scott Marshall
2011 J jnl
J. Biomed. Semant.
Andrea Splendiani, Albert Burger, Adrian Paschke, Paolo Romano, M. Scott Marshall
2011 J jnl
J. Cheminformatics
Matthias Samwald, Anja Jentzsch, Christopher Bouton, Claus Kallesøe, Egon L. Willighagen, Janos G. Hajagos, M. Scott Marshall, Eric Prud'hommeaux, Oktie Hassanzadeh, Elgar Pichler, Susie Stephens
2011 ed.
SWAT4LS
Adrian Paschke, Albert Burger, Paolo Romano, M. Scott Marshall, Andrea Splendiani
2011 ed.
SWAT4LS
Albert Burger, M. Scott Marshall, Paolo Romano, Adrian Paschke, Andrea Splendiani
2011 conf
WIMS
Aravind Venkatesan, Ward Blondé, Erick Antezana, Mats Skillingstad, M. Scott Marshall, Bernard De Baets, Vladimir Mironov, Martin Kuiper
2011 J jnl
J. Biomed. Semant.
Joanne S. Luciano, Bosse Andersson, Colin R. Batchelor, Olivier Bodenreider, Tim Clark, Christine K. Denney, Christopher Domarew, Thomas Gambet, Lee Harland, Anja Jentzsch, Vipul Kashyap, Peter J. Kos, Julia Kozlovsky, Timothy Lebo, M. Scott Marshall, Jamie P. McCusker, Deborah L. McGuinness, Chimezie Ogbuji, Elgar Pichler, Robert L. Powers, Eric Prud'hommeaux, Matthias Samwald, Lynn M. Schriml, Peter J. Tonellato, Patricia L. Whetzel, Jun Zhao, Susie Stephens, Michel Dumontier
2011 conf
MIE
Matthias Samwald, Holger Stenzhorn, Michel Dumontier, M. Scott Marshall, Joanne Luciano, Klaus-Peter Adlassnig
2011 J jnl
CoRR
Matthias Samwald, Holger Stenzhorn, Michel Dumontier, M. Scott Marshall, Joanne Luciano, Klaus-Peter Adlassnig
2011 conf
SWAT4LS
Helena F. Deus, Jun Zhao, Jamie P. McCusker, Ronan Fox, Eric Prud'hommeaux, James Malone, Sudeshna Das, Michael Miller, Tomasz Adamusiak, Philippe Rocca-Serra, M. Scott Marshall
2010 conf
ISoLA (1)
Marco Roos, Sean Bechhofer, Jun Zhao, Paolo Missier, David R. Newman, David De Roure, M. Scott Marshall
2010 ed.
SWAT4LS
M. Scott Marshall, Albert Burger, Paolo Romano, Adrian Paschke, Andrea Splendiani
2010 conf
SWPM@ISWC
Helena F. Deus, Jun Zhao, Satya S. Sahoo, Matthias Samwald, Eric Prud'hommeaux, Michael Miller, M. Scott Marshall, Kei-Hoi Cheung
2010 ch.
Semantic e-Science
M. Scott Marshall, Marco Roos, Edgar Meij, Sophia Katrenko, Willem Robert van Hage, Pieter W. Adriaans
2010 conf
SWAT4LS
Adianto Wibisono, Marco Roos, M. Scott Marshall
2009 J jnl
BMC Bioinform.
Kei-Hoi Cheung, H. Robert Frost, M. Scott Marshall, Eric Prud'hommeaux, Matthias Samwald, Jun Zhao, Adrian Paschke
2009 J jnl
Briefings Bioinform.
Alan Ruttenberg, Jonathan Rees, Matthias Samwald, M. Scott Marshall
2009 J jnl
BMC Bioinform.
Marco Roos, M. Scott Marshall, Andrew P. Gibson, Martijn J. Schuemie, Edgar Meij, Sophia Katrenko, Willem Robert van Hage, Konstantinos Krommydas, Pieter W. Adriaans
2008 conf
eScience
Spiros Koulouzis, Edgar Meij, M. Scott Marshall, Adam Belloum
2008 conf
SWAT4LS
Marco Roos, M. Scott Marshall, Andrew P. Gibson, Pieter W. Adriaans
2007 conf
OWLED
C. Maria Keet, Marco Roos, M. Scott Marshall
2007 J jnl
Bioinform.
Lennart J. G. Post, Marco Roos, M. Scott Marshall, Roel van Driel, Timo M. Breit
2007 J jnl
BMC Bioinform.
Alan Ruttenberg, Tim Clark, William J. Bug, Matthias Samwald, Olivier Bodenreider, Helen Chen, Donald Doherty, Kerstin Forsberg, Yong Gao, Vipul Kashyap, June Kinoshita, Joanne Luciano, M. Scott Marshall, Chimezie Ogbuji, Jonathan Rees, Susie Stephens, Gwendolyn T. Wong, Elizabeth Wu, Davide Zaccagnini, Tonya Hongsermeier, Eric Neumann, Ivan Herman, Kei-Hoi Cheung
2007 ch.
The Semantic Web: Real-World Applications from Industry
Vipul Kashyap, Kei-Hoi Cheung, Donald Doherty, Matthias Samwald, M. Scott Marshall, Joanne Luciano, Susie Stephens, Ivan Herman, Raymond Hookway
2006 conf
OTM Workshops (1)
M. Scott Marshall, Lennart J. G. Post, Marco Roos, Timo M. Breit
2001 J jnl
Softw. Pract. Exp.
M. Scott Marshall, Ivan Herman, Guy Melançon
2001 A conf
GD
Ulrik Brandes, Markus Eiglsperger, Ivan Herman, Michael Himsolt, M. Scott Marshall
2000 conf
INFOVIS
Ivan Herman, M. Scott Marshall, Guy Melançon
2000 A conf
GD
Ulrik Brandes, M. Scott Marshall, Stephen C. North
2000 J jnl
IEEE Trans. Vis. Comput. Graph.
Ivan Herman, Guy Melançon, M. Scott Marshall
2000 A conf
GD
Ivan Herman, M. Scott Marshall
1999 conf
Eurographics (State of the Art Reports)
Iván Herman, Guy Melançon, M. Scott Marshall
1999 book
David J. Duke, Ivan Herman, M. Scott Marshall
1999 conf
VisSym
Iván Herman, M. Scott Marshall, Guy Melançon, David J. Duke, Maylis Delest, Jean-Philippe Domenger
redb/extractors/elf_extractor.py
← Index redb/extractors/elf_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class ELFExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious
        )
        # Store ELF object if provided, otherwise we'll create it per-operation for security
        self._provided_elf = elf
        self._elf_file_valid = None  # Cache validity check

