Mahdi Jamei

14 papers C 2Journal 7Unranked 5
YearRankTypeTitle / Venue / Authors
2020 J jnl
IEEE Trans. Smart Grid
Ciaran M. Roberts, Anna Scaglione, Mahdi Jamei, Reinhard Gentz, Sean Peisert, Emma M. Stewart, Chuck McParland, Alex McEachern, Daniel B. Arnold
2020 J jnl
IEEE J. Sel. Areas Commun.
Mahdi Jamei, Raksha Ramakrishna, Teklemariam Tesfay, Reinhard Gentz, Ciaran M. Roberts, Anna Scaglione, Sean Peisert
2019 J jnl
CoRR
Alex Robson, Mahdi Jamei, Cozmin Ududec, Letif Mones
2018 conf
SmartGridComm
Teklemariam Tesfay, Mahdi Jamei, Anna Scaglione, Mojdeh Khorsand, Kory Hedman, Rida A. Bazzi
2018 conf
SmartGridComm
Mahdi Jamei, Anna Scaglione, Sean Peisert
2018 J jnl
CoRR
Mahdi Jamei, Anna Scaglione, Sean Peisert
2017 J jnl
CoRR
Mahdi Jamei, Anna Scaglione, Ciaran M. Roberts, Emma M. Stewart, Sean Peisert, Chuck McParland, Alex McEachern
2017 conf
HICSS
Mahdi Jamei, Anna Scaglione, Ciaran M. Roberts, Emma M. Stewart, Sean Peisert, Chuck McParland, Alex McEachern
2016 J jnl
CoRR
Mahdi Jamei, Anna Scaglione, Ciaran M. Roberts, Emma M. Stewart, Sean Peisert, Chuck McParland, Alex McEachern
2016 J jnl
IEEE Internet Comput.
Mahdi Jamei, Emma M. Stewart, Sean Peisert, Anna Scaglione, Chuck McParland, Ciaran M. Roberts, Alex McEachern
2015 conf
CPS-SPC@CCS
Georgia Koutsandria, Reinhard Gentz, Mahdi Jamei, Anna Scaglione, Sean Peisert, Chuck McParland
2014 C conf
ICSEng
Arman Sargolzaei, Mahdi Jamei, Kang K. Yen, Arif I. Sarwat, Mohamed N. Abdelghani
2014 conf
CIASG
Imtiaz Parvez, Mahdi Jamei, Aditya Sundararajan, Arif I. Sarwat
2014 C conf
ICSEng
Mahdi Jamei, Arif I. Sarwat, S. S. Iyengar, Faisal Kaleem
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"