Mahdi Aiash

59 papers B 5C 3Misc 1Journal 24Unranked 26
YearRankTypeTitle / Venue / Authors
2025 J jnl
Network
Mohammad Emran Hashimyar, Mahdi Aiash, Ali Khoshkholghi, Giacomo Nalli
2023 J jnl
Sensors
Abdullahi Chowdhury, Shahriar Kaisar, Mahbub E. Khoda, Ranesh Kumar Naha, Mohammad Ali Khoshkholghi, Mahdi Aiash
2023 B conf
TrustCom
Abdullahi Chowdhury, Mohammad Manzurul Islam, Shahriar Kaisar, Mahbub E. Khoda, Ranesh Naha, Mohammad Ali Khoshkholghi, Mahdi Aiash
2023 J jnl
Internet Things
Ed Kamya Kiyemba Edris, Mahdi Aiash, Mohammad Ali Khoshkholghi, Ranesh Naha, Abdullahi Chowdhury, Jonathan Loo
2022 J jnl
Network
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Loo
2022 J jnl
Array
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Loo
2021 J jnl
Network
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Loo
2021 J jnl
Int. J. Secur. Networks
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Kok-Keong Loo, Mohammad Shadi Al Hakeem
2020 conf
SDS
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Kok-Keng Loo
2020 conf
FMEC
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Kok-Keng Loo
2020 conf
FMEC
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Kok-Keng Loo
2019 conf
SmartWorld/SCALCOM/UIC/ATC/CBDCom/IOP/SCI
Ed Kamya Kiyemba Edris, Mahdi Aiash, Jonathan Loo
2018 J jnl
Int. J. Electron. Secur. Digit. Forensics
Mohammad Muneer Kallash, Jonathan Loo, Aboubaker Lasebae, Mahdi Aiash
2018 conf
UCC Companion
Gayathri Karthick, Glenford Mapp, Florian Kammueller, Mahdi Aiash
2018 C conf
ICSOFT
Ed Kamya Kiyemba Edris, Mahdi Aiash
2017 J jnl
Veh. Commun.
Rand Raheem, Aboubaker Lasebae, Mahdi Aiash, Jonathan Loo, Robert Colson
2017 J jnl
Int. J. Inf. Syst. Serv. Sect.
Rand Raheem, Aboubaker Lasebae, Mahdi Aiash, Jonathan Loo
2016 conf
Trustcom/BigDataSE/ISPA
Tayeb Kenaza, Mahdi Aiash, Jonathan Loo, Aboubaker Lasebae, Gill Whitney
2016 J jnl
Inf.
Anhtuan Le, Jonathan Loo, Kok Keong Chai, Mahdi Aiash
2016 conf
Trustcom/BigDataSE/ISPA
Tayeb Kenaza, Khadidja Bennaceur, Abdenour Labed, Mahdi Aiash
2016 B conf
Intelligent Environments
Rand Raheem, Aboubaker Lasebae, Mahdi Aiash, Jonathan Loo
2016 conf
Trustcom/BigDataSE/ISPA
Ahmad Azab, Mamoun Alazab, Mahdi Aiash
2016 conf
ANT/SEIT
Tayeb Kenaza, Mahdi Aiash
2015 C conf
SECRYPT
Mahdi Aiash, Jonathan Loo
2015 J jnl
Concurr. Comput. Pract. Exp.
Mahdi Aiash
2015 J jnl
J. Netw. Comput. Appl.
Mahdi Aiash, Jonathan Loo
2015 J jnl
J. Netw. Comput. Appl.
Jonathan Loo, Mahdi Aiash
2015 conf
AINA Workshops
Mahdi Aiash, Robert Colson, Mohammad Muneer Kallash
2015 J jnl
J. Electr. Comput. Eng.
Fragkiskos Sardis, Glenford E. Mapp, Jonathan Loo, Mahdi Aiash, Alexey V. Vinel
2015 J jnl
J. Netw. Comput. Appl.
Jonathan Loo, Mahdi Aiash
2015 J jnl
Comput. Networks
Jernej Kos, Mahdi Aiash, Jonathan Loo, Denis Trcek
2015 conf
TrustCom/BigDataSE/ISPA (1)
Midhun Babu Tharayanil, Gill Whitney, Mahdi Aiash, Chafika Benzaid
2015 conf
