Malik Shahzad Kaleem Awan

19 papers B 2C 2Journal 3Unranked 11
YearRankTypeTitle / Venue / Authors
2025 conf
BCCA
Malik Shahzad Kaleem Awan, Vincent A. Knight, Omer Rana, Pete Burnap
2016 J jnl
Comput. Secur.
Malik Shahzad Kaleem Awan, Pete Burnap, Omer F. Rana
2015 conf
CIT/IUCC/DASC/PICom
Malik Shahzad Kaleem Awan, Pete Burnap, Omer F. Rana
2015 conf
HPCC/CSS/ICESS
Malik Shahzad Kaleem Awan, Pete Burnap, Omer F. Rana, Amir Javed
2015 conf
SafeConfig@CCS
Malik Shahzad Kaleem Awan, Pete Burnap, Omer F. Rana
2015 B conf
ASONAM
Pete Burnap, Amir Javed, Omer F. Rana, Malik Shahzad Kaleem Awan
2013 conf
HPCS
Malik Shahzad Kaleem Awan, Stephen A. Jarvis
2013 B conf
EC-TEL
Lei Shi, Malik Shahzad Kaleem Awan, Alexandra I. Cristea
2013 conf
ICCSW
Lei Shi, Malik Shahzad Kaleem Awan, Alexandra I. Cristea
2013
Malik Shahzad Kaleem Awan
2013 conf
AMCIS
Lei Shi, Alexandra I. Cristea, Malik Shahzad Kaleem Awan, Craig D. Stewart, Maurice Hendrix
2012 conf
HPCC-ICESS
Malik Shahzad Kaleem Awan, Stephen A. Jarvis
2012 conf
HPCS
Malik Shahzad Kaleem Awan, Stephen A. Jarvis
2011 J jnl
Expert Syst. Appl.
Mian M. Awais, Malik Shahzad Kaleem Awan
2011 J jnl
Appl. Soft Comput.
Malik Shahzad Kaleem Awan, Mian M. Awais
2010 C conf
CIT
Malik Shahzad Kaleem Awan, Stephen A. Jarvis
2008 conf
ECBS
Malik Shahzad Kaleem Awan, Mian M. Awais
2007 C conf
AICCSA
Malik Shahzad Kaleem Awan, Mian M. Awais
2007 conf
IAT
Malik Shahzad Kaleem Awan, Mian M. Awais
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"