Majeed M. Hayat

76 papers A 2B 7C 5Misc 4Journal 34Unranked 24
YearRankTypeTitle / Venue / Authors
2024 conf
IPDPS (Workshops)
Muna Tageldin, Majeed M. Hayat, Jered Dominguez-Trujillo, Patrick G. Bridges
2024 conf
ICC
Ahmed Ajeena, Jie Gao, Majeed M. Hayat, Lian Zhao, Xuemin Shen
2023 C conf
IGARSS
Mutian Zhuang, Majeed M. Hayat
2022 J jnl
IEEE Syst. J.
Pankaz Das, Rezoan A. Shuvro, Kassie Povinelli, Francesco Sorrentino, Majeed M. Hayat
2021 J jnl
IEEE Trans. Netw. Sci. Eng.
Kshitij Bhatta, Majeed M. Hayat, Francesco Sorrentino
2021 J jnl
CoRR
Kshitij Bhatta, Majeed M. Hayat, Francesco Sorrentino
2020 conf
OFC
Payman Zarkesh-Ha, Robert Efroymson, Earl Fuller, Joe C. Campbell, Majeed M. Hayat
2020 J jnl
IEEE Syst. J.
Pankaz Das, Rezoan A. Shuvro, Mahshid Rahnamay-Naeini, Kassie Povinelli, Nasir Ghani, Majeed M. Hayat
2019 conf
ISGT Europe
Rezoan A. Shuvro, Pankaz Das, Joana M. Abreu, Majeed M. Hayat
2019 Misc conf
ACSSC
Francisco Pérez, Balasubramaniam Santhanam, Bipesh Shrestha, Walter Gerstle, Majeed M. Hayat
2019 conf
ISGT Europe
Rezoan A. Shuvro, Pankaz Das, Mahshid Rahnamay-Naeini, Francesco Sorrentino, Majeed M. Hayat
2019 J jnl
IEEE Commun. Mag.
Diogo Oliveira, Nasir Ghani, Majeed M. Hayat, Jorge Crichigno, Elias Bou-Harb
2018 conf
MILCOM
Pankaz Das, Rezoan A. Shuvro, Mahshid Rahnamay-Naeini, Nasir Ghani, Majeed M. Hayat
2018 Misc conf
ACSSC
Satish Mandal, Balu Santhanam, Majeed M. Hayat
2018 J jnl
IEEE Trans. Geosci. Remote. Sens.
Justin B. Campbell, Francisco Pérez, Qi Wang, Balasubramaniam Santhanam, Ralf Dunkel, Armin W. Doerry, Tom Atwood, Majeed M. Hayat
2017 J jnl
IEEE Geosci. Remote. Sens. Lett.
Francisco Pérez, Balu Santhanam, Ralf Dunkel, Majeed M. Hayat
2017 Misc conf
ICNC
Pankaz Das, Mahshid Rahnamay-Naeini, Nasir Ghani, Majeed M. Hayat
2017 J jnl
IEEE Trans. Parallel Distributed Syst.
Zhuoyao Wang, Majeed M. Hayat, Nasir Ghani, Khaled B. Shaban
2017 B conf
WiMob
Pankaz Das, Rezoan A. Shuvro, Zhuoyao Wang, Mahshid Rahnamay-Naeini, Nasir Ghani, Majeed M. Hayat
2016 J jnl
IEEE Trans. Smart Grid
Mahshid Rahnamay-Naeini, Majeed M. Hayat
2015 J jnl
IEEE Trans. Commun.
Georges El-Howayek, Majeed M. Hayat
2015 J jnl
IEEE Trans. Computers
Feng Gu, Khaled B. Shaban, Nasir Ghani, Samee Khan, Mahshid Rahnamay-Naeini, Majeed M. Hayat, Chadi Assi
2014 conf
MWSCAS
Javad Ghasemi, Payman Zarkesh-Ha, Sanjay Krishna, Sebastián E. Godoy, Majeed M. Hayat
2014 conf
CloudNet
Zhuoyao Wang, Majeed M. Hayat, Nasir Ghani, Khaled B. Shaban
2014 Misc conf
ACSSC
Adebello Jelili, Balu Santhanam, Majeed M. Hayat
2014 J jnl
IEEE Trans. Image Process.