AINA Workshops
Antonio Carnielli, Mahdi Aiash
2014 conf
AINA Workshops
Mahdi Aiash, Glenford E. Mapp, Aboubaker Lasebae, Jonathan Loo
2014 J jnl
Inf. Vis.
Neesha Kodagoda, Simon Attfield, Tinni Choudhury, Chris Rooney, Glenford E. Mapp, Phong Hai Nguyen, Louis Slabbert, B. L. William Wong, Mahdi Aiash, Yongjun Zheng, Kai Xu, Aboubaker Lasebae
2014 conf
AINA Workshops
Fragkiskos Sardis, Glenford E. Mapp, Jonathan Loo, Mahdi Aiash
2014 Misc conf
UCC
Fragkiskos Sardis, Glenford E. Mapp, Jonathan Loo, Mahdi Aiash
2014 conf
SOSE
Glenford E. Mapp, Mahdi Aiash, Brian Ondiege, Malcolm Clarke
2014 J jnl
Int. J. Commun. Syst.
Mahdi Aiash, Jonathan Loo
2014 conf
AINA Workshops
Jose Sinti, Fowzan Jiffry, Mahdi Aiash
2014 conf
AINA Workshops
Mahdi Aiash, Glenford E. Mapp, Orhan Gemikonakli
2013 B conf
NSS
Mahdi Aiash
2013 B conf
NSS
Mahdi Aiash
2013 conf
FGCT
Rand Raheem, Aboubaker Lasebae, Mahdi Aiash, Jonathan Loo
2013 J jnl
IEEE Trans. Multim.
Fragkiskos Sardis, Glenford E. Mapp, Jonathan Loo, Mahdi Aiash, Alexey V. Vinel
2013 conf
WWIC
Mahdi Aiash, Ameer Al-Nemrat, David S. Preston
2013 conf
FGCT
Thamer A. Alghamdi, Aboubaker Lasebae, Mahdi Aiash
2013 conf
FGCT
Ali Hussein Raheem, Aboubaker Lasebae, Mahdi Aiash, Jonathan Loo
2012 J jnl
Int. J. Commun. Syst.
Anhtuan Le, Jonathan Loo, Aboubaker Lasebae, Mahdi Aiash, Yuan Luo
2012 B conf
TrustCom
Mahdi Aiash, Glenford E. Mapp, Raphael C.-W. Phan, Aboubaker Lasebae, Jonathan Loo
2012 J jnl
CoRR
Mahdi Aiash, Glenford E. Mapp, Aboubaker Lasebae
2012 J jnl
EURASIP J. Wirel. Commun. Netw.
Mahdi Aiash, Glenford E. Mapp, Aboubaker Lasebae, Raphael Chung-Wei Phan, Jonathan Loo
2012 conf
WTS
Mahdi Aiash, Glenford E. Mapp, Aboubaker Lasebae, Jonathan Loo, Fragkiskos Sardis, Raphael C.-W. Phan, Mario Augusto, Edson dos Santos Moreira, Renata Maria Porto Vanni
2012 J jnl
J. Comput. Networks Commun.
Glenford E. Mapp, Ferdinand Apietu Katsriku, Mahdi Aiash, Naveen Chinnam, Roberto Rigolin Ferreira Lopes, Edson dos Santos Moreira, Renata Maria Porto Vanni, Mario Augusto
2012 conf
IEEE VAST
Sharmin (Tinni) Choudhury, Neesha Kodagoda, Phong Hai Nguyen, Chris Rooney, Simon Attfield, Kai Xu, Yongjun Zheng, B. L. William Wong, Raymond Chen, Glenford E. Mapp, Louis Slabbert, Mahdi Aiash, Aboubaker Lasebae
2011 conf
AINA Workshops
Glenford E. Mapp, Mahdi Aiash, Hélio Crestana Guardia, Jon Crowcroft
2010 conf
AICT
Mahdi Aiash, Glenford E. Mapp, Aboubaker Lasebae, Raphael Chung-Wei Phan
2010 C conf
SECRYPT
Glenford E. Mapp, Mahdi Aiash, Aboubaker Lasebae, Raphael Chung-Wei Phan
2009 conf
NBiS
Glenford E. Mapp, Fatema Shaikh, Mahdi Aiash, Renata Maria Porto Vanni, Mario Augusto, Edson dos Santos Moreira
redb/extractors/detectiteasy.py
← Index redb/extractors/detectiteasy.py python
import inspect
from pprint import pprint
import subprocess
import json
from typing import Any
from datetime import datetime, timezone
import os
from dotenv import load_dotenv