    def _with_elf_file(self, operation):
        """Safely execute an operation with an ELF file using context manager.

        Args:
            operation: A callable that takes an ELFFile object and returns a result

        Returns:
            The result of the operation, or None if an error occurred
        """
        if self._provided_elf:
            try:
                return operation(self._provided_elf)
            except ELFError as e:
                if "String Table not found" in str(e):
                    self.log.warning(f"String table missing in ELF {self.hash.sha256}: {e}")
                    return None
                else:
                    self.log.error(f"ELF format error {self.hash.sha256} Full error: {e}")
                    return None
            except Exception as e:
                self.log.error(f"Error processing ELF file {self.hash.sha256} Full error: {e}")
                return None

        try:
            with open(self.filepath, 'rb') as f:
                elf = ELFFile(f)
                if not elf:
                    raise ELFError("Empty file?")
                return operation(elf)
        except ELFError as e:
            if "String Table not found" in str(e):
                self.log.warning(f"String table missing in ELF {self.hash.sha256}: {e}")
                return None
            else:
                self.log.error(f"ELF format error {self.hash.sha256} Full error: {e}")
                return None
        except Exception as e:
            self.log.error(f"Error reading ELF file {self.hash.sha256} Full error: {e}")
            return None

    def _is_elf_file(self):
        """Check if the file is a valid ELF binary."""
        if self._elf_file_valid is not None:
            return self._elf_file_valid

        def check_elf_validity(elf):
            # pyelftools ELFFile object existing means it's valid ELF
            # Just check that we can access the header
            header = elf.header
            return header is not None

        try:
            result = self._with_elf_file(check_elf_validity)
            self._elf_file_valid = bool(result)
            return self._elf_file_valid
        except Exception as e:
            self.log.error(f"Error checking ELF file: {e}")
            self._elf_file_valid = False
            return False

    def _is_64bit(self):
        """Check if the ELF binary is 64-bit."""
        def check_64bit(elf):
            return elf.header.get('e_ident', {}).get('EI_CLASS') == 'ELFCLASS64'

        try:
            result = self._with_elf_file(check_64bit)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking ELF bitness: {e}")
            return False

    def _is_stripped(self):
        """Check if the ELF binary is stripped (no symbol table)."""
        def check_stripped(elf):
            # Look for symbol table sections
            for section in elf.iter_sections():
                if section.name in ['.symtab', '.strtab']:
                    return False
            return True

        try:
            result = self._with_elf_file(check_stripped)
            return result if result is not None else True
        except Exception as e:
            self.log.error(f"Error checking if ELF is stripped: {e}")
            return True

    def _has_debug_info(self):
        """Check if the ELF binary contains debug information."""
        def check_debug_info(elf):
            # Look for debug sections
            debug_sections = ['.debug_info', '.debug_line', '.debug_str', '.debug_abbrev']
            for section in elf.iter_sections():
                if section.name in debug_sections:
                    return True
            return False

        try:
            result = self._with_elf_file(check_debug_info)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking debug info: {e}")
            return False

    def _get_architecture(self):
        """Get the architecture of the ELF binary."""
        def get_arch(elf):
            machine = elf.header.get('e_machine', 'EM_NONE')