Biliana S. Paskaleva, Sebastián E. Godoy, Woo-Yong Jang, Steven C. Bender, Sanjay Krishna, Majeed M. Hayat
2014 conf
OFC
Kaile Liang, Hao Bai, Mahshid Rahnamay-Naeini, Feng Xu, M. Batayneh, Majeed M. Hayat, Nasir Ghani
2014 J jnl
IEEE Trans. Geosci. Remote. Sens.
Qi Wang, Matthew Pepin, Aleck Wright, Ralf Dunkel, Tom Atwood, Balu Santhanam, Walter Gerstle, Armin W. Doerry, Majeed M. Hayat
2014 J jnl
IEEE Trans. Parallel Distributed Syst.
Jorge E. Pezoa, Majeed M. Hayat
2014 conf
CloudNet
Mahsa Pourvali, Hao Bai, Feng Gu, Khaled B. Shaban, Mahshid Rahnamay-Naeini, Jorge Crichigno, Majeed M. Hayat, Samee Ullah Khan, Nasir Ghani
2014 conf
OFC
Hao Bai, Feng Gu, Kaile Liang, Mahshid Rahnamay-Naeini, Samee Khan, Majeed M. Hayat, Nasir Ghani
2013 B conf
GLOBECOM
Mahshid Rahnamay-Naeini, Nasir Ghani, Majeed M. Hayat
2013 conf
GlobalSIP
Mahshid Rahnamay-Naeini, Majeed M. Hayat
2013 conf
SoSE
Feng Gu, Khaled B. Shaban, Nasir Ghani, Majeed M. Hayat, Chadi Assi
2012 conf
ACSCC
Qi Wang, Balu Santhanam, Matthew Pepin, Majeed M. Hayat
2012 J jnl
IEEE Trans. Parallel Distributed Syst.
Jorge E. Pezoa, Majeed M. Hayat
2012 B conf
ICIP
Qi Wang, Matthew Pepin, Ralf Dunkel, Tom Atwood, Armin W. Doerry, Balu Santhanam, Walter Gerstle, Majeed M. Hayat
2012 J jnl
IEEE Trans. Geosci. Remote. Sens.
Qi Wang, Matthew Pepin, Ryan J. Beach, Ralf Dunkel, Tom Atwood, Balu Santhanam, Walter Gerstle, Armin W. Doerry, Majeed M. Hayat
2011 conf
CDC/ECC
Zhuoyao Wang, Majeed M. Hayat, Mahshid Rahnamay-Naeini, Yasamin Mostofi, Jorge E. Pezoa
2011 C conf
IGARSS
Qi Wang, Matthew Pepin, Ryan J. Beach, Ralf Dunkel, Tom Atwood, Armin W. Doerry, Balu Santhanam, Walter Gerstle, Majeed M. Hayat
2011 B conf
ICCCN
Mahshid Rahnamay-Naeini, Jorge E. Pezoa, Ghady Azar, Nasir Ghani, Majeed M. Hayat
2010 C conf
IGARSS
Biliana S. Paskaleva, Majeed M. Hayat, Woo-Yong Jang, Yagya D. Sharma, Steven C. Bender, Sanjay Krishna
2010 J jnl
IEEE Trans. Parallel Distributed Syst.
Jorge E. Pezoa, Sagar Dhakal, Majeed M. Hayat
2010 B conf
ICPP
Jorge E. Pezoa, Majeed M. Hayat, Zhuoyao Wang, Sagar Dhakal
2009 J jnl
IEEE Trans. Commun.
Peng Sun, Majeed M. Hayat, Abhik K. Das
2009 conf
ICPP Workshops
Jorge E. Pezoa, Sagar Dhakal, Majeed M. Hayat
2008 conf
IGARSS (5)
Biliana S. Paskaleva, Majeed M. Hayat, Woo-Yong Jang, Sanjay Krishna
2008 J jnl
IEEE Trans. Geosci. Remote. Sens.
Biliana S. Paskaleva, Majeed M. Hayat, Zhipeng Wang, J. Scott Tyo, Sanjay Krishna
2008 J jnl
IEEE Trans. Control. Syst. Technol.
Zhong Tang, J. Douglas Birdwell, John N. Chiasson, Chaouki T. Abdallah, Majeed M. Hayat
2007 conf
ICASSP (3)
Sagar Dhakal, Jorge E. Pezoa, Majeed M. Hayat