from redb.extractors.enum import Tag
from redb.models.dataclasses import DIEinfo
from redb.extractors.extractor import Extractor

load_dotenv(override=True)

class DIEExtractor(Extractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        precomputed_hashes=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix, elastic_index, known_benign, known_malicious,
            precomputed_hashes=precomputed_hashes
        )
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.die_info = None
        self.die_info_dict = {}
        self.elastic_index = self.index_prefix + "-die"

    def _recursive_entry(self, die_dict, master_key):
        self.log.debug(inspect.currentframe().f_code.co_name)
        if master_key:
            self.die_info_dict[master_key] = {}
        else:
            self.die_info_dict = {}
        for value in die_dict:
            if "type" in value:
                type_key = value["type"].lower().replace(" ", "_")
                name = value.get("name", "")
                version = f"({value.get('version')})" if value.get("version") else ""
                info = f"[{value.get('info')}]" if value.get("info") else ""

                if master_key:
                    self.die_info_dict[master_key][type_key] = f"{name}"
                    self.die_info_dict[master_key][f'{type_key}(full)'] = f"{name}{version}{info}"
                else:
                    self.die_info_dict[type_key] = f"{name}"
                    self.die_info_dict[f'{type_key}(full)'] = f"{name}{version}{info}"

            elif "parentfilepart" in value:
                child_key = (
                    value["parentfilepart"].lower().replace(" ", "_")
                    + "."
                    + value["filetype"].lower().replace(" ", "_")
                )
                if master_key:
                    self._recursive_entry(value["values"], f"{master_key}.{child_key}")
                else:
                    self._recursive_entry(value["values"], f"{child_key}")

    def _extract_dieinfo(self):
        """
        Execute a command-line binary with arguments and parse its JSON output.

        :param command: The command or path to the binary to execute
        :param args: Additional arguments to pass to the command
        :return: Parsed JSON output as a Python object
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # Construct the full command
        # command = "nfdc" # UNCOMMENT FOR PROD
        # command = "/Users/p4c0/_tools/NFD.app/Contents/MacOS/nfdc" # COMMENT FOR TESTING ON MAC
        command = os.getenv("DIE_PATH")
        args = ["-durj", self.filepath]
        full_command = [command] + list(args)
        TIMEOUT = int(os.getenv("DIE_TIMEOUT", "180"))

        try:
            # Execute the command and capture its output
            result = subprocess.run(
                full_command,
                capture_output=True,
                text=True,
                check=True,
                timeout=TIMEOUT,
            )

            # Parse the JSON output
            nfdc_output = json.loads(result.stdout)

            # Extract the DIE information from the json output
            for die_entry in nfdc_output["detects"]:
                if die_entry["parentfilepart"] == "Header":
                    master_key = (
                        die_entry["parentfilepart"].lower().replace(" ", "_")
                        + "."
                        + die_entry["filetype"].lower().replace(" ", "_")
                    )
                    self._recursive_entry(die_entry["values"], None)

            # pprint(json.dumps(self.die_info_dict, indent=2)) #debug
            self.die_info = DIEinfo(result.stdout, self.die_info_dict)
            self.log.debug(f"NFDC-DIE JSON dump: todo")
        except subprocess.TimeoutExpired:
            self.log.error(f"The DIE command timed out after {TIMEOUT} seconds")
            return None
        except subprocess.CalledProcessError as e:
            self.log.error(f"Error executing DIE command: {e}")
            self.log.error(f"Command output (stderr): {e.stderr}")
            return None
        except json.JSONDecodeError as e:
            self.log.error(f"Error parsing DIE JSON output: {e}")
            self.log.error(f"Raw output: {result.stdout}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.die_info
        elif exporter_type == "ClickHouseExporter":
            # Convert DIE info to JSON string
            die_info_json = json.dumps(self.die_info_dict)
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                die_info_json,
                datetime.now(timezone.utc)
            ]]
            
            column_names = [
                'sha256', 'md5', 'sha1', 'die_info', 'analysis_date'
            ]
            
            column_type_names = [
                'String', 'String', 'String', 'JSON', 'DateTime64(3, \'UTC\')'
            ]
            
            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_die"

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            self._extract_dieinfo()
            
            # Check if there's a packer in the DIE results
            is_packed = False
            if self.die_info_dict:
                # Check if 'packer' exists in the DIE results
                is_packed = bool(self.die_info_dict.get('packer'))
            
            return self.die_info  # Return the extracted data instead of exporting directly
        except Exception as e:
            self.log.error(f"Error extracting DIE information: {e}")
            return None

    def tag(self):
        return Tag.DIEC.value