Man-Ki Yoon

39 papers A* 4A 11B 4Misc 2Journal 13Unranked 4
YearRankTypeTitle / Venue / Authors
2026 J jnl
CoRR
Richard Habeeb, Man-Ki Yoon, Hao Chen, Zhong Shao
2025 Misc conf
SEC
Yuheng Zhu, Man-Ki Yoon
2025 A conf
ACSAC
Richard Habeeb, Hao Chen, Man-Ki Yoon, Zhong Shao
2024 conf
VTC Fall
Yuheng Zhu, Dhruva Ungrupulithaya, Boluo Ge, Man-Ki Yoon
2024 B conf
TrustCom
Youbin Kim, Man-Ki Yoon
2023 A conf
ICDCS
Man-Ki Yoon
2022 J jnl
Proc. ACM Program. Lang.
Mengqi Liu, Zhong Shao, Hao Chen, Man-Ki Yoon, Jung-Eun Kim
2022 A conf
DSN
Man-Ki Yoon, Jung-Eun Kim, Richard M. Bradford, Zhong Shao
2021 A* conf
USENIX Security Symposium
Man-Ki Yoon, Mengqi Liu, Hao Chen, Jung-Eun Kim, Zhong Shao
2020 A conf
DATE
Jung-Eun Kim, Richard M. Bradford, Man-Ki Yoon, Zhong Shao
2020 A* conf
ICRA
Valerie Chen, Man-Ki Yoon, Zhong Shao
2020 J jnl
Proc. ACM Program. Lang.
Mengqi Liu, Lionel Rieg, Zhong Shao, Ronghui Gu, David Costanzo, Jung-Eun Kim, Man-Ki Yoon
2019 A conf
ICDCS
Man-Ki Yoon, Zhong Shao
2019 J jnl
IEEE Internet Things J.
Kyungtae Kang, Insup Lee, Kai Liu, Man-Ki Yoon, Kyung-Joon Park
2019 conf
DSN Workshops
Valerie Chen, Man-Ki Yoon, Zhong Shao
2019 J jnl
CoRR
Valerie Chen, Man-Ki Yoon, Zhong Shao
2019 J jnl
CoRR
Man-Ki Yoon, Jung-Eun Kim, Richard M. Bradford, Zhong Shao
2017 J jnl
CoRR
Chien-Ying Chen, AmirEmad Ghassami, Sibin Mohan, Negar Kiyavash, Rakesh B. Bobba, Rodolfo Pellizzoni, Man-Ki Yoon
2017 J jnl
CoRR
Subin Yi, Janghoon Ju, Man-Ki Yoon, Jaesik Choi
2017 conf
IoTDI
Man-Ki Yoon, Sibin Mohan, Jaesik Choi, Mihai Christodorescu, Lui Sha
2017
Man-Ki Yoon
2017 conf
ICCPS
Man-Ki Yoon, Bo Liu, Naira Hovakimyan, Lui Sha
2016 J jnl
Real Time Syst.
Sibin Mohan, Man-Ki Yoon, Rodolfo Pellizzoni, Rakesh B. Bobba
2016 A* conf
ASPLOS
Man-Ki Yoon, Negin Salajegheh, Yin Chen, Mihai Christodorescu
2016 J jnl
Computer
Lui Sha, Marco Caccamo, Renato Mancuso, Jung-Eun Kim, Man-Ki Yoon, Rodolfo Pellizzoni, Heechul Yun, Russell Kegley, Dennis R. Perlman, Greg Arundale, Richard M. Bradford
2016 A conf
RTAS
Man-Ki Yoon, Sibin Mohan, Chien-Ying Chen, Lui Sha
2016 Misc conf
SYSTOR
Man-Ki Yoon, Mihai Christodorescu, Lui Sha, Sibin Mohan
2015 A conf
RTAS
Rodolfo Pellizzoni, Neda Paryab, Man-Ki Yoon, Stanley Bak, Sibin Mohan, Rakesh Bobba
2015 J jnl
CoRR
Man-Ki Yoon, Sibin Mohan, Jaesik Choi, Mihai Christodorescu, Lui Sha
2015 A* conf
DAC
Man-Ki Yoon, Lui Sha, Sibin Mohan, Jaesik Choi
2014 B conf
COMPSAC
Jung-Eun Kim, Man-Ki Yoon, Richard M. Bradford, Lui Sha
2014 B conf
ECRTS
Sibin Mohan, Man-Ki Yoon, Rodolfo Pellizzoni, Rakesh Bobba
2013 A conf
DATE
Man-Ki Yoon, Jung-Eun Kim, Richard M. Bradford, Lui Sha
2013 A conf
DATE
Jung-Eun Kim, Man-Ki Yoon, Sungjin Im, Richard M. Bradford, Lui Sha
2013 A conf
IEEE Real-Time and Embedded Technology and Applications Symposium
Man-Ki Yoon, Sibin Mohan, Jaesik Choi, Jung-Eun Kim, Lui Sha
2011 A conf
RTSS
Man-Ki Yoon, Jung-Eun Kim, Lui Sha
2010 J jnl
IEEE Trans. Computers
Man-Ki Yoon, Chang-Gun Lee, Junghee Han
2008 J jnl
IEEE Trans. Computers
Min-Young Nam, Mhd. Zaher Al-Sabbagh, Jung-Eun Kim, Man-Ki Yoon, Chang-Gun Lee, Eun Yong Ha
2008 B conf
DCOSS
Jung-Eun Kim, Man-Ki Yoon, Junghee Han, Chang-Gun Lee
redb/extractors/decompiler/_archive/DecompileGhidra-old.py
← Index redb/extractors/decompiler/_archive/DecompileGhidra-old.py python
from hashlib import sha256
import inspect
from pathlib import Path
import subprocess
import json
import subprocess
import json
import os
import tempfile
import uuid
import shutil
import time