2007 J jnl
IEEE Trans. Parallel Distributed Syst.
Sagar Dhakal, Majeed M. Hayat, Jorge E. Pezoa, Cundong Yang, David A. Bader
2006 J jnl
IEEE Commun. Lett.
Byonghyok Choi, Majeed M. Hayat
2006 A conf
IPDPS
Sagar Dhakal, Majeed M. Hayat, Jorge E. Pezoa, Chaouki T. Abdallah, J. Douglas Birdwell, John N. Chiasson
2006 C conf
ACC
J. Douglas Birdwell, Zhong Tang, John N. Chiasson, Chaouki T. Abdallah, Majeed M. Hayat
2005 J jnl
IEEE Commun. Lett.
Peng Sun, Majeed M. Hayat
2005 A conf
IPDPS
Stephen Pellicer, Yi Pan, P. Sun, Majeed M. Hayat
2005 C conf
ACC
Zhang Tang, John White, John N. Chiasson, J. Douglas Birdwell, Chaouki T. Abdallah, Majeed M. Hayat
2005 conf
COMPSAC (2)
J. Douglas Birdwell, John N. Chiasson, Chaouki T. Abdallah, Majeed M. Hayat, Zhong Tang, John White
2005 B conf
WCNC
Sagar Dhakal, Majeed M. Hayat, Mohammad Elyas, Jean Ghanem, Chaouki T. Abdallah
2005 B conf
SMC
Ousseini Lankoande, Majeed M. Hayat, Balu Santhanam
2005 conf
ICIP (3)
Ousseini Lankoande, Majeed M. Hayat, Balu Santhanam
2005 J jnl
IEEE Trans. Control. Syst. Technol.
John N. Chiasson, Zhong Tang, Jean Ghanem, Chaouki T. Abdallah, J. Douglas Birdwell, Majeed M. Hayat, Henry N. Jerez
2004 conf
CDC
Zhong Tang, J. Douglas Birdwell, John N. Chiasson, Chaouki T. Abdallah, Majeed M. Hayat
2004 conf
CDC
Jean Ghanem, Chaouki T. Abdallah, Majeed M. Hayat, Sagar Dhakal, J. Douglas Birdwell, John N. Chiasson, Zhong Tang
2004 J jnl
Concurr. Pract. Exp.
Yi Pan, Cos S. Ierotheou, Majeed M. Hayat
2003 conf
CDC
Sagar Dhakal, Biliana S. Paskaleva, Majeed M. Hayat, Edl Schamiloglu, Chaouki T. Abdallah
2002 J jnl
J. Electronic Imaging
Zikuan Chen, Mohammad A. Karim, Majeed M. Hayat
2002 J jnl
IEEE Trans. Image Process.
Majeed M. Hayat, M. Sajjad Abdullah, Adel Joobeur, Bahaa E. A. Saleh
2002 conf
ICPP Workshops
Yi Pan, Cos S. Ierotheou, Majeed M. Hayat
2001 J jnl
Pattern Recognit.
Zikuan Chen, Mohammad A. Karim, Majeed M. Hayat
2001 J jnl
IEEE Trans. Image Process.
Stephen C. Cain, Majeed M. Hayat, Ernest E. Armstrong
2000 J jnl
IEEE Trans. Inf. Theory
John A. Gubner, Wei-Bin Chang, Majeed M. Hayat
1999 J jnl
IEEE Trans. Inf. Theory
Majeed M. Hayat, John A. Gubner, Sajjad Abdullah
1996 J jnl
IEEE Signal Process. Lett.
John A. Gubner, Majeed M. Hayat
1996 J jnl
IEEE Trans. Neural Networks
Majeed M. Hayat, Bahaa E. A. Saleh, John A. Gubner
1995 J jnl
IEEE Trans. Commun.
Majeed M. Hayat, Bahaa E. A. Saleh, John A. Gubner
redb/extractors/ioc_extractor/ioc_extractor.py
← Index redb/extractors/ioc_extractor/ioc_extractor.py python
"""
IOC Extractor - Extractor class for extracting IOCs from decompilation results.