            # Map common machine types to readable names
            arch_map = {
                'EM_386': 'x86',
                'EM_X86_64': 'x86_64',
                'EM_ARM': 'ARM',
                'EM_AARCH64': 'ARM64',
                'EM_MIPS': 'MIPS',
                'EM_PPC': 'PowerPC',
                'EM_PPC64': 'PowerPC64',
                'EM_SPARC': 'SPARC',
                'EM_RISCV': 'RISC-V'
            }

            return arch_map.get(machine, machine)

        try:
            result = self._with_elf_file(get_arch)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting architecture: {e}")
            return "unknown"

    def _get_endianness(self):
        """Get the endianness of the ELF binary."""
        def get_endian(elf):
            data_encoding = elf.header.get('e_ident', {}).get('EI_DATA')
            if data_encoding == 'ELFDATA2LSB':
                return "little"
            elif data_encoding == 'ELFDATA2MSB':
                return "big"
            return "unknown"

        try:
            result = self._with_elf_file(get_endian)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting endianness: {e}")
            return "unknown"

    def _get_file_type(self):
        """Get the file type of the ELF binary."""
        def get_file_type(elf):
            etype = elf.header.get('e_type', 'ET_NONE')

            # Map file types to readable names
            type_map = {
                'ET_NONE': 'none',
                'ET_REL': 'relocatable',
                'ET_EXEC': 'executable',
                'ET_DYN': 'shared_object',
                'ET_CORE': 'core_dump'
            }

            return type_map.get(etype, etype)

        try:
            result = self._with_elf_file(get_file_type)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting file type: {e}")
            return "unknown"

    def _is_pie(self):
        """Check if the ELF binary is position-independent executable."""
        def check_pie(elf):
            # PIE binaries are typically ET_DYN type
            etype = elf.header.get('e_type', 'ET_NONE')
            if etype == 'ET_DYN':
                # Check if it has an entry point (executable) vs library
                entry_point = elf.header.get('e_entry', 0)
                return entry_point > 0
            return False

        try:
            result = self._with_elf_file(check_pie)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking PIE: {e}")
            return False

    def _has_stack_protection(self):
        """Check if the binary has stack protection (canaries)."""
        def check_stack_protection(elf):
            # Look for stack protection symbols
            stack_symbols = ['__stack_chk_fail', '__stack_chk_guard']

            for section in elf.iter_sections():
                if hasattr(section, 'iter_symbols'):
                    for symbol in section.iter_symbols():
                        if symbol.name in stack_symbols:
                            return True
            return False

        try:
            result = self._with_elf_file(check_stack_protection)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking stack protection: {e}")
            return False

    def _has_nx_bit(self):
        """Check if the binary has NX bit (non-executable stack)."""
        def check_nx_bit(elf):
            # Look for GNU_STACK segment
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_GNU_STACK':
                    flags = segment.header.get('p_flags', 0)
                    # Check if execute flag is NOT set (NX enabled)
                    return not (flags & 0x1)  # PF_X = 0x1
            return False

        try:
            result = self._with_elf_file(check_nx_bit)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking NX bit: {e}")
            return False

    def _has_relro(self):
        """Check if the binary has RELRO (Relocation Read-Only)."""
        def check_relro(elf):
            # Look for GNU_RELRO segment
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_GNU_RELRO':
                    return True
            return False

        try:
            result = self._with_elf_file(check_relro)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking RELRO: {e}")
            return False

    def _get_build_id(self):
        """Extract build ID from notes section."""
        def get_build_id(elf):
            # Look for build ID in notes sections
            for section in elf.iter_sections():
                if section.name == '.note.gnu.build-id':
                    for note in section.iter_notes():
                        if note['n_type'] == 'NT_GNU_BUILD_ID':
                            # Convert bytes to hex string
                            build_id = note['n_desc']
                            if isinstance(build_id, bytes):
                                return build_id.hex()
                            return str(build_id)
            return None

        try:
            result = self._with_elf_file(get_build_id)
            return result
        except Exception as e:
            self.log.error(f"Error getting build ID: {e}")
            return None

    def _count_sections(self):
        """Count the number of sections in the ELF file."""
        def count_sections(elf):
            return elf.header.get('e_shnum', 0)

        try:
            result = self._with_elf_file(count_sections)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting sections: {e}")
            return 0

    def _count_segments(self):
        """Count the number of segments (program headers) in the ELF file."""
        def count_segments(elf):
            return elf.header.get('e_phnum', 0)

        try:
            result = self._with_elf_file(count_segments)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting segments: {e}")
            return 0

    def _count_symbols(self):
        """Count the total number of symbols in symbol tables."""
        def count_symbols(elf):
            symbol_count = 0
            for section in elf.iter_sections():
                if hasattr(section, 'iter_symbols'):
                    symbol_count += section.num_symbols()
            return symbol_count

        try:
            result = self._with_elf_file(count_symbols)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting symbols: {e}")
            return 0

    def _get_dependencies(self):
        """Get list of dynamic dependencies."""
        def get_dependencies(elf):
            dependencies = []
            dynamic_section = elf.get_section_by_name('.dynamic')
            if dynamic_section:
                for tag in dynamic_section.iter_tags():
                    if tag.entry.d_tag == 'DT_NEEDED':
                        dependencies.append(tag.needed)
            return dependencies

        try:
            result = self._with_elf_file(get_dependencies)
            return result if result is not None else []
        except Exception as e:
            self.log.error(f"Error getting dependencies: {e}")
            return []