from dotenv import load_dotenv

from redb.extractors.enum import Tag
from redb.models.dataclasses import Decompiled
from redb.extractors.extractor import Extractor


class DecompileGhidra(Extractor):
    def __init__(
        self,
        filepath,
        log,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
    ):
        super().__init__(
            filepath, log, index_prefix, elastic_index, known_benign, known_malicious
        )
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.elastic_index = self.index_prefix + "-ghidra"
        self.ghidra_path = "/opt/ghidra"
        self.java_script_path = (
            self.ghidra_path
            + "/Ghidra/Features/Base/ghidra_scripts/GhidraDecompilerScript.java"
        )
        self.decompiled = None
        load_dotenv()
        self.decompiled_folder = os.getenv("DECOMPILED_FOLDER", "/opt/decompiled")
        self.log.debug(f"Decompiled folder: {self.decompiled_folder}")

    def run_command(self, cmd, env=None):
        try:
            self.log.info(f"Starting command: {' '.join(cmd)}")
            start_time = time.time()
            TIMEOUT = 1200  # 20 minutes in seconds
            process = subprocess.Popen(
                cmd, env=env, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True
            )

            while True:
                output = process.stdout.readline()
                if output:
                    print(output.strip())
                if process.poll() is not None:
                    break
            try:
                stdout, stderr = process.communicate(timeout=TIMEOUT)
            except subprocess.TimeoutExpired:
                process.kill()
                self.log.error(f"Ghidra timed out after {TIMEOUT} seconds")
                # raise subprocess.TimeoutExpired(process.args, TIMEOUT)
                return None
            end_time = time.time()

            self.log.debug(
                f"Command finished. Execution time: {end_time - start_time:.2f} seconds"
            )
            self.log.debug(f"Return code: {process.returncode}")

            if process.returncode != 0:
                self.log.error(f"Error output:\n{stderr}")
                return None
            return stdout
        except Exception as e:
            self.log.error(f"Error running command {' '.join(cmd)}: {e}")
            return None

    def analyze_binary(self):
        self.log.debug(f"Ghidra path: {self.ghidra_path}")
        self.log.debug(f"Binary path: {self.filepath}")
        self.log.debug(f"Java script path: {self.java_script_path}")

        # Check if Java script exists
        if not os.path.exists(self.java_script_path):
            self.log.error(f"Error: Java script not found at {self.java_script_path}")
            return None

        # Set up environment variables
        env = os.environ.copy()
        java_home = "/usr/lib/jvm/java-17-openjdk-amd64"  # Adjust this path if needed
        env["JAVA_HOME"] = java_home
        env["PATH"] = f"{java_home}/bin:{env['PATH']}"
        env["LD_LIBRARY_PATH"] = f"{java_home}/lib:{env.get('LD_LIBRARY_PATH', '')}"
        env["DECOMPILED_FOLDER"] = self.decompiled_folder

        # Print environment variables for debugging
        self.log.debug(f"JAVA_HOME: {env['JAVA_HOME']}")
        self.log.debug(f"PATH: {env['PATH']}")
        self.log.debug(f"LD_LIBRARY_PATH: {env['LD_LIBRARY_PATH']}")

        # Check Ghidra installation
        analyzeHeadless_path = f"{self.ghidra_path}/support/analyzeHeadless"
        self.log.debug(
            f"analyzeHeadless exists: {os.path.exists(analyzeHeadless_path)}"
        )

        # Create a temporary project directory
        project_path = tempfile.gettempdir() + "/ghidra_" + str(uuid.uuid4())
        os.makedirs(project_path, exist_ok=True)
        self.log.debug(f"Created temporary project path: {project_path}")
        output_file = ""

        try:
            # Run Ghidra's headless analyzer
            analyze_cmd = [
                analyzeHeadless_path,
                project_path,
                "TempProject",
                "-import",
                self.filepath,
                "-postScript",
                self.java_script_path,
                self.sha256,
                "-deleteProject",
            ]

            result = self.run_command(analyze_cmd, env=env)
            if result is None:
                return None

            # Read the output JSON file
            output_file = os.path.join(
                self.decompiled_folder, self.sha256 + "-decompiled.json"
            )
            if os.path.exists(output_file):
                with open(output_file, "r") as f:
                    functions = json.load(f)
                return functions
            else:
                self.log.error(
                    f"Output file {output_file} not found. Ghidra analysis may have failed."
                )
                return None
        finally:
            # Clean up
            if os.path.exists(project_path):
                shutil.rmtree(project_path)
                self.log.debug(f"Deleted temporary project path: {project_path}")

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            functions = self.analyze_binary()

            if functions:
                self.log.info(f"Extracted functions from {self.filepath}:")
                for func in functions:
                    id = sha256(func["address"].encode()).hexdigest()
                    self.decompiled = Decompiled(
                        _id=id,
                        decompiled_function_name=func["name"],
                        decompiled_function_address=func["address"],
                        decompiled_function=func["decompiled"],
                    )
                    self.export_to_elastic([self.decompiled])
            else:
                self.log.error("No decompiled functions extracted.")
            return True
        except Exception as e:
            self.log.error(f"Error extracting decompiled information: {e}")
            return None

    def tag(self):
        return Tag.DECOMPILED.value