This extractor works with in-memory data from DecompileBinja, following the
standard Extractor pattern to support both ClickHouse and PrintExporter (dry-run).

Usage:
    # After DecompileBinja completes:
    ioc_extractor = IOCExtractorFromResults(
        analysis_results=decompiler.analysis_results,
        sha256=sha256,
        log=logger,
        exporters=exporters,
        index_prefix=index_prefix
    )
    ioc_extractor.export_data()
"""

import inspect
from datetime import datetime, timezone
from pathlib import Path
from typing import Any, List, Dict, Optional

from redb.extractors.enum import Tag
from redb.extractors.database_exporters import DatabaseExporter

# Import the IOCScraper and related classes from standalone module
from redb.extractors.ioc_extractor.standalone_ioc_extractor import (
    IOCScraper,
    IOCType,
    SourceType,
    ExtractedIOC,
)
from typing import Set


class IOCExtractorFromResults:
    """
    Extracts IOCs from in-memory decompilation results.

    This follows a simplified Extractor pattern but doesn't inherit from Extractor
    since it doesn't read from a binary file - instead it takes already-processed
    analysis results from DecompileBinja.
    """

    def __init__(
        self,
        analysis_results: Dict[str, Any],
        sha256: str,
        log: Any,
        exporters: Optional[List[DatabaseExporter]] = None,
        index_prefix: Optional[str] = None,
        tld_file: Optional[Path] = None,
        suppress_types: Optional[Set[IOCType]] = None,
        js_context: bool = False,
    ):
        """
        Initialize IOC Extractor with analysis results.

        Args:
            analysis_results: Dict containing 'strings' and 'decompiled' lists from DecompileBinja
            sha256: Sample SHA256 hash
            log: Logger instance
            exporters: List of database exporters (ClickHouse, Print, etc.)
            index_prefix: Index prefix for database
            tld_file: Optional path to TLD list file
            js_context: When True, the underlying IOCScraper rejects FQDN
                candidates that match JS object-access syntax (see
                JS_FP_TLDS / JS_FP_SLDS). Set this for the JS pipeline only;
                APK suppresses FQDN entirely via suppress_types and binary
                callers leave it disabled.
        """
        self.log = log
        self.log.debug(f"Creating {self.__class__.__name__}")
        self.analysis_results = analysis_results
        self.sha256 = sha256
        self.exporters = exporters or []
        self.index_prefix = index_prefix
        self.scraper = IOCScraper(
            tld_file, suppress_types=suppress_types, js_context=js_context,
        )
        self.extracted_iocs: List[ExtractedIOC] = []

    def extract(self) -> List[ExtractedIOC]:
        """
        Extract IOCs from strings and decompiled functions in analysis_results.

        Returns:
            List of ExtractedIOC objects
        """
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.extracted_iocs = []

        # Extract from strings
        strings_count = self._extract_from_strings()

        # Extract from decompiled functions
        functions_count = self._extract_from_decompiled()

        # Extract from text-based artefact surfaces (JS, PowerShell, etc.)
        text_count = self._extract_from_text()

        self.log.info(
            f"Extracted {len(self.extracted_iocs)} IOCs for {self.sha256[:16]}... "
            f"(strings: {strings_count}, functions: {functions_count}, "
            f"text: {text_count})"
        )

        return self.extracted_iocs

    def _extract_from_strings(self) -> int:
        """Extract IOCs from sample's strings."""
        count = 0
        strings = self.analysis_results.get("strings", [])

        for s in strings:
            string_value = s.get("string", "")
            string_offset = s.get("string_offset", 0)

            if isinstance(string_value, bytes):
                string_value = string_value.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(string_value, SourceType.STRING, str(string_offset)):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_decompiled(self) -> int:
        """Extract IOCs from sample's decompiled functions.

        Supports both Binja format (key: "decompiled", fields: "decompiled_function",
        "decompiled_function_hash", "function_type") and APK format (key:
        "decompiled_content", fields: "decompiled_method", "decompiled_method_hash",
        "method_type").
        """
        count = 0

        # Binja format
        decompiled = self.analysis_results.get("decompiled", [])
        for func in decompiled:
            func_type = func.get("function_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_function", "")
            func_hash = func.get("decompiled_function_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        # APK format (decompiled_content with method-level fields)
        decompiled_content = self.analysis_results.get("decompiled_content", [])
        for func in decompiled_content:
            func_type = func.get("method_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_method", "")
            func_hash = func.get("decompiled_method_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_text(self) -> int:
        """Extract IOCs from text-based artefact surfaces.

        Walks `analysis_results["text_raw"]` and `analysis_results["text_normalized"]`,
        each a list of `{"content": str, "content_hash": str}` dicts. Each
        list is routed through its own SourceType (`TEXT_RAW` /
        `TEXT_NORMALIZED`) so analysts can distinguish IOCs that were already
        present in the raw source from those exposed only after normalisation
        (deobfuscation/beautification). Generic across text-based formats —
        used by JS today, intended for PowerShell, Python, email body,
        extracted PDF/Office text in the future.
        """
        count = 0

        for key, source_type in (
            ("text_raw", SourceType.TEXT_RAW),
            ("text_normalized", SourceType.TEXT_NORMALIZED),
        ):
            for entry in self.analysis_results.get(key, []):
                content = entry.get("content", "")
                content_hash = entry.get("content_hash", "unknown")

                if isinstance(content, bytes):
                    content = content.decode('utf-8', errors='replace')

                for ioc in self.scraper.scrape(content, source_type, content_hash):
                    self.extracted_iocs.append(ioc)
                    count += 1

        return count

    def prepare_export_data(self, exporter_type: str) -> Any:
        """
        Prepare data for specific export type.

        Returns tuple for ClickHouse or list of dicts for Print/Elasticsearch.
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        if not self.extracted_iocs:
            return None

        now = datetime.now(timezone.utc)

        if exporter_type == "ClickHouseExporter":
            data = [
                [
                    self.sha256,
                    ioc.ioc_type.value,
                    ioc.ioc_value,
                    ioc.source_type.value,
                    ioc.source_identifier,
                    now,
                ]
                for ioc in self.extracted_iocs
            ]

            column_names = [
                "sha256",
                "ioc_type",
                "ioc_value",
                "source_type",
                "source_identifier",
                "extracted_at",
            ]

            column_type_names = [
                "FixedString(64)",
                "Enum8('ipv4'=1, 'ipv6'=2, 'fqdn'=3, 'url'=4, 'email'=5, 'server'=6, "
                "'hash_md5'=10, 'hash_sha1'=11, 'hash_sha256'=12, 'cve'=20, 'cwe'=21, 'cpe'=22, "
                "'crypto_btc'=30, 'crypto_eth'=31, 'crypto_xrp'=32, 'crypto_bch'=33, "
                "'crypto_ada'=34, 'crypto_substrate'=35, 'path_linux'=40, 'path_windows'=41, "
                "'registry_key'=42, 'onion'=50)",
                "String",
                "Enum8('decompiled_function'=1, 'disassembled_function'=2, 'string'=3, "
                "'text_raw'=4, 'text_normalized'=5)",
                "String",
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

        else:
            # For PrintExporter and others - return list of dicts
            return [
                {
                    "sha256": self.sha256,
                    "ioc_type": ioc.ioc_type.value,
                    "ioc_value": ioc.ioc_value,
                    "source_type": ioc.source_type.value,
                    "source_identifier": ioc.source_identifier,
                    "extracted_at": now.isoformat(),
                }
                for ioc in self.extracted_iocs
            ]

    def get_clickhouse_table(self) -> str:
        """Return the ClickHouse table name for IOCs."""
        return "redb_iocs"

    def tag(self) -> str:
        """Return the tag for this extractor."""
        return Tag.IOC.value if hasattr(Tag, 'IOC') else "ioc"

    def export_data(self) -> bool:
        """
        Export extracted IOCs to all configured exporters.

        Returns:
            True if export succeeded, False if failed, None if no data
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # First extract the IOCs
        extracted = self.extract()

        if not extracted:
            self.log.debug("No IOCs extracted, skipping export")
            return None

        success = True

        from redb.extractors.database_exporters import PrintExporter, ClickHouseExporter

        for exporter in self.exporters:
            try:
                if isinstance(exporter, PrintExporter):
                    # For PrintExporter, pass the list of dicts
                    export_data = self.prepare_export_data("PrintExporter")
                    success &= exporter.export(export_data)

                elif isinstance(exporter, ClickHouseExporter):
                    # For ClickHouse, pass tuple with table info
                    export_data = self.prepare_export_data("ClickHouseExporter")
                    if export_data:
                        success &= exporter.export(
                            export_data,
                            table=self.get_clickhouse_table(),
                            column_names=export_data[1],
                            column_type_names=export_data[2]
                        )

            except Exception as e:
                self.log.error(f"Error exporting IOCs to {exporter.__class__.__name__}: {e}")
                success = False

        